Live data from Hacker News

The Framework Laptop Chromebook Edition

frame.work

441–450 of 476 posts

Re: The Framework Laptop Chromebook Edition

#441

Earlier quoted context omitted.

I'm a fan of Linux and a fan of ChromeOS. but are the user experience and security better on ChromeOS than Linux? It's a bit simpler than linux but I'd say Linux is a close second.

I can't hand my non-technical family member a Linux device and expect it still work a week later without any intervention.

I installed Linux to a number of people, mostly over 50, some over 70. All of them but one kept using it, and the one who went back to Windows was forced because of an application he had at work whose copy protection made it impossible to run it under WINE. That was some years ago, with Linux desktop less advanced than it is now, and before the Windows GUI experience reached its lowest with Win 8 and beyond.

If you spend some time configuring the OS, Linux is actually much easier and safe to use than Windows for a series of often overlooked reasons:

1- Application installation and removal is centralized: you fire up the distribution package manager and can install almost all software, including lots of 3rd party, using the same interface; no need to wander around the net with the risk of landing on a malicious page disguised as a download site.

2- Drivers are built at kernel level and nearly all of them are already included: if you buy a new device, chances are that besides not having to insert any drivers CD, they are already included in the distribution.

3- Hardware support doesn't come with added bloatware: say, you connect the new printer and can safely ignore the accompanying CD or their manufacturer's site downloads, which usually will attempt to make you download crippled version of commercial products and other junk along the drivers. Under Linux you use the supplied applications with all hardware of that class.

etc.

Some 20 years ago I was working at a company operating in the sports betting field; we had abut 50 points of sale deployed all over the country and my assignment was to find a way to allow each remote point of sale to work in the safest possible way, no distractions and including remote support on demand. All of this of course in the cheapest possible way. The best thing about working in a small company is that sometimes you can earn the freedom of choosing the rope to hang yourself with: I'm not interested in the betting world, but that problem was intriguing, and I had carte blanche. The solution I came up with after some fiddling was a RedHat distro plus WindowMaker "desktop" with a restricted launcher whose dockapps allowed the operator to check/write emails, file for a remote support connection, open StarOffice and a couple other things I don't recall. The system was essentially in kiosk mode, with the browser set so that it would open fullscreen to operate only on the company webpage. I had to write the scripts to file for remote support since all the points of sale had dynamic IPs which could change by the time we could reach them, therefore the connection had to be the other way around. I solved this by using a remote "pinger" written in Ruby that would periodically send some data about the remote station, so we immediately had the who+where data pair, and a receiving Ruby application on our side would populate a GTK list (I used Glade and Anjuta iirc) with the stations that asked for intervention. As soon as a local operator clicked on one element, a reverse ssh tunnel was opened and we had the remote shell ready. To my memory that contraption never failed; with very slow connections (~2002, so 1 Mbit down/ 128Kbit up when we were lucky) luxuries such as VNC were out of question. 50 points of sales could be easily managed by a single operator.

Of course I'm not suggesting to turn every Linux PC in a tight closed terminal that does 3 things only. My point is that you can effectively turn a Linux desktop into something that non tech people can work without troubles, but that doesn't come out of the box, as it doesn't with Windows: you can have everything from a dumbed down terminal that couldn't be crashed by a colony of cats walking on the keyboard for a week, to something so advanced and full of knobs that you can literally do everything, including shooting yourself in the foot. Some work is needed though.

Re: The Framework Laptop Chromebook Edition

#442
post #326

Earlier quoted context omitted.

The other guy is arguing that you don't have to accept that risk at all if you don't use an OS from a data harvesting company. I don't care who watches me through my camera, I was just trying to point out that people aren't stupid about the hardware switch. Some just find it ironic that there is a hardware shut off for a camera on a computer operated by Google.

Apple, Microsoft and Google are all data harvesting companies. And any other OS, including Linux, can have spyware, rootkits or other malicious software installed all the way down to the BIOS. If you want privacy when around an internet-connected camera and microphone there is no substitute for a hardware switch.

Again, the discussion is about camera security at all times, not just when you're not using it.

I think regardless of the fact that it is technically possible with any hardware and any operating system, it is difficult to argue that the risk is the same on Linux as it is on windows or ChromeOS.

I doubt ChromeOS or windows are spying on you through your camera either when you are or are not using it, but people can be sure their Linux distro isn't.

Re: The Framework Laptop Chromebook Edition

#443
post #2

I'm happy to answer questions anyone has on this product!

First of all I'm very much on board with ideas behind framework laptop. Thanks for your work :-) Is there any roadmap for wider distribution in Europe? Especially eastern part.

it's not a real solution, but one can always use a forwarder to ship it from the US (that's what I did)

Re: The Framework Laptop Chromebook Edition

#444

Earlier quoted context omitted.

This is actually the first I’m hearing of Chrome OS supporting Linux apps out of the box. I always dismissed Chrome OS as a glorified iPad or Android tablet with a keyboard and desktop. I’m mostly happy with my Linux-based HP dev one, but this is causing me to seriously consider a Chromebook (like this Framework variant) next upgrade.

To be clear on what you're getting: It runs a (Linux) VM and you get root on (a container on) that VM. Not trying to rain on your parade (because it's really quite useful!) but it's limited in what it can do. (eg it can't change the host's wifi MAC address.) Chromebooks have easy access to developer mode which gives you root access to the host OS though, so it's kinda moot.

Thanks for the detailed description. Might still consider it, or at least look for a cheaper Chromebook just to play around with and get a feel first.

At any rate, Chromebooks sound more capable than I previously gave them credit for, enough so that they will now be part of my evaluation next time I upgrade.

Between the Framework Laptop now supporting Chrome OS and some of the info in this thread, Chromebooks and Chrome OS no longer seem like just the cheap Google Docs appliances for schools that I originally thought they were, which is pretty cool.

Re: The Framework Laptop Chromebook Edition

#445
post #381

Earlier quoted context omitted.

If an oven leaked a lot of pm2.5 or Carbon Monoxide and it happened to still be legal, it would still be an ethical obligation for someone that is aware of these issues to recommend against that oven even if someone just wants the cheap/easy option and does not comprehend the risks. Those that can comprehend significant technical risks are obligated to recommend a low-risk strategy until people have enough relevant u…

I agree with most of what you said. I think privacy is important and it is important to educate people on these issues. I just think that say a grocery store worker that just wants to get the bills paid for next month and enjoy life a little has a different set of priorities than a tech worker making > 60,000 USD. There are more people like that in the United States than tech workers.

Sire. It is on tech workers to not exploit everyone else that does not understand the dangers.

Re: The Framework Laptop Chromebook Edition

#446
post #445

Earlier quoted context omitted.

I agree with most of what you said. I think privacy is important and it is important to educate people on these issues. I just think that say a grocery store worker that just wants to get the bills paid for next month and enjoy life a little has a different set of priorities than a tech worker making > 60,000 USD. There are more people like that in the United States than tech workers.

Sire. It is on tech workers to not exploit everyone else that does not understand the dangers.

I agree.

Re: The Framework Laptop Chromebook Edition

#447
post #162

Earlier quoted context omitted.

Yes they also don't protect you from car accidents or heart disease. What's your point? The purpose of a privacy switch is to make sure that Google (or anyone else, including hackers) isn't spying on you through your camera or microphone. This one accomplishes exactly that.

How will the switch protect me if I'm in a video call with my SO? I can trust a Linux system. A system running Google adware (some even call it spyware), not so much.

Never transmit onto the internet anything that would ruin your life if it became public, that's my motto. Regardless of how safe the transmission is in theory.

Re: The Framework Laptop Chromebook Edition

#449

Earlier quoted context omitted.

Would you be at all concerned about the security and privacy of your guest user’s data, given your employer’s propensity for slurping up and storing whatever user data they can get their hands on? What if your guest user was searching for terms related to abortion in a US state where that procedure is (or will shortly be) illegal? What if they’re doing that and you happen to be physically near a provider of abortions…

The host operating system does not give me more or less confidence in the security of a guest user’s web browsing data.

Then you are either uninformed or willfully ignorant of 1) how operating systems and browsers work and 2) your employer's past actions relating to collecting and storing user data.

Re: The Framework Laptop Chromebook Edition

#450

Earlier quoted context omitted.

I guess in practice this doesn't come up often. but it's a powerful testament to your confidence in ChromeOS' security. You are implying that you don't feel the same way about a Linux user guest login. But why? What additional security measures are present in ChromeOS that are missing from popular Linux distros? I don't doubt the features are there, I'm genuinely curious what they are.

You can harden and configure a Linux system to have many of the ChromeOS security features, but ChromeOS has all of these enabled by default: - All user data is encrypted at the login level. A guest user cannot access any other users’ data. Whereas in Ubuntu, for example, home directories have 755 permissions. - The Linux userspace in ChromeOS is actually running on KVM, so ChromeOS itself is insulated from user-inst…

What if the attacker is the one who built and shipped the OS to begin with? Everything you say is true, but it doesn't matter as long as user data (history, location, etc) is being shipped off to Google.

Or, put another way: your threat model is a nefarious hacker or three-letter-agency who might secretly modify your hardware/software to get your data. Mine is surveillance capitalism. ChromeOS is secure under your threat model, but is _built by the attacker_ under mine.

Both of these threat models are important to consider, but one is much more relevant to a larger portion of the population than the other.

Post reply on HN