Live data from Hacker News

FSF announces Librephone project

fsf.org

81–90 of 669 posts

Re: FSF announces Librephone project

#81

Earlier quoted context omitted.

That… seems reasonable? My bank does that with their website and their mobile app. I was able to setup 2fa using a totp app, so i don’t rely on sms for that part

It is given the environment. But it does highlight the poor security of desktop browsers where they are only trusted to do anything when a phone app approves it. While the phone app is considered secure enough to just stay logged in perpetually without any external confirmation. To hack the banks app you have to find an exploit in iOS or Android which would allow you to read the other apps private storage, which is b…

> But it does highlight the poor security of desktop browsers where they are only trusted to do anything when a phone app approves it.

Does it? The browser doesn't do anything, the person sitting at the computer where the browser is running is what performs the actions. The reauthentication and 2fa is meant to authenticate and authorize the user, not the browser.

The attack vector of someone else using your phone using an app that doesn't require (re)authentication is independent of the browser or the app itself being trusted. That your bank doesn't periodically require some kind of re-authentication for their app is a security hole, but because the device could fall into the wrong hands, not because the code/app/browser used to access it isn't trusted.

Re: FSF announces Librephone project

#82
post #35

>Librephone aims to close the last gaps between existing distributions of the Android operating system and software freedom I am so happy they are focusing on Android, one of the most popular operating systems widely used by every day people. This is important work for providing user friendly, free software to users. Let's just hope they don't fall into the trap of disqualifying binary blobs sent as part of drivers v…

Are you hoping the Free Software Foundation _doesn't_ prioritize Free Software ? For people who are okay with random bits of proprietary software doing who-knows-what on their devices there are various alternatives already.

I initially made the same misread that you did...

The OP's point is, having the firmware permanently burnt-in on a ROM chip vs loaded as a binary blob via a driver doesn't change the "non-free"-ness of the firmware itself.

So opting for hardware which has a "fully-open-source" driver, but runs a binary blob encoded into the hardware, doesn't make the system fully open.

It's a take for a more Free system, not for accepting binary blobs.

(Or I guess for acknowledging that if you're willing to allow binary blobs stored in hardware, then dynamically-loaded binary blobs doesn't change the "free"-ness.)

Re: FSF announces Librephone project

#83
post #38

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

I hope all the things you mention never become mandatory some day because I currently use my phone for voice and text only. Sooner than later I plan to get rid of my phone all together. I'm gonna surprise the phone company and get a land line. That means any online service that uses SMS/text to verify me will fail.

If you're being serious, you're in for a rude awakening. POTS lines are dead and being replaced with VOIP and VoIP to pots modems on the premise. lots of cities have already started to grub the copper out and replaced it a long time ago with fiber.

Re: FSF announces Librephone project

#85

https://librephone.fsf.org/FAQ.html Currently scope only seems to go as far as the operating system

That's really as far as they need to go; if the userland is compatible with Linux, it can use all of the work that KDE and other organizations have put into building mobile interfaces. These projects have stuff that works, but the lack of firmware for chips that can connect to modern cell infrastructure means that they can't really create an appealing product. The OS layer is where all previous Linux phone efforts ha…

> The OS layer is where all previous Linux phone efforts have failed

The OS layer is where the existing projects are thriving, with various distros and shells to choose from to match one's needs and tastes. It's the appropriate hardware that's in undersupply. I'm using a Librem 5, a 2019 design, and if I wanted to switch to something newer I can't because there's no viable upgrade path on the market. No other hardware vendor has invested significant resources into mobile GNU/Linux since then, everything else is either purely community-based or uses Halium.

Re: FSF announces Librephone project

#86

Earlier quoted context omitted.

I can’t tap my PC to buy a burrito at Chipotle.

So you pay more money and also give up your privacy for what you could pay cash for. I don't think you're the target market for this phone.

I pay less money for my burrito than I would with cash, but the reason I use my phone is convenience, not cost.

> I don't think you're the target market for this phone.

My comment is downstream of the entertaining of a possibility of:

> a significant user base that runs alternative operating systems

... which isn't going to happen if you ask your users to give up commonly used features. It will forever be a niche project, at best.

Re: FSF announces Librephone project

#87
post #41

Earlier quoted context omitted.

Use the website. I’ve never seen a bank where a mobile app is the only option for remote access. If my bank did that, I’d switch banks.

UBS bank mandates their "Secure Access" app as second factor even when logging in from a desktop. They used to allow the smart card reader for existing customers that had it as a work around for a few years but they disabled that. Also many websites are making it remarkably hard to not use the app if they even remotely sense you're not on an actual PC. FB and LinkedIn aren't banks but prime examples.

Good reason to stop using that bank.

I like my credit union.

Re: FSF announces Librephone project

#88
The phone is the critical root identity anchor for most of the world now. And many countries outside of the west has already made the Sim card a root identity. Additionally to make it trustworthy (think Google wallet and digital wallets and so on) to work they cannot trust the end user because effectively you the user don't own your own identity. So that's why the phone has to be proprietary - so that it's secure element can be trusted in interactions with the state-big-tech nexus. I talked about my experience with this while attempting to cross borders in SEA. https://polykey.com/blog/architecting-anti-fragile-trust-at-...

Re: FSF announces Librephone project

#90

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

Indeed, binary blobs are not much of a problem; it's anti-user "security" that has to be attacked. Otherwise we'll end up with user-hostile systems that we can see the source code of but can't modify, in contrast to systems that we can't see the source code of but can modify. The Windows modding scene of the late 90s/early 2000s is a good example of the latter (and I've joked that every power user was a novice reverse-engineer), while Android is turning out to be a good example of the former.

Stallman had a good idea for free (as in freedom) software, but then "missed the forest for the trees" by focusing on the source code.

Post reply on HN