Live data from Hacker News

FSF announces Librephone project

fsf.org

121–130 of 669 posts

Re: FSF announces Librephone project

#121
post #116
post #106

Earlier quoted context omitted.

There is one solution to this problem that many people reading this message can contribute to: Make sure your app has a progressive web app version that has feature parity with the store apps. That way, the app will work on phones like the librephone, and, if Apple or Google decide to kick you off the store, you and your users have some recourse. As a bonus, it’s compatible with open source — users can modify the app…

...and packaging my app as a PWA is going to help with cantankerous bank/ditigal-id apps, how, exactly?

Momentum.

Re: FSF announces Librephone project

#123
post #3

> Practically, Librephone aims to close the last gaps between existing distributions of the Android operating system and software freedom. The FSF has hired experienced developer Rob Savoye (DejaGNU, Gnash, OpenStreetMap, and more) to lead the technical project. He is currently investigating the state of device firmware and binary blobs in other mobile phone freedom projects, prioritizing the free software work done…

The time is right, but I still don’t think this project can accomplish much because people are generally happy with their phones.

That said, the phone market is huge. They could sell enough devices to fund future development which might be good enough even if it doesn’t slow down Apple or Google. At least then there will be a device for those of us who are not happy with the state of things.

Re: FSF announces Librephone project

#124

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

> What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS?

Log in to your bank over the internet, the normal way.

Re: FSF announces Librephone project

#125

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

Yeah... Corporations and governments are starting to push remote attestation. There'll be little point to a free computer if it gets us denied service everywhere. At this point we're gonna end up marginalized, like second class citizens of society.

Re: FSF announces Librephone project

#126
post #6
post #5

Earlier quoted context omitted.

It becomes much harder to force attestation on people if there's a significant user base that runs alternative operating systems.

Do you really NEED to be forced to attest if you can make your phone look like any damn PC using a browser?

My bank doesn't let me do anything in the browser without 2FA, and the only 2FA they offer is their smartphone app.

My other bank offers 2FA via chip reader as an alternative. I guess that's somewhat viable for an alternative phone OS, if you want to carry the reader around with you

That might just be European banks though

Re: FSF announces Librephone project

#127

Earlier quoted context omitted.

> But it does highlight the poor security of desktop browsers where they are only trusted to do anything when a phone app approves it. Does it? The browser doesn't do anything, the person sitting at the computer where the browser is running is what performs the actions. The reauthentication and 2fa is meant to authenticate and authorize the user, not the browser. The attack vector of someone else using your phone usi…

That is true. I guess one of the main differences is the bank app can run a faceid check when you open the app and before you make a transaction while websites don't have access to these apis. So they are forced to make you approve the action via your phone.

Every banking phone app I've used auto-logouts after being idle or unused for a bit, and my primary bank's app requires 2fa using an app that exists on the same device -- a second factor that secures nothing. They probably are not explicitly considering the phone more secure than a computer, but rather a good 80% of this is security theater or a checkbox on some baseline security checklist that was implemented without really understanding what the implications, for usability and security, were going to be.

Re: FSF announces Librephone project

#128
post #119

Earlier quoted context omitted.

This is the big barrier here, and unfortunately, it is legally impossible to open source. In most countries, the spectrum that cell phone carriers use is licensed to the carrier, under the condition they only connect devices that are guaranteed to comply with the requirements of using that spectrum. The end user (i.e. the person with the phone) has no license to use the spectrum. So in order to get regulatory certifi…

theoretically, there is lte cbrs where spectrum not licensed.

[deleted]

Re: FSF announces Librephone project

#129
post #119

Earlier quoted context omitted.

This is the big barrier here, and unfortunately, it is legally impossible to open source. In most countries, the spectrum that cell phone carriers use is licensed to the carrier, under the condition they only connect devices that are guaranteed to comply with the requirements of using that spectrum. The end user (i.e. the person with the phone) has no license to use the spectrum. So in order to get regulatory certifi…

theoretically, there is lte cbrs where spectrum not licensed.

[deleted]

Re: FSF announces Librephone project

#130

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

Yeah... Corporations and governments are starting to push remote attestation. There'll be little point to a free computer if it gets us denied service everywhere. At this point we're gonna end up marginalized, like second class citizens of society.

> There'll be little point to a free computer if it gets us denied service everywhere. At this point we're gonna end up marginalized, like second class citizens of society.

Given the apparent trajectory of the corporate/government model of organizing society, it seems like they're going to be the ones that will be second-class citizens.

Post reply on HN