Earlier quoted context omitted.
No software is "easy to inspect". Only a tiny fraction of users will ever even try. When things are inspected and problems are found, you need a way to revoke the malicious bits. You'll never notify everyone, which is one of the roles app stores play. You trust hardware and software by establishing boundaries. We figured this out long ago with the kernel mode/user mode privilege check and other things. You want apps…
> The banks - who are generally on the hook if something goes wrong, or at least have to pay a lot of lawyers to get off the hook - are not interested in moral arguments, they want a risk-reduced environment or no app for you - as is their right. If they pay for the phone and ship it to you then I agree. Otherwise, they have an obligation to serve their community (part of their banking charter) and that may include m…
FSF announces Librephone project
201–210 of 669 posts
Re: FSF announces Librephone project
#202Re: FSF announces Librephone project
#203Earlier quoted context omitted.
The time is right, but I still don’t think this project can accomplish much because people are generally happy with their phones. That said, the phone market is huge. They could sell enough devices to fund future development which might be good enough even if it doesn’t slow down Apple or Google. At least then there will be a device for those of us who are not happy with the state of things.
> The time is right, but I still don’t think this project can accomplish much because people are generally happy with their phones. Is there survey data available on this? Anecdotally, everybody I know hates their phones. In fact, I think if you asked, "what's the biggest pain point in your life right now?" I think most people will point to their phones.
If you asked normal average people "what's the biggest pain point in your life right now?" they would point to financial, societal, or health issues.
The vast majority of people when asked specifically about their phones probably wish that they were a newer model or had a longer battery life. As long as it communicates with people, lets them access banking and social media, and has a few of their niche hobby/entertainment apps nobody actually cares about the licensing of the modem firmware or the fact you can't install TempleOS on it.
Re: FSF announces Librephone project
#204Re: FSF announces Librephone project
#205Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…
Indeed, binary blobs are not much of a problem; it's anti-user "security" that has to be attacked. Otherwise we'll end up with user-hostile systems that we can see the source code of but can't modify, in contrast to systems that we can't see the source code of but can modify. The Windows modding scene of the late 90s/early 2000s is a good example of the latter (and I've joked that every power user was a novice revers…
RMS is afraid of trees!
Re: FSF announces Librephone project
#206Earlier quoted context omitted.
Not really. If their security depends on enslaving the user, their security sucks. Real security, be it your financial transactions or keeping your bird pictures safe, doesn't depend on any secret algorithm. Because it's secure.
The threat models aren't secret algorithms, they're apps reading the contents of the screen, stealing keystrokes, MITM attacks against 2FA, and much more.
I don't have this problem on my computers, they run free software. My wifes thinkpad runs free software. The friends I gave a computer with various GNU+Linux distros don't have this problem.
Add Google Chrome with its spammy extensions to the mix and they start getting problems.
Re: FSF announces Librephone project
#207Earlier quoted context omitted.
Depends on the bank's policies. Currently it tends to be when you transfer to a new destination and/or above a certain amount. I could certainly imagine a bank requiring it for every PC-initiated transaction as and when they reach a point where most normie customers are using their app.
"Every PC-initiated transaction" doesn't make sense to me. What type are transactions are you talking about?
Bank transfers and I guess direct debit authorisations (if your bank requires you to confirm those) and reauthorisation/confirmation of card payments that were blocked by the bank's fraud detection. I think those are the only kinds of transactions one would ever use a PC for? I mean for me most of my day-to-day transactions are me paying by debit card in a shop, but you can't do that on a PC in the first place; pretty much everything else I do on my PC.
Re: FSF announces Librephone project
#208Re: FSF announces Librephone project
#209Earlier quoted context omitted.
> The banks - who are generally on the hook if something goes wrong, or at least have to pay a lot of lawyers to get off the hook - are not interested in moral arguments, they want a risk-reduced environment or no app for you - as is their right. If they pay for the phone and ship it to you then I agree. Otherwise, they have an obligation to serve their community (part of their banking charter) and that may include m…
No charter requires allowing access from any device. The charters don't even require banks to be open during hours most of their customers are off work.