Live data from Hacker News

We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

theguardian.com

11–20 of 49 posts

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#12
post #5

Earlier quoted context omitted.

So you don't trust large US tech companies. Fair. But why do you expect people can trust a group of anonymous developers building open source smartphones?

Isn't that a large part of the open-source nature? Audit the code or hardware designs yourself, determine their trustworthiness from that. It's much harder to trust something when you can't examine the inner workings of it.

Ok thanks, I get that. But how many people can do that? Like 0.001% of the population?

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#13
post #3

As I understand, the GSM and Bluetooth modules are closed source because patents etc? We would need open hardware for the entire phone, then the software will come.

That's the opposite of how patents work; if there were patents involved they'd be public record and we could look them up.

No, these modules are closed because it's simpler than making them open. Someone is getting ready to type "FCC and other regulatory bodies prohibit consumer reconfiguration of specific certified radios" but that has nothing whatsoever to do with openness. Being able to monitor something and being able to configure it are not the same thing.

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#14

Earlier quoted context omitted.

Isn't that a large part of the open-source nature? Audit the code or hardware designs yourself, determine their trustworthiness from that. It's much harder to trust something when you can't examine the inner workings of it.

Ok thanks, I get that. But how many people can do that? Like 0.001% of the population?

How many people can authenticate a dollar bill? How many people can validate a cryptographic signature? How many people can direct a blockbuster action movie?

The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#16
post #11

Won't help unless we have open chat protocols. All the open phones in the world won't help if you use closed-source WhatsApp / Facebook. And you kinda have to if you want to talk to your less tech savvy friends and family.

And open chat protiocols won't help because we don't have open source smartphones :) Maybe this battle is on different fronts and there are many factors that are into play.

In the EU there is a law in preparation that will force big players in chat networks to open up to third parties: The Digital Markets Act (DMA): https://ec.europa.eu/info/strategy/priorities-2019-2024/euro...

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#17
post #14

Earlier quoted context omitted.

Ok thanks, I get that. But how many people can do that? Like 0.001% of the population?

How many people can authenticate a dollar bill? How many people can validate a cryptographic signature? How many people can direct a blockbuster action movie? The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.

There's also the matter of traceability.

Even if there is no direct audit of the code, once a vulnerability is discovered it can be traced back to the person(s) who introduced it.

With a closed system, only the owner of the source code history can do that. With open source, any person in the world can, and can start a discussion to understand whether it was malicious or not, if the person(s) should be banned from pushing code, new code security standards to be adopted, etc. You lean on the world's expertise at that point.

Bad things happen. It's important to have the ability to understand why and mitigate for the future.

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#18

When we tech people warned about this, the answer was always "I got nothing to hide". Now that it affects journalists, they are all shocked and write articles. We need till it hits politicians, then we can have new laws.

Unheard past warnings do not change the situation we live in. Agree we need this to hit someone on the upper floor.

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#19
post #14

Earlier quoted context omitted.

How many people can authenticate a dollar bill? How many people can validate a cryptographic signature? How many people can direct a blockbuster action movie? The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.

There's also the matter of traceability. Even if there is no direct audit of the code, once a vulnerability is discovered it can be traced back to the person(s) who introduced it. With a closed system, only the owner of the source code history can do that. With open source, any person in the world can, and can start a discussion to understand whether it was malicious or not, if the person(s) should be banned from pus…

Nope, it can be traced back to a random nickname on the Internet, using a computer somewhere in the globe.

Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss

#20
I want privacy. I also sort-of buy the "nothing to hide" argument - as another comment below says, for most people risk-adjusted cost of privacy loss is greater than the cost of maintaining it.

But this article writes about the very people who have plenty to hide (for good reason!). I think it's a bit misleading to say investigative journalists have "nothing to hide" - confidential sources, on-going stories, contacts, whereabouts etc. Mixing this up, in my eyes, is not helping the "privacy for the masses" adoption.

Post reply on HN