All the open phones in the world won't help if you use closed-source WhatsApp / Facebook. And you kinda have to if you want to talk to your less tech savvy friends and family.
We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
11–20 of 49 posts
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#12Earlier quoted context omitted.
So you don't trust large US tech companies. Fair. But why do you expect people can trust a group of anonymous developers building open source smartphones?
Isn't that a large part of the open-source nature? Audit the code or hardware designs yourself, determine their trustworthiness from that. It's much harder to trust something when you can't examine the inner workings of it.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#13As I understand, the GSM and Bluetooth modules are closed source because patents etc? We would need open hardware for the entire phone, then the software will come.
No, these modules are closed because it's simpler than making them open. Someone is getting ready to type "FCC and other regulatory bodies prohibit consumer reconfiguration of specific certified radios" but that has nothing whatsoever to do with openness. Being able to monitor something and being able to configure it are not the same thing.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#14Earlier quoted context omitted.
Isn't that a large part of the open-source nature? Audit the code or hardware designs yourself, determine their trustworthiness from that. It's much harder to trust something when you can't examine the inner workings of it.
Ok thanks, I get that. But how many people can do that? Like 0.001% of the population?
The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#15Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#16Won't help unless we have open chat protocols. All the open phones in the world won't help if you use closed-source WhatsApp / Facebook. And you kinda have to if you want to talk to your less tech savvy friends and family.
In the EU there is a law in preparation that will force big players in chat networks to open up to third parties: The Digital Markets Act (DMA): https://ec.europa.eu/info/strategy/priorities-2019-2024/euro...
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#17Earlier quoted context omitted.
Ok thanks, I get that. But how many people can do that? Like 0.001% of the population?
How many people can authenticate a dollar bill? How many people can validate a cryptographic signature? How many people can direct a blockbuster action movie? The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.
Even if there is no direct audit of the code, once a vulnerability is discovered it can be traced back to the person(s) who introduced it.
With a closed system, only the owner of the source code history can do that. With open source, any person in the world can, and can start a discussion to understand whether it was malicious or not, if the person(s) should be banned from pushing code, new code security standards to be adopted, etc. You lean on the world's expertise at that point.
Bad things happen. It's important to have the ability to understand why and mitigate for the future.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#18When we tech people warned about this, the answer was always "I got nothing to hide". Now that it affects journalists, they are all shocked and write articles. We need till it hits politicians, then we can have new laws.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#19Earlier quoted context omitted.
How many people can authenticate a dollar bill? How many people can validate a cryptographic signature? How many people can direct a blockbuster action movie? The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.
There's also the matter of traceability. Even if there is no direct audit of the code, once a vulnerability is discovered it can be traced back to the person(s) who introduced it. With a closed system, only the owner of the source code history can do that. With open source, any person in the world can, and can start a discussion to understand whether it was malicious or not, if the person(s) should be banned from pus…
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#20But this article writes about the very people who have plenty to hide (for good reason!). I think it's a bit misleading to say investigative journalists have "nothing to hide" - confidential sources, on-going stories, contacts, whereabouts etc. Mixing this up, in my eyes, is not helping the "privacy for the masses" adoption.