Live data from Hacker News

Librem One – A growing bundle of ethical services

librem.one

111–120 of 136 posts

Re: Librem One – A growing bundle of ethical services

#111

> Librem Mail. Main Features: Safe (We delete unencrypted emails after 30 days) I don't understand encrypted email very much at all. Is encryption on emails that I have received controlled by the sender? Almost all of the transactional emails I have received (receipts, confirmation numbers, etc) are probably unencrypted, right? This doesn't sound desirable.

Almost 100% of the email aimed at most people does not use PGP, and thus temporary in this scheme. That means that it gets deleted every 30 days. However, doesn't that only mean that the librem One user loses their copy (unless they made a backup), but the other party gets to keep theirs?

What am I missing that causes this to make sense as a feature?

Re: Librem One – A growing bundle of ethical services

#112

Earlier quoted context omitted.

Speaking as the project lead for Matrix - we are hoping that we will see some kind of financial support from Purism to fund the prioritised bugfixes/features/support they need around Synapse and Riot to ensure Librem.one's (and the Librem 5's) success.

$8/month is rather steep for some email and IM hosting. So there should be revenue left to share with you and the other upstream projects. Personal side note: I’m not a fan of branding open source apps. It delays security updates and waters down the original brands; Riot and K9 have good reputations; Why not utilize those?

I can imagine two reasons for branding.

The first is that librem may need to make changes that cannot be accepted by upstream. It can be features they need to have now to keep users happy. But another example could be that they want their Riot to default to their homeserver and not to matrix.org. You don't want to wait until you get a trademark conflict with the main project.

The second reason could be that Librem has to market their brand. If they keep Riot for example, people type it in google and end up on the official riot site, then it may be hard for Librem to attract new users.

Re: Librem One – A growing bundle of ethical services

#113
post #112

Earlier quoted context omitted.

$8/month is rather steep for some email and IM hosting. So there should be revenue left to share with you and the other upstream projects. Personal side note: I’m not a fan of branding open source apps. It delays security updates and waters down the original brands; Riot and K9 have good reputations; Why not utilize those?

I can imagine two reasons for branding. The first is that librem may need to make changes that cannot be accepted by upstream. It can be features they need to have now to keep users happy. But another example could be that they want their Riot to default to their homeserver and not to matrix.org. You don't want to wait until you get a trademark conflict with the main project. The second reason could be that Librem ha…

> But another example could be that they want their Riot to default to their homeserver and not to matrix.org.

This isn't valid. They could absolutely ship Riot with its existing branding, with a config set to use their (or any other) homeserver. The matrix.org homeserver just happens to be the default (at the moment).

Re: Librem One – A growing bundle of ethical services

#114
post #58
post #47

Earlier quoted context omitted.

Agreed, just OSS software on it's own is great but these products need proper marketing and delivery. If Purism is offering clean and transparent connections to services backing them combined with some sort of delivery (update) + support mechanism, that is already far better than just telling someone to download 5-6 apps + subscribe to 3-4 services (VPN, email server, backup server, etc). It's not as ideal as a purel…

If we want federated services, like matrix, to take off then we need to find a way to get users to pay for it. Everybody is still free to set up a server at home or on a VPS. But there has to be a place you can point ordinary people to.

www.modular.im

Re: Librem One – A growing bundle of ethical services

#115
post #107

I'm too much disappointed with this bullshit, because it's coming from a company which I really appreciated 'n respected. AFAIK, Purism hasn't yet delivered the Librem 5 phone. If that's case, then it's a priority violation. Now, the best Purism can do is abort this bullshit and pay all the backers their money back before it's too late.

It is not clear to me that the two are competing for resources. Getting a phone working requires completely different staff from bringing up online services, and a steady cash flow can lift the pots on all the burners.

To me, it still looks like a priority or some other kind of problem. Sorry :) Let's assume all of this as a "good intentioned mistake" and hope that Purism abolish this ASAP.

Re: Librem One – A growing bundle of ethical services

#116
post #22

This is quite dishonest, they make it seem like they develop the apps themselves. But they don't and they give no credit to the actual original apps. Librem Chat = Riot.im Librem Social = Mastodon (specifically the Tusky app) Librem Mail = K9 Mail Librem Tunnel = OpenVPN

I agree and this strikes me as odd as well. I really want to like this product and it’s squarely in the area of a service I would pay monthly for. But, the Social app looks exactly like a twitter screen shot, and the VPN looks identical to PIA’s iOS app. The chat UI isn’t great, and the Mail app is even worse. They all look like apps you would find on F-Droid which are great, but I wouldn’t feel excited about paying…

Millions of active users is for Librem Social only, that is the fediverse. See more stats on https://fediverse.network/reports/2018

With Librem One you get a Mastodon account on there own Mastodon instance. That instance can speek with all other instances on the fediverse with ActivityPub protocol. So yes, with Librem Social you can easy connect with more then 2 million people.

Re: Librem One – A growing bundle of ethical services

#117
post #112

Earlier quoted context omitted.

I can imagine two reasons for branding. The first is that librem may need to make changes that cannot be accepted by upstream. It can be features they need to have now to keep users happy. But another example could be that they want their Riot to default to their homeserver and not to matrix.org. You don't want to wait until you get a trademark conflict with the main project. The second reason could be that Librem ha…

> But another example could be that they want their Riot to default to their homeserver and not to matrix.org. This isn't valid. They could absolutely ship Riot with its existing branding, with a config set to use their (or any other) homeserver. The matrix.org homeserver just happens to be the default (at the moment).

Imagine somebody using a Librem Riot version that has been modified to default to the Librem homeserver. Now that user needs to use Riot on a new device and ends up with the standard Riot. The user doesn't see any difference but just finds that it fails.

If the user calls Librem support then they have figure out what is going on. Which costs money and they still have a frustrated user.

Branding is often not about what is technically or legally possible, but about creating the right perception with users.

Re: Librem One – A growing bundle of ethical services

#118
post #89

Lots of great criticism on this thread. Lots of great reasons to maybe stay away from Purism. However... What I personally think is really interesting here is the bundle. I don't want to pay $10/month for a Twitter clone. I don't want to pay it for VPN. I don't want to pay it for email, or file storage, or contact manager, or payment system. But as a bundle? $10/month to actually solve all of my digital privacy conce…

ISPs could offer this bundle as part of the internet connection like they (used to) offer an email account and web page.

That is a FANTASTIC idea.

The challenge, at least in my neck of the woods, is that all the independent ISPs got purchased by bigger players who aren't exactly in a rush to be innovative.

Re: Librem One – A growing bundle of ethical services

#119
post #58

Earlier quoted context omitted.

If we want federated services, like matrix, to take off then we need to find a way to get users to pay for it. Everybody is still free to set up a server at home or on a VPS. But there has to be a place you can point ordinary people to.

www.modular.im

While I think modular.im is a good idea for the Matrix devs to hopefully be able to sustain development, getting more third-party hosts should be the name of the game.

And while I love the Matrix.org folks and all the work they've been doing, the recent hack was such a complete shit-show (with so many glaringly bad decisions). This was likely the result of nowhere near enough resources to dedicate to infrastructure, so maintaining thousands of clients' infrastructure as well would be a very bad decision.

Personally, there's no way I would use them for hosting if I was planning on not using matrix.org anyway.

Re: Librem One – A growing bundle of ethical services

#120
post #19

It's a bit of a shame that Librem Tunnel doesn't use WireGuard, though I imagine they'll switch once it's in mainline. Otherwise, seems like a pretty neat idea -- it could open the door to more lay-people using open protocols like Matrix without everyone jumping on Matrix.org for free or having to self-host. I am interested to see how the Librem Files/Backup system will work if it comes about (I would guess NextCloud…

> It's a bit of a shame that Librem Tunnel doesn't use WireGuard, though I imagine they'll switch once it's in mainline. It's a bit of a shame that WireGuard still requires out of tree components to work.. I'm rooting for it to get accepted/merged, but until it does it just becomes a greater risk to build a business off of it.

It's in the process of being merged into net-next and mainline right now[1] and most of the hangups are around the new crypto library that WireGuard uses[2].

But honestly though, the risk is identical to any other kernel module -- the author and future subsystem maintainer ensures it builds and works with all new and old kernels, and releases snapshots very regularly. Almost all distributions have packages for WireGuard which are automatically rebuilt with new kernel releases.

There are arguments against using it because it's still (on paper) pre-1.0 software but given it's had fairly widespread use for the past 3 years and no security nightmares it's shown to be quite a bit more secure than

[1]: https://marc.info/?l=linux-netdev&m=155323912319537&w=2 [2]: https://lwn.net/Articles/770750/

Post reply on HN