Live data from Hacker News

Librem One – A growing bundle of ethical services

librem.one

121–130 of 136 posts

Re: Librem One – A growing bundle of ethical services

#121

This is quite dishonest, they make it seem like they develop the apps themselves. But they don't and they give no credit to the actual original apps. Librem Chat = Riot.im Librem Social = Mastodon (specifically the Tusky app) Librem Mail = K9 Mail Librem Tunnel = OpenVPN

When I scrolled down I saw some of the the base Foss projects get named in a list. Librem Mail – Standard SMTP/IMAP/POP MTA, with OpenPGP Librem Tunnel – OpenVPN Librem Chat – Matrix, XMPP (coming soon) Librem Social – ActivityPub Edit: formatting

Those are just the protocols. They should also list the client application they're forking as well. What they're doing is like forking nginx selling you a webserver, then when people ask what it's based on they reply with 'http(s)'.

Also notice, in their "alternative graphics" none of the open source clients are listed.

Re: Librem One – A growing bundle of ethical services

#122

Lots of great criticism on this thread. Lots of great reasons to maybe stay away from Purism. However... What I personally think is really interesting here is the bundle. I don't want to pay $10/month for a Twitter clone. I don't want to pay it for VPN. I don't want to pay it for email, or file storage, or contact manager, or payment system. But as a bundle? $10/month to actually solve all of my digital privacy conce…

A future integration/compatibility with NextCloud will be awesome.

https://en.wikipedia.org/wiki/Nextcloud

Re: Librem One – A growing bundle of ethical services

#123
post #25

This is really frustrating, and basically the exact same thread as happened a while back with another list of "ethical alternatives". You can't call something ethical without going into detail about what you mean. and: Policy No Ads No Tracking We respect you is not useful. The value in ethics is in the conversation around what is ethical, not in a big, friendly "this is ethical" sticker. This is as useful as "do no…

isn't "ethical" one of those subjective terms though? so... no-one can say their product/service is "ethical" without getting into a semantic argument about what "ethical" means or... anyone can call their product/service "ethical" and it's up to the buyer to work out if their definition of that agrees

That's my point. The value is in the discussion around what's considered ethical, not in the label.

What I would like is for services like this to provide, up-front, a more complete discussion of how they've arrived at their recommendations, and what criteria they consider.

Re: Librem One – A growing bundle of ethical services

#124

This is quite dishonest, they make it seem like they develop the apps themselves. But they don't and they give no credit to the actual original apps. Librem Chat = Riot.im Librem Social = Mastodon (specifically the Tusky app) Librem Mail = K9 Mail Librem Tunnel = OpenVPN

Agreed it's kind of dishonest. I mean technically it isn't but it sure does obscure a lot of volunteer hard work by a lot of people.

I did wonder how they got all these apps out of the gate so quickly.. they didn't.

Re: Librem One – A growing bundle of ethical services

#125
post #119

Earlier quoted context omitted.

www.modular.im

While I think modular.im is a good idea for the Matrix devs to hopefully be able to sustain development, getting more third-party hosts should be the name of the game. And while I love the Matrix.org folks and all the work they've been doing, the recent hack was such a complete shit-show (with so many glaringly bad decisions). This was likely the result of nowhere near enough resources to dedicate to infrastructure,…

i'm currently finishing up the postmortem writeup on the security breach, but the tl;dr is that the old infra surrounding the matrix.org server had grown organically and hadn't received any proper ops love.

modular.im however runs on entirely different infra, and was set up by a professional ops team, was not compromised during the breach, and should be considered trustworthy. Also, money from Modular goes directly to supporting the core Matrix.org team, so if people don't use it due to concern over the breach it's going to hurt us badly. This is doubly true if people end up using other paid hosting providers (like Librem.one) which don't actually contribute any funding back to the project.

Re: Librem One – A growing bundle of ethical services

#126
post #119

Earlier quoted context omitted.

While I think modular.im is a good idea for the Matrix devs to hopefully be able to sustain development, getting more third-party hosts should be the name of the game. And while I love the Matrix.org folks and all the work they've been doing, the recent hack was such a complete shit-show (with so many glaringly bad decisions). This was likely the result of nowhere near enough resources to dedicate to infrastructure,…

i'm currently finishing up the postmortem writeup on the security breach, but the tl;dr is that the old infra surrounding the matrix.org server had grown organically and hadn't received any proper ops love. modular.im however runs on entirely different infra, and was set up by a professional ops team, was not compromised during the breach, and should be considered trustworthy. Also, money from Modular goes directly t…

I fund you folks on Liberapay so you've already got my $10/mo (and much more) without the other overhead of taking care of my messaging service. I also self-host so am not going to use Librem.one anyway[+]. However...

> old infra surrounding the matrix.org server had grown organically and hadn't received any proper ops love

I'm sorry to be a bit harsh, but "hosting package and android signing keys on production servers" and "not putting services on an internal network accessible only by VPN" aren't small mistakes. They're major screw-ups. An "organically grown" setup where the signing keys were on one developer's laptop would've arguably been more secure than the old setup.

Don't get me wrong, I really want you to do well (I've used Matrix for years and have donated >£1500 over that time). But I have to be honest with you that trust in your infrastructure is going to be very hard to get back. Hell, it took until last week for some of the remaining services from the breach to be back up (fedtester was down last week from memory)!

The offer for hosting matrix.org packages on OBS is still open. It'd reduce at least a bit of maintenance overhead and would at least allow homeserver operators to get the latest packages independently of the main matrix.org infra. :D

> and was set up by a professional ops team

Given that the ops team is presumably employed by New Vector, why wasn't the matrix.org infrastructure fixed before launching a new product? Was this something that was planned to happen but never did, or was the long-term plan to shut off matrix.org and get everyone to switch to Modular?

[+] Though I'm surprised that you seem to see public offerings of Matrix homeservers to be a negative rather than a success of the protocol -- surely this plan was obvious given the Librem 5 wanting to use Matrix as the main messaging service. Obviously I think they should contribute back to Matrix.org, but isn't focusing on that missing the wood for the trees? Also the main benefit people will have out of a service like Librem.one is that you are paying for all of the services provided, not just one. I have a feeling selling "just another chat system" to folks (which is what most people think when they first see Matrix) will be much harder than selling "G-suite that protects your privacy".

Re: Librem One – A growing bundle of ethical services

#127
post #69

It looks as though the mail service won't support custom domains.

Got a reply from my question asking about custom domains: Hello,

On Tuesday, 30 April 2019 at 23:29, [me] wrote: > Hi there, will you support custom email domains? I'd love to migrate from > Google Apps!

We're looking into it, but cannot say nothing for sure for now.

> -[me]

Kind regards,

-- [support person] Purism support

Re: Librem One – A growing bundle of ethical services

#128
post #120

Earlier quoted context omitted.

> It's a bit of a shame that Librem Tunnel doesn't use WireGuard, though I imagine they'll switch once it's in mainline. It's a bit of a shame that WireGuard still requires out of tree components to work.. I'm rooting for it to get accepted/merged, but until it does it just becomes a greater risk to build a business off of it.

It's in the process of being merged into net-next and mainline right now[1] and most of the hangups are around the new crypto library that WireGuard uses[2]. But honestly though, the risk is identical to any other kernel module -- the author and future subsystem maintainer ensures it builds and works with all new and old kernels, and releases snapshots very regularly. Almost all distributions have packages for WireGu…

> the risk is identical to any other kernel module

Nope, it's not identical. There's a forcing function (e.g. Linus) to help motivate maintainers to fix their crap in the kernel tree if it breaks. That forcing function does not exist for out of tree patches.

Re: Librem One – A growing bundle of ethical services

#129
post #85

Earlier quoted context omitted.

PGP is a two-party system. The sender has a public/private keypair, and the recipient has a public/private keypair. The sender encrypts a message with the sender's priv key and the recipient's pub key. The recipient decrypts the message with the the sender's pub key and the recipient's priv key. > Almost all of the transactional emails I have received (receipts, confirmation numbers, etc) are probably unencrypted, ri…

> The sender encrypts a message with the sender's priv key and the recipient's pub key. You just need the recipient's public key to encrypt. Are you thinking about the sender adding a cryptographic signature, too? > The recipient decrypts the message with the the sender's pub key and the recipient's priv key. You don't need the sender's public key, just the recipient's private key to decrypt. Though, if there's also…

I was attempting to explain in a simplified manner, since OP said that they did not know much about email encryption. But if you want to be semi-technical about it:

Both the sender's and recipient's public keys are required to calculate a shared secret. That shared secret is then used to encrypt the message. The recipient's priv key is used to decrypt the message.

Edit: Validating a digital signature is typically part of the process when using all-in-one software (eg: Thunderbird's Enigmail extension). That is why I mention the use of private keys. Again, an oversimplification on my part in response to OP's statement "Is encryption on emails that I have received controlled by the sender?", which is false.

See: https://tools.ietf.org/html/rfc4880#section-2.1

Re: Librem One – A growing bundle of ethical services

#130
post #126

Earlier quoted context omitted.

i'm currently finishing up the postmortem writeup on the security breach, but the tl;dr is that the old infra surrounding the matrix.org server had grown organically and hadn't received any proper ops love. modular.im however runs on entirely different infra, and was set up by a professional ops team, was not compromised during the breach, and should be considered trustworthy. Also, money from Modular goes directly t…

I fund you folks on Liberapay so you've already got my $10/mo (and much more) without the other overhead of taking care of my messaging service. I also self-host so am not going to use Librem.one anyway[+]. However... > old infra surrounding the matrix.org server had grown organically and hadn't received any proper ops love I'm sorry to be a bit harsh, but "hosting package and android signing keys on production serve…

firstly - thank you for supporting the project :)

wrt the security practices on the old infra; yes - clearly they were major screw-ups. all I can do is spell out what we did wrong, and that we are painfully aware of the errors, and what we are doing to fix it going forwards.

> why wasn't the matrix.org infrastructure fixed before launching a new product.

because we put all our energy into getting modular sorted properly to try to increase $ to fund the team, rather than tidying up the old infra, with the expectation of eventually moving matrix.org over to the new hosting infra RSN.

> Though I'm surprised that you seem to see public offerings of Matrix homeservers to be a negative

It's very much a positive from the protocol's perspective. But from the painful practicality of keeping the team funded, it's a problem to spend time supporting Librem-specific issues if there's no $ to cover the time, as it just ends up sucking time from the core project. There is a massive risk of the tragedy of the commons here. In other words: from the perspective of keeping the team paid to work on Matrix as their day job, we'd rather users bought Matrix hosting from providers who funnel some of the revenue back to the core team. Hopefully Purism will end up doing so.

Post reply on HN