Live data from Hacker News

Librem One – A growing bundle of ethical services

librem.one

131–136 of 136 posts

Re: Librem One – A growing bundle of ethical services

#131

Earlier quoted context omitted.

isn't "ethical" one of those subjective terms though? so... no-one can say their product/service is "ethical" without getting into a semantic argument about what "ethical" means or... anyone can call their product/service "ethical" and it's up to the buyer to work out if their definition of that agrees

That's my point. The value is in the discussion around what's considered ethical, not in the label. What I would like is for services like this to provide, up-front, a more complete discussion of how they've arrived at their recommendations, and what criteria they consider.

that's reasonable, I guess... though I can see a point where they want to sell things, rather than engage in endless discussions about everyone's opinion of what "ethical" means ;)

Re: Librem One – A growing bundle of ethical services

#132
post #120

Earlier quoted context omitted.

It's in the process of being merged into net-next and mainline right now[1] and most of the hangups are around the new crypto library that WireGuard uses[2]. But honestly though, the risk is identical to any other kernel module -- the author and future subsystem maintainer ensures it builds and works with all new and old kernels, and releases snapshots very regularly. Almost all distributions have packages for WireGu…

> the risk is identical to any other kernel module Nope, it's not identical. There's a forcing function (e.g. Linus) to help motivate maintainers to fix their crap in the kernel tree if it breaks. That forcing function does not exist for out of tree patches.

If we were talking about the out-of-tree VirtualBox drivers I would agree with you. But we're not -- WireGuard has proven itself to be incredibly solid for the past 3 years and supports all kernels since 3.10 (with each commit getting tested against all of those kernels).

To be honest, that is far more stringent requirements than most subsystems in the Linux tree. Being in-tree is better for a variety of reasons, but just because something is in-tree doesn't make it significantly more stable or safe (I can think of several counter-examples where Linus hasn't motivated maintainers to fix mistakes and breaking changes).

Re: Librem One – A growing bundle of ethical services

#133
post #126

Earlier quoted context omitted.

I fund you folks on Liberapay so you've already got my $10/mo (and much more) without the other overhead of taking care of my messaging service. I also self-host so am not going to use Librem.one anyway[+]. However... > old infra surrounding the matrix.org server had grown organically and hadn't received any proper ops love I'm sorry to be a bit harsh, but "hosting package and android signing keys on production serve…

firstly - thank you for supporting the project :) wrt the security practices on the old infra; yes - clearly they were major screw-ups. all I can do is spell out what we did wrong, and that we are painfully aware of the errors, and what we are doing to fix it going forwards. > why wasn't the matrix.org infrastructure fixed before launching a new product. because we put all our energy into getting modular sorted prope…

I look forward to reading your write-up. And I really do hope that Purism gives money back to you folks and the other original projects (unfortunately there are many more counterexamples than examples of this happening in the past). Wasn't there already some agreement with them in order for them to have decided to use Matrix on the Librem 5 -- or is there no such revenue-sharing arrangement? (Or was the arrangement "host your own homeserver"?)

Re: Librem One – A growing bundle of ethical services

#134
post #133

Earlier quoted context omitted.

firstly - thank you for supporting the project :) wrt the security practices on the old infra; yes - clearly they were major screw-ups. all I can do is spell out what we did wrong, and that we are painfully aware of the errors, and what we are doing to fix it going forwards. > why wasn't the matrix.org infrastructure fixed before launching a new product. because we put all our energy into getting modular sorted prope…

I look forward to reading your write-up. And I really do hope that Purism gives money back to you folks and the other original projects (unfortunately there are many more counterexamples than examples of this happening in the past). Wasn't there already some agreement with them in order for them to have decided to use Matrix on the Librem 5 -- or is there no such revenue-sharing arrangement? (Or was the arrangement "…

> Wasn't there already some agreement with them in order for them to have decided to use Matrix on the Librem 5 -- or is there no such revenue-sharing arrangement?

We were hoping they would funnel $ from the Librem 5 campaign to help support Matrix, and there was an agreement to do so if the campaign reached a given threshold. So far we haven't seen anything, but live in hope.

Re: Librem One – A growing bundle of ethical services

#135
post #85

Earlier quoted context omitted.

PGP is a two-party system. The sender has a public/private keypair, and the recipient has a public/private keypair. The sender encrypts a message with the sender's priv key and the recipient's pub key. The recipient decrypts the message with the the sender's pub key and the recipient's priv key. > Almost all of the transactional emails I have received (receipts, confirmation numbers, etc) are probably unencrypted, ri…

> The sender encrypts a message with the sender's priv key and the recipient's pub key. You just need the recipient's public key to encrypt. Are you thinking about the sender adding a cryptographic signature, too? > The recipient decrypts the message with the the sender's pub key and the recipient's priv key. You don't need the sender's public key, just the recipient's private key to decrypt. Though, if there's also…

Yes, that is the detail that was glossed over.

The difficult part is for the sender to get a copy of the recipient's public key. In practice, a sender will always sign with their private key, since they can just send a copy of their public key with the message.

I think GP thought it necessary to give a complete example, but not a complete explanation.

Re: Librem One – A growing bundle of ethical services

#136
post #39

This is quite dishonest, they make it seem like they develop the apps themselves. But they don't and they give no credit to the actual original apps. Librem Chat = Riot.im Librem Social = Mastodon (specifically the Tusky app) Librem Mail = K9 Mail Librem Tunnel = OpenVPN

The VPN isn't a hosted service? Just the client software? A few others mention they are connected to subscription systems, such as the back-up service. So it seems to be more than just repackaged software, but software + service + support (the big barrier for most OS adoption - requiring the customer to set up and configure 6 different services). Either way, anything that gets people using more encrypted open-source…

I advise a good program VeePN, it works not bad
Post reply on HN