Let’s start to discuss where we stand with open source smartphones, both in terms of software and hardware. Really worried about privacy and human rights. We cannot trust Apple and Google on this..
So you don't trust large US tech companies. Fair. But why do you expect people can trust a group of anonymous developers building open source smartphones?
We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
21–30 of 49 posts
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#22Let’s start to discuss where we stand with open source smartphones, both in terms of software and hardware. Really worried about privacy and human rights. We cannot trust Apple and Google on this..
So you don't trust large US tech companies. Fair. But why do you expect people can trust a group of anonymous developers building open source smartphones?
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#23As I understand, the GSM and Bluetooth modules are closed source because patents etc? We would need open hardware for the entire phone, then the software will come.
That's the opposite of how patents work; if there were patents involved they'd be public record and we could look them up. No, these modules are closed because it's simpler than making them open. Someone is getting ready to type "FCC and other regulatory bodies prohibit consumer reconfiguration of specific certified radios" but that has nothing whatsoever to do with openness. Being able to monitor something and being…
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#24Earlier quoted context omitted.
There's also the matter of traceability. Even if there is no direct audit of the code, once a vulnerability is discovered it can be traced back to the person(s) who introduced it. With a closed system, only the owner of the source code history can do that. With open source, any person in the world can, and can start a discussion to understand whether it was malicious or not, if the person(s) should be banned from pus…
Nope, it can be traced back to a random nickname on the Internet, using a computer somewhere in the globe.
You don't get commit rights as a random person, so yes, a commit can usually be traced back to a person. Sure, the committer could have received a patch from a unknown person, but then he's still responsible for the commit.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#25Earlier quoted context omitted.
That's the opposite of how patents work; if there were patents involved they'd be public record and we could look them up. No, these modules are closed because it's simpler than making them open. Someone is getting ready to type "FCC and other regulatory bodies prohibit consumer reconfiguration of specific certified radios" but that has nothing whatsoever to do with openness. Being able to monitor something and being…
But, so, in short, we are screwed for practical open radios? Or is there a way out?
or we can try to reverse engineer existing basebands, but I'm not aware of any successful projects working toward that.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#26Earlier quoted context omitted.
Ok thanks, I get that. But how many people can do that? Like 0.001% of the population?
How many people can authenticate a dollar bill? How many people can validate a cryptographic signature? How many people can direct a blockbuster action movie? The point is, right now, nobody can audit these things. Once someone -- anyone! -- can, everyone else can benefit.
USGOV has a pretty comprehensive guide on how to validate them:
https://www.uscurrency.gov/sites/default/files/downloadable-...
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#27Earlier quoted context omitted.
Nope, it can be traced back to a random nickname on the Internet, using a computer somewhere in the globe.
I guess you have never had commit rights to any Linux distribution or such? You don't get commit rights as a random person, so yes, a commit can usually be traced back to a person. Sure, the committer could have received a patch from a unknown person, but then he's still responsible for the commit.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#28Earlier quoted context omitted.
So you don't trust large US tech companies. Fair. But why do you expect people can trust a group of anonymous developers building open source smartphones?
You clearly don’t understand the transparency and power of open source code. Fair.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#29Let’s start to discuss where we stand with open source smartphones, both in terms of software and hardware. Really worried about privacy and human rights. We cannot trust Apple and Google on this..
Purchasing phones which ensure frequent software patches for a number of years is a far better tactic IMHO. For example I recently purchased a Nokia X20 (https://www.clove.co.uk/products/nokia-x20) which has a promised 3 years of OS upgrades...something I've not seen by other manufacturers.
Re: We see Project Pegasus, we must have Open Source Smartphones: let’s discuss
#30Earlier quoted context omitted.
There's also the matter of traceability. Even if there is no direct audit of the code, once a vulnerability is discovered it can be traced back to the person(s) who introduced it. With a closed system, only the owner of the source code history can do that. With open source, any person in the world can, and can start a discussion to understand whether it was malicious or not, if the person(s) should be banned from pus…
Nope, it can be traced back to a random nickname on the Internet, using a computer somewhere in the globe.
In any case, "a random nickname on the Internet, using a computer somewhere in the globe" is a lot more information than none.
Finding out that that's the case for a given project is part of traceability.