FSF announces Librephone project
631–640 of 669 posts
Re: FSF announces Librephone project
#632Earlier quoted context omitted.
To a driver whose car just died on I 405 in heavy traffic that is a distinction without a difference.
> that is a distinction without a difference Yes, agreed, the entire idea of OTA updates to cars has a lot of bad consequences. No matter the license. So when we analyze the entire position of the FSF, all three cases listed above, I don't think you actually agree with them. FSF isn't against updating firmware on the fly, they just want certain things when it happens. And those things won't improve safety.
But: Stallman & the FSF are idealists, they are not in a position to argue for practical measures, by definition they have to take a relatively extremist position and dig in. If they didn't do that they would get nowhere. So I understand why they're doing it but I do not think their stance is overly practical or workable. But everybody will dilute that stance in their own particular way and so the net effect is potentially positive. If they would take a much milder stance then that positive effect would be diminished.
Re: FSF announces Librephone project
#633Earlier quoted context omitted.
/e/ isn't a safe option for regular people. It doesn't provide the most basic privacy and security patches or protections. Multiple years of important privacy and security patches being missing is terrible for a personal computer with tons of sensitive data. Replacing the stock OS on a Pixel 7 with an OS multiple years behind on important privacy/security patches and protections with different service privacy issues…
I think your threat model is wildly backwards if you believe that average users are concerned about threats from bugs in old kernel versions. In all of your posts, you carelessly (or deliberately?) conflate privacy and security. This is the same shell game that Google themselves play in their marketing https://www.tomsguide.com/phones/google-pixel-phones/the-pix... Your idea of a super-secure phone is a modern kernel…
Taking advantage of privacy flaws in older versions of software is the norm and not treated as malware by most platforms, app stores, news sites or the public at large. Many widely used apps abuse privacy flaws in older Android versions. That happens both in the form of privacy bugs which were fixed in newer versions and weaknesses in the design addressed by newer OS versions. Only privacy patches for issues considered bugs which are assigned a High or Critical severity are backported. The severity is very subjective and they try to avoid adding a large number of backported patches since some OEMs struggle to keep up with it and adding more patches would make it harder. As an example, VPN leaks are only considered Low or Moderate severity issues by Android and don't get backported. Many other kinds of privacy issues are similarly only fixed for the latest OS releases. As another example, many important privacy improvements are not considered bug fixes at all and aren't candidates for being backported regardless of importance. Many privacy improvements require changing the APIs used by apps with new target API levels which can't be backported without breaking compatibility.
A large portion of the missing patches in /e/ we're referring to are privacy patches, not security patches. However, security patches are also needed to protect privacy. Many apps and services abuse the privacy vulnerabilities. The patches being referred to are a mix of both. A large subset are privacy patches, especially the Moderate and Low severity patches due to how they assign severity. Only certain particularly awful classes of privacy vulnerabilities can get considered High or Critical severity to be candidates for Android's backporting to older releases.
Apps exploiting security vulnerabilities to get code execution would be considered malware and is rare, but apps abusing many privacy flaws in older Android is the norm among mainstream apps. You're wrongly interpreting the regular stream of patches for vulnerabilities as only being for security issues when many are for privacy issues. With /e/, you aren't getting the bare minimum to protect privacy and security. Privacy also depends on security and is not an entirely separate thing as you're portraying it. We're not conflating them but rather they're very closely related. You're also disregarding privacy vulnerabilities and the steadily improving standard Android privacy protections.
Re: FSF announces Librephone project
#634Earlier quoted context omitted.
> that is a distinction without a difference Yes, agreed, the entire idea of OTA updates to cars has a lot of bad consequences. No matter the license. So when we analyze the entire position of the FSF, all three cases listed above, I don't think you actually agree with them. FSF isn't against updating firmware on the fly, they just want certain things when it happens. And those things won't improve safety.
Agreed. But: Stallman & the FSF are idealists, they are not in a position to argue for practical measures, by definition they have to take a relatively extremist position and dig in. If they didn't do that they would get nowhere. So I understand why they're doing it but I do not think their stance is overly practical or workable. But everybody will dilute that stance in their own particular way and so the net effect…
Re: FSF announces Librephone project
#635Earlier quoted context omitted.
Agreed. But: Stallman & the FSF are idealists, they are not in a position to argue for practical measures, by definition they have to take a relatively extremist position and dig in. If they didn't do that they would get nowhere. So I understand why they're doing it but I do not think their stance is overly practical or workable. But everybody will dilute that stance in their own particular way and so the net effect…
I would say that exempting unchangeable blobs is a big concession all by itself and the idealist position is that roms with programs need to be open source too.
I don't even mind the ROMS, I mind the ROMS that I can not read out myself.
Re: FSF announces Librephone project
#636Earlier quoted context omitted.
> we all would agree that there's some functions of government related to war and security that should not be transparent Yeah I don't know that this premise is true. For a lot of examples you might give WRT war or security, I feel like some will take the approach that "if you can't do it transparently then you probably shouldn't be doing it at all". > I feel that if the FSF recognizes that there's some areas that ar…
Yeah I don't know that this premise is true. For a lot of examples you might give WRT war or security, I feel like some will take the approach that "if you can't do it transparently then you probably shouldn't be doing it at all". If your enemy knows your entire plan of attack in a battle you will lose. This isn't theoretical it's just a fact. It's why military organizations invest so much in intelligence. Knowing wh…
Re: FSF announces Librephone project
#637I'm confused. Hasn't the Librephone been in stalled development for over a decade?
In contrast, Librephone has only been aannounced this week, and it attempts to reverse engineer stuff related to device firmware and binary blobs. It's not the same as creating another Android distro, and any usable results won't be tied to Android, so they for example can be used to give better support for mobile non-Android Linux efforts.
Re: FSF announces Librephone project
#638Earlier quoted context omitted.
> The hope is that the M2-M5 won’t be that different from the M1 models - after all, Apple doesn’t want to spend their money reinventing the wheel From the Asahi Linux website, M2 is sufficiently similar to M1, while M3 and M4 won't likely be supported soon due to significant differences.
They're aiming to perfect their support for M1/M2 prior to working on the M3 and later models. Seems like a sensible choice, given that even a baseline M1 or M2 Mac is still a highly compelling device for a vast majority of uses. And Asahi will become more relevant as these devices cease to be supported by newer releases of macOS.
Maybe in 2020. Lenovo released an ARM chromebook this summer which has benchmark performance of M1/M2 chips and is perfectly supported by Linux (ChromeOS) out of the box.
Re: FSF announces Librephone project
#639Earlier quoted context omitted.
> we all would agree that there's some functions of government related to war and security that should not be transparent Yeah I don't know that this premise is true. For a lot of examples you might give WRT war or security, I feel like some will take the approach that "if you can't do it transparently then you probably shouldn't be doing it at all". > I feel that if the FSF recognizes that there's some areas that ar…
"Yeah but the problem here is that the FSF has this annoying track record of being proven correct, over and over again" It's not that FSF is proven correct, it's that the FSF disapproves of 99.9% of software, it's easy for them to look back when there's a scandal and say "see? we told you so.". Too many false positives.
Re: FSF announces Librephone project
#640Earlier quoted context omitted.
This post was fine up until you decided to be sexist for no reason. If you're using "feminine" as an insult, professing "obvious" connotations, you need to reflect on why you have these associations.
[flagged]
Please don't do that on HN. It's not what this site is for, and destroys what it is for.