Live data from Hacker News

FSF announces Librephone project

fsf.org

651–660 of 669 posts

Re: FSF announces Librephone project

#651
post #21

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

In an emergency, can't you call your bank over the phone? Do you depend on it still if you have a Computer?

No, with some banks you can't.

I tried calling Starling Bank in the UK when my phone screen stopped working. I assumed they would have basic phone banking service.

They told me no. The only service they could provide over the phone was registering a new device to resume access to bank services via their mobile app.

Although they have a web banking service, which can he used on a desktop, that requires authentication via the mobile app too. It's not TOTP, it's their own thing.

As I needed to make a transaction, I had no choice but to buy a new phone in a hurry.to do it.

Several people suggest switching banks and credit card services, but I've found that not so easy. I have accounts with several banks (some for business), and 3 of them require use of their mobile app. Most credit card services I use also require use of their app. Some have websites that hand you over to the app at some point in the flow.

Re: FSF announces Librephone project

#652
post #91

Ultimately, I don't think the most important challenge is in binary firmware blobs, but the software which people depend upon to run their lives. What does it matter if you can run a completely free software stack on your phone, if your bank software (or your required government ID, as is looking depressingly likely) requires you to run a Big Tech approved phone OS? Perhaps the FSF can't do much about that, but that…

i think the best solution to this would be some sort of docker-project for people to remotely access a device hooked up to a raspberry pi or something at home via adb via https://github.com/Genymobile/scrcpy as "natively" as possible.

I agree, and I've done similar to this for mobile banking successfully. This is the way :)

However, I expect at some point they'll insist on biometric authentication.

That'd exclude people who can't use the biometrics. But one bank (Revolut) told me that they're dropping customers who don't have a passport or driving license in the UK, for KYC reasons that they said they were required to follow, despite there being a large number of people without either.

So I expect banks to have no problem excluding <x% of people in a discriminatory way, if they can find an excuse, eventually.

Re: FSF announces Librephone project

#653

Earlier quoted context omitted.

I hate to complain, but I can't help but feel this is kind of impossible with the resources available to the people working on it. Reverse engineering a modern phone would take years and years of work from many people, and by the time you have it worked out, the phone is obsolete and very few people still use it. The Apple Silicon macbooks seem a good example. The M1 came out about 5 years ago now and with a whole pr…

> The Apple Silicon macbooks seem a good example. The M1 came out about 5 years ago now and with a whole project and a lot of work later there is still limited hardware support. Having to put this effort in for all the models of phones seems massive. Apple Silicon isn't a single SoC. They have support for the M1 and M2 lines across both Macbooks, the Mini, iMac and Studio. It's the same thing with phones, isn't it? Y…

How is that going for e.g. postmarketOS? Doesn’t seem to be that simple

Re: FSF announces Librephone project

#654

Earlier quoted context omitted.

Because they aren’t focusing on a specific piece of hardware… I’m really not sure what you are expecting? The librephone project to be focused on librem5 instead of the hardware used in thousands of other devices?

> Because they aren’t focusing on a specific piece of hardware… How can you reverse engineer firmware without focusing on a specific piece of hardware? Firmware is tied to hardware, isn't it?

[deleted]

Re: FSF announces Librephone project

#655

Earlier quoted context omitted.

Because they aren’t focusing on a specific piece of hardware… I’m really not sure what you are expecting? The librephone project to be focused on librem5 instead of the hardware used in thousands of other devices?

> Because they aren’t focusing on a specific piece of hardware… How can you reverse engineer firmware without focusing on a specific piece of hardware? Firmware is tied to hardware, isn't it?

Clearly you are just trolling now.

Re: FSF announces Librephone project

#656
post #599

Earlier quoted context omitted.

Yeah I don't know that this premise is true. For a lot of examples you might give WRT war or security, I feel like some will take the approach that "if you can't do it transparently then you probably shouldn't be doing it at all". If your enemy knows your entire plan of attack in a battle you will lose. This isn't theoretical it's just a fact. It's why military organizations invest so much in intelligence. Knowing wh…

I'm not at war with anybody though.

Good for you, but that has nothing to do with whether secrecy is necessary in a security context.

Re: FSF announces Librephone project

#657
post #656

Earlier quoted context omitted.

I'm not at war with anybody though.

Good for you, but that has nothing to do with whether secrecy is necessary in a security context.

it does, however, point out that there's not been a valid security context listed where secrecy would be necessary.

Re: FSF announces Librephone project

#658

Finally! It took the FSF long enough to catch up with the overwhelming usage of mobile devices, but it's better late than never. I like that this project is trying to tackle something much more challenging that can't be done with just software: reverse engineering device firmware and binary blobs, the pieces of software that actually make hardware components interface with an OS. Understanding how this stuff function…

I hate to complain, but I can't help but feel this is kind of impossible with the resources available to the people working on it. Reverse engineering a modern phone would take years and years of work from many people, and by the time you have it worked out, the phone is obsolete and very few people still use it. The Apple Silicon macbooks seem a good example. The M1 came out about 5 years ago now and with a whole pr…

I thought Asahi Linux had made some pretty sizeable progress, it was a very impressive project and labour of love and talent.

Re: FSF announces Librephone project

#659
post #3

> Practically, Librephone aims to close the last gaps between existing distributions of the Android operating system and software freedom. The FSF has hired experienced developer Rob Savoye (DejaGNU, Gnash, OpenStreetMap, and more) to lead the technical project. He is currently investigating the state of device firmware and binary blobs in other mobile phone freedom projects, prioritizing the free software work done…

The time is right: the building is burning down around us, time to buy a fire extinguisher

Re: FSF announces Librephone project

#660
post #332

Earlier quoted context omitted.

The camera is also surprisingly software dependent. Using the pixel camera vs using default configuration with an app called open camera, the difference is so clear. The camera is basically all software — the images are pure trash before processing.

I, too, have noticed this. Would be curious if anyone has a more in-depth article to read about why the difference is so stark!

puri.sm/posts/cameras-its-complicated/
Post reply on HN