Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

881–890 of 927 posts

Re: Your phone is about to stop being yours

#881

Earlier quoted context omitted.

Pretty much any modern phone is also full of blobs that run on the main CPU to ensure basic functionality, with only a handful of exceptions. Just consider how many features stop working or get severely degraded on various phones when you use a clean AOSP build on them (provided that you can do it at all in the first place). Android's driver infrastructure effectively encourages non-free blobs in "vendor" partitions,…

> You can have "some debate" on absolutely anything, but that doesn't yet mean it makes any sense. Sure, but from the fact that anything can be debated it does not follow that any given debate is nonsensical, which is kind of what you did there. > ...whatever debate you're referring to is unlikely to be held in good faith. I don't know which is odder, that assertion, or the notion that two completely different securi…

> I only mention that because a contingent of voices as high in volume as they are few in number endlessly shoehorning the Librem 5 into numerous threads no matter how much of a non-sequitur it takes, has me suddenly paying more attention these days to what's coming from the Purism camp. The more I do the more disingenuous the rhetoric seems.

It seems to be mainly fsflover. You can search “Librem 5” messages in HN and it’s flooded with messages by them.

https://hn.algolia.com/?dateEnd=1777075200&dateRange=custom&...

https://hn-wrapped.kadoa.com/fsflover

Re: Your phone is about to stop being yours

#883
I don't get it. Just ten to twelve years ago we did just fine without mobile banking apps. Just go to the bank. I've been using graphene with no g shite for a year and have zero issue paying bills on my laptop. If my bank starts requiring two factor from an app to pay in a browser I'll switch banks or just cost them money by paying in person.

Re: Your phone is about to stop being yours

#884

Earlier quoted context omitted.

I'm tired of arguing with you. I see no effort from your side to come to some understanding or to clarify anything. Here's why. > On the Librem laptop, the tampering is done by PureBoot What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say. > If…

> I see no effort from your side to come to some understanding or to clarify anything. Accusing me of your own sins. > What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say. On the laptop, messing with the system memory (/run) and dumping firmwar…

A bit aggressive, but understandable.

> If anything, it makes it harder to audit and figure out which firmware version is being run than if the firmware were to be shipped along with the OS.

Yep. https://docs.puri.sm/Hardware/Librem_5/Maintenance/Modem.htm...

"These files are controlled by a third-party and are not publicly accessible. Contact Purism Support to request these files for a firmware update"

---

Don't bother arguing with fsflover. They're a Purism evangelist that refuses to view things objectively.

https://hn.algolia.com/?dateEnd=1777075200&dateRange=custom&...

https://hn-wrapped.kadoa.com/fsflover

---

Damn. They even argued with marcan (Hector Martin known for Asahi Linux) in 2022. At this point I'm guessing they're a bot.

https://news.ycombinator.com/item?id=29841267

---

For fsflover, what Purism is doing is moving the non-auditable part of the OS onto a separate storage device so that they can claim that the OS is "Fully Auditable" and FSF certified even though the non-auditable and non-free part is mounted into the OS filesystem during boot. It's deceptive marketing and you're spreading that marketing.

Other open mobile OSes aren't trying to hide the fact that there needs to be proprietary components for hardware.

The only thing I concede is that the drivers are FOSS, which is why some performance and functionality is degraded compared to phones using non-free drivers. You could develop an AOSP phone using the same FOSS drivers as well, you'll just have the same issues.

Re: Your phone is about to stop being yours

#885

Earlier quoted context omitted.

> https://news.ycombinator.com/item?id=47943487 You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487

Because it's true, and I know what he said, I am not confused at all. Did you not read anything at all? On the Librem laptop, the tampering is done by PureBoot and inject into /run/firmware. The other user was linking the stuff with the laptop. *On a Librem 5, it is stored on a separate chip, then they read it with the initramfs, then mount it on top of the regular filesystem at /lib/firmware*. Like I said, it's just…

For the record, the "jail" only exists so PureOS (or any other distro) does not have to distribute any blobs within its repositories or include them in their images - though distros still can if they choose to, like postmarketOS does for example. There's very little difference between a firmware blob that's stored in a peripheral's internal flash, NOR flash or OS rootfs when it comes to user freedom, in the end it gets executed the same way on the same hardware. Having a separate place for these blobs only simplifies their management and allows to put a clear distinction of what's free and what's not. The important thing is that, regardless of whether the "jail" is used or not, there's not a single blob that runs on the user's CPU within the user's system on the Librem 5, which isn't a unique property for a phone but rare nevertheless; the peripherals are a different thing and Purism has never claimed that there are no blobs there (in fact, the existence of e.g. the DDRC blob was being highlighted already in very early development).

(also, the NOR flash itself already had to be there because that's what TPS65982 boots from, so the "jail" is just using the 4MB storage that would otherwise remain mostly empty)

Re: Your phone is about to stop being yours

#886

Earlier quoted context omitted.

> I see no effort from your side to come to some understanding or to clarify anything. Accusing me of your own sins. > What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say. On the laptop, messing with the system memory (/run) and dumping firmwar…

A bit aggressive, but understandable. > If anything, it makes it harder to audit and figure out which firmware version is being run than if the firmware were to be shipped along with the OS. Yep. https://docs.puri.sm/Hardware/Librem_5/Maintenance/Modem.htm... "These files are controlled by a third-party and are not publicly accessible. Contact Purism Support to request these files for a firmware update" --- Don't bot…

> what Purism is doing is moving the non-auditable part of the OS onto a separate storage device so that they can claim that the OS is "Fully Auditable" and FSF certified even though the non-auditable and non-free part is mounted into the OS filesystem during boot.

Yup, that's part of it.

But remember, even if they didn't do it, there's still a matter of them by using components with internal flash storage for the firmware instead of shipping firmware with the OS and letting the OS upload them. Like that's not a hackjob like the /lib/firmware or /run/firmware stuff or anything, but it's not like it's any more "open" than any other system, if not being a bit more opague. Of course the marketing would still be deceptive then.

Re: Your phone is about to stop being yours

#887

Earlier quoted context omitted.

> We are not on a normies forum but on HN. Being on HN does not mean that you are familiar with the intricacies of hardware and low-level software. > I only say, that if you want to have a third option, you can have it today. There will be compromises, which can be dealt with by technical users. I think it’s irresponsible to promote it as an alternative device without noting that it’s less secure and full of footguns…

This is not a forum with legal advises. I inform people about an option, which they asked for. GNU/Linux phones have a similar security approach to GNU/Linux on desktop. People explicitly seeking GNU/Linux should know this. They can also ask or search the Internet. > I think it’s irresponsible to promote it as an alternative device without noting that it’s less secure and full of footguns I disagree with you here. In…

Relevant conversation about those technicalities: https://news.ycombinator.com/item?id=30042576

Though with a username of fsflover, I think you'll be biased.

Also, another relevant thread (that you were even a part of!) discussing the pointlessness of what Purism did to fit the technicalities: https://news.ycombinator.com/item?id=29841267

It's actually worse than I thought. There's the initramfs /lib/firmware loading workaround for the FSF certification of the OS.

But even before that there is code run by the main CPU that loads instructions for the secondary core to load a blob from separate flash memory to pass to the memory controller to initialize it.

All that just to attempt to fit the technicalities of the FSF RYF hardware certification while still loading a blob like every other phone microprocessor.

---

It's interesting that I could make a device that burns efuses to make it obsolete and it could still be considered FSF Respects Your Freedom certified.

Re: Your phone is about to stop being yours

#888

Earlier quoted context omitted.

Plenty of useful apps != general purpose computing capabilities. You are not allowed to run computations that have not been approved by Apple if you are using an iPhone. Yes, the hardware is powerful, but it is cryptographically locked down. It is physically local, but the control of the hardware is entirely non-local and 100% owned by Apple.

unless you're using an API that requires an entitlement, you can still get an apple developer account and sign whatever code you want and run it on your devices.

Technically you don’t even need a dev account to run your own app. You need a dev account to distribute it in TestFlight and on the App Store.

You can install your own “Flip Off Steve Jobs” app directly from Xcode if you so desire.

Re: Your phone is about to stop being yours

#889
post #207

Earlier quoted context omitted.

Or /e/

/e/OS is not (y)our friend. The CEO of Murena says that security hardening is only pedophiles and spies: https://mastodon.social/@GrapheneOS@grapheneos.social/116353... https://www.clubic.com/actualite-604786-murena-e-os-intervie... They spread the same narrative as the governments/organizations that push Chat Control, age verification, etc.

Weird way to promote the /e/ project.

Your first sentence and that last link are practically at war with each other.

Re: Your phone is about to stop being yours

#890
post #207

Earlier quoted context omitted.

Or /e/

GrapheneOS is significantly more secure, more private, and more free. Not sure why you would use /e/.

I can see the alure of having a very secure mobile device and can understand why you personally wouldn't see a reason to use anything else.

But Graphene requires too much fidling to get spouse approval.

/e/ might not be as secure as GrapheneOS but it is at least as secure as everything else. Plus it actively helps you preserve your privacy and use self hosted services.

Post reply on HN