Menu

Main Menu
Talk Get Daily Search

Member's Online

    User Name
    Password

    Jolla - alike, or how Jolla adopted the Google's anti-open-source practices.

    Reply
    Page 4 of 5 | Prev |   2     3   4   5   | Next
    pichlo | # 31 | 2018-02-08, 06:18 | Report

    Originally Posted by benny1967 View Post
    It just so happens that their agenda is pretty close to my personal needs.
    Says the man to whom Stallman is a god, apparently oblivious to the irony.

    To be clear, I do not care much about open or closed. The most important factor is whether it works. Open is an added benefit. And, for the most part, Sailfish does not, which is why I am back to Maemo. But there are purists out there to whom open is the panacea. The fact that they flock to Jolla indicates that they are clutching at straws.

    Originally Posted by
    It's incredible SailfishOS is still there, that Jolla still manages to push updates out. I really don't care what their "agenda" is. All I know is that would they go out of business, there wouldn't be a real alternative at the moment.

    That is one point we both agree on.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 5 Users Say Thank You to pichlo For This Useful Post:
    Amboss, Feathers McGraw, juiceme, mosen, thedead1440

     
    JulmaHerra | # 32 | 2018-02-08, 06:42 | Report

    Originally Posted by pichlo View Post
    It would be nice if people realized that Jolla is just another company with their own agenda. Not the saviour they want it to be.
    It would also be nice if people realized that there won't be a "saviour" without someone with deep pockets and exceptional will to do something without business case. Jolla is just a company trying to build a product to make profit in a way that embraces some parts of open source ideology. If it wasn't, there would not be SailfishOS as FOSS-model doesn't seem to generate much income to startups.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 3 Users Say Thank You to JulmaHerra For This Useful Post:
    Amboss, juiceme, mosen

     
    deprecated | # 33 | 2018-02-08, 08:35 | Report

    Originally Posted by Yaltaaaaaaaaaaaaaaaaa View Post

    And I'm concerned about the privacy threats here too, especially when SailfishOS is to be bought by the Russian Rostelkom. Especially when it comes to things like the keyboard.
    Rostelkom has absolutely nothing to do with it. The Russian interest (especially in the government sector) is to provide an alternative to the CIA/NSA honeypots that come with US agreements and litigation, a la Google/Apple duopoly. The Russian government (and other governments, naturally) don't trust products or services from Google or Apple, and rightfully so.

    Meanwhile, run a tcpdump and look for suspect connections. Trace them back to their source and prove that the packets contain any data that violates Jolla's privacy policy, then I'll start to subscribe to your conspiracy theory.

    More on the point, though, the vast majority of closed bits on Sailfish are the UX and arbitration using Android device drivers.

    If you've a problem with unauditable code or proprietary binary blobs, I have some bad news for you:

    Anything you use day-to-day has arbitrary code that isn't open to public scrutiny, unless you have the good fortune to own one of a handful of older Thinkpads (or a select few other notebooks) or some one-off smartphone with a fabled open baseband.

    I don't think the bits like Alien Dalvik, Exchange support or XT9 should be counted, as they're licensed from third parties. Jolla open sourcing someone else's work after leasing it from them just doesn't make sense.

    If you'd like to develop a completely open binary free handset with an open baseband and a completely open mobile OS, by all means. I'm sure there will be people lined up to pledge their support.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 5 Users Say Thank You to deprecated For This Useful Post:
    Amboss, juiceme, magullo, meego_leenooks1, mosen

     
    benny1967 | # 34 | 2018-02-09, 09:20 | Report

    Originally Posted by pichlo View Post
    Says the man to whom Stallman is a god
    I don't believe in gods.

    I admire people with an extraordinary intellect, people who create something excitingly new, people who change the world and other peoples lives for the better. Richard Stallman is one of them. He changed the world. Without the concept of free software and (more importantly) the idea of copyleft, we'd not be here today discussing Sailfish or Maemo.

    I admire people who stick to their own ideas more radically than others can. It needs those extreme evangelists for us more pragmatic people to find their place on the axis.

    Edit | Forward | Quote | Quick Reply | Thanks

    Last edited by benny1967; 2018-02-09 at 10:35.
    The Following 12 Users Say Thank You to benny1967 For This Useful Post:
    Amboss, ejjoman, endsormeans, juiceme, lal, MartinK, meloferz, mosen, richie, Saturn, sulu, thedead1440

     
    gerbick | # 35 | 2018-02-09, 14:56 | Report

    Originally Posted by deprecated View Post
    If you'd like to develop a completely open binary free handset with an open baseband and a completely open mobile OS, by all means. I'm sure there will be people lined up to pledge their support.
    Playing devil's advocate here; do we really have proof of this in the real world?

    The majority has since traded security and extensibility for convenience and access. Don't get me wrong, I'm all about options - I still consider Jolla an option - but so far nothing has outright stayed an option and been highly adopted.

    Not yet.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 5 Users Say Thank You to For This Useful Post:
    Amboss, endsormeans, juiceme, pichlo, thedead1440

     
    endsormeans | # 36 | 2018-02-09, 15:25 | Report

    Bingo.
    What he said ....
    (gerbick... that is....)

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 3 Users Say Thank You to endsormeans For This Useful Post:
    Amboss, juiceme

     
    marmistrz | # 37 | 2018-02-09, 15:32 | Report

    Originally Posted by deprecated View Post
    Meanwhile, run a tcpdump and look for suspect connections. Trace them back to their source and prove that the packets contain any data that violates Jolla's privacy policy, then I'll start to subscribe to your conspiracy theory.
    Playing the devil's advocate a little here for the whole post.

    Are you sure that your model covers all computationally-bounded adversaries?

    There's a lot of potential scenarios that are not so naive.
    Actually, the naive approach is a really stupid one. If the software is sending some data all the time, the user may notice extraordinary consumption of mobile data. Even on wifi this may be relatively easy to track.

    A clever adversary will filter the gathered data - based on keywords, on the content. Upload it to the remote side only when there's something really big found.

    The adversary may wait for a remote signal to start sending the data gathered. If there's no signal to upload the data, they may even discard it.

    If the adversary is the store application - it may disguise the traffic by intertwining it with real, legitimate traffic - e.g. base64 encode it, split into chunks, add to the payload, recover back at the remote side.

    The adversary may wait with uploading anything until anything worth uploading, and when the damage done is unrecoverable. E.g. when it finds a bitcoin wallet worth over X BTC.

    The only way to prove that this can't be done is to examine the source code - or reverse engineer it. I do not claim this is actually done - but possibly can, and invisible source makes it much easier to hide rogue intentions.

    More on the point, though, the vast majority of closed bits on Sailfish are the UX and arbitration using Android device drivers.

    Originally Posted by
    I don't think the bits like Alien Dalvik, Exchange support or XT9 should be counted, as they're licensed from third parties. Jolla open sourcing someone else's work after leasing it from them just doesn't make sense
    IMHO cjk input on Jolla should not depend on proprietary bits, seeing how good the open-source building blocks are. Keyboard is one of the most delicate areas when it comes to security, that's the perfect place to place a keylogger, and from what I've heard, the cjk input bits are binary .so libraries.

    Originally Posted by
    If you've a problem with unauditable code or proprietary binary blobs, I have some bad news for you:

    Anything you use day-to-day has arbitrary code that isn't open to public scrutiny, unless you have the good fortune to own one of a handful of older Thinkpads (or a select few other notebooks) or some one-off smartphone with a fabled open baseband.
    You seem to forget one thing. It's much, much more difficult to exploit the firmware without userland support than to do that directly in userland (example, let's stick to the keyboard apps: it's much easier to write a keylogger in the keyboard app than in the CPU firmware)

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 5 Users Say Thank You to marmistrz For This Useful Post:
    Amboss, Feathers McGraw, juiceme, rinigus, suicidal_orange

     
    deprecated | # 38 | 2018-02-09, 18:02 | Report

    Originally Posted by gerbick View Post
    Playing devil's advocate here; do we really have proof of this in the real world?

    The majority has since traded security and extensibility for convenience and access. Don't get me wrong, I'm all about options - I still consider Jolla an option - but so far nothing has outright stayed an option and been highly adopted.

    Not yet.

    I'm with you there. I move to what best suits my needs at the time. So far, nothing has nailed it. Not sure it will, either.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 3 Users Say Thank You to deprecated For This Useful Post:
    Amboss, Feathers McGraw, juiceme

     
    gerbick | # 39 | 2018-02-09, 20:32 | Report

    Originally Posted by deprecated View Post
    I'm with you there. I move to what best suits my needs at the time. So far, nothing has nailed it. Not sure it will, either.
    Won't lie. I've not been fully happy with any option since Maemo - mind you, I was not enamored with the N900 due to GPS & telephony issues alongside build quality issues (wonky USB port) - and even then, it was mostly the N810 that my happiness was fulfilled the most.

    I think it's great to want these things, even applaud those companies that attempt it, but then I always see the bickering that comes after an announcement. Case in point, Purism.

    Folks were happy. It was using a chipset that they approved of. Then suddenly... they seem to have folks that are now requesting pretty much outlier stuff and being pushed aside because it's not a device that has an offline pager modem that can be turned off (or something like that).

    Huh?

    A device to satisfy them all has yet to happen. Probably will never happen because somebody will point out some overlooked item that a very minor slice of potential customers will ever require. But they sure as hell vocally want it.

    Until then, I'm forced to use something that I truly do not agree with fully (iOS/Android). I want something that gives me freedom while spying on me less. Or at least let me know WHAT is spying on me because I have access to enough of the source code and can attempt to prepare myself for what is being snooped on. Until then... I'm still wearing my tin foil cap and hoping that helps.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 8 Users Say Thank You to For This Useful Post:
    Amboss, endsormeans, Feathers McGraw, juiceme, JulmaHerra, lal, pichlo, thedead1440

     
    r0kk3rz | # 40 | 2018-02-09, 21:22 | Report

    Originally Posted by gerbick View Post
    A device to satisfy them all has yet to happen. Probably will never happen because somebody will point out some overlooked item that a very minor slice of potential customers will ever require. But they sure as hell vocally want it.
    People are free to be unreasonable, and its to be expected in a space started by a guy who refuses to compromise on basically anything at all.

    I guess the problem is that there are so few projects targetting the 'free open source' market that they end up being kitchen sink products with everything (eg. neo900) or cast aside for not catering to some rather individual requirements.

    Edit | Forward | Quote | Quick Reply | Thanks
    The Following 4 Users Say Thank You to r0kk3rz For This Useful Post:
    Amboss, endsormeans, Feathers McGraw, juiceme

     
    Page 4 of 5 | Prev |   2     3   4   5   | Next
vBulletin® Version 3.8.8
Normal Logout