back

by calvinmorrison·7y ago·view on hn ↗
2019, the year of an open source phone. I almost can't believe it. I'm super happy they're not reinventing the entire wheel and are using an ecosystem that already exists (GNOME). Much of the non librem specific work is being done upstream which is great.
5 comments
Hopefully also the year of Linux (with the standard desktop stack) on touch-first and small-screen devices, thanks to Librem 5's choice of cooperation with the overall Linux community. Admittedly, we were there before with environments such as QTopia, GPE and Hildon, but these were niche efforts targeted to a handful of very expensive and low-performing devices (thus, their code was never shared "upstream" as is happening now)-- the situation today is quite different.
An Open Source phone would only be actually beneficial if there will be an automated transparent and trusted global support infrastructure for it that would require zero user interaction.

I use an iPhone because it’s the most secure hardware and software combination you can get and you are guaranteed to receive support for 5> years.

I don’t want to have to compile my own kernels, set up my own chain of trust or deploy my own patches. It’s too cumbersome which would lead to procrastination that is if you don’t screw up something in the process to being with.

Also as far as the hardware goes I have currently more faith in Apple being able to get and secure its supply chain than a small company which completely relies on Chinese OEMs for its design.

The baseband will not be open source, it will have to use blobs as such other than running a more vanilla flavor of Linux I don’t see it being any different than any phone that can run AOSP.

Yet you get hardware kill-switches for the baseband and mic that assures you of your privacy when you require it. Much better than any 'assurance' from Apple that you can trust them to be the good guys. Has everyone forgotten that Apple, along with every other major platform, complies with FISA requests or their foreign equivalents? How do you think Apple operates in China?

They will be good guys until they decide they will not be good guys for arbitrary reasons or if they are forced to comply with a Government decree.

I'd much rather put my trust in a good-enough hardware platform that I _know_ I can control when required.

As long as your network traffic is sanitary before it hits the baseband (Tor, VPN, or something you trust) you're good on that end. A better design would be to have three settings for the mic: baseband, app processor, killed, so you could run the audio path through free software as well (VoIP). The idea is to minimize what the baseband is doing in the system, and assume it's malicious. It's hard to duplicate PhD person years on the signal processing side, and, if you get that far, then navigate the IP minefield.
Can some baseband processors access memory on the host processor?
Strong disagree; progress is progress, and not yet being perfect does not make it pointless.
Yep. It’s a bad philosophy when it actively deflects from possible changes to the circumstances comprising progress. In this case, it’s much easier to make an open source phone than cell network. Not to mention no one has the sort of capital to setup an open cell network.
Being imperfect relative to the flagship commercial phones is a problem, because ultimately end-users have to use these things for them to remain going concerns, and it's hard to see which users are better served by a less secure phone stack.
That would be imperfection in terms of features, not security. And yes, users do need to be able to actually do what they want, but the bar isn't that high and it certainly isn't uniform; some of us are happy with web browser, SMS, and a shell. Further features will widen the appeal, but for starting out they seem to be doing fine.

I believe that it is at least an equally secure phone stack vs most Android (granted, with the root of trust in the user rather than manufacturer, which I think is a good thing), and only might lose against Apple and Google flagships thanks to hardware features.

"Versus most Android" is, of course, a dodge, because the Android ecosystem ranges from comically insecure phones to expensive devices that asymptotically approach the security of iPhones. Achieving parity with commodity Android devices doesn't help end-users; every user who uses a Librem device to obtain that weak level of security has probably been harmed by the project.

This isn't to say that it's impossible to build a device that is more secure than an iPhone! It isn't. Librem simply isn't doing it; they have other priorities, including feature parity with modern smartphones. They're not willing to make the serious tradeoffs needed to get security given their circumstances.

By "most Android", I mean "everything without a Titan chip". I'm not convinced that it's meaningfully less secure for anything but targeted attacks by abnormal skilled attackers. Should be better, if its kernel is better maintained.
Considering the plethora of ARM trustzone and bootloader attacks against Android devices I don't think an abnormal skilled attacker means what you think it means the average repair shop can extract data from the majority of android phones today.

You also have successful key recovery/bypass attacks against most non-hardware backed crypto Android devices as well.

Like Thomas said it's not impossible to build a secure device, it's not even impossible to build a secure open mobile device but it doesn't seem that they are doing it.

Their focus is on having feature parity, using commodity hardware and just having an FSF approved stack. Having an FSF approved stack doesn't make you more secure by default.

And usability has a great impact on security, I remember the early android days where getting a file off the device was PITA so myself and many others were running an FTP server on the phone, and since most of our phones were rooted im pretty sure it was running as root.

The other side is things like permissions while mobile operating systems aren't that great still they've began taking application permissions really seriously going through the Librem documentation I don't see anything that is even remotely close to the level of granularity that Android and iOS offer today.

Sure they might add that in the future but the point being is still that there is little chance that the first phone they launch would be more secure than an android phone yet alone a modern iPhone in fact I would bet at least one paycheck that they would be considerably less secure at least initially, and then it's the question of how they would be able to maintain and support their platform given their size to begin with.

I don't doubt the intentions of the developers I just highly doubt that anything they set is even remotely achievable.

>An Open Source phone would only be actually beneficial if there will be an automated transparent and trusted global support infrastructure for it that would require zero user interaction.

I think that's a given except for the zero interaction. Even my android phone alerts me of updates. Anyways, you make it sound like it's nearly an impossible task, but nearly every day my ubuntu laptop alerts me of updates and then updates in the background far more seamlessly than my windows workstation. Plus the distro has over 4 years of support. This is something linux distros figured out years ago.

Updates on Android phones are carrier, region and OEM dependant.
I don't know what Librem 5 will offer in the end, but I think your response argues a false dichotomy with zero evidence. There is no "automated transparent and trusted global support infrastructure [...that requires] zero user interaction" for anything and (given how we improve things in real life) apparently such a thing is unnecessary. If you want to know how something works, you either learn how it works and do the vetting & improvement yourself, or get someone you trust to do this work on your behalf. Computer hardware and software is no different. The question is whether you're allowed to do this work at all, whether it's possible for you to hand someone you have good reason to trust the device and software to do this vetting for you.

There are many good reasons not to trust Apple or any proprietor. You claim an iPhone is "the most secure hardware and software combination you can get" but you offer no evidence to let us understand how you arrive at that conclusion. Proprietary software (such as iPhone's default OS, iOS) is untrustworthy by default because nobody but the proprietor has permission to inspect the software's source code, alter the software to fix problems or improve the software, or help the community by distributing improved software. You don't have the freedoms of free software (running, modifying, sharing published computer software including commercially). So in order to estimate Apple's trustworthiness we can't examine the thing itself in the most reasonable and thorough way. We have to fall back on something else such as Apple's reputation and consider how they treat their users. Apple left years-old remotely-exploitable security bugs in programs thus leaving users vulnerable (see http://www.telegraph.co.uk/technology/apple/8912714/Apple-iT... or https://truesecdev.wordpress.com/2015/04/09/hidden-backdoor-... for details). When it comes to iOS issues things are no better: iOS is the prototype of a software jail (hence the term "jailbreaking" to liberate one's device, and thus the user, from such control). Apple can and regularly does extract data from iPhones to give to the state (per http://arstechnica.com/apple/2014/05/new-guidelines-outline-...) and Apple's claimed security improvements rely on software users can't vet, improve, or share. https://www.gnu.org/proprietary/malware-apple.html has lots of examples of various kinds of Apple proprietary malware many examples include software iPhone users run. Apple also works against letting users get fixes without going through Apple, slows down iPhones users won't "upgrade", and disallows using older versions of iOS or non-iOS operating systems (because why let users control their computers).

This is all par for the course with proprietors; proprietary software (nonfree software, software that doesn't respect a user's freedom and community) is often malware (software designed to mistreat its users). The worst part is that because these programs are proprietary, motivated and knowledgeable users are not permitted to vet, improve, or distribute software that could benefit themselves and the entire community.

Just like Maemo did, oh well.
Maemo phones did not isolate the cellular modem from the rest of the system. Also, a number of essential packages on the Nokia N900 were (and still remain today) closed source.
It's odd that Jolla doesn't just open-source Sailfish OS.
Jolla doesn’t make devices any more. Their only business case is licensing their OS to paying customers. While many packages in Sailfish are open-source, naturally the company is holding back a lot of things in order to serve as the exclusive provider of the OS.
Weren't a lot of the useful components for Maemo open source? Eg: the GTK+ Hildon stuff for example? Why can't/didn't Purism re-use any of that?
A number of under the hood elements are being reused. Telepathy still drives the messaging system, and ofono is being used for the modem. The GTK2 UI from Maemo was dead in the water even before the shift to QT when Meego was released, so it makes sense that they would base a new GTK UI on a modern Gnome. A QT UI is available in the form of SailfishOS.

Regardless, the "interesting" work on the Librem 5 sits with none of these levels, but further down the stack, with mainlining the kernel work needed for the device. After that, the userland work provided by Gnome/Plasma Mobile/Ubuntu Touch/Mer all become interchangeable.

Sorry off topic but if I could follow one person for experience, not bring biased and knowledge of the state of the art of software tooling (and tonnes of other things... but tools are useful and not easy to find) then I would follow you. Your comments are very informative.
Thanks, just a random grey beard guy with too much free time between builds. :)
While I use Gnome, and like the way it looks, I feel it's a mistake on a phone unless they are doing a lot of heavy editing. While it's gotten better, the JS -still- leaks and randomly pegs the CPU. In a phone I would imagine a battery life measured in minutes.
The in-development "Phosh" shell does not use JS at all; it is not based on GNOME Shell, even though the work on Phosh is being done as part of the GNOME project.
Without running the exact numbers I feel like running down an entire average size cell phone battery in a few minutes would lead to everything bursting into flame. I don't think an average cell phone cpu can actually exhaust an average battery in that time frame.

I feel like if it were going all out at all times for no reason it would still last a few hours.

Also pretty sure this thing runs gtk apps NOT gnome which renders your analysis flawed.

Yours and other comment did reveal my analysis was flawed, thanks for that.

Re: the first two points, I really don't think so. I have a Nexus 5x that would kill the battery in around an hour if video chatting (to your point, it did get very very hot). There is also a recently revealed 'bug' in the NXP SoC being used by Librem themselves, who claimed it was killing the battery in an hour. I figure anything under 2 hours is fair game to be 'measured in minutes.'

How old is the battery in the nexus 5? It's a 5 year old phone at this point. Daily charging could have put it through 1000 or more charge cycles at this point.
Isn't 2019 the year of Linux on the desktop? :)

I'm willing to put up 100CAD that it won't ship this year.

Pardon my ignorance but what is the criteria for a linux desktop being a thing? Is it a certain minimum market share?

There's plenty of linux desktops out there. There is certainly a ways to go, I'm not trying to deny that, I'm just wondering what constitutes a successful linux desktop. User-friendliness? Where are the goalposts exactly?

I think "year of Linux on the desktop" is mostly an old Slashdot meme. There are no specific goalposts, it's just used to make fun of Linux adoption.
As with many fine things, not everything in life is about how many people are ... , but who is.

To bend Obama's words a bit: If you’ve got a computer business, you didn’t build that. Somebody else made that happen.

I'd take you up on that bet. The Librem 5 will ship this year.
That was 2016. With wsl ;). Oh wait, the year of gnu on desktop I meant. And the year when Linux could drop any hope of being used on desktop.
If you lose you should Sonate the money to them
If they ship a final product by 2019-12-31, I'll donate 500CAD to any charity they pick
How about you commit to buying their device if they do ship it this year. I'd read those blog posts about your experience - along with any doses of humble pie you ~may~ have to eat.
I'll commit to buying one.
Please do this.
To quantify this now. Are you counting a final product as them going GA, allowing anyone to buy and get one? Or are you counting a final product one that you do not consider beta. The latter is very open to interpretation.
Going GA and shipping to customers.