Maru OS – A complete desktop experience on a smartphone
maruos.com
maruos.com
A basic and egregious security blunder is more than a bit of a red flag.
and makes me wonder if it is the tip of the iceberg.
If you already see that the tip sticking out has a mine on it, the tons of iceberg only give you the difference in the degree of egregiously bad.
The way I see it, this is a "toy" (for the time being). The "2013 devices" makes me thing that this is a "toy" for people like "us" that have a Nexus rotting away somewhere and "it would be cool to fool around on your 30-inch screen and nothing more!
It would be better if they would up-front say "this is not secure", "this is a demo", "this is a toy", "this is not the OS you're looking for".
Imaginary CEO-CTO dialog:
CEO: hey! I just read that we can throw away the PCs and replace them with some old phones that we can buy for $50 on ebay! START!!!
CTO: but.. let me explain.. I quit!!
I'm writing this on a 2013 Nexus, thank you very much! A year ago it stopped booting and I tried searching for a newer, comparable tablet to replace it: no such device exists. I ordered a replacement main board and couldn't be happier. Until someone makes a new 7-inch tablet with a full HD display, it will continue to not rot in my hands for a few more years.
Bolting on security later seldom works well.
As a gadget enthusiast, I loved tinkering with it. But it is simply not practical for daily use (yet). I think it could end up being a nice FOSS alternative to Microsoft's Continuum project, especially if the developer can get it working on a newer device.
This isn't just "unhardened", this is a lack of basic security, and after Mirai, nobody should be doing this shit.
So many other options: not enabling sshd per default, ask for a password, display a random password on the phone, allow uploading a public key... possibilities are endless.
and sure, you can blame it on the people using the software, but that doesn't stop a bunch of ssh servers with default credentials being open to the network.
My definition of super polished includes 'renders without javascript enabled'.
The fact passwords are on by default for sshd on most distributions is crazy.
1. User tries to SSH to rpi over LAN from their laptop.
2. rpi SSH server sends back a request for a torrent of the 1999 smash hit "The Matrix"
3. laptop sends torrent "The Matrix" iso.
4. If the average latency dips below a threshold value, don't connect.
5. If it's done in five minutes, connect.
6. set rpi's SSH server to key-based authentication for strong keypair that was generated on user's laptop.
7. Done.
sshd won't let you login with an empty password by default.
To be fair, I had a Pi2 and used it to watch videos but it died and my tablet or my TV+USB key are more convenient to use now. I guess some people would use a Chromecast instead.
Thank you for all the critical feedback on security in this thread. Maru used to ship with sshd disabled [0] but it was enabled because of all the requests I was getting from users who wanted to run the system headless without needing an HDMI display and BT keyboard/mouse around to set sshd up. I assumed that users would change the default password after the initial login, but as many of you have pointed out, hope is not a strategy when it comes to security. I've opened up an issue [1] to fix this.
Please feel free to open up issues (or, even better, PRs!) at any time if you have further suggestions for improvement. It's thanks to feedback like this that Maru continues to move onwards and upwards.
[0]: https://github.com/maruos/maruos/issues/22#issuecomment-2296... [1]: https://github.com/maruos/maruos/issues/76
It is very easy to accidentally add egregious security vulnerabilities to products if you don't know what you're doing. In fact, accruing small security issues (like this SSH password problem) is the default state of the world.
As a user, I pay the cost when products I use have bad security. If I get hacked via your product, it might be embarrassing for you, but its my device and my data that gets compromised. And because of that, I expect most small companies will not care about their product's security as much as I do as a consumer.
Of course, once a company grows large enough they'll hire a person or a team to look into their software security. At that point they'll fix all the obvious security issues. The database will gain a password. The root AWS account will stop being shared out amongst employees. Work laptops will have full disk encryption turned on to protect against theft, etc.
But until then, as a customer, I should be really nervous. How can you tell the secure products apart from the insecure ones? Well, one of the most obvious signs is that secure products will have already fixed the obvious mistakes. Things like connecting to backend services using unencrypted HTTP. Things like a backdoor-by-default SSH password published on the website.
That is why we (security wonks) make a big deal out of small security problems when they're obvious. They're a sign that nobody has even taken a look at the security situation, and for every obvious problem there's probably 10 more that aren't obvious. This issue might get fixed, but thats why your reply doesn't make me less nervous.
---
And thats a shame, because your project seems super cool and I really want you to succeed! This has come across much more negative than I intended, and I'm more frustrated at the startup industry over this than I am frustrated with you or what you're doing. Hopefully you can get a security review done at some point to make sure there aren't any other simple problems that need to be dealt with. I'm looking forward to seeing where it goes.
"Now it's very simple.If you want to enable SSH, all you need to do is to put a file called ssh in the /boot/ directory.Thats all. And don't forget to change the password"
So how about 'touch sdcard/boot/ssh' to enable ssh ?
Having everything in the cloud seems to have made this somewhat redundant for most users, though I still hope one day I can carry all my data around, of course given proper encryption and backups and the ability to distinguish between safe and possibly monitored (public) displays/inputs.
Or maybe wireless displays are missing so that decision to quickly do a task with a mouse and keyboard leaves out the cable plugging aspect.
As you mentioned, I think this makes it redundant with the cloud when you can make thin-ish clients for everything, like Chromebooks, or Apple and Microsoft's initiatives to seamlessly transfer your workflow from one device to another.
I personally would love something like this. Just in case I need to get some work done off my phone. I do no want another computer.
Have you considered having a cheap chromebook backup or something?
Sure, and those people are the perfect target market for being able to connect to full keyboard, mouse, and display from their phone without the need to buy another computer.
I'm not sure how it worked as Ubuntu Mobile really kinda died off and I never tried it myself.
There are many other projects that have attempted this (none of which I can remember, but I've seen this concept a bunch). It makes a lot of sense. Your phone is already running a Linux kernel. You should be able to create a chroot or a container system that has a standard Linux distribution. You add some hardware/hotplug hooks, some data-sync apps and you should have a Linux desktop hidden in your phone.
Phone < Laptop < Desktop
I used to have a Sony Vaio that I would hookup to big screens at each work space.
Now I use dropbox to sync desktops. My main machine has a GTX 1070 running a 4K @ 60Hz with an m2 SSD, and it was half the price of my laptop (I had to build it, but I had fun doing it). It's ten times as fast. And no more laptop hugging.
I think the key is working with the premise that any Maru user will have a main laptop or desktop. For example, if I could work with my phone in a window on my desktop, that would be amazing. And where I don't have a more powerful machine, I would just connect my phone directly to the monitor. Also dropbox is a must.
I'm surprised my Android doesn't do this already though... How hard would it be for a smartphone to double as a ChromeBox?
"maru" is the default sudo password. When installing debian packages, you may need to enter "root" as a password"
Oy.
If the UIs supported a seamless mode, that would be icing.
It's Android devices after all...
For devices that support a vanilla android, I imagine the driver issue is already worked out and there would be no problem getting them to work in a kernel that you can compile yourself, even if not the default debian kernel.
I realize that some may have a strong preference for OSS software, which a debian desktop would be excellent for.
I owned an Atrix with a lapdock, which was the first device to embrace this concept. Unfortunately, it was poorly handled by Motorola in the sense that you had to hack it to enable a full linux desktop, instead of what was basically a Chromebook.
What really made me give up on it was the fact that it never got updated, so you were stuck with Android 2. It was pretty useful even as a workstation and saved me as I used it exclusively for a couple of weeks, while my laptop needed repair.
I was already thinking about trying something like that again, by getting a phone that had hdmi output and i'll definetely take a shot on that! good luck to them!
In any case it was years ahead of its time.
Sold all the components individually though - I think someone used the Lapdock with a Raspberry Pi in the end.
Yes, you could use some HDMI to DisplayPort adapter and in theory the thunderbolt display should support that, but you'd lose the webcam, ethernet, firewire, USB, microphone, speakers and daisy chaining support as DP does not support the data pipeline.
Is it? This type of “All Your PC Are Belong To Phone” type of fads have been attempted (and so far, miserably failed) for many, many years now. Looking at the website, I see little reason why this should succeed where others have failed.
Perhaps Maru is smooth enough on new hardware?
(Still have the lapdock lying around, now hooked into RPi.)
[0] https://www.riscosopen.org/content/downloads/raspberry-pi
I don’t think this has been done before, or maybe I’m just hopelessly unaware?
Either way, I think it’s quite interesting.
I have a windows phone with continuum and tried it, and while it is executed quite well, it wasn't very useful due to the lack of apps. You can use any windows 10 device as a screen/keyboard/mouse, but usually the laptops I have near me are mine, so they already have everything I need. If it had an ability to carry a self-contained programming environment I might have played around with it more.
It does make a fine fallback presenting device. You put your powerpoint slides on the phone, and if all else fails you can project your slides to any w10 laptop that's near.
I'm glad someone is trying to move forward with the idea of using the very capable computer in your pocket as more than a phone. I mean my current phone has more ram than my last laptop....
It's not like you can use these phone-desktop solutions without a keyboard, mouse, dock, display, etc. anyway. You still need hardware.
As a proof of concept, I've been itching to get a few of those USB SATA toaster things and set them up at my desks. The only hitch is finding a laptop these days with a 2.5" bay that's easy to get to.
Would you use something like this?
It was pretty slow though. These days though, read and write speeds (on USB 3) are over 10x faster. So even without the hardware changes you describe, it's already more than feasible :)
Shared storage
SD card data like camera photos and downloads are shared so you can coordinate your work seamlessly.
This might be confusing for some, given that the only devices supported right now are Nexus devices, which famously lack an SD slot.Should we tell them?
The most successful tablet-laptop attempt thus far has active cooling simply so they don't have to throttle back performance.
It's possible that more energy efficient processors will come about and prove me wrong, but they've been working on the heat dissipation problem for decades now (yes, even in desktops/servers).
This is with a mid-range phone from a couple years ago. I think you're being overly pessimistic.
https://www.extremetech.com/mobile/215724-microsoft-announce...
And desktops are emerging without fans too -
If not, is it able to use the Nix package manager or something like this?
To properly use it, you need:
1) An Android phone (easy to satisfy) that you're comfortable enough installing another OS on (so... a more technical user)
2) An HDMI monitor (which could actually be a TV)
3) A SlimPort USB-to-HDMI cable
4) A bluetooth mouse and bluetooth keyboard
5) No desktop (since using it and this seem to be mutually exclusive for most casual setups)
Most people don't have a bluetooth keyboard/mouse lying around, so the time/cost investment to set this up is not only just installing a new OS on your phone, but also buying hardware (keyboard, mouse, and potentially monitor if you don't already have a computer) [and potentially also waiting for it to arrive if you buy online]. And, after this investment, the target market seems to be people that'd be comfortable doing the above while _not_ also buying a desktop to go with it. So... either technical hobbyists/tinkerers and/or people that want a $50-100 machine (and are savvy enough to set it up).
I would _love_ to use something like this, but I move enough that it doesn't make sense to have a desktop (and, therefore, the same mostly applies to monitor+keyboard), and if I were to live in one place long enough to have a desktop, I'd just buy a desktop (because I likely wouldn't use it _and_ this). Am I just not the target market for something like this (even though it legitimately excites me)?
If I read that correctly, they are just ignoring the problem and share files on the phone between Android apps and programs running on Debian, which seems like it could work most of the time. (No idea if there is Blender for Android, but I am pretty sure there are .doc readers for Android.)
For as many tasks that newer phones could likely take on, you are not drafting graphical work on an iPad Pro, you are not building 3D models for print or media on a frickin Samsung Galaxy and you are not simulating weather patterns and doing storm calculations on a goddamn Windows Phone. The desktop PC is not going anywhere and I don't mean to sound so angry but this constant narrative that is produced by tech media AGAIN and AGAIN and AGAIN that somehow these little, for lack of a better word, toys are going to replace the actual machinery behind the products so many consume is demonstrably false and irritating to read over and over.
How old are you? I thought similar in the 1980's whenever I saw people tinkering with their toy PC's running DOS and Windows 3. They weren't going to replace MVS on an IBM mainframe, or VMS on a DEC, or VME on an ICL. The 'V' in those names stood for "virtual" -- how could PC's replace that?
I wonder how this works: is Android a virtual machine within the Maru/Debian host? It would be very interesting to be able to use the underlying Linux networking, for example, to control the Android functionality.
I want different files on my desktop that I don't want on my phone—like accounting and tax stuff. I might want Skype on my PC, but not on my phone (because I can just call people), etc. etc.
iCloud and similar are a good balance, allowing you to have a shared virtual folder that you can browse on both your phone and desktop and is kept synchronized automatically. Google apps are great to keep things syncronized, too: contacts, passwords (iCloud or Google Chrome), etc.
I use macOS as a desktop OS and Android as a mobile OS, and I'm perfectly happy with using the right tool for the job which works well for what you need to do, instead of a security-nightmare OS and complicated mobile OS.
Just my two cents.
[0] https://en.wikipedia.org/wiki/Mobile_operating_system#By_ope...
And yet, then I think why would I bother carrying a laptop-minus-cpu plus a phone with desktop ability when I could just do what I currently do and carry a phone and a full laptop? I can see this brings a bit of flexibility, and my files/config would always be on my person, etc. But we have global and close-enough-to ubiquitous internet now - isn't that sufficient or even better?
I guess I just don't get the use case. Or maybe I get the use case(s) but not the business case.
The other company that tried was Ubuntu, their effort was called Unity if I'm correct. That was axed recently as they needed to focus on profit-making parts of the company. Also, I don't think any mainstream ubuntu phone with unity was ever released.
Finally, Apple's strategy is clearly different, they see iOS and macOS as clearly different beasts, and will probably never try to directly merge the two. Data-sharing is the way to go for them.
- If I use it on the go, I need an external screen and keyboard. I'd rather carry a laptop or just the keyboard und use the tiny screen (possible with stock android already). And if you are somewhere with a screen, there is probably also a machine at which you could boot some live distro.
- files are "in sync" between desktop and mobile. But the few file-types I open on my phone can just as well be synced over the internet (mostly just txt and a pdf every now and than).
- less expensive (but a desktop that beats a phone is probably also cheap to get)
If there was a really cheap laptop dock for it it might make sense for me, otherwise I don't get it.
Years ago Canonical demoed Ubuntu for Android (http://musho.tk/l/666778c3) which was freaking cool.
Most phones nowadays have means to connect to displays and keyboard/mices. We have cores, speed and ram.
WHY ISN'T THIS A THING YET?
I have seen banks hand out expensive ThinkPads to people to basically use Internet Explorer and Outlook, plus company phones and stuff.
My speculation is that whomever gets this thing right first is going to make a metric futon of money.
I'd like to see: 1. The source code 2. Support for newer devices (might go hand in hand with 1) 3. Support for wireless HDMI adapters, having to carry no cables at all would be very neat, although I guess this needs a power supply to last for any useful amount of time
Carry a keyboard and screen in your hold bag, the phone with your data and applications in your pocket.
Instead of contriving ridiculously convoluted solutions to a non-problem we could simply stop electing politicians who propose implementing ludicrous airport security theatre.
THe problem here is that most of the public believes that security theater is real security. Unless that changes, most politicians will espouse their "firm positions on security" in order to help them get elected.
THe ones who "get it" tend to be in the independent/libertarian camps (last I looked) - and they don't get a whole lot of public support.
I think it can be done. If you think of another notorious modern two-party system neither of the UK's dominant parties today existed before the 19th century. Given how fast opinions spread these days it should be possible to bring about significant change in a matter of years rather than decades. Think about how quickly movements like the Pirate Party became successful in some countries. That they declined just as quickly again in most of these countries can be mostly attributed to their own stupidity rather than systems that are inherently averse to change.
> and peripherals are ubiquitous.
I'm not sure what you're specifically thinking of, with that. I know that I've got many more PC peripherals than phone ones.
This can now be achieved on the Samsung Galaxy S8 with the accompanying dock. It's global, rolled out to anywhere you can buy a Samsung S8.
If a cable has to be used, i'd prefer it to be a single USB-C, which also charges the phone while plugged in and being a desktop. Possibly to a dock with a keyboard/mouse/monitor and other ports.
ARM processors have made some insane progress over the recent years, maybe in another 4-6 from now they will actually be quick enough to really make this a solid experience.
[0] https://groups.google.com/d/msg/maru-os/rsSpHZ0DIJA/mEfp_J9M...
Deleted comment
Looks cool.
> Android
Pass.
Mainline Linux is possible on the 2013 Nexus 7, but you might fry your flash if one of the parameters is wrong.
Probably would need to make a custom OS. I'd probably base it on BSD
Here's where we are today: If I spend any significant amount of time away from one of my devices (phone, laptop, desktop), it piles up with dozens of notifications. Even with cloud based apps, there's no shared state. So when I get back to a device, I have to clear away all the notifications, assuming that they must have appeared on the other device at some point. And if I change a password on my laptop, because of one of the dozens of data breaches that have happened this month, I have to retrieve my new password out of my password manager and re-login on my phone. At any given point, 2 or 3 apps on my phone are in a "logged out" state because I use them primarily on one of my computers, so i'm actually not getting all my notifications everywhere, and I miss some of them.
Also, even with google drive, not every file on my computer is immediately available on my phone and vice versa. So if I need access to a file on the go, there's a good chance it won't be there.
I don't expect this to solve all these problems, but I'm looking forward to a day when I don't have to carry my laptop everywhere I go.