Debian for Mobile
mobian-project.org
mobian-project.org
Privacy&security trustworthiness-wise, Mobian is an unknown quantity (at least, to me).
That should be a big concern for something as sensitive as a smartphone/handheld, which tend to handle people's electronic communication, authentication for even more sensitive resources, etc.
One path to trust would be to become an official Debian project, and to be scrutinized by broader Debian people.
And the Mobian Team: https://gitlab.com/mobian1
Debian packaging has a nice feature too in that you can check the source used to build it, and any of the packages will be reproducible. So if you don't trust any of the Builds on the Mobian repository, you can actually check them all yourself.
For any sufficiently large project, this becomes basically infeasible unless you have serious resources or known risks to account for.
"You can check the source" is almost a meme - how many people check the source of stuff they use? Likely very few. Most depend on history of trust and audits, and well funded groups paying people check.
Debian packaging (the quilt format) will watch the upstream git repo and will error out if the repo being packaged is different than what is upstream. The only way to add patches is to put them into the "Debian/Patches" folder and explicitly put them in there.
In addition, one of the default CI pipelines for the Gitlab called "reprotest", which checked various environment differences to ensure that the package is reproducable.
The outcome of this is it is signifiantly easier to check that a downstream package matches upstream for the average person, rather than checking all of the source, they can look at where upstream points to and check if reprotest passes.
If someone is going to insert vulnerabilities, they are probably going to hide it well as an innocent-looking patch. So, you need a C security expert. Moreover, they probably need to do this work full-time to inspect every patch, since you do not really know what you are looking for.
As the recent covert introduction of vulnerabilities in the Linux kernel [1] and Debian OpenSSL incident [2] have shown, catching patches that introduce vulnerabilities is hard.
[1] https://lwn.net/Articles/853717/ [2] https://lwn.net/Articles/282038/
At any rate, I think the approach taken is fine. The project is actively upstreaming changes to Debian. But if you care about security, etc., it is probably better to wait until the changes have landed in Debian and you can install vanilla Debian.
Respectfully, I do not think so. I went into great detail about how Debian has technical measures to prevent tampering from upstream. If one does not trust upstream programs....well that is a bit out of scope of this issue.
> Who is going to check all the patches by hand in debian/patches?
By policy, we only introduce patches there if it is absolutely necessary, so there actually aren't very many assuming you really want to. I'd argue its a tractable problem.
> But if you care about security, etc., it is probably better to wait until the changes have landed in Debian and you can install vanilla Debian.
As I said earlier, many of the Mobian devs are the same as the Debian on Mobile team, so assuming you don't trust the Mobian devs, you probably shouldn't trust the packages we put in Debian proper as well.
This was actually the whole point.
People say "trust us because you can check the code" but checking the code is so complex that you need trust because you can't verify everything.
> As I said earlier, many of the Mobian devs are the same as the Debian on Mobile team, so assuming you don't trust the Mobian devs, you probably shouldn't trust the packages we put in Debian proper as well.
This is where the trust comes in. Not in the availability of the code.
There are still quite some packages that are not reproducible:
https://tests.reproducible-builds.org/debian/reproducible.ht...
If you look at the list, including some core packages such as gcc and Perl.
Reproducible builds are an additional safety net and you can easily check what differs between builds.
Debian packaging has a nice feature too in that you can check the source used to build it, and any of the packages will be reproducible.
Which is demonstrably false, as the link in my comment shows.
[1] I never said that packages are not peer-reviewed.
Debian is currently in freeze but after the upcoming release it will start getting quick updates for every package.
The Mobian project is uploading the majority of its packages into Debian already and the goal is to reach 100%.
At that point it will be only plain Debian.
This website looks like it got put together by a bunch of hackers, which is fine, but to attract even more contributors and other enthusiasts it might be good to at least put an intro and screenshots on the main page.
Yeah, we try not to gatekeep folks from editing the Wiki, which is a double edged sword, like you said.
> which is fine, but to attract even more contributors and other enthusiasts it might be good to at least put an intro and screenshots on the main page.
Thank you for the feedback! would there be anything specific you would want to see for an intro/screenshots?
It's the first thing I look for when I'm curious about a mobile (and presumably animation-heavy) piece of software.
If you have any specific you find that would be useful, I am happy to add them as well.
https://wiki.mobian-project.org/doku.php?id=devices
PostmarketOS runs on more devices (and is a great Distribution!), but they also run a lot more devices through Halium (which is a compatibility layer).
So then out of curiosity, how are you all able to port to so many devices? Do you have a bunch of volunteers, or all most of the devices not too difficult to port to pmOS?
pmOS has really good tooling called pmbootstrap. They are able to use the downstream kernels directly (or a mainline kernel if the device supports it), and it generally isn't too difficult to get pmOS to boot with the downstream kernel. However, because of the downstream kernel, you may not get a lot of features, and will have to work to port the features to pmOS.
They also have device catagories, so if someone wants to see the status of a device, they can look here: https://wiki.postmarketos.org/wiki/Devices which bins the devices for a user to quickly understand how well a device runs pmOS.
So developing for Mobian is no different than developing for Debian (in fact then I don't need to use the Modem, I just do all of my development on a Debian Machine).
So this isn't a Mobian issue per se?
EDIT: I also checked, you can install PWAs via Epihpany (which is installed by default on Mobian).
For applications, Debian ships firejail.
Not explicitly no. Implicitly, it would be the same as Debian, and I would argue we go for sane/common sense security defaults.
Is there a particular threat your worried about/want me to comment on?
https://blog.mobian-project.org/posts/2021/02/18/what_is_mob...
And the basic answer is:
"Mobian aims to integrate the standard Debian distribution with Phone-specific projects and modifications in a distribution that works on certain mobile phones and tablets, such as the Pinephone, the Pinetab and the Librem 5. The idea is to minimize the Mobian specific pieces by “upstreaming” changes to the original projects as much as possible."
Its a wiki for a lot of tips and tricks to get Mobian working on the Pinephone. It has a couple of other devices it will run on, but the Pinephone/Librem 5 are the most mature.
(Disclaimer: I'm one of the devs for Mobian).
(You can of course compile the GTK 4 stack yourself if you want. It's Linux after all.)
> Should I use it?
I mean...of course i will say "yes you should!", so I guess I am more curious what you are expecting or if you have specific expectations?
> What should I expect my experience to be?
Mobian uses Phosh as the default environment, so if you have used any Pinephone Distribution with Phosh, that's about what to expect.
If you have not used Phosh....well to be honest I do not know of any good Video reviews for it, but I imagine such videos exist.
> Is the OS stable? Are there apps that crash a lot?
The OS and the apps are stable, Mobian is based on testing/sid, but if we have apps that arenot a part of Debian proper, we try to make sure they are stable.
> Should I be aware of any shortcomings that would hamper a normal phone experience?
Using it as a phone is almost there, but for me, the notable shortcoming is the lack of MMS. This is being worked on (actually I have been the primary person to work on it), and I am hoping it will be included sooner than later (within the next couple of months). I have also been working on getting Visual Voicemail to work.
Wifi Calling also does not work, and no efforts have been made on that.
But Calls, SMS, Voicemail, VoLTE (though this can be carrier dependent) all work!
Debian on Mobile team: https://salsa.debian.org/DebianOnMobile-team
Mobian Team: https://gitlab.com/mobian1
[0] https://github.com/orgs/droidian/projects/1 [1] https://github.com/orgs/droidian/projects/3
Android in the hand, Tux on the dock.
They have a "terminal" layout, which works well for me when I need more full-PC layouts.
But the default UI based on Phosh is problematic. Minimal configuration, broken and convoluted approach to scaling makes it rather hard to use.
Also, no project mailing list?
I’ve been eyeing the Pinephone for quite some time now. Do you use yours as a daily driver? Or have you paired it with an a more-mainstream iPhone/Android?
I’m currently using an iPhone as my social circle uses primarily uses iMessage and I’ve found it hard to migrate. As a secondary device for debugging, testing, and a “burpsuite playground” I’m using an extremely cheap Nokia I picked up a few years ago.
I think a Pinephone would be cool to replace the Android I have.
Apple loves to lock you into their ecosystem (need an iPhone to use Apple Watch, etc), but iMessage is incredibly effective and often overlooked. If you use it heavily and want to move away from Apple, your options are to simply not take part in those conversations, or to convince everyone else to switch to something else. It sucks.
I know many people with iPhones but nobody ever tried to invite me to an iMessage group chat. Nobody even tried to message me with it directly, because it would have switched over to SMS and I've literally never had an SMS from a person. Just automated notifications and spam.
Not that we're much better off here because we're still stuck with proprietary stuff like WhatsApp but at least it's not locked to one platform.
Now that this has some attention, what can people like me and other readers do to help you get this over the finish line?
(thank you!)
Long story short, I have been working which the Chatty developer to integrate MMS support into his program:
https://source.puri.sm/kop316/chatty/-/tree/wip/sadiq/mm-acc...
The primary program for MMS support is here:
https://gitlab.com/kop316/mmsd/
I have a few TODOs on that (which I haven't had tine for recently, but I should be able to get back to it this week). There's a few TODOs in there, so maybe work on them? (But then again, it's more a function of working with the chatty Dev than anything else).
Help testing and refining the code is also welcome too!
There is also a Matrix room you are welcome to join if you want to help, or to see how things are:
I haven’t tried mine nowadays, and there is always great progress when I check back, but I simply can’t imagine using it as a daily driver.
Why do you say that? EDIT: Sorry, I did not read your whole comment. I would offer that Phosh has gotten more and more mature, and I find it to work extremely well now.
> Also, no project mailing list?
Most communication with Mobian happens on the Matrix Channel: https://matrix.to/#/#mobian:matrix.org
Well, my main issue with Phosh is that it seems to be designed with assumption that display scaling is set to 2. But Pinephone display is not high-DPI enough to justify that, so many applications are unusable with that (or need application-specific workarounds, like setting zoom to 50% in Firefox and terminal to counteract that).
One can set display scaling to more fitting 1, which fixes applications but breaks Phosh, who now has icons too small to be practical on touch screen. And i do not see a reasonable way to confugure icon sizes short of replacing GTK resources for that or perhaps writing custom GTK-CSS style for that.
there are also some interesting reverse engineering details here: https://xnux.eu/devices/feature/modem-pp-reveng.html
I get the impression Mobian is more like Debian itself. anyone is welcome, whatever tech you have.