This is backed by hard data on malicious attacks from the Dept. of Homeland Security and the FBI. 79% occurred on Android, and just 0.7% on iPhone.
I'm also 100% positive this will have no effect on the reasoning of the FSF.
This is backed by hard data on malicious attacks from the Dept. of Homeland Security and the FBI. 79% occurred on Android, and just 0.7% on iPhone.
I'm also 100% positive this will have no effect on the reasoning of the FSF.
You have got to be kidding.
For an ecosystem where its been the 'norm' to slurp users entire address books[1], NOTHING about Apple's 'curated, controlled' approach protects users.
Please get real.
1. https://news.ycombinator.com/item?id=3563016
2. https://news.ycombinator.com/item?id=5632934
3. https://news.ycombinator.com/item?id=3564830
4. http://www.idownloadblog.com/2012/09/27/facebook-ios-6-phone...
Yes, Apple just told us your fingerprint will be stored locally. So? Does that mean Apple si telling the truth, or couldn't leave a backdoor for NSA to get the data? No it doesn't, and we wouldn't know if they did do that. That's the problem with closed software.
It's also a guarantee that Apple knows this, so why bother lying?
That's also the problem with open software people get off of the internet/provider in binary form instead of compiling it themselves.
That is, all software.
I don't have a solution for this problem, I'm just commenting the fact that it is more complex than "compile from source" and that you have to draw a line somewhere unless you assemble your hardware from raw materials and write your own software.
If one is going to reason in black and white, then the only answer is that everything, absolutely everything, is susceptible to being compromised. In such a black and white world, there's no security benefit for open source software, because it is also possible that you could be tricked into running something that compromises your security, as it is also possible to have a design flaw in the architecture of open source code, as it is with closed source code.
It is only when one allows the concept of risk that a coherent security picture can emerge. Leave absolutes to mathematical proofs, and trust and risk assessments to the real world, at least until we can prove code correctness for an entire computer system.
Not stretching the point at all, because this isn't the only case of a security or trust breach, and once that is broken, you have no reason to trust them again.
OP's post made the ridiculous claim that somehow Apple's 'controlled' approach protects users. I provided evidence which proved that false.
Blame Path &c., not Apple, for abusing a feature that was originally provided for the convenience of developers and users together.
> Blame Path &c., not Apple
Oh sure, I won't blame Apple for leaving the door wide open and turning a blind eye for years! Wow.
This is foolish. Every non-trivial piece of software will eventually succumb to a security flaw. This does not mean the software is untrustworthy in toto.
You fix the bug and move on.
You may not have any interest in those restrictions on communication, but you'd have an easier time getting someone to admit their ignorance.
Anyway, for years apps have been collecting user data without interference.
My point still stands. Apple can't protect users on their own platform. Keep those blinders on, I guess.
> NOTHING about Apple's 'curated, controlled' approach [that of having a closed source operating system] protects users
Definitely shifted goal posts.
Unrelated: you've said nothing to support this point anywhere throughout this thread.
That's not true.
Nah, no where did that happen. It's just hard for some people to handle truths and make connections.
The address book was an example of that.
Open source software freedom means the freedom to write software that slurps up whole address books.
And it's the user's responsibility to read the source code to ensure it's not doing that. Because obviously most people are capable to do that and also have the time to do that for every piece of software they install, right?
At the end of the day, I'd rather Apple and the NSA have my data than some random hacker in russia.
I'm running swype (a keyboard) without access to the network (it crashes if it tries to update) and it works just fine for its intended purpose.
And 2.3 is OLD!
oh, and no, google android and operator/major brand abused android sucks and should be left out of this discussion. Buying locked phones (and by locked i mean the boot loader being blocked) is the same as buying an iphone. sadly.
I know what "Free Software" means. Your definition has no connection to what you assert here: "Apple could still have audited free software into its appstore as it does for nonfree software currently."
So, unless you're suggesting that apps be distributed as source code, and compiled locally on your phone, there's no way to determine if the binary the App store distributes is an accurate uncompromised representation of the original source. Furthermore, expecting normal users to examine source code for security holes is an unreasonable burden. The security of iPhone apps is based on how much we trust Apple to maintain that security, and to review the apps. Not in our personal freedom to examine the source code, which we can do already, for many apps.
You confuse developer control/freedom with user control/freedom. They are very different things. A user doesn't have programming skills, and their personal interests are in freedom from malware- freedom from developers that have the ability to do whatever they feel like with the user's data. They have no interest in being able to compile their own apps and run them on their own hardware.
On the other hand, developers are interested in having the freedom of not being in a sandbox. not having to go through an app review/approval process. The freedom from security restrictions. The freedom to slurp address books. The freedom to override any hardware button, use any API, without limit.
Do you not see how developer freedom and user freedom are in conflict?
That's simply not true. If Apple opened its distribution process, and everything was cross compiled (which is already the case) none of what I quoted above would be true. This is nothing for or against free software, it is about correctness.
You would have to mean something else by "open its distribution process"
Or just blindly trust that Apple knows what they're doing and that it has its customer's interests bound to its own commercial interests.
Sheesh, does everyone on HN need everything spelled out for them?
Well, for one, that doesn't happen anymore without specific user approval.
Second, even with that hole, still SOMETHING protects the users more, hence the huge disparity in attacks and malware between the two platforms.
For example, what you described is your adress book data taken by the company whose app you use without your consent. That's bad, but not as bad as your whole data (and device) being taken by malicious software you never even intended on using.
This of course has little to do with curation -- except that curation helps too, in that malicious apps can be blocked. Apple's curated approach is why it literally has 1/100th the malicious attacks of Android. It chokes malware at the distribution point.
I noticed you had no response to that point.
Source: http://www.darkreading.com/privacy/more-than-25-of-android-a...
That is, where users have a choice of a curated package repository maintained by middlemen who have the users' interests at heart. And where packages and the changes to those packages have an audit trail.
The Google Play store is a disaster from the GNU perspective -- zillions of nearly-identical closed-source programs, most of them pretty lousy, no curation by a trusted third party, no access to source anyway (so not so easy to curate even if you wanted to), no ability to fetch an old version or see what has changed, no way to "take over" an abandoned package and bring it up to date or improve it, no way for a distributor to make programs play nicely together, and no way for a distributor to modify programs to make them less privacy-invasive or battery-intensive or whatever users might want.
FSF isn't complciated - don't give your users anything without including the source. And don't restrict the users ability to modify and run said software however they want.
Fedora fails for this reason - it's 100% free software with some firmware blobs kept aside that are, yknow, necessary to make some hardware work.
It's dogmatic to the point of absurdity. A piece of software is free software because of what it is, not because of what its makers suggest/allow you install on it.
And so, if its a binary with a license that prohibits redistribution, modification, ships without source, or is just a series of hex values in a struct, I don't see how its free software?
Though that gets into the mess that is open EE technical documents on firmware, chipsets, mainboards, circuit layouts, etc - pretty much none of which exist, because so few companies offer them, it is nigh impossible to get an open platform.
Which sucks, and is something I'd throw money at to see fixed.
Untenable position. A user should not be forced to jump through hoops to make their hardware work just for what is essentially an ideological reason (and indeed, an average user would rightly reject such software.)
>If your computer can't run without binary blobs, yet you are a free software proponent
If the goal of the FSF is to make people care about the free-ness of their operating system, they could certainly go about it a better way.
The problem with the whole "approval" thing is that the very name of the organization combined with that action is misleading. Example, if I ran a group called the Cool Software Foundation and maintain a list of cool software, and I made it a point to single out your $application as not being approved, that carries the connotation that your app is not cool.
s/cool/free or any other objective adjective.
In other words, the distro itself very much is free software, and the FSF by their dogmatism is being misleading. I'm with BSD on this one.
That's entirely unsurprising.
The more centralized you build a system, the easier it is to completely own.
Also, there's a massive confound in that Android phones come a lot cheaper than iPhones, making them far more accessible for the typical targets of active government surveillance.
Making sure the new locks fit all these old keys we have lying around, basically. Standard government cost saving measure.
In the US, the only one gets fingerprinted are by being arrested or for certain back ground checks( e.g ones for teachers, some bank employees, and security clearances).
In contrast, owning Apple would be a massive win.
But you're free to treat everything I say and do as an attempt to spy on me. How will that change your behavior? Or are you being deliberately obtuse for the sake of disrupting discussion?
Also, you've still not proven to me that you don't work for the NSA.
If you think that isn't a legitimate insight, or if you're so blazing-fast that you'd already made that inference, I suppose you're entitled to think that, but it's very difficult for most humans to re-compute all of their cached thoughts in the light of new information, and the NSA leaks aren't any different.
Throwing the NSA thing at Apple is ridiculous frankly. It seems that the vast majority of tech companies were involved, including the likes of Google and all seemed to be far more embroiled is the sordid affair than Apple. So why are they more likely to be sharing stuff that anyone else? It's all very disingenuous from where I'm standing.
That is a valid counterstatement to the statement "Walled gardens make users more safe."
I can't see how that was obtuse. What part did you not understand?
> Encryption used in Apple's iMessage chat service has stymied attempts by federal drug enforcement agents to eavesdrop on suspects' conversations, an internal government document reveals.
I'm a strong proponent of free software, but I do see your point, that there's safety for non-technical people in a walled garden, as long as you trust the gardener.
I'm wondering if the concept of free-software and a walled garden are really that incompatible. Let's say the garden has a gate, that a user has to go through a clear process in order to allow to install non-recommended software.
This would give a similar level of protection for non-technical people, but will still be free-software, and allow technical users to install whatever they want.
One effect would be that, if the gardeners decide not to recommend some popular software, then many users would be inclined to disable the safety features, thus reducing overall safety, so there will be a penalty if the gardeners are too strict.
They are defiantly compatible. Consider the way Debian (and many others) approach the problem. Almost all software is installed through the package manager, which gets the software from a set of repositories. These repositories can be as much of a walled garden as the repository owners want them to be. The main difference is that, it is possible to add third party repositories, and/or remove first party repositories (or sidestep the package manager entirely).
I truly find your comment disingenuous and suspect as you only mention apparent malware and virii while the tone I infered from the article seemed a little more nuanced.
These seem like nice, trustworthy sources.
Poe's Law strikes again.
Sadly, but understandingly, user will value the niceties of iOS and alike more than the potential damage to their privacy.
NSA aside, I think their fingerprint system is a security improvement. Although there are methods to easily fool fingerprint sensors : [http://dasalte.ccc.de/biometrie/fingerabdruck_kopieren?langu...
No password < 4-digit code < fingerprint < complex password
Perhaps not your "NSA backdoor" variety of security though...