HN user

letstrynvm

285 karma
Posts0
Comments58
View on HN
No posts found.
My FOSS Story 7 years ago

Assuming the author uses their own software, disabling the ability to hear about problems with it before you trip over it themselves is counterproductive. The minority of users would fix it and offer a PR in my experience, more would be willing to drop the author a note in an issue.

Unfortunately that useful information comes mixed in with, eg, users who think the author's time is worth so much less than theirs (didn't the author demonstrate it was worth nothing by offering this work for free?) they want hand-holding for every little thing. The author can put it in README.md and point these guys at it when closing their issue.

Android is a bit of a siren... since there are many devices on current hardware working great, it looks like it should be possible to be the starting point for a lovely FOSS solution.

But it isn't, due to the Android approach of piling together unmaintainable vendor junk like gpu driver and sensors on old kernel that doesn't work with FOSS gpu apis, radioactive horror story wifi / bt stack using non-upstream apis. The different kernels as a whole are individual flies in amber that are impossible to keep working on newer upstream basis.

Therefore your 'secure FOSS phone' becomes the usual Android security apocalypse as soon as the vendor stops patching the security holes found monthly; that's if your vendor even bothered patching and updating those pieces quarterly or even once.

Purism got it right that there's no way to get the needed result - that it's like putting linux on your x86_64 laptop - out of Android / existing devices. The story seems to be about whether their laptop business and the kickstarter gave them enough runway and ability to pay suppliers up front for initial production.

The problem isn't that they're somehow oblivious to the various problems... the problem seems to be from this guy's articles that they don't have money and manpower to tackle them.

That's not really solveable.

Their focus has been okay... the foss os stack, the gpu driver the apps... even if they fail other projects can pick these up.

It's just very difficult to get to the point you have enough pieces in good shape for a minimal usable set of functionality in 2019. A month or so ago on a devkit, the browser was crashy and juddery scrolling, not janky but going away to think on things for a bit, failing to update any more etc.

They're kind of responsible for all the pieces in the stack, unlike a normal phone company who get OOT kernel and drivers and gpu pieces handed to them all good by the soc vendor. if they can hold out and keep their nerve, it shows signs it will get there. But maybe in 2-5 years for the software imho.

Fast buses operate at some multiple of a reference clock wired up to both sides, it's often 1/2 or 1/8th of the actual data rate which each side arrives at by feeding the reference clock to an on-die pll.

This can create ambiguity in which bit of the 2 or 8 or whatever is on the bus, and temperature, board design, bus length, humidity etc change the phase where the best sampling place is for the data signal. So there is 'training' to test which fine delay between the receiver pll clock and the data gives the lowest error rate when used to sample the incoming data. Periodically some buses must pause and do retraining to account for, eg, temperature changes.

That email says how the author doesn't like rms or his various writings, then switches to an unrelated drama about how the author fell out with a major contributor and there's some ongoing shitstorm in the project due to that.

The title makes it sound like rms' fault but he only features to be ritually denounced in the first half.

I had to google what guile was I'll certainly be trying to avoid it now.

I have a cheap dedicated server with outgoing Postfix mail forwarding with sasl auth, nsd for the domains, a few web services over tls. Git server via gitolite + git-daemon. Mailman.

Incoming mail points directly to an RPi at home on dsl... Postfix + Dovecot IMAP. It's externally accessible, my dedicated server does the dynamic dns to point to the RPi; the domain MX points to that. Outgoing mail forwards through the dedicated server, which has an IP with good reputation and DKIM.

This gets me a nice result that my current and historical email is delivered directly to, and stays at, home, and my outgoing mail is still universally accepted. There's no dependency on google or github. There's no virtualization, no docker, no containers, just Linux on the server and on the rpi to keep up to date. It uses OS packages for everything so it stays up to date with security updates.

Because in 2019 msft finds itself making big $$$ from renting servers running Linux and associated FOSS stack.

I skipped the rest after his trying to equate concluding you're not going to get accepted to a particular conference with 'ego'.

Having self-respect and deciding not to keep uselessly abasing yourself to a clique that's never going to anoint you is perfectly reasonable. As the previous poster said the article author seems over-blessed with ego thinking he knows enough to hand out blanket advice putting the fault on others.

"problematic person" eh...

He's clearly a freethinker, and we have all gotten a lot of advantages from his courage doing his thing and making his vision for FOSS a reality.

Now he's said his thoughts on this too... it's legitimate for him to do so and "problematic" everyone is in a huge panic to punish him in case the mob should get set on them.

It's the Gnome webKit browser Epiphany (aka Gnome web).

I'd prefer firefox but I don't have any real beef with it. Except on the dev kit the scrolling is more or less unusable. It might be a 'feature' of the dev kit since the imx8 runs hot enough to burn your hand on that due to hardware problems that shouldn't exist on the real device.

I paid for a "dev kit"... it's not like I have unreasonable expectations. I went back to check it to figure out if I should buy an actual phone... I kept my money in my pocket.

I can handle quite a bit of dust and pieces coming month by month but I can't handle no wireless comms and a crashy and slow browser. At least the internet and the browser operation have to be reliable and fluid or nobody can use it for normal operations. I'll try it again in a few months.

Wish them all the best, but I tried the latest firmwate image on my dev kit last week and although there's plenty of progress, many things are not there, at least on that image + platform combination.

No lte, no wifi, browser scrolls at ~10fps, browser crashes, display has some hw jittering if you look closely.

I guess some of these are solved on the production hw (they use a different lte module) but still, only consider it if you have a pain threshold or have booked to go into hypersleep for 18 mo.

These large rich tech companies are really responsive to 'compliance' with the letter and spirit of laws that otherwise might cause severe losses. Look at, eg, gpdr, and google suddenly getting religion about you being able to mass-download your data. Yes you can legislate solutions to corporate behaviours.

If he was though, it'd have various implications such as it not being difficult to prove he had access to his own private keys.

I can imagine you might be the guy and not want to prove it, or it to be known. But actively claiming to be the guy and not proving it indisputibly when you could... what'd be the point?

Important code needs love, it needs to be improved, made more robust, have security issues handled, consolidated if it starts to bloat, to be cleaned and kept legible even for whitespace so you or the next guy can easily see and continue to look after all the moving parts.

If it's important, it needs and deserves all those things; they are not "churn" but maintenance.

Agree with the rest... every other solution is FOSS. A closed proprietary tool has a big mountain to climb.

Every good programmer loves to learn a new language.

Er... no. I am still seeing new ways to leverage C after 40 years on it. Creating a new language is the ultimate self-indulgence.

prompting outrage when there isn't a good reason for it.

Can you expand on why there's 'no good reason for it'?

The equivalent is my peering in your window to see and note down what you rub one out to... every time. And you don't know what I do with that information or where it will leak to.

That sounds perfectly fine to you, does it?

Yeah... but it's security theatre.

They will just use memcpy_s with the dest len and the len set to the same var. Or strncpy with the limit set to strlen(src) etc. These guys will tell you it's suddenly using 'modern security practices'.

Conversely depending on the code strcpy / memcpy can be 100% safe.

I think these guys are selling static analysis, so they find themselves using these oversimplified metrics... it's a shame because it looks like there was no lack of real issues.