maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   SailfishOS (https://talk.maemo.org/forumdisplay.php?f=52)
-   -   MWC2018 news (https://talk.maemo.org/showthread.php?t=100221)

benny1967 2018-03-04 09:02

Re: MWC2018 news
 
Quote:

Originally Posted by LouisDK (Post 1541974)
So with shared source codes with selected 3rd party you'll enable them to explore new backdoors and make custom compiled version with added backdoors.

Also since the parts in question is closed source the public won't be able so spot differences in custom vs. vanilla Sailfish parts or search for backdoors themselves.

How can this be labelled as secure?

It's secure from their partners' point of view. Just as it's 'full open source' only from their partners' point of view.

pichlo 2018-03-04 09:10

Re: MWC2018 news
 
Quote:

Originally Posted by benny1967 (Post 1541992)
It's secure from their partners' point of view. Just as it's 'full open source' only from their partners' point of view.

Which is fair enough. He who pays the piper calls the tune.

Which brings me back to the point I've been trying to get across for years. Jolla is NOT the open-source messiah some would like to see it as. It is just another company trying to make a living.

Pim 2018-03-04 10:12

Re: MWC2018 news
 
Actually, isn't it the case large-enough governments can get full source code access to most operating systems, even Windows, under appropriate non-disclosures and other conditions etc?

kinggo 2018-03-04 10:21

Re: MWC2018 news
 
And what would change if they are?
Would that atract new OEMs to make HW with sailfih? No.
Would that made carriers to support it? No.
Would that made 183643 new developers? No. And particulary BIG NO since from inception for some misterious reasons Jolla does not support paid apps and does not won't people to make money on their work. Meanwhile, I just paid 80€ to sygic a few days ago so that I can have mirrorlink function within their nav app.
Would that made various different 3rd party apps that we need or use on a daily basis or here and there, but still use, on other platforms suddenly appear on sailfish? No.

Signal is apparently way better option than Telegram because it's fully open........But AFAIK they don't allow access to 3rd party apps. So how is that better than any closed source app?

There's 66538 different problems with Jolla and sailfish but a few closed source components are not one of those.

LouisDK 2018-03-04 20:01

Re: MWC2018 news
 
Quote:

Originally Posted by richie (Post 1541978)
It work like this according to this old image https://pbs.twimg.com/media/Cylz-a0WQAAzJ6i.jpg

So Jolla will oversee any code going back in to SailfishOS to maintain independent offering. Leaking code is probably prohibited by commercial contracts.

This doesn't mean that any 3rd party with source code access could omit telling Jolla about found security bugs and use these as backdoors.

Also an NDA doesn't guarantee that source code won't get leaked even trough it's prohibited. Just look at the recent leak of iBoot code.

As I've understood from your picture Jolla doesn't have access to Sailfish RUS specific source code meaning backdoors could be inserted without Jollas knowledge. Only into the RUS specific version though.

tortoisedoc 2018-03-04 20:40

Re: MWC2018 news
 
Quote:

Originally Posted by LouisDK (Post 1542023)
This doesn't mean that any 3rd party with source code access could omit telling Jolla about found security bugs and use these as backdoors.

Also an NDA doesn't guarantee that source code won't get leaked even trough it's prohibited. Just look at the recent leak of iBoot code.

As I've understood from your picture Jolla doesn't have access to Sailfish RUS specific source code meaning backdoors could be inserted without Jollas knowledge. Only into the RUS specific version though.

That'd be a GPL violation right there. Which translates into a higher risk for the players (for example the RUS specific version).

Bottomline : get caught with your pants down, and it's trouble ;)

EDIT : this for the OPEN components. It might actually be that Jolla will be forced to open up the (remaining) closed ones for security validation.

m4r0v3r 2018-03-04 21:45

Re: MWC2018 news
 
the best way to ensure something is what it says it is. is you take a code and build it, and it should behave the same way the code says.

so if a russian code base changes something, you should be able to simply install a "vanilla" sfos and see whats what.


All times are GMT. The time now is 12:14.

vBulletin® Version 3.8.8