View Single Post
Jaffa's Avatar
Posts: 2,535 | Thanked: 6,681 times | Joined on Mar 2008 @ UK
#68
Can I ask that the wiki page is used as a way of those of us who understand Elena's design (fantastic presentation and really good design given the requirements, IMHO) to ask questions in a structured and sensible way?

The more end-user/enthusiast questions can be dealt with through communication channels such as Talk and Planet; leaving the impact on Elena's (and others') time to be minimised?

So, good questions:

When Maemo 6 has booted into a "trusted" mode and has the DRM features available; will a maemo.org extras package be able to modify a file in the rootfs? Will postinst scripts run as root? Will root be available for modifying files installed for unverified binaries (such as editing a file my own app has installed?)

Can a signed image be booted into with an unsigned kernel, but with fewer capabilities available?
Bad questions:

Can't I just get root and modify /etc/init.d/... to turn off DRM and get at all my copy-protected music?

Why are you so evil to allow companies which are subsidizing my device to control what I do with it?
Certainly, once Elena's presentation (and the video) is online, I plan on writing up my own take on it, and helping lbt come up with a good list of questions. I don't want to scare Elena and the other security framework developers off from the community.

PS. The initial comments about "open" and "closed" device modes refer to people who want the full freedoms afforded them today. However, most users will still be able to dabble with a single paid-for app (using DRM to ensure copy protection) and get most of their apps from maemo.org Extras.

PPS. I spoke to Niels immediately after Elena's talk and there are two useful things we can do on Downloads and/or Packages: showing the capabilities requested by a package (by parsing its Aegis manifest) whilst a user is browsing the apps (before having to install it), and making the autobuilder check that an app doesn't request any privileges which aren't available to apps available through Extras.

PPPS. I'm very glad that the effort we're putting in to Extras QA and -testing isn't going to be wasted by users only being able to get community apps through Ovi Store if they want DRM. As I said, good design here.
__________________
Andrew Flegg -- mailto:andrew@bleb.org | http://www.bleb.org
 

The Following 4 Users Say Thank You to Jaffa For This Useful Post: