Re: Privacy Concerns with UbuntuPhone

Thomi Richards <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <CAN2KdQ-NXxWLrdUHOtNdSf9+-ADRpzDoaNqfVaRZRt-QegBdqw@mail.gmail.com>
Hi,


On 30 April 2014 23:15, Danyl Strype <[email protected]> wrote:

>
> Thomi, it might be bad vibrations in my tinfoil hat (nice image BTW ;)
> but I can't help but feel your responses here are coloured by bad
> feelings resulting from my harsh words about Ubuntu and the Amazon
> Lens etc some month back.


I don't think my replies are coloured by anything other than my genuine
feelings on the matter. Of course, it's impossible to be completely
objective in life...



> I welcome the UbuntuPhone, and the work you
> folks are doing, just as I welcome Android, Replicant, FirefoxOS and
> all the other free code mobile OS you mentioned. I understand that all
> of these teams are constrained by an oligopoly of hardware
> manufacturers, as I said in my first email on this topic, and network
> gatekeepers, as revealed by this discussion (again, thanks to everyone
> who's chipped in).
>
> I'd like to think you're pushing the software freedom boat out as far
> as you can, at each stage of development. Mind you, it does make it
> hard to give you the benefit of the doubt, when you engage in a flurry
> of fallacies (ad hominem, false binary, strawman etc) in defence of
> the proprietary components of your employer's product, rather than
> saying something like 'yes, we are concerned about the proprietary
> baseband, and we will continue to push for a fully open stack until
> our influence in the mobile industry (combined with that of other free
> code OS teams) is enough to achieve it'.
>

So, first of all, I'm explicitly *not* "pushing the freedom boat out as far
as I can". I don't believe that open source software is the panacea to cure
all ailments. I obviously think it's pretty damn hot, since I'm as involved
as I am, but I'm not as extreme in my advocacy. Part of the disagreement
here is probably due to the fact that I don't think having an open baseband
OS is anywhere near the top of the list of problems we need to spend energy
addressing.

Second, my "flurry of fallacies". You mention three, and I'd like to
address them in order:

ad hominem:

I really try very hard not to do this. I've just re-read my four replies to
this thread, and I honestly cannot see where I have attacked you, or anyone
else on the thread. The closest I could find was this:

The original post sounded (to me, at least) like it was couched in absolute
> terms. My point is that absolutes don't exist here, just like in your car
> analogy. You can make yourself more safe - probably - but don't kid
> yourself into thinking that wearing your seatbelt makes you totally
> safe.... that's obviously stupid.
>

If that's what you're referring to, you'll notice that the 'obviously
stupid' was directed at the idea that wearing a seatbelt makes you
invulnerable. Anyway - if you still feel that I've slighted you somehow, I
apologise - that wasn't my intention at all.

false binary:

At several times in this thread I've said the exact opposite. Security &
Privacy are _not_ boolean properties. I said as much in my last reply.

strawman:

Well, we're arguing about hypotheticals here. We have to, since we're
talking about the potential impact of a future OS against an unknown
adversary of unknown strength. Inn these situations, all you can do is to
say "this is what my model of the future looks like, and against that
model, these points are valid". Without either a time travel device, or
more evidence, there's not much else we can do here.


I need to make it clear - again - that I'm speaking personally here, NOT on
behalf of my employer.

You suggested that I could have said something like "yes, we are concerned
about the proprietary baseband, and we will continue to push for a fully
open stack until our influence in the mobile industry (combined with that
of other free code OS teams) is enough to achieve it". I suppose I took
that as a given. *of course* I'd like an open baseband. TBH though, there
are a ton of things I'd like more. It's just not that important to me. This
whole thread has been me trying (probably poorly) to explain *why* an open
baseband would be nice, but is not the most important thing to have *iff*
you're trying to enhance your privacy in the face of an increasingly
hostile surveillance state.


> Worik and Katinka have already addressed your false binary on
> security/privacy (since it can't be perfect it's not worth worrying
> about).


Well, that's fine, except that's not what I said at all.. Again, read my
last reply, where I agree that privacy isn't a binary state. I feel like
you're putting words in my mouth. I've never suggested that privacy or
security are binary states, merely that, if you're trying to protect
yourself from the state (or anyone with significantly more resources than
you have), your privacy has to be pretty damn good in order to be even a
little bit effective.


> It's true that software freedom is not an ironclad guarantee
> that software is privacy-respecting, secure, and bug-free. What
> software freedom is usually pretty good at though, is making sure that
> software does not have malicious functions built in as 'features',
> such as sending an endorsements for the device I'm using, to everyone
> in my address book, purporting to be from me. This may not send my DNA
> to the NSA, but it's still highly undesirable. This kind of
> profit-motivated malware is prevented by using devices running free
> code software, because such software can be swapped out for a
> non-malware fork or alternative.
>

I agree 100%. However, you're now talking about two different things.
Malware != privacy. If you want to have a talk about how using open source
software reduces the risk of malware, I suspect we'll agree much more than
we do now.


>
> As for the surveillance state, again you're right that there's no
> ironclad certainty of privacy. The more authoritarian the state, the
> less privacy there is. However, there's a big difference between the
> effort involved in stealing my handheld and cracking into it, and
> passively harvesting my data through backdoors hidden in proprietary
> components. Technologists can't (by ourselves) prevent authoritarian
> states, but we can certainly design our technology so that it serves
> user freedom and democracy, and frustrates invasive authorities as
> much as possible. This is basic social responsibility in engineering.
> http://citizenengineer.org/
>
>
Yes, I agree with most of this, except that you have the idea that cracking
my cell phone is the best way of finding out who I've been talking to. If
you want to take a pragmatic view of the problem, I suspect you'd do better
to target the upstream components in the cell network, rather than my
personal devices.


> Protecting our privacy and security from our government may seem a
> fairly theoretical concern in Aotearoa for most people (for now).
>

Not at all, it seems (to me) like an urgent, pressing matter. I just don't
think the original topic, from which we've strayed quite a long way now -
has much to do with enhancing privacy from a surveillance state. I'm _not_
talking about the prevention of casual snooping, I'm talking about
protecting yourself from an entity with significant resources to bring to
bear.


> However, I can't overlook the fact that friends and colleagues of mine
> were spied on for two years and arrested on completely fabricated
> charges in Operation8. No convictions except for four counts of being
> collectively in the presence of some old hunting rifles without a gun
> license, charges which would have been dropped like the other 14
> people's were (due to illegal state surveillance according to the
> Supreme Court), if not for the trumped up criminal gang charges, on
> which they were not convicted. Then there was the DotCom raid. The NZ
> state is not always gentle with those who threaten elite interests
> (whether its fossil fuel mining and monocrop forestry oligopolies, or
> proprietary software and copyright oligopolies), however
> non-violently, and we need to remember that old quote about freedom
> and eternal vigilance.
>
>
Yup - that sucks, and the list goes on for a long long way.


> On 22 April 2014 17:48, Thomi Richards <[email protected]> wrote:
> >> only when it's turned on eh? It must be old :) <<
>
> Until a libre handheld is available, I use the oldest phones I can
> find which still work.
>
> >> I'm assuming that we'd all rather have a third player in the mobile
> market (whether it be Canonical or someone else) than keep the existing two
> players in power? <<
>
> At the end of the day, I'm not the least bit interested in the number
> or the power struggles between proprietary vendors. Until you resolve
> the proprietary baseband limitation, you are essentially a
> subcontractor to proprietary vendors, as are Android, FirefoxOS, et
> al.
>
>
Your interests are your own, but I think that's a little misguided. Ubuntu
Touch may be shipping on devices with a closed baseband, but we're shipping
with almost everything else open. Compare that with whatever the latest
device from Apple or Microsft is, and I think we've improved things
significantly. Even devices running android are shipping with more and more
proprietary code. "Somewhat open" seems to be a better deal than "not open
at all". If your interests were representative of everyone else's, I fear
that we won't get an open source phone achieving significant market share
any time soon.


> >> Regarding closed device drivers, this isn't a new situation for Linux
> either - 15 years ago it was very hard to buy a desktop computer that
> didn't rely on proprietary drivers <<
>
> Yes, but this is not mandated by your ISP. Bit of a difference. Alex
> has covered this point beautifully with his road/car/driving analogy.
>
> >> If you want to make any real positive changes here, I can see two
> approaches. One is to improve the software we already have, particularly
> the crypto stack. <<
>
> I'm a user and an advocate for users, not a programmer. It's a bit
> hard to convince people that the participation of non-coders is valued
> in open source communities, when we keep getting told that to
> contribute we need to "improve the software".
>

Your participation (and that of other non-coders) is absolutely valued in
open source communities, just not in this way. There are many things
non-coders can do to help the open source world, but expecting non-coders
to strengthen our crypto stack is a little... optimistic. That's OK though,
because there are plenty of other avenues for these people, some of which
you mention below.


>
> >> The other is to lobby government for fairer and clearer legislation
> around when, where, and how surveillance is permitted. Maybe, once those
> things are sorted, the next task will be to tackle device firmware. <<
>
> I'm already active on the this second bit through my work with the
> Pirate Party, giving advice to the ICT spokesperson for the Greens,
> networking with activists from Mana, Internet Party, and other parties
> and organisations. In fact this is why we're having this conversation.
>

Good on you. I hope you keep up the good work in this department.


> You missed the third approach though, which is to support vendors who
> can provide a usable product that respects my software freedoms and my
> privacy, even if their product is not the prettiest or whatever. This
> is one way I use what little influence I have to push vendors towards
> greater respect for software freedom. It's up to the vendors who are
> developing devices, and encouraging people to use them, to decide
> whether they care about these principles, or my custom (which
> admittedly doesn't add up to much $).
>
>
You're correct, I should have mentioned this. At the moment though, I'm not
aware of any vendor that meets these requirements. Maybe in a few years
you'll be able to buy a phone that's both usable and has open drivers, but
I'm not aware of one today.

 As Paul mentioned in his reply, the current options have some pretty
serious drawbacks.

I can see that you care about this particular piece of the technology stack
a great deal. I'm always happy to answer questions about what I'm up to at
work, and I've stayed on this list, despite frequent unpleasant threads,
for exactly that reason. I'm a little surprised that you seem to have read
malice in my earlier replies. I'd like to assure you that none was
intended.

Cheers,
-- 
Thomi Richards

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.