Re: Privacy Concerns with UbuntuPhone

Rob Pearson <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <[email protected]>
I'm fine with UbuntuPhone using this bit of closed source software,
as no-one probably has a choice anyway. The point I was making was
this could be simply the risk that it would be harder to control
device contention if it was open source. Cheap jammers are rare,
but enormously riskier would be if multiple devices end up with this
bit tweaked that causes issues in certain conditions, we'd end up
with unreliable billion dollar networks almost impossible to fix,
this bit is almost impossible to police. Telecom say they spent
$550million to install the XT network, and they didn't even design
the kit, it took others much more cash to develop it. So maybe
it's simpler to keep it closed until forced to open it, I can't see
that happening.

Regarding the quality of software and comparing closed vs open,
closed isn't necessarily any worse if the rewards are there,
aeroplanes have been taking off, flying and landing fly-by-wire for
30 years, I'd assume it is closed software. And spaking of this
does Google use a 3-way voting system like aeroplanes with
fly-by-wire, as there must be more random issues to overcome with
a car on a flat road than an aeroplane in the air.

Rob

On 25/04/14 8:25 AM, Alex King wrote:

Hi Rob,

The navigation system on motor vehicles unwisely allows user input
into the fine detail of vehicle tracking. If the user makes a
mis-adjustment a few degrees to the right, it can result in death
of the user and other innocent users, and closure of an arterial
route for a few hours while the mess is cleaned up, with
associated system disruption in the local area.

If we were developing cars today, would we put steering wheels in
them that allow users to do that? It's like cell phones with a
frequency knob on them, you manually control your connection to
the base station and whether you are interfering with other users.

But the thing is, actually most people play nice with the system
and don't use its potential to wreck havoc.

Now if you are NZTA and you have spent billions on roads, and you
are auditing the software stack for automated vehicles to drive on
roads, would it be better to license only devices with a
proprietary stack, or allow open source?

Personally I wouldn't want to get in a vehicle controlled by
Microsoft under any circumstances, and while apple might be able
to get me from a to b ok, the requirement for every passenger to
have their credit card inserted into the car at all times while
travelling doesn't appeal.

Accepting an open source stack means accepting a risk that someone
may play with it, they may make modifications that are dangerous,
they might kill themselves and a few others. Not only _might_
this happen, but it is almost certain _to_ happen, in isolated
cases. (Some people say that after a while all the really stupid
people will be killed off, but unfortunately new ones keep being
born). We already in fact accept this kind of risk on our roads
with our current system, we accept a level of death and maiming.

But on the other hand, allowing open source into the mix will
undoubtedly raise the standard vehicle control systems and make
them safer overall.

The consequences of opening up cell phone basebands to open source
and the associated risk of stupid mistakes are not as serious as
the consequences of stupid mistakes on when driving or modding
your car. There are benefits in having a group of people familiar
with this stuff (ala mechanics, rally drivers and enthusiasts).
We also need some form of police (or reputation network) who will
detect stupid stuff on the cell phone network, triangulate signals
and tap people on the shoulder. This wouldn't be cheap, but it
will make the network more secure.

Unfortunately, despite the current cell phone industry being based
on proprietary basebands, is not safe from the types of risks I
mention above anyway. If they really want to, people can get or
construct software controlled radios. I know of several old 2g
phones that have been reverse engineered, you can mod them to
allow complete software control of the radio. I'm sure the same
is true of some 3g devices. I don't believe the companies have
systems in place to deal with devices that don't play by the
rules. The consequence is that the whole system is very fragile.
Allowing open source and associated policing can only improve that
situation.

The consequences of licensing everything and allowing a duopoly of
companies to control it all, is expensive cell phone services.

Cheers,

Alex

On 24/04/14 11:46, Rob Pearson wrote:

It's probably got a lot to do with contention control, on
wireless networks with varying coverage and multiple mobile
devices it is very hard to achieve. If you know what you're
doing you can get more than your fair share of bandwidth from
the basestation you're registered to, or jam it, or jam it
intermittently if you want to be annoying. If you don't know
what you're doing and adjust the contention control on your
device you could jam it rendering the basestation useless for
other users. The companies that spend 10s of millions
installing this kit nationwide will never want people to be able
to fiddle with this, they depend on their subscribers income.
This will be a big part of the code they are worried about,
perhaps this has already been said. Rob

On 23/04/2014 4:35 p.m., Robin
Sheat wrote:

Thomi Richards schreef op di 22-04-2014 om 17:48 [+1200]:

Welllllll..... I'm still not convinced that a totally open source
software stack would give us any more real security or privacy than we
already have, for two main reasons.

It can't hurt, and it may help. At the least, it can aid in preventing
the sort of abuses that closed source software can have:

http://arstechnica.com/security/2014/04/easter-egg-dsl-router-patch-merely-hides-backdoor-instead-of-closing-it/

I would argue that it is able to provide _better_ security for me as an
end user, while being aware that virtually nothing is perfect.

Robin.

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.