https://twitter.com/CopperheadOS/status/972536015436107777 … Forbidding people from making secure devices with an immutable hardware root of trust: freedom! Forbidding killing people with drones: slavery! Today's ethics lesson brought to you by the GPL3.
Yes it would be great if we could get some sort of universal consensus on the right restrictions. I don't see that happening.
-
-
It would be nice if we didn't deal with daily hate mail and endless misinformation campaigns against us based on our choice of license but that's not the world we live in. If people keep bringing it up as a topic by bothering us / trying to hurt us it will remain an active topic.
-
If Free Software activists want to go around accusing people of being unethical or lacking values for their choice of license clauses they should be prepared for some criticism of their views. That arbitrary set of rules about what is ethical will probably change again with GPL4.
End of conversation
New conversation -
-
-
Re: hw root of trust, there are totally ways to do it that leave user freedom to change or replace sw, free of vendor lock-in.
-
To replace software, sure, but the firmware leading up to when the user configured key is read needs to be verified from a hardware root of trust. It's also inherently more secure to have an immutable key without relying on state. Can close most of the gap but never all of it.
-
We're quite aware since we only currently support phones using an owner-controller public key to verify the OS from the late stage firmware. If we made our own device we'd hard-wire the key instead of storing it in protected state. Even if the benefits are small they do exist.
-
Could sell devices where the users could blow the sec fuses to set up using their own key but that's setting up a recipe for disaster because it's too easy for people to turn it into a brick and blame the vendor.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.