8 ms·
Absolutely agree - there should be regulation demanding a 5 year period of security updates (or similar).. Check out https://www.lineageos.org https://www.line
by outlog 8y ago
Absolutely agree - there should be regulation demanding a 5 year period of security updates (or similar)..
Check out https://www.lineageos.org https://www.lineageos.org or one the other dists out there - and get that loaded up..
- OpenBSD-supreme 8y agoNo, that's not strong enough. It should be indefinitely (or owner has right to damages) UNLESS the entire spec and interface of a device is completely, comprehensively, and publically documented from the silicon up, and the device must either lack software integrity checking or it must be fully under the owner's control (eg purge OEM public key, replace with his own). This should apply to all products containing microprocessors and software to execute, and should apply to burned in ROMs too (since that software in ROM should be user writable/replaceable, this should discourage use of burn in ROMs). This should apply to the end product, so the whole car, TV, washing machine, vacuum cleaner, cellphone, game console, Intel CPUs and chipsets, etc, must have its microcontroller interfaces and specs fully and publically documented or damages could be awarded later once exploits appear. This should tamp down on IoT for fridges and can openers too as what OEM wants to either document IP xor expose themselves to potentially unlimited civil liabilities.
- qubex 8y agoDo you really want legislators defining what is and what is not a ‘security’ issue?
- jononor 8y agoWhat is your proposal for fixing that devices are not updated these days?
- rattlesnakedave 8y agoGet a new device and pick a manufacturer that provides updates.
- felix_nagaand 8y agoSo daydream. Such a company doesn't exist.
- fghtr 8y agoHere you go: https://puri.sm/products/librem-5/ https://puri.sm/products/librem-5/
- votepaunchy 8y agoYou do realize that phone is only available for preorder? They may not even be around in 3 or 5 years. The OP likely suggested Apple (5s is in its 6th year of updates).
- fghtr 8y ago>You do realize that phone is only available for preorder? Yes, it is only for preorder, but the devkit already exists [0]. > They may not even be around in 3 or 5 years. If they manage to make the final version of the phone (which is quite likely), it won't matter anymore, since the OS is just GNU/Linux. Correspondingly, the updates do not so much depend on the phone manufacturers. [0] https://puri.sm/posts/how-we-designed-the-librem-5-dev-kit-with-100-free-software/ https://puri.sm/posts/how-we-designed-the-librem-5-dev-kit-w...
- SketchySeaBeast 8y agoSo how does that solve a problem lineage os doesn't? You're buying into a phone that should get continued support for years to come, assuming the company survives, and they don't end up finding the maintenance burnden utterly untenable (once they on model version 3, I can't see it being the easiest thing to support the older models - Apple does, but Apples huge). It seems to be relatively underpowered (though that's really up to how many resources the system uses), and I can't imagine will age well. There will be little to no mainstream app support (they seem to be touting "just run it in a browser" as a solution to that - I thought we left those dark ages). It seems like a neat, niche product, like a raspberry pi phone, but it doesn't give me a lot of hope for the future.
- Wowfunhappy 8y agoIn an ideal world, my preference would be for the government to enforce some sort of standardized driver interface and user-modifiability guidelines, such that users have the ability to update their own devices.
- koolba 8y agoThat’s literally one of the jobs of government, to step in when the private sector does not regulate itself well enough to protect consumer interests. It’s not about wanting the government to step in, its about having no other recourse.
- kingofhdds 8y agoI'm not sure any of us has a right to speak for every consumer. I live in a country were majority would likely prefer cheaper devices w/o any security guarantees. Forcing producers to provide 5(?)-years updates will make prices rise, and it could be against interests of a large segment of consumers. The only regulation which I believe would be beneficial for all is obligatory transparency. There should be clear warnings like "The producer expects you to replace this device in 2 years, and will not support it after that", or "This producer doesn't promise anything in regard of this device - use at your own risk"
- rlpb 8y ago"The producer expects this device to be unsafe after 2 years" would be more accurate :)
- EpicEng 8y ago>I'm not sure any of us has a right to speak for every consumer. Yet almost every civilization on Earth has already decided that we, the masses, _do_ have a right to speak for everyone when it constitutes a common good. In the US, you have to wear a seatbelt in most states. Your food is regulated by the FDA. Your cars must meet certain safety standards, as does your home. This list goes on and on.
- jayshua 8y agoJust because a lot of people do it doesn't mean it's the right choice though. Most Republicans seem to disagree from what I can tell.
- 8y ago
- Broken_Hippo 8y agoDo you think companies are going to choose "security" issues wisely? Do you have an actual solution that doesn't involve government, doesn't have the companies deciding themselves, and that the general public can do?
- capitol_ 8y agoYes, that seems like a very good idea, the market seems to be incapable of regulating itself on security issues.
- Dirlewanger 8y agoThe past decade has seen an explosion in software being put and used everywhere. With that comes an explosion of bugs that are exploited. Literally hundreds of millions of people have had all their shit stolen from numerous services that have a laissez-faire approach to application security. It's like getting into an automobile accident; you're basically guaranteed to get into at least one in your lifetime. If you've used the Internet, private data of yours is virtually guaranteed to be leaked by at least one service you use. I'm not a fan at all of excessive government overreach, but the private tech sector is utterly incompetent of policing itself because a) they don't give a shit, and b) no one is holding them accountable enough (you could argue shareholder should, but there's rarely an impact to bottom lines when security breaches happen). The only thing that will make them care is if an impartial 3rd party that can force them to care.
- gilrain 8y agoYes, I really do want the government I pay for to at least attempt to protect me from pervasive, daily threats. "Do you really want legislators deciding what is and is not 'reckless' driving?" Yup!
- rlpb 8y agoThey don't need to. For example in the UK, goods sold need to be of "satisfactory quality" at the time of sale, and if in breach then the seller has to make it good for up to six years after sale, depending on the expected market lifetime of the product. Something like that is all that's required in primary legislation. What is missing is a finding that a sufficiently severe security vulnerability present at time of sale falls short of the expected standard. The general concept could be enforced by a court ruling setting precedent or by still quite generic legislation. Finally it would be up to the courts to decide on a case-by-case basis what constitutes "sufficiently severe" in specific cases. That's no different to how everything else in law works.
- sitkack 8y agoYou pack a lot of fallacies into one sentence! False dichotomy, boogie man with the bonus of scare quotes. Mandating security updates for some amount of time after a product is sold isn't 'legislators defining security issues'.
- tohnjitor 8y agoGoogle has already addressed the issue with Android One. Android One certified devices are guaranteed at least two years of security updates. Most of the manufacturers already have such devices available.
- 131012 8y agoAny advices, caveats or other thoughts on this process?