Sailfish OS: Clarifying claims about open/closed source, security and privacy

For what it’s worth, Jolla has an annual subscription 58.8EURO and no data sharing with them is required. I hope you’re all-in!

I would love if Jolla could add service subscriptions (e.g. cloud space, VPN) that would be valuable to me.

3 Likes

Of course I’m all in! Not for the annual yet, but since 2018, I’ve purchased 6 or 7 licenses! :wink:
And now i’ll be purchasing the J2.

Native no-log VPN/Wireguard out of the box would be great indeed!

2 Likes

yeah… maybe that thread is on its way to get obsessed with G OS, which is kinda pretty much off topic at this point, I think. Things have been said about G OS, lets maybe get back on the main thread topic…

1 Like

Good question and good answers in this thread!

I’ve ordered the phone, why?

  1. Security:

TLDR; I have more trust in system on which I can do fully live inspection, rather than a tech giant telling me to trust them that they keep my system safe

People just get it all wrong. The fundamental security is a physical separation of concern. The world is going into crazy and scary direction where security is burned under obscurity. I like the comment made somewhere above in this thread, nowadays the user/owner is modeled as the top threat vector, whilst real attackers are a secondary thing. Banks force us to use mobile app as 2FA but at the same time they claim in the fine print that they don’t take any responsibility for mobile breach :rofl: Therefore since many years I keep an iPhone in a drawer, just for the 2FA apps (I don’t even use email or web on it), whilst I use <$200 phone as a daily driver. I don’t ever log into sensitive apps/webs from my daily driver, nor connect there my personal email. When traveling I use my daily phone as a hotspot to access sensitive apps from the laptop. When around home, I don’t really feel a need to have instant access to anything personal! It’s fine if I check messages in the morning/evening. When someone needs to reach me urgently, they can call me, or ping me on gmail (but I teach everyone that the gmail on my phone is not for sensitive information, and in general should not be used). The net result? I don’t really fear loosing my daily phone, I don’t really fear smashing it or wearing it off (I won’t buy a protective cover worth 1/4 or more of the price of the phone), and most importantly I don’t fear loosing my 2FA and going through the hassle of re-acquiring them (you probably know the stupidity of the security departments “we can’t let the users install our 2FA app on more than one phone at the same time”, like WTF, I have more than one Yubikey precisely because I can loose one someday).

Of course I use a few convenience apps on my daily driver which have my payment method configured, but I use a separate bank account for that. This way it is much easier to review the transactions and control damage. I never have on that account more than 1k. If I loose my daily driver, I’ll block the card when I get home, that’s it. There’s still only a very slim chance it could be harvested from my lost phone and misused.

Now regarding Linux phone, the unbeatable advantage is the root access. I’m not a security expert but I use computers since ‘80 and can get my way around spotting suspicious things if I have full view/access. The problem with the duopoly devices is that a malware have more rights than you, the user. Once a malware gets in you’re on the mercy that the tech giant will somehow spot it at some time in the future. Not to mention that the OSes are full of “built in malware-like” so you can’t really tell what is it when your phone obviously behaves strangely, maybe it’s malware, maybe it’s the tech giant doing something without clearly asking you.

  1. Privacy:

That one is obvious, there’s no privacy on Android nor IOS.

  1. Open/Closed source:

I don’t like the fact that Sailfish is not fully opensource, but I’m happy that it’s open enough to let me run full forensic check whenever I want. I have tried to use Ubuntu Touch. Its user mode is fully open source, but yeah, still full of annoying usability bugs and realistically zero native apps. I keep fingers crossed for its success, but for now I don’t have the time to fix bugs in the OS and develop the apps I need at the same time.

I understand that the closed source parts are partially a legacy, partially a business model. However I hope it’ll be fully open one day. For example several Open Source projects amended their licenses to prevent commercial use by cloud providers in recent years. I hope such model would also suit Sailfish. Open the source so legitimate users could review it, contribute to, and recompile as they please for own use, but attach a license clearly preventing free re-use by foreign business models trying to grab it for free to re-sell.

13 Likes