I don't care if a Linux distribution offers proprietary applications or not. I just want to be able to filter it out, and that they offer open alternatives first.
I'm not a purist, I want people to be informed users, not just sheep that get fed whatever corporations want them to eat. If they still choose to use closed source software, then that is fine.
I'm in an organization that helps people install Linux on their devices, and we collectively decided to install Linux Mint. I never used it myself, and to me, the distribution doesn't matter too much.
However, I was negatively surprised that Linux Mint decided to mix closed-source proprietary software together with open-source software: http://packages.linuxmint.com/search.php?release=alfa§ion=import&keyword=
They also advertise them in top positions on their package installers, which also doesn't show the packages licenses anywhere. To me advertising them and mixing them like they are the same is bad... They also don't offer ways to filter them out... So... while I still install LM for others, I'm not a fan....
You seem to be missing my point. You are arguing against a point I did not make.
I'm not the owner of that laptop, I would just be a user. So with my argument I wouldn't have a right install my own keys on it. I don't need to trust that device. It isn't mine. It is the one of my employer in that case the bank.
So I never said that the bank should trust my personal laptop with their data.
However, if I am a customer of that bank, and they give me access to my account data from my private laptop or smartphone. Then they have no right to enforce someone else to put their root of trust on my device. I need to be able to trust my device to protect my data, so the root of trust needs to come from me. If I don't want to manage my device or if I don't trust myself to do so, I should be able to transfer my trust temporarily to some other third party, and pay them to do it for me.
Imagine if you went to work at a bank in IT for example. They issue you a laptop.
Who is the owner of that device? The Bank.
Who is the owner of that network? The Bank.
So they are the arbiter of trust in that area. They are free to exclude non-bank-owned devices.
I work in IT, and I'm fine with getting a company laptop for company work. I don't trust that laptop. I isolate it when I work at home. But the company trusts it, and that is fine.
Sure, we can do that, but keep in mind that unilateral individual actions will not make the difference, all you can do is trying to create more broad awareness, form coalition and support for tighter laws and regulation, in order to have meaningful effect.
Also avoid blaming or moralizing individuals for their own choices, this will cause fatigue and infighting, which will distract from focus on policy change.
You are not giving a reason for your statement. The owner is the one that bought a device. The sole arbiter about what a device should do or shouldn't do. The person responsible of the device. The owner must trust their device in order for the device to be trusted. It doesn't matter what if other people do or do not trust that device, they are not the owners. They should take care to protect their own data on their own devices.
Pipelining? Rabbit-holing? Trojan horsing?
I disagree. For any actual security, the owner of the secrets is the only one that can be trusted. It is their secrets. Their own interest to keep them save.
Any company or government is a shifting entity, maybe now they are trustworthy, but maybe in some years they aren't.
Owners are the only stabile point, because it is their data. They should be able to transfer the trust to a company or government to handle security, but they also need to be able to take away that trust and access, and either handle it themselves or transfer that trust to some other entity.
It is not okay for companies or government to hold the data of individuals hostage... That is not security, that is a business strategy.
Also software... I would love to have regulations that make it clear that the root of trust on all devices need to start by the owner of the device, not by the vendor... That would allow the end users to repair the software on their devices... Replacing it with whatever else they want. Next would be to provide hardware documentation to the owners to program their own devices... I don't expect that to happen, but I can dream.
An old professor of mine made the half-joke that anything with 'science' in its name isn't really science. He was a computer science professor.
I suppose he meant that computer science is closer to applied science aka. engineering than 'real' science like maths and physics, and all their subcategories.
Anyway... In the end everyone that graduated studying computer science got a Bachelor/Masters degree of science, not engineering... And it doesn't matter anyway...
cmhe
0 post score0 comment score
Yeah... But LM has spotify, Google Earth, Dropbox and Sublime Texteditor mixed in open source software (like d-feet, a dbus inspection tool) in their repos... Those aren't propritary Codecs, WiFi driver or firmware...
Debian and Ubuntu have different APT repo sections for closed source stuff. That is what I would have expected...