• 1 Post
  • 21 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2025

help-circle


  • I know that’s the case in the US with FCC regulations. Not sure about other countries. I believe SDRs are illegal here (US), although things like the HackRF One and Flipper Zero are still sold. Getting the modem to be whitelisted for use on carriers is a whole other story, though.

    So isolating a proprietary, off the shelf modem from the system RAM by not having it be on a PCIe-like bus and having a hardware killswitch would be the next best option.


  • It’s a shame there aren’t any open source modem designs out there. Something that concerns me with Qualcomm SoCs is that their integrated modems have complete access to the system RAM (or at least, that’s what I heard). Would it be possible to interface with the modem through a more limited protocol that supports hotplugging, like USB for instance? That way, it can also be completely disconnected with a killswitch like what the Librem 5 has.



  • I don’t think they are the norm for small projects, mainly due to price. While an external security audit would be nice, I’m talking more about the question of how many people have looked at your code who also happen to be security experts? I think asking you to get an actual professional security audit would be unreasonable due to the cost of getting one.

    So fingerprintd depends on the phone having a TPM? That makes sense. For whatever reason, I thought it did the actual processing itself.


  • I’m asking you about your code specifically. You’re not a maintainer of 81voltd, so asking you about that wouldn’t make too much sense. I am asking you and not the maintainers of 81voltd out of convenience, though, since you are easy to get a hold of on a convenient platform and are likely to respond. If I were to get a hold of the 81voltd maintainers, I would be asking them the same question.

    Wouldn’t fingerprintd also have an attack surface, given it’s an authentication daemon?


  • I’d ask if there’s a chance at GNOME Mobile support since that’s by far my favorite mobile Linux DE, but given their strict anti-AI policies, I don’t think that would be a possibility, at least not if upstreaming is the end goal.

    This isn’t a question exclusive to the use of AI, but moreso involves being new to low level systems coding in general, and that is one of security. Given smartphones in particular are highly portable devices that are the first to be seized, especially in more fascist-leaning countries such as the US, security is of upmost concern, even compared to other computing devices like a laptop, desktop, or a server. Not including your kernel code that has already been mainlined, has your code been audited by any security experts, especially your userspace code that is not part of the kernel, and thus will not be reviewed by any kernel maintainers?


  • If you agree with the points, then how is the ban shortsighted? It’s not like the ban can’t be revisited in the future.

    While you do host a repo, pmOS device packages can’t depend on imsd/fingerprintd/etc. since they’re not in pmOS’s main repo, so it adds extra steps for the end-user. I’m unsure if pmbootstrap supports building images with external APKs either, and if not, it would have to be done post-install.

    There is another problem that I haven’t mentioned, and that is since your packages already exist, that demotivates other people from working on LLM-free code that performs the same task, even if it doesn’t eliminate it entirely.

    If you do not fully understand the code you’re working on in a deep, architectural sense, is that something you are willing to improve upon over time to the point where you will no longer need to use LLMs to code?

    I await your post about it, as I’m curious about your viewpoint, especially going more in-depth.


  • The already mainlined kernel patches wouldn’t need to be rewritten since they’re already in the mainline kernel. I didn’t see where you specified that before.

    But not all HWE is in the kernel. For example, your userspace VoLTE daemon is extremely useful for those who need VoLTE, but would not be able to be packaged in pmOS so other devices can benefit from it, since pmOS is the de facto mainline Linux distro for mobile (there are others, but pmOS is the largest and where most development is done). Same goes for your fingerprint daemon.

    There is, of course, also the ethical matter of using AI, as the pmOS page mentions, but balancing issues of pragmatism and principles have been a challenge in the FOSS community since the beginning (ex: “free software” vs “open source”).

    On the last point about understanding the code, I feel you’ve shown that you are able to understand the code that you commit, or at least I hope that you do. I’m willing to take you at your word when it comes to that.