Yes, AOSP includes a lot of GPLv2 code and we use GPLv2 licensing ourselves including for our Vanadium browser project. We don't want GrapheneOS to be more restrictively licensed than the Linux kernel and AOSP so we avoid GPLv3 code bundled with the OS. GPLv3 is perfectly acceptable for apps in our App Store but we don't want it for the ones in the OS.
It does make a difference. GrapheneOS includes a lot of GPLv2 code from AOSP and we choose it as a license for several of own projects within GrapheneOS.
A compilation of a covered work with other separate and independent works, which are not by their nature extensions of the covered work, and which are not combined with it such as to form a larger program, in or on a volume of a storage or distribution medium, is called an “aggregate” if the compilation and its resulting copyright are not used to limit the access or legal rights of the compilation's users beyond what the individual works permit. Inclusion of a covered work in an aggregate does not cause this License to apply to the other parts of the aggregate.
If you'd include a GPLv3 gallery app in, say, a mobile OS, it does not mean that the rest of the OS has to be under the GPLv3. It merely means that you cannot limit the user's right when it comes to the GPLv3-part (the gallery app). They would still be allowed to redistribute/modify it and you have to provide the source code on request.
You only have to make other code GPLv3 if you somehow create a derivative work (e.g. linking against a GPLv3 library).
The issue isn't that GPLv3 applies to non-derivative OS components but rather that the terms apply to the overall redistribution of the OS. Including any GPLv3 component means GrapheneOS cannot be used in products where AOSP can be used due to having additional restrictions beyond GPLv2. We don't want more restrictive licensing than AOSP. We're fine with using additional GPLv2 code as long as we're sure it's not going to move to GPLv3 or that if it does we're prepared to maintain it ourselves.
idk but I saw people saying there are problems with it.
I hear it conflicts with GPLv2 and other permissive licensing. GPLv2 doesn't allow restrictions added by GPLv3, the two aren't compatible. iirc it would restrict how users or companies use GOS.
GOS is an open source software project, they know how licenses work in practice better than most of the rest of us.
IDK, but I have read a lot of objections from feminists as well.
Where I live, the religious population is under 10 per cent, but complete atheists will argue like this as well.
I suspect the "ick" factor is simply inherent here. Kids provoke instinctive protective/emotional reactions in a way that other phenomena don't.
For example, it is quite obvious that Trump faces a lot more popular backlash due to his suspected connections with Epstein than over his actual threats to Denmark/Greenland and war with Iran.
Non-religious people are also susceptible to the FUD about supposedly or genuinely new things. Whatever innate ick there clearly is, it gets co-opted to demonize much wider ranges of things, and conversely can be suppressed like in the Epstein's circle's case. I don't find it convincing that the legislators passing reactionary prohibitions are just driven by a natural ick rather than particular agenda.
Touche.. actually a good point, but actually those are two different situations.
With one, I'm accessing a website and trusting that the certificate is signed by someone I trust; so the trust in my browser certificates (which include certificates from hundreds of certificate authorities all over the world, any one of which could be compromised, robbed, or controlled by an adversarial person or even government) is extended to the site that I'm visiting. To say this is weak sauce rather understates how bad this actually is. (To paraphrase Churchill, this is the worst possible design, except for all the rest.)
With the other, I'm logging into a server for the first time (and I could simply deploy the same trusted host key to all my ssh servers via an autoscaling configuration or whatever). I think it's debatable if TOFU is worse or better than your (granted clever) metaphor.
(to those who'd recommend userify, yes - great for the client login issue and definitely increases security, but to parent's point, TOFU is still needed unless you want to distribute host pubkeys)
Pairing is absolutely necessary for bidirectional authentication, where each party must verify the identity of the other end.
To visit this site, there is no pairing, because the site does not know who I am.
In order to verify the identity of the HN site, I must trust that the maintainers of the installation packages of the browsers that I use (Firefox, Vivaldi, Chromium) have ensured that the built-in certificates have reached me through a secure path. This actually requires much more trust than when someone answers "yes" to the SSH unknown host message.
If I use certificates for accessing e.g. the network of my employer, then my work computer must be paired with some corporate server, i.e. a unique certificate has been generated for myself and it has been copied to some certificate authority server for signing and then to my computer, and also a certificate of the local certificate authority has been copied to my personal computer.
While pairing is unavoidable for bidirectional authentication, it is not necessarily direct between the end points. Both end points must have been paired with at least one other computer but they need not have been paired between themselves previously if there exists some path through secure connections that have been originally created by pairing.
When certificates are used, usually the pairings are not done directly between end points, but each computer must be paired with the server hosting the certificate authority.
The term "pairing" is not used frequently, but it should have been preferred, because frequently the users do not understand which are the exact actions on which the security of their communications depend, which leads to various exploits. The critical security actions are those that perform the pairing.
"Pairing" of 2 systems, e.g. A and B, means that some information must be transmitted through a secure channel from A to B and some other information must be transmitted through a secure channel from B to A. An alternative pairing method is to generate both pieces of information on one of the 2 systems and transmit both of them through a secure channel to the other. The information exchange channels must already be secure, because before pairing authentication is impossible.
The pairing between a PC and the server hosting the certificate authority can be done in various ways, depending on where the PC certificate is generated. If the certificate is generated at the certificate authority than both it and the root certificate must be copied through a secure channel to the PC. If the certificate is generated on the PC, it must be sent through a secure channel to the CA for signing, then it must be sent back also through a secure channel.
In practice, administrators are not always careful enough for the channels through which certificates are copied to be really secure. For instance they may be copied through network links that are not yet authenticated, which is equivalent with the TOFU method optionally used by SSH.
This passionate apologia of nihilism is not consistent with not caring what other people do or want. If "virtue signalling" elicits such reaction, perhaps it's actually working. Besides, voting with your wallet, an actual tangible action, is not virtue signalling.
If you ever visit Bonaire let me know and I can show you the abundance of life we are stewarding on my land.
It's mostly setting healthy boundaries on what we perceive we can affect. I don't buy American food (except Cocoa Rice Crispies), functionally it's a boycott. Is that the reasoning? No, it just tastes like crap.
> I truly don't understand where ya'll draw the line.
> I truly don't care what other people do or want, I just look to ensure I can live the life I desire while respecting that which others want or impose.
This is nihilism. If you have any beliefs, you don't seem to feel it important or necessary to exercise them. You acquiesce without even being challenged.
> Another example is AI. I despise it, and honestly think it's evil. Yet I'm using it to secure financial stability in a way that does not require AI to sustain.
This is also nihilism. You claim to have a belief, but do not exercise it. In your own example, your beliefs are meaningless; you are ultimately lead to whatever action is the most likely to lead to material comfort.
The only people who thrive in a dictatorship are its enforcers. And by the way a dictatorship needs quite a lot of them. That's how, decades after its fall, you get voices saying it wasn't all that bad, there were some nice things actually, or we should do it again.
And also your neighbors absolutely will sell you out.
I agree. A foreign powered civil war is worse than that.
Thriving in a dictatorship, even not as an enforcer, is possible. It's a worse life in general but still a life you can live.
Generally speaking, the only life that truly sucks in a dictatorship is if you become an enemy of the state. That doesn't generally apply to all citizens because, if it did, a dicatorship would quickly end in revolt. That is the theory behind strong sanctions. It's believed that if you starve a nation eventually the citizens revolt. The problem is it takes little resources to keep people happy, ultimately.
Are we still talking about massive companies with power to arbitrarily decide how billions of people use the personal computers they bought? Who's doing the feeling? Why would we presume all of their conduct to be moral?
reply