Showing posts with label Source. Show all posts
Showing posts with label Source. Show all posts

Monday, 8 January 2018

New Open Source Mobile OS Puts Privacy Front and Center

A renowned Linux innovator has developed a new mobile operating system, called "Project eelo," in an effort to provide a level of data privacy that traditional Android and iOS devices fail to offer.


The new eelo system will allow mobile phone users to regain control over their personal information at a price they can afford, said Gael Duval, who created Mandrake Linux back in 1998.

Apple has become too expensive, too boring and is "going crazy with its products," he said, while Google has "become too big" and is capturing too much information about what we do.

"They want to know us as much as possible to sell advertising," Duval wrote in a post introducing eelo"s Kickstarter campaign, which has more than doubled its goal with 14 days remaining.



"People are free to do what they want," Duval wrote. "They can choose to be voluntary slaves. "But I do not want this situation for me anymore."

After deciding to leave Google and Apple for eelo, Duval received more than 6,000 reads from a couple of articles he posted detailing his plans, he told LinuxInsider.

The eelo project on Kickstarter reached more than 200 percent of goal after only 15 days.

More than 2,000 people have registered at
eelo.io since December 20 in response to his posted updates, Duval added.

eelo"s Lineage


The new eelo project is a fork of the LineageOS, which is an open source system that runs mainstream Android applications. Open source modules are layered on top of that, which help create a consistent mobile and Web system, Duval said.

The project, which calls for the developers to sell preloaded eelo smartphones and provide some premium services, will run as a nonprofit. As a community project, it will welcome contributors.

The developers will release privacy-enabled smartphone ROMs, as well as smartphones for ordinary users, with associated Web services.

They have been testing custom builds of LineageOS/eelo on the LeEcho Le2 -- a 5.5-inch smartphone with a 1080 x 1920 pixel screen, 3G RAM, 32 GB storage, a finger sensor on the back and a 4K camera -- for about Pounds130, and on a Xiaomi Mi5S.

The developers plan to have downloadable ROMs for a range of devices by 2018, Duval said, as well as a limited number of post-market Flashed devices. He also plans to discuss partnerships with Fairphone, Essential phone or similar devices, and plans to industrialize the phone by 2019.

Privacy Tradeoffs


Many consumers have expressed a desire for greater control over their experience with mobile devices, but there has to be a balance between the value proposition and customers" willingness to share on a personal level.

"Information is currency, and people are going to want more control over who has information on their behaviors and habits on a mobile device," said Ryan Spanier, director of research at
Kudelski Security.

"Eelo is focused on maintaining privacy," he told LinuxInsider, "preventing tracking and monetization of your actions without your consent."

There is growing consumer interest in a potentially less-intrusive operating system for mobile devices, but the task of establishing one in the market is daunting, said independent analyst Jeff Kagan.

Though there have been some prior efforts, no alternative mobile OS has been able to compete with iOS and Android, he told LinuxInsider.

Even if privacy is a concern, the majority of consumers don"t understand the relationship between privacy and the mechanics of their personal technology well enough to persuade them to make the shift to eelo, suggested Paul Teich, principal analyst at Tirias Research.

"Success will be made on social media stickiness and whether enough consumers or organizations think they can get "more privacy" -- whatever that means to them -- than stock Google Android or Apple iOS products," he told LinuxInsider.

Developing leading products like the iPhone and other devices involves the willingness to make tradeoffs, noted Gartner analyst Tuong Nguyen.

Companies must invest substantial resources to make their products appeal to the specific needs of their customers, he told LinuxInsider.

"Google spends a lot of time and effort to make [products] easy to use," Nguyen said, "to keep you within their ecosystem."

Saturday, 30 December 2017

Apple to open source its first graphical OS from the Lisa

Apple had a number of massive hits in the early 80s as the personal computer revolution was picking up steam. However, the Apple Lisa was not one of them. This computer was an undeniable flop, but it’s an important part of technology history.

It was one of the first systems to run a graphical user interface (GUI), and included much more advanced hardware than competing systems. You may soon be able to relive the age of Lisa now that the source code has been recovered. Apple is checking over the code and could give the green light to release it in a few months.

The code was recovered thanks to the diligence of the Computer History Museum. The museum’s software curator Al Kossow announced the find on a Lisa mailing list a few days ago. According to Kossow, the code has been handed off to Apple, which is reviewing it in advance of release. Considering the age of the software, there’s not likely to be any sensitive information in there.

It’s not often a computer that performed so poorly in the marketplace has such historic significance, but the Lisa came at an unusual time. Apple was still riding high on the success of the Apple II series, but more competitors were appearing every quarter. Co-founder Steve Jobs was famously excited by the demos of a GUI he saw at Xerox in the late 1970s, and the Lisa was the first machine to leverage that technology.

It even had a mouse! Apple spent upward of $50 million developing the first Lisa, which hit the market with a starting price of $9,995 in 1983. Apple only sold about 100,000 units of the Lisa, but the lessons learned from Lisa led Apple to develop the very successful Macintosh a year later. Despite predating the original Macintosh, the Lisa was significantly more powerful, with support for up to 2MB of RAM (the Mac topped out at 512KB and initially shipped with just 128KB). While the Mac’s CPU is clocked nominally faster, at 7.8MHz instead of 5MHz, the 6800K CPU and video controller can’t simultaneously communicate with system RAM. This reduced the Mac’s overall performance relative to its earlier and vastly more expensive counterpart.



Even the name “Lisa” comes with a lot of historic baggage. At the time, Apple said the name was an acronym for Local Integrated System Architecture. However, many suspected the name was a reference to Jobs’ first daughter Lisa Nicole Brennan, who he denied fathering for years. In his later years, Jobs admitted the computer was named after his daughter.

Fans of classic computing should keep an eye on the Computer History Museum’s website for the Lisa source code, as well as information about the historic importance of the Lisa. According to Kossow, the only thing included in the code dump that likely won’t make it into the final release is part of the LisaWrite word processor. That application shipped with an embedded version of the American Heritage dictionary for the spell checker. Apple doesn’t own that, so it can’t unilaterally choose to release it.

Monday, 25 December 2017

New Open Source Tools Test for VPN Leaks

ExpressVPN on Tuesday launched a suite of open source tools that let users test for vulnerabilities that can compromise privacy and security in virtual private networks.
Released under an open source MIT License, they are the first-ever public tools to allow automated testing for leaks on VPNs, the company said. The tools are written primarily in Python, and
available for download on Github.

Originally used to conduct automated regression testing on ExpressVPN"s own software, the tools allow users to check VPNs that might not be providing complete protection to users, said Harold Li, vice president at ExpressVPN.

"We believe the VPN industry as a whole has a duty to properly protect users who place their trust in our products," he told LinuxInsider. "We"re open-sourcing these tools as part of an initiative to encourage the entire VPN industry to join us in investing in and identifying and addressing leaks."

Leaky Gut


One-third of the participants in a November study Propeller Insights conducted for ExpressVPN cited cybersecurity as a reason to use a VPN, particularly to protect against cybersnooping over WiFi connections. About 25 percent cited the use of VPNs to make sure their ISP did not see their cyberactivity, while 15 percent said they used VPNs to protect against government surveillance.

The VPN testing tools can detect a wide range of potential leaks, the company said, including the exposure of an IP address during a WebRTC leak. Also, users" Web activity can be exposed when they switch from a wireless to a wired connection. Unencrypted data can leak when VPN software crashes or cannot reach its server.

ExpressVPN claims to be one the largest consumer virtual private networks in the world, providing one of the largest platforms for a variety of operating systems, including Windows, iOS, Android, Linux and others.

The company offers extensions for a variety of browsers, including Chrome, Firefox and Safari. It supports VPN configurations for a variety of gaming consoles, including Xbox and PlayStation, as well as streaming video platforms such as Amazon"s Fire TV, Apple TV and others.

Trust but Verify


VPNs allow users to use private networks rather than untrusted public networks, but they still can leave them vulnerable in certain situations, said Andrew Howard, chief technology officer at Kudelski Security.

"They cannot protect data once it leaves the VPN, and administrators should not assume that a VPN connection to their network is safe, even if properly authenticated," he told LinuxInsider.

There are opportunities for data leakage when setting up or tearing down VPNs, and leaks can happen during connection drops or software crashes, Howard said.

VPNs can help mitigate the probability of successful attacks leveraging any Wifi vulnerability, including man-in-the-middle attacks, said Leigh Ann Galloway, cybersecurity resilience lead at Positive Technologies.

"VPN technology itself is quite well thought out from the point of information security, but the specific implementations might have flaws, just like any software," she told LinuxInsider.

Vulnerabilities have been found in implementations like OpenVPN, Galloway noted.

In terms of data transfer, there can be leaks during implementation, she added. Leaks also might be attributable to certain software settings or applied encryption algorithms, depending upon stability, length of keys, and methods of key generation.