Hacker News new | ask | show | jobs
by alexandrerond 1754 days ago
I'm very happy to see that Sailfish keeps shipping because more alternatives are always good.

I tried to use it a while ago (Sailfish 3) but was driven off it because of the huge gap between the marketing and the actual reality.

The claim that they are privacy and security focused was total bogus (and perhaps someone can comment if it still is).

To use the phone features, a Jolla account is needed, so it will "ping home to Jolla". Privacy policy is pretty standard, so they reserve the right to track you all they want and of course, this is tied to your license, payment method etc. So much for privacy focused...

What fully drove me off was that they launched full disk "encryption", but the LUKS encryption-key password they used was the user's numeric pin (4-8 digits long). So encryption keys could be bruteforced by a kid and they seemed to be fine with it (I don't know if nowadays it supports a passphrase).

Then I also learned that apps in the "app-store" were not signed in any way so impossible to certify that what you are installing is actually coming from the app repository etc. the phone was just lacking basic security all over the place.

I hope they are closer now to closing the "gap" between their marketing and the reality.

7 comments

There is still some truth to this. But the os does not phone home like google and apple phones do. Not even close. Package signing is usable but still not widly adopted. App jails are still in beta, since, 4. Luks passphrases are almost ready for noobs. I decided to work on it since it only calls home when you ask. And ui.
Thank you. That fish has sailed for me.
I think that gap has more to do with manpower/funding than a lack of genuine desire on Jollas part to make those features work. I still don't understand why it's so hard for there to be a market for alternatives to iOS and Android, but as the Microsoft Nokia fiasco as well as the Ubuntu phone and delays of the Purism Librem phone show, it's not easy.

I've been using Jolla and Meego before that and I like the interface a lot better than the main players. Granted, I'm not much of a phone/app user beyond the basics like a music player, calendar, clock and TOTP app, so your mileage may vary.

Thanks for this, I was thinking of trying it on an Android media device. Is there a fork or is this totally proprietary?
Nemo Mobile and/or Mer are, I think, the FOSS builds/parts (I forget; there are way too many pieces and too many names in the mix), but the sailfish GUI is proprietary so YMMV.

https://wiki.pine64.org/index.php?title=PinePhone_Software_R...

> I'm very happy to see that Sailfish keeps shipping because more alternatives are always good.

If you are searching for actually user-respecting alternatives based on FLOSS, have a look at Librem 5 and Pinephone.

Someone needs to build a true BSD phone to free FLOSS from the monopoly of Linux.

Then a Haiku phone to break the monopoly of UNIX.

NetBSD or MINIX phone...
Why not "just" use Inferno? ;)

https://www.youtube.com/watch?v=LYPBAckCEQo

i think if we're deciding what people hypothetically decide to do with their time and effort, someone needs to just work on getting one interface to the point of being stable and usable for the basics. From what I can tell there's a ton of options all with their own shortcomings right now. We don't really need yet another half complete option
Oh, and I don't have to beg apple to sign for me. Signed via play or the apple store means nothing. Signed with my gpg key, sure.
The use of GPG is a red flag for me in anything being developed past 2006. Just stop it already, it's terrible and there are better alternatives
It is indeed terrible, but it's how I do signing and mail encryption. what is your suggestion?
From their website:

"The mobile OS with built-in privacy"

Literally uses cookies on their website

You said nothing of privacy on their website, and since when are cookies the benchmark for privacy. You can literally just clear them.