Hacker Newsnew | past | comments | ask | show | jobs | submit | pabs3's commentslogin

In the last year sometime I ran the Haiku live image off USB on my only laptop (2011 X201t), it worked fairly well.

> Are you really checking all the files in there, even the binaries?

One should never trust the binaries, always build them from source, all the way down to the bootloader.

https://bootstrappable.org/

Checking all the files is really the only way to deal with potential malware, or even security vulns.

https://github.com/crev-dev/


Nice ideal, but Chrome/Firefox would take days to build on your average laptop (if it doesn't run out of memory first).

The latest Firefox build that Debian did only took just over one hour on amd64/armhf and 1.5 hours on ppc64el, the slowest Debian architecture is riscv64 and the last successful build there took only 17.5h, so definitely not days. Your average modern developer-class laptop is going to take a lot less than riscv64 too.

I think Bootstrappable Builds from source without any binaries, plus distributed code audits would do a better job than locking down already existing binaries.

https://bootstrappable.org/ https://github.com/crev-dev/


> the device will only boot the vendor's signed firmware

That sounds like what Software Freedom Conservancy would call a GPL violation:

https://sfconservancy.org/blog/2021/mar/25/install-gplv2/ https://sfconservancy.org/blog/2021/jul/23/tivoization-and-t... https://events19.linuxfoundation.org/wp-content/uploads/2017...


> That sounds like what Software Freedom Conservancy would call a GPL violation

Sure, it is. So what? Have you got 200k for lawyers and years of your life to spend in court fighting over it?

I have personally contacted the SFC with ample evidence of deliberate and wilful GPL violations, such as providing a written offer for source code and then ignoring or flat out refusing requests for the source code. The SFC has acknowledged the vendors are violating the spirit and letter of the GPL.

Nothing happens. The SFC is one organisation with limited resources, FOSS developers don't want to spend their time in court, they'd rather develop software. Vendors know 9 times out of 10 they will get away with the GPL violation scot-free.

It's fine to put on your rose colored glasses and pretend GPL forces companies to release source code. Reality is, the vendors have a larger marketing budget than the entire SFC endowment and the vendor's legal team is happy to tar-pit requests ad infinitum.


It is definitely true that any license including the GPL requires effort and resources to enforce, and that almost all authors of GPL software don't have enough of those.

If the SFC lawsuit against Vizio succeeds, then there will be another option; since yourself and others are third-party beneficiaries of the contract embodied in the GPL between Linux kernel developers and hardware vendors that ship Linux; start a class action with other users of the hardware where GPL violations are present, and sue for GPL compliance instead of money. The lawyers will get their legal costs presumably and the users should get source code. Probably some law firms would take this on just for the legal costs, especially if the Vizio precedent makes it easy to win future cases.

https://sfconservancy.org/copyleft-compliance/vizio.html

PS: I don't think SFC have an endowment, they are just directly funded by people who support their goals.


PS: another tactic I have seen applied for GPL enforcement is for the copyright holder to have customs block devices on import since they contain illegally obtained software. This is pretty rare, but can be effective.

Nothing happens my as, until your company gets sued by the FSF and your reputation online gets to the dustbin.

The FSF doesn't sue companies generally, they don't have the resources for that.

Have you considered adding WiFi when someone goes out of BLE range?

Yes, definitely as a fallback! Currently working on a new build. If you are interested in testing please see the following link to become a tester!

https://play.google.com/apps/testing/com.redgrid.red_grid_li...


I currently don't have a use-case for the app, but will keep it in mind if I ever do.

The SFC thinks the GPL is both a license and a contract, see this lawsuit:

https://sfconservancy.org/copyleft-compliance/vizio.html


ArchiveTeam definitely do not intend to kill websites with too fast crawling, but definitely have done that unintentionally and always will stop/slow the crawling when it happens.

Even the distributed crawling system has monitoring and controls to ensure it doesn't kill sites.


Take a look at Arcan, it supports both X11 and Wayland (and I think other protocols too).

https://arcan-fe.com/


Is this open-source or open-weights ML?

yes, indeed. we are working on adding mit licensed phonemizers too by this weekend, so you'll be able to use these models as you like :)

I think you misunderstood the question. I guess its only open-weights not open-source then.

For some insight into the original question, take a look at the Debian ML policy:

https://salsa.debian.org/deeplearning-team/ml-policy


Whats the training data for this?

Sounds like the voice actors from Critical Role but I just came off of watching 48 hours of Campaign 3 so I'm probably imagining things.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: