Live data from Hacker News

A faster heart for F-Droid

f-droid.org

61–70 of 231 posts

Re: A faster heart for F-Droid

#61
I think all the criticism of what F-Droid is doing here (or perceived as doing) reflects more on the ones criticising than the ones being criticised.

How many things went upside down and all the "right" things were done (corporate governance, cloud native deployment, automation, etc.). The truth is none of these processes are actually going to make things more secure, and many projects went belly up despite following these kinds of recommendations.

That being said, I am grateful to F-Droid fighting the good fight. They are providing an invaluable service and I, for one, am even more grateful that they are doing it as uncompromisingly as possible (well into discomfort) according to their principles.

Re: A faster heart for F-Droid

#62

> this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access. I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argu…

> a $400,000 grant

IDK if they could bag this kind of grant every year, but isn't this the scale where cloud hosting starts to make sense?

Re: A faster heart for F-Droid

#63

It's frankly embarrassing how many of the comments on this thread are some version of looking at the XKCD "dependency" meme and deciding the best course of action is to throw spitballs at the maintainers of the critical project holding everything else up.

At the very least, it's reasonable to expect the maintainers of such a project to be open about their situation when it's that precarious. Why wouldn't you take every opportunity to let your users and downstream projects know that the dependency you're providing is operating with no redundancy and barely enough resources to carry on when things aren't breaking? Why wouldn't they want to share with a highly technical audience any details about how their infrastructure operates?

Re: A faster heart for F-Droid

#64
post #26

Earlier quoted context omitted.

Depends on the thread model, which one is worse. State actor? Gets into data centre, or has to break into a privately owned apartment. Criminal/3rd party state intelligence service? Could get into both, at a risk or with blackmail, threats, or violence. Dumb accidents? Well, all buildings can burn or have an power outage.

> State actor? Gets into data centre, or has to break into a privately owned apartment. I don’t think a state actor would actually break in to either in this case, but if they did then breaking into the private apartment would be a dream come true. Breaking into a data center requires coordination and ensuring a lot of people with access and visibility stay quiet. Breaking into someone’s apartment means waiting until…

> The question is their relative frequency, which is where the data center is far superior.

as a year long f-droid user I can't complain

Re: A faster heart for F-Droid

#65
post #62

> this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access. I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argu…

> a $400,000 grant IDK if they could bag this kind of grant every year, but isn't this the scale where cloud hosting starts to make sense?

You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.

Re: A faster heart for F-Droid

#66
post #37

Earlier quoted context omitted.

> shove it in a special someone's basement They didn't say what conditions it's held in. You're just adding FUD, please stop. It could be under the bed, it could be in a professional server room of the company ran by the mentioned contributor.

100%. Just as an example I have several racks at home, business fiber, battery backup, and a propane generator as a last resort. Also 4th amendment protections so no one gets access without me knowing about it. I host a lot of things at home and trust it more than any DC.

> Also 4th amendment protections so no one gets access without me knowing about it.

If there's ever a need for a warrant for any of the projects, the warrant would likely involve seizure of every computer and data storage device in the home. Without a 3rd party handling billing and resource allocation they can't tell which specific device contains the relevant data, so everything goes.

So having something hosted at home comes with downsides, too. Especially if you don't control all of the data that goes into the servers on your property.

Re: A faster heart for F-Droid

#67
post #63

It's frankly embarrassing how many of the comments on this thread are some version of looking at the XKCD "dependency" meme and deciding the best course of action is to throw spitballs at the maintainers of the critical project holding everything else up.

At the very least, it's reasonable to expect the maintainers of such a project to be open about their situation when it's that precarious. Why wouldn't you take every opportunity to let your users and downstream projects know that the dependency you're providing is operating with no redundancy and barely enough resources to carry on when things aren't breaking? Why wouldn't they want to share with a highly technical…

> when it's that precarious

assumptions

Re: A faster heart for F-Droid

#69
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

> commodity hardware

Apart from the "someone's basement", as objected to in this thread, it also doesn't say they acquired "commodity hardware"; I took it to suggest the opposite, presumably for good reason.

Re: A faster heart for F-Droid

#70
post #17
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

As someone that has run many volunteer open source communities and projects for more than 2 decades, I totally get how big "small" wins like this are. The internet is run on binaries compiled in servers in random basements and you should be thankful for those basements because the corpos are never going to actually help fund any of it.

It's a shame mozilla wont step up to fund it. They've spunked way more money on way dumber things.
Post reply on HN