Earlier quoted context omitted.
Yikes. They don't need a "special arrangement" for those requirements. This is the bare minimum at many professionally run colocation data centers. There is not a security requirement that can't be met by a data center -- being secure to customer requirements is a critical part of their business. Maybe the person who wrote that is only familiar with web hosting services or colo-by-the-rack-unit type services where re…
A super duper secure locked cabinet acessible only to them or anyone with a bolt cutter. You want to host servers on your own hardare? Uh yikes. Let's unpack this. As a certified AWS Kubernetes professional time & money waster, I can say with authority that this goes against professional standards (?) and is therefore not a good look. Furthermore, I can confirm that this isn't it chief.
A faster heart for F-Droid
81–90 of 231 posts
Re: A faster heart for F-Droid
#82Earlier quoted context omitted.
Yikes. They don't need a "special arrangement" for those requirements. This is the bare minimum at many professionally run colocation data centers. There is not a security requirement that can't be met by a data center -- being secure to customer requirements is a critical part of their business. Maybe the person who wrote that is only familiar with web hosting services or colo-by-the-rack-unit type services where re…
A super duper secure locked cabinet acessible only to them or anyone with a bolt cutter. You want to host servers on your own hardare? Uh yikes. Let's unpack this. As a certified AWS Kubernetes professional time & money waster, I can say with authority that this goes against professional standards (?) and is therefore not a good look. Furthermore, I can confirm that this isn't it chief.
And you're not going to even get close to the cabinet in a data center with a set of bolt cutters. But even if you did, you brought the wrong tool, because they're not padlocked.
Re: A faster heart for F-Droid
#83Earlier quoted context omitted.
Don't bet on receiving money in the future.
It's a community donation-supported project. That's kind of the whole deal. Regardless, the ongoing interest on $400K alone would be enough to pay colo fees.
Re: A faster heart for F-Droid
#84Earlier quoted context omitted.
"I understand this is a volunteer effort, but it's not a good look." I would agree, that it is not a good look for this society, to lament so much about the big evil corporations and invest so little in the free alternatives.
You can't just host servers in your own basement! You need to pay out the ass to host servers in some big company's basement!
Having two servers in two basements not near each other would be good, having five would be better, and honestly paying money to put them in colo facilities to have more reliable power, cooling, etc. would be better still. Computer hardware is very cheap today and it doesn't cost that much money to get a substantial amount of redundancy, without being dependent on any single big company.
Re: A faster heart for F-Droid
#85Re: A faster heart for F-Droid
#86Earlier quoted context omitted.
You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.
Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can't visit.
Basically anywhere with cage or cabinet colocation is going to have site access, because those delineations only make sense to restrict on-site human access.
Re: A faster heart for F-Droid
#87Modern machines go up to really mental levels of performance when you think about it and for a lot of small scale things like F droid I doubt it takes a lot of hardware to actually host it. A lot of its going to be static files so a basic web server could put through 100s of thousands of requests and even on a modest machine saturate 10 gbps which I suspect is enough for what they do. This just reads to me like they…
Re: A faster heart for F-Droid
#88Earlier quoted context omitted.
You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.
Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can't visit.
Re: A faster heart for F-Droid
#89Earlier quoted context omitted.
Eh... The set of people who can maliciously modify it is the people who run f-droid, instead of the cloud provider and the people who run f-droid. It'd be nice if we didn't have to trust the people who run f-droid, but given we do I see an argument that it's better for them to run the hardware so we only have to trust them and not someone else as well.
You actually do not have to trust the people who run f-droid for those apps whose maintainers enroll in reproducible builds and multi-party signing, which only f-droid supports unlike any alternatives.
I've been using Obtainium more recently, and the idea is simple: a friendly UI that pulls packages directly from the original source. If I already trust the authors with the source code, then I'm inclined to trust them to provide safe binaries for me to use. Involving a middleman is just asking for trouble.
App stores should only be distributors of binaries uploaded and signed by the original authors. When they're also maintainers, it not only significantly increases their operational burden, but requires an additional layer of trust from users.
Re: A faster heart for F-Droid
#90Earlier quoted context omitted.
> shove it in a special someone's basement They didn't say what conditions it's held in. You're just adding FUD, please stop. It could be under the bed, it could be in a professional server room of the company ran by the mentioned contributor.
100%. Just as an example I have several racks at home, business fiber, battery backup, and a propane generator as a last resort. Also 4th amendment protections so no one gets access without me knowing about it. I host a lot of things at home and trust it more than any DC.