Live data from Hacker News

A faster heart for F-Droid

f-droid.org

81–90 of 231 posts

Re: A faster heart for F-Droid

#81

Earlier quoted context omitted.

Yikes. They don't need a "special arrangement" for those requirements. This is the bare minimum at many professionally run colocation data centers. There is not a security requirement that can't be met by a data center -- being secure to customer requirements is a critical part of their business. Maybe the person who wrote that is only familiar with web hosting services or colo-by-the-rack-unit type services where re…

A super duper secure locked cabinet acessible only to them or anyone with a bolt cutter. You want to host servers on your own hardare? Uh yikes. Let's unpack this. As a certified AWS Kubernetes professional time & money waster, I can say with authority that this goes against professional standards (?) and is therefore not a good look. Furthermore, I can confirm that this isn't it chief.

[deleted]

Re: A faster heart for F-Droid

#82

Earlier quoted context omitted.

Yikes. They don't need a "special arrangement" for those requirements. This is the bare minimum at many professionally run colocation data centers. There is not a security requirement that can't be met by a data center -- being secure to customer requirements is a critical part of their business. Maybe the person who wrote that is only familiar with web hosting services or colo-by-the-rack-unit type services where re…

A super duper secure locked cabinet acessible only to them or anyone with a bolt cutter. You want to host servers on your own hardare? Uh yikes. Let's unpack this. As a certified AWS Kubernetes professional time & money waster, I can say with authority that this goes against professional standards (?) and is therefore not a good look. Furthermore, I can confirm that this isn't it chief.

Colocation is when you use your own hardware. That's what the word means.

And you're not going to even get close to the cabinet in a data center with a set of bolt cutters. But even if you did, you brought the wrong tool, because they're not padlocked.

Re: A faster heart for F-Droid

#83

Earlier quoted context omitted.

Don't bet on receiving money in the future.

It's a community donation-supported project. That's kind of the whole deal. Regardless, the ongoing interest on $400K alone would be enough to pay colo fees.

Since you've already done the math, what's the interest on $400k pay for the colo costs?

Re: A faster heart for F-Droid

#84
post #24

Earlier quoted context omitted.

"I understand this is a volunteer effort, but it's not a good look." I would agree, that it is not a good look for this society, to lament so much about the big evil corporations and invest so little in the free alternatives.

You can't just host servers in your own basement! You need to pay out the ass to host servers in some big company's basement!

I don't have a problem with an open source project I use (and I do use F-Froid) hosting a server in a basement. I do have a problem with having the entire project hosted on one server in a basement, because it means that the entire project goes down if that basement gets flooded or the house burns down or the power goes out for an extended period of time, etc.

Having two servers in two basements not near each other would be good, having five would be better, and honestly paying money to put them in colo facilities to have more reliable power, cooling, etc. would be better still. Computer hardware is very cheap today and it doesn't cost that much money to get a substantial amount of redundancy, without being dependent on any single big company.

Re: A faster heart for F-Droid

#86
post #65

Earlier quoted context omitted.

You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.

Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can't visit.

I've only ever seen that at data centers that offer colo as more of a side service or cater to little guys who are coloing by the rack unit. All of the serious colocation services I've used or quoted from offer 24/7 site access.

Basically anywhere with cage or cabinet colocation is going to have site access, because those delineations only make sense to restrict on-site human access.

Re: A faster heart for F-Droid

#87

Modern machines go up to really mental levels of performance when you think about it and for a lot of small scale things like F droid I doubt it takes a lot of hardware to actually host it. A lot of its going to be static files so a basic web server could put through 100s of thousands of requests and even on a modest machine saturate 10 gbps which I suspect is enough for what they do. This just reads to me like they…

Which is itself kind of suspicious - why can't they say "yeah we pay for Colo in such-and-such region" if that is what they are doing? Why should that be a secret?

Re: A faster heart for F-Droid

#88
post #65

Earlier quoted context omitted.

You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.

Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can't visit.

To be quite honest I've never seen a colo that didn't offer access at all. The cheapest locations may require a prearranged escort because they don't have any way to restrict access on the floors, but by the time you get to 1/4 rack scale you should expect 24/7 access as standard.

Re: A faster heart for F-Droid

#89
post #19
post #10

Earlier quoted context omitted.

Eh... The set of people who can maliciously modify it is the people who run f-droid, instead of the cloud provider and the people who run f-droid. It'd be nice if we didn't have to trust the people who run f-droid, but given we do I see an argument that it's better for them to run the hardware so we only have to trust them and not someone else as well.

You actually do not have to trust the people who run f-droid for those apps whose maintainers enroll in reproducible builds and multi-party signing, which only f-droid supports unlike any alternatives.

Why have we normalized "app stores" that build software whose authors likely already provide packages of?

I've been using Obtainium more recently, and the idea is simple: a friendly UI that pulls packages directly from the original source. If I already trust the authors with the source code, then I'm inclined to trust them to provide safe binaries for me to use. Involving a middleman is just asking for trouble.

App stores should only be distributors of binaries uploaded and signed by the original authors. When they're also maintainers, it not only significantly increases their operational burden, but requires an additional layer of trust from users.

Re: A faster heart for F-Droid

#90
post #37

Earlier quoted context omitted.

> shove it in a special someone's basement They didn't say what conditions it's held in. You're just adding FUD, please stop. It could be under the bed, it could be in a professional server room of the company ran by the mentioned contributor.

100%. Just as an example I have several racks at home, business fiber, battery backup, and a propane generator as a last resort. Also 4th amendment protections so no one gets access without me knowing about it. I host a lot of things at home and trust it more than any DC.

Which one of those things do you think you can't get in a datacenter?
Post reply on HN