Live data from Hacker News

A faster heart for F-Droid

f-droid.org

91–100 of 231 posts

Re: A faster heart for F-Droid

#91

> this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access. I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argu…

It's just a build server no? If that's the case it's not the end of the world.

Or does it also serve the APKs?

Re: A faster heart for F-Droid

#92

Earlier quoted context omitted.

Yikes. They don't need a "special arrangement" for those requirements. This is the bare minimum at many professionally run colocation data centers. There is not a security requirement that can't be met by a data center -- being secure to customer requirements is a critical part of their business. Maybe the person who wrote that is only familiar with web hosting services or colo-by-the-rack-unit type services where re…

A super duper secure locked cabinet acessible only to them or anyone with a bolt cutter. You want to host servers on your own hardare? Uh yikes. Let's unpack this. As a certified AWS Kubernetes professional time & money waster, I can say with authority that this goes against professional standards (?) and is therefore not a good look. Furthermore, I can confirm that this isn't it chief.

Because it's a secret, we don't know if it's mom's basement where the door doesn't really lock anyways, just pull it real hard, or if it's at Uncle Joey's with the compound and the man trap and laser sensors he bought at government auction through a buddy who really actually works at the CIA.

Re: A faster heart for F-Droid

#93
post #26

Earlier quoted context omitted.

Depends on the thread model, which one is worse. State actor? Gets into data centre, or has to break into a privately owned apartment. Criminal/3rd party state intelligence service? Could get into both, at a risk or with blackmail, threats, or violence. Dumb accidents? Well, all buildings can burn or have an power outage.

> State actor? Gets into data centre, or has to break into a privately owned apartment. I don’t think a state actor would actually break in to either in this case, but if they did then breaking into the private apartment would be a dream come true. Breaking into a data center requires coordination and ensuring a lot of people with access and visibility stay quiet. Breaking into someone’s apartment means waiting until…

> Data centers are built with redundant network connectivity, backup power, and fire suppression. [...] The question is their relative frequency, which is where the data center is far superior.

Well, I remember one incident were a 'professional' data center burned down including the backups.

https://en.wikipedia.org/wiki/OVHcloud#Incidents

I know no such incident for some basement hosting.

Doesn't mean much. I'm just a bit surprised so many people are worried because of the server location and no one had mentioned yet the quite outstanding OVH incident.

Re: A faster heart for F-Droid

#94
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

"Nothing is ever good enough" (tm)

If I were running a volunteer project, I would be dumping thousands a month into top-tier hosting across multiple datacenters around the world with global failover.

Re: A faster heart for F-Droid

#95
post #65

Earlier quoted context omitted.

You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.

Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can't visit.

Every colo I've visited has a system for allowing physical access for our equipment, generally during specific operating hours with secure access card.

Re: A faster heart for F-Droid

#96

Earlier quoted context omitted.

It's a community donation-supported project. That's kind of the whole deal. Regardless, the ongoing interest on $400K alone would be enough to pay colo fees.

Since you've already done the math, what's the interest on $400k pay for the colo costs?

at a (fairly modest) 3.3 its like 1100/month.

I don't know what kind of rates are available to non-profits, but with 400k in hand you can find nicer rates than 3.3 (as of today, at least).

that covers quite a few colo possibilities.

Re: A faster heart for F-Droid

#97
post #44

Earlier quoted context omitted.

I never questioned or thought twice about F-Droid's trustworthiness until I read that. It makes it sound like a very amateurish operation. I had passively assumed something like this would be a Cloud VM + DB + buckets. The "hardware upgrade" they are talking about would have been a couple clicks to change the VM type, a total nothingburger. Now I can only imagine a janky setup in some random (to me) guy's closet. In…

> It makes it sound like a very amateurish operation. Wait until you find out how every major Linux distributions and software that powers the internet is maintained. It is all a wildly under-funded shit show, and yet we do it anyway because letting the corpos run it all is even worse.

What do you mean by "major distribution"?

e.g. AS41231 has upstreams with Cogent, HE, Lumen, etc... they're definitely not running a shoestring operation in a basement. https://bgp.tools/as/41231

Re: A faster heart for F-Droid

#98
post #26

Earlier quoted context omitted.

Depends on the thread model, which one is worse. State actor? Gets into data centre, or has to break into a privately owned apartment. Criminal/3rd party state intelligence service? Could get into both, at a risk or with blackmail, threats, or violence. Dumb accidents? Well, all buildings can burn or have an power outage.

> State actor? Gets into data centre, or has to break into a privately owned apartment. I don’t think a state actor would actually break in to either in this case, but if they did then breaking into the private apartment would be a dream come true. Breaking into a data center requires coordination and ensuring a lot of people with access and visibility stay quiet. Breaking into someone’s apartment means waiting until…

>Breaking into a data center requires coordination and ensuring a lot of people with access and visibility stay quiet

Or just a warrant and a phone call to set up remote access? In the UK under RIPA you might not even need a warrant. In USA you can probably bribe someone to get a National Security Letter issued.

Depending on the sympathies of the hosting company's management you might be able to get access with promises.

I dare say F-Droid trust their friends/colleagues more than they trust randos at a hosting company.

As an F-Droid user, I think I might too? It's a tough call.

Re: A faster heart for F-Droid

#99

Earlier quoted context omitted.

Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can't visit.

To be quite honest I've never seen a colo that didn't offer access at all. The cheapest locations may require a prearranged escort because they don't have any way to restrict access on the floors, but by the time you get to 1/4 rack scale you should expect 24/7 access as standard.

Same. We would colo and had racks behind chain link fencing that was locked behind cipher locks

Re: A faster heart for F-Droid

#100

It's frankly embarrassing how many of the comments on this thread are some version of looking at the XKCD "dependency" meme and deciding the best course of action is to throw spitballs at the maintainers of the critical project holding everything else up.

F Droid is no where near being a critical project holding Android up. The Play Store, and the Play Services themselves are much more critical. Being open source doesn't make you immune from criticism for not following industry standards or being called out for poor security.
Post reply on HN