Live data from Hacker News

F-Droid Board of Directors nominations 2026

f-droid.org

101–110 of 160 posts

Re: F-Droid Board of Directors nominations 2026

#101
post #96

Earlier quoted context omitted.

The other apps are clients. The apps themselves don't actually contain any content, they're just code. An app that itself contains an offline copy of a book with NSFW text is not the same thing. Meanwhile Reddit is a doubly poor example because even though the service contains NSFW content, it marks it as such, and then the client not only doesn't itself contain it but gives the user a separate opportunity to select…

Bible apps often don’t contain the text directly, but allow the user to download a preferred translation on initial startup. That didn’t prevent them from being marked NSFW. And clearly that wasn’t the standard anyway. Before the introduction of the policy restricting religious texts, the only apps F-Droid had marked NSFW were frontends to porn sites, even though the apps presumably contained no sexual content direct…

I would still say that counts as the app providing the content, not users. It's not user uploaded, it's app uploaded.

Re: F-Droid Board of Directors nominations 2026

#102

Earlier quoted context omitted.

This is however not their main argument. I doubt they would accept such pull request.

It would require a significant commitment of limited resources to broadly support insecure devices with very little upside, and to do so would constitute gross mismanagement of the project. Meanwhile, others are completely free to fork numerous GrapheneOS improvements or benefit from their upstream improvements (as some have, including Google). Why can't you understand that?

I never mentioned any commitment except accepting pull requests, did I? Qubes can do that and doesn't require a fork. Are you saying they have much more resources?

Re: F-Droid Board of Directors nominations 2026

#103

Earlier quoted context omitted.

Qubes OS, operating system designed for security, doesn't prevent its installation on computers without VT-d. It will just warn you.

The problem with laptops is that UEFI is a shadow operating system that keeps running after boot, with a bunch of security vulnerabilities. Furthermore all Intel / AMD chips have a microprocessor state called SMF which if you trigger it basically gives you carte blanche to do whatever you want. "Trusted Boot" is a meme on x86. If you really want something like that you need to do what Oxide Computer is doing and rip…

I use Qubes with TPM and Heads and with a hardware key. All based on FLOSS, so its possible.

Re: F-Droid Board of Directors nominations 2026

#104
post #96

Earlier quoted context omitted.

The other apps are clients. The apps themselves don't actually contain any content, they're just code. An app that itself contains an offline copy of a book with NSFW text is not the same thing. Meanwhile Reddit is a doubly poor example because even though the service contains NSFW content, it marks it as such, and then the client not only doesn't itself contain it but gives the user a separate opportunity to select…

Bible apps often don’t contain the text directly, but allow the user to download a preferred translation on initial startup. That didn’t prevent them from being marked NSFW. And clearly that wasn’t the standard anyway. Before the introduction of the policy restricting religious texts, the only apps F-Droid had marked NSFW were frontends to porn sites, even though the apps presumably contained no sexual content direct…

It should be pretty obvious why porn apps are marked NSFW despite not containing any content. Substantially all of the content they can be used to access is NSFW, whereas it's reasonably possible to access only SFW content on Reddit.

Which would also explain the Bible apps without an initial copy. Choosing which translation to download when substantially all of them are translations of the same NSFW text means that substantially all of the users would end up with NSFW content on their device by using the app.

Re: F-Droid Board of Directors nominations 2026

#105
post #49

Earlier quoted context omitted.

>Close to every bank in the EU requires their user to have an app Possibly this was hyperbole but in any case it's not correct at all. Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way. Even Wise, a cutting-edge neobank, does not require you to use its app. And its website accepts standard TOTP authenticator for 2FA. Revolut is app-only, which is why I never use i…

> Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way. My wording was bad, sorry; but try to install their app just once. After that, I'd bet you won't ever be able to go back to SMS validation (which is what I was talking about at the end of my comment). If not, I'd be curious to know the banks you're talking about (to consider switching to them, for one thing). Wh…

>I'd be curious to know the banks you're talking about

Fortuneo (internet-only subsidiary of Crédit Mutuel) and LCL. I have had both their apps installed at points in the past. In both cases they defaulted back to SMS 2FA upon uninstalling, though I remember worrying I would have the problem you describe.

Ultimately I can't see how a bank could get away with forcing (rather than just pushing) existing customers to install an app. This would surely be a breach of contract.

Re: F-Droid Board of Directors nominations 2026

#106

Earlier quoted context omitted.

>Close to every bank in the EU requires their user to have an app Possibly this was hyperbole but in any case it's not correct at all. Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way. Even Wise, a cutting-edge neobank, does not require you to use its app. And its website accepts standard TOTP authenticator for 2FA. Revolut is app-only, which is why I never use i…

Here in The Netherlands banks used to offer authenticator devices, which they are phasing out (you can still use them, but they wont replace them once they run out of battery). Pretty much all banks switched to app-only. No SMS at all (which is not surprising, because SMS is not secure). Also, IMO fingerprint/face-based authentication is much nicer/quicker, especially for online payment flows like iDEAL (Dutch predec…

>And banks here work on GrapheneOS

Until they don't.

Re: F-Droid Board of Directors nominations 2026

#107

Earlier quoted context omitted.

Qubes OS, operating system designed for security, doesn't prevent its installation on computers without VT-d. It will just warn you.

As one who has lived out of both operating systems for years, I struggle with the way you invariably make value judgments about GrapheneOS every time it comes up in a thread, based on your (justifiable) appreciation for Qubes OS. The same thing happens in reverse on the GrapheneOS forums, by the way. Both lines of thinking are faulty, and attempting to directly extrapolate from one project to the other (in either dir…

> In addition to all that, by the nature of the respective code bases it presents a significantly smaller attack surface than a computer running Qubes OS.

I critisize precisely because I don't understand what you're talking about. The last relevant VM escape was in 2006, discovered by Rutkowska herself. Since then, nothing could access my secrets in an offline vault VM. I would appreciate a clarification, how GrapheneOS can be more secure without reliable virtualization.

AFAIK Xen security relies on 100k LoC. And this is in addition to the virtualization. How many LoC does GrapheneOS require to provide its security? How can it have less attack surface than Xen? Developers replying to me here never provided an understandable reasoning, only keep repeating that it's "very, very secure", without even mentioning any threat model.

Doesn't GrapheneOS rely on closed Google's hardware to provide its security? I would never trust Google with that. How can I not critisize such approach?

Re: F-Droid Board of Directors nominations 2026

#108
post #39

Earlier quoted context omitted.

Imagine if the Linux project had this same mentality. Thank goodness they don't.

Which leads to things like laptop sleep working inconsistently. Instead of having a good reputation, Linux's reputation gets hurt by all the random devices it allegedly supports.

Devices designed for Linux work flawlessly, just like it happens with Mac and Windows.

Re: F-Droid Board of Directors nominations 2026

#109
post #96

Earlier quoted context omitted.

Bible apps often don’t contain the text directly, but allow the user to download a preferred translation on initial startup. That didn’t prevent them from being marked NSFW. And clearly that wasn’t the standard anyway. Before the introduction of the policy restricting religious texts, the only apps F-Droid had marked NSFW were frontends to porn sites, even though the apps presumably contained no sexual content direct…

It should be pretty obvious why porn apps are marked NSFW despite not containing any content. Substantially all of the content they can be used to access is NSFW, whereas it's reasonably possible to access only SFW content on Reddit. Which would also explain the Bible apps without an initial copy. Choosing which translation to download when substantially all of them are translations of the same NSFW text means that s…

[deleted]

Re: F-Droid Board of Directors nominations 2026

#110
post #96

Earlier quoted context omitted.

Bible apps often don’t contain the text directly, but allow the user to download a preferred translation on initial startup. That didn’t prevent them from being marked NSFW. And clearly that wasn’t the standard anyway. Before the introduction of the policy restricting religious texts, the only apps F-Droid had marked NSFW were frontends to porn sites, even though the apps presumably contained no sexual content direct…

It should be pretty obvious why porn apps are marked NSFW despite not containing any content. Substantially all of the content they can be used to access is NSFW, whereas it's reasonably possible to access only SFW content on Reddit. Which would also explain the Bible apps without an initial copy. Choosing which translation to download when substantially all of them are translations of the same NSFW text means that s…

Except, of course, that the Bible in any translation is not NSFW, certainly in the common usage of the term. It contains depictions of violence and sex, yes. But so does Fanny Hill, and that hasn’t legally been considered obscene in the UK or the USA in over fifty years. F-Droid’s excuse, that they needed to restrict Bible apps to protect F-Droid from legal liability, is not believable.
Post reply on HN