Live data from Hacker News

F-Droid Board of Directors nominations 2026

f-droid.org

111–120 of 160 posts

Re: F-Droid Board of Directors nominations 2026

#111
post #96

Earlier quoted context omitted.

Bible apps often don’t contain the text directly, but allow the user to download a preferred translation on initial startup. That didn’t prevent them from being marked NSFW. And clearly that wasn’t the standard anyway. Before the introduction of the policy restricting religious texts, the only apps F-Droid had marked NSFW were frontends to porn sites, even though the apps presumably contained no sexual content direct…

It should be pretty obvious why porn apps are marked NSFW despite not containing any content. Substantially all of the content they can be used to access is NSFW, whereas it's reasonably possible to access only SFW content on Reddit. Which would also explain the Bible apps without an initial copy. Choosing which translation to download when substantially all of them are translations of the same NSFW text means that s…

You're trying to be clever, but the context from the drop has been to distinguish "a sincere belief" from this sort of rhetorical underhandedness that you are indulging in.

Not only is this not going to convince anyone that there's anything behind it other than an attempt to formulate a winning argument (having set that as your goal) irrespective whether there's any actual sincerity to the words you're choosing, but it's going to come comes across to a healthy portion the world's population as the opposite of clever: that anyone who's convinced themselves that it really is clever and that no one can possibly permeate this forcefield of insincerity is a perhaps-delusional, and definitely-insufferable halfwit.

Re: F-Droid Board of Directors nominations 2026

#112

Earlier quoted context omitted.

GrapheneOS works only with Pixel devices, which doesn't make it much useful for the vast majority of Android users.

GrapheneOS is working with a manufacturer to change this:[0] > We're working with a major OEM and the devices will be the future versions of existing models they have now. The devices will be priced similarly to Pixels. The initial devices will have a flagship Snapdragon SoC for the best security and support time. Snapdragon flagships have significantly better CPU and GPU performance than Pixels. Snapdragon provides…

That "major OEM" seems to be Motorola, i.e. Lenovo.

Re: F-Droid Board of Directors nominations 2026

#113
post #99

Earlier quoted context omitted.

Even with Google's changes, F-Droid will continue to work with Android phones that do not use Google GMS. If you care about your actually owning your device, install something else than stock OS. I would recommend GrapheneOS, since the security of some/most other alternatives is pretty bad.

AFAIK every popular Android phone uses a qualcomm modem chip with a separate OS that has complete access to ram. NSA most certainly has a backdoor there and such complete access to any Android phone. This was common knowledge after the Snowden stuff. I don't think this has changed at all since. Only few niche phones (pinephone) separate these systems or have a hardware switch to disable the cellular system.

> NSA most certainly has a backdoor there and such complete access to any Android phone.

Citation needed?

> This was common knowledge after the Snowden stuff.

Not to me, it isn't? As far as I'm aware, most of the Snowden stuff were centered around PRISM, which allowed widescale wiretapping of internet backbone, as well as agreements with big cloud providers to allow tapping into their data.

I haven't seen anything indicating that there was widespread compromise of personal computing devices at such a deep level of the root of trust. I haven't seen any indication that the NSA has a backdoor in the earlyboot CPU of any device, whether that is the Qualcomm boot processor, the Intel Management Engine or the AMD Platform Security Processor (which all have similar capabilities and hidden firmware).

If I missed anything/have links to research into these backdoors, I'd like to see them!

Re: F-Droid Board of Directors nominations 2026

#114

Earlier quoted context omitted.

Reduced security has always annoyed me a bit as an argument. Sort of in the same way as signal deprecating SMS because it's insecure. I get all or nothing when your threat model is state actors. However, for most people, the benefit is just freedom from corporate agendas. Not everyone needs kernel hardening, or always E2EE (as with signal). Personally I just like the features it provides (e.g. scoped storage, disabli…

Oh man, I am still annoyed about Signal removing SMS support. Had to add another app to my phone and I can now no longer accidentally discover that someone I'm texting has Signal, which happened more than once to me!

I only just installed Signal in some abandoned corner of one of my devices to be able to communicate with my 'highschool' classmates (in reality a Dutch Gymnasium so a totally different school system and age group but you get the idea) and had to get the blasted thing working without Google services on a device which for some specific purposes sometimes enables these but mostly has them disabled. As soon as Signal gets a whiff of even a stub of Google services is refuses to work without a fully fledged Google services implementation. To fix this I had to add 'disable Signal' to my 'enable rudimentary Google services' script and to do that I had to find the package name:

   org.thoughtcrime.securesms
So yes, they're still called 'secure SMS' even though that is no longer part of the deal.

I'll only use it for the specified purpose since I far prefer my own XMPP server with OMEMO encryption - which is based on the same 'double ratchet' keying as Signal uses.

Re: F-Droid Board of Directors nominations 2026

#115
post #99

Earlier quoted context omitted.

Even with Google's changes, F-Droid will continue to work with Android phones that do not use Google GMS. If you care about your actually owning your device, install something else than stock OS. I would recommend GrapheneOS, since the security of some/most other alternatives is pretty bad.

AFAIK every popular Android phone uses a qualcomm modem chip with a separate OS that has complete access to ram. NSA most certainly has a backdoor there and such complete access to any Android phone. This was common knowledge after the Snowden stuff. I don't think this has changed at all since. Only few niche phones (pinephone) separate these systems or have a hardware switch to disable the cellular system.

>I don't think this has changed at all since.

There is common knowledge to suggest that it is not the case (or maybe is no longer the case):

>Mainstream smartphones do not provide DMA access from the baseband to the application processor's memory... Yes, getting baseband access then lets you monitor regular voice and SMS comms. But no, it does not instantly compromise the AP so using the Signal app would still be secure. https://news.ycombinator.com/item?id=10906488

>Apple mitigates baseband processor vulnerabilities by putting it behind what's essentially an IOMMU. https://news.ycombinator.com/item?id=29440154

>This is false FUD that keeps being repeated. It's not true. No iPhone ever has had a baseband with DMA access to my knowledge, and modern Qualcomm devices have advanced IOMMU systems to firewall away the baseband from the rest of system memory. I'm sure some phones somewhere existed where the baseband was privileged, but it's not the norm. https://news.ycombinator.com/item?id=30393283

>Connecting a cellular radio via USB provides far less isolation than the approach of a tiny kernel driver connected to an IOMMU isolated cellular radio on mainstream devices. USB has immense complexity and attack surface, especially with a standard Linux kernel configuration. Forensic data extraction companies mostly haven't bothered using attack vectors other than USB due to it being such a weak point. Many of the things people claim about cellular radios in mainstream smartphones are largely not true and they're missing that other radios are implemented in a very comparable way. https://news.ycombinator.com/item?id=46841004

Re: F-Droid Board of Directors nominations 2026

#116

Earlier quoted context omitted.

It should be pretty obvious why porn apps are marked NSFW despite not containing any content. Substantially all of the content they can be used to access is NSFW, whereas it's reasonably possible to access only SFW content on Reddit. Which would also explain the Bible apps without an initial copy. Choosing which translation to download when substantially all of them are translations of the same NSFW text means that s…

Except, of course, that the Bible in any translation is not NSFW, certainly in the common usage of the term. It contains depictions of violence and sex, yes. But so does Fanny Hill, and that hasn’t legally been considered obscene in the UK or the USA in over fifty years. F-Droid’s excuse, that they needed to restrict Bible apps to protect F-Droid from legal liability, is not believable.

Let's consider the two possibilities here:

1. They have a policy of marking apps as NSFW if using them has a high probability of loading NSFW content onto the device. We can't easily rule this out. It's a small project so they have to be reserved about compliance issues because they don't have the resources to defend against expensive litigation and they could just be exercising an abundance of caution.

2. They're trolling Republicans with malicious compliance. They don't like the laws being enacted, they know the people enacting them like the Bible, so they apply the policy in the way which is maximally adversarial to the opponents imposing it on them. "If you don't like the consequences of your law then feel free to repeal it."

Which one of these is even objectionable? It seems like you want that if they're doing the second one they should admit to it, but in that case they're just maintaining kayfabe. The trolling is more effective when it's ambiguous. It's obvious that it could be that. If the message is to invite their opponents to go eat sand then it's not being lost in translation. But making that explicit only makes it easier to dismiss them as antagonists, or retaliate against them for being overtly defiant.

Whereas if they play it straight, what is someone going to say? That it shouldn't apply to this, right? Okay, then we need to pin down the rules for how exceptions work. Exceptions that could then be applied to other things. Which is to their advantage to have their opponents doing in this context because then they want the exceptions to be broad and reasonable instead of not caring if someone else is getting screwed by them.

Re: F-Droid Board of Directors nominations 2026

#117

Earlier quoted context omitted.

GrapheneOS is working with a manufacturer to change this:[0] > We're working with a major OEM and the devices will be the future versions of existing models they have now. The devices will be priced similarly to Pixels. The initial devices will have a flagship Snapdragon SoC for the best security and support time. Snapdragon flagships have significantly better CPU and GPU performance than Pixels. Snapdragon provides…

That "major OEM" seems to be Motorola, i.e. Lenovo.

I hope HMD reach out next: https://www.hmdsecure.com/

Re: F-Droid Board of Directors nominations 2026

#118

Earlier quoted context omitted.

Indeed. Sadly the reality is that most other Android devices are simply not secure enough. Many Android phones do not have a separate secure enclave (outside Pixel and IISC Samsung flagship and A5x range), so they are vulnerable to breaking PIN-based unlocking, side channel attacks, etc. Besides that they often only provide old vendor kernel trees, old firmware blobs, etc. So, you have to wonder whether you want such…

Reduced security has always annoyed me a bit as an argument. Sort of in the same way as signal deprecating SMS because it's insecure. I get all or nothing when your threat model is state actors. However, for most people, the benefit is just freedom from corporate agendas. Not everyone needs kernel hardening, or always E2EE (as with signal). Personally I just like the features it provides (e.g. scoped storage, disabli…

>Not everyone needs kernel hardening, or always E2EE (as with signal).

If application processors and hardware crypto accelerators are good enough to make this invisible to the end user, then why not? Why not have everyone be on hardened kernels by default and let them opt-in to insecure ones instead of the other way around?

Re: F-Droid Board of Directors nominations 2026

#119
post #33

Earlier quoted context omitted.

This is asked again and again. Apparently you guys in the USA or in other parts of the world are still lucky, but in Europe banks must be compliant with regulation that more or less force them to do 2FA through their app with the biometric authentication of either an Android or an iOS phone. There are other ways (eg giving a hardware OTP generator to customers,) but apps are the cheapest solution.

Do you have a link with information about this? I'm just wondering since I'm currently using 3 different European banks without any biometric authentication to unlock my phone, password manager or provide a 2FA. I'm asking so that I can adjust in time to any new regulations I'm not aware of.

This https://en.wikipedia.org/wiki/Strong_customer_authentication

Re: F-Droid Board of Directors nominations 2026

#120

Earlier quoted context omitted.

Indeed. Sadly the reality is that most other Android devices are simply not secure enough. Many Android phones do not have a separate secure enclave (outside Pixel and IISC Samsung flagship and A5x range), so they are vulnerable to breaking PIN-based unlocking, side channel attacks, etc. Besides that they often only provide old vendor kernel trees, old firmware blobs, etc. So, you have to wonder whether you want such…

> Sadly the reality is that most other Android devices are simply not secure enough. This seems like a bad reason for not supporting a device. If the device doesn't have a hardware feature then the OS it came with can't be doing it either, and then all you're doing is leaving the user with all of the other security problems in the OEM OS that otherwise could have been improved by replacing it.

The point of GrapheneOS isn't improving a generic device's security, it's about setting an example for a highly private and secure OS. It's a FOSS project, so nothing stops a committed individual or community from using other device targets, but the main project chooses specifically to use their smaller resources to pursue excellence rather than mediocrity.
Post reply on HN