Live data from Hacker News

Mobifree – An open-source mobile ecosystem

f-droid.org

171–180 of 182 posts

Re: Mobifree – An open-source mobile ecosystem

#171

Earlier quoted context omitted.

I'd never use F-Droid due to how insecure it is. They still modify all app signatures, so you can't even verify what you're installing is authentic.

"insecure" is a strong word that shouldn't be used willy-nilly like that. F-Droid recompiles all of its applications to ensure that everything in them is free software, and that the source code provided by the upstream is actually what is in the released binary. To this end, they produce reproducible builds, allowing anyone to rebuild the sources locally and verify that they match.

Which is also how most Linux distros work. So if you use Linux to install software via it's package manager, you already participate in this model. It moves trust to the package repo rather than the app developer.

Re: Mobifree – An open-source mobile ecosystem

#172

Nice! I see MicroG is part of this initiative too: https://mobifree.org/ I hope it becomes a bit more mainstream now. Some custom roms like lineage are very hostile to it because they're afraid Google will do more against them if they include it. You can't even mention it in their community or you will get kicked. It's nothing nasty though, it's just a bare minimum implementation of google play services remade in ope…

The main problem now with many custom ROMs is VoLTE support. Many countries are shutting down 3G networks, and many VoLTE solutions (for 4G and 5G voice) are not available in the open source ROMs.

Yeah that sucks. The industry really screwed up those standards. The whole idea of a standard is that it's... Well standard. That it always works and you don't have to validate each device and firmware.

But for me voice is no longer a big deal. I do all my calls on WhatsApp anyway.

Re: Mobifree – An open-source mobile ecosystem

#173
I think what is realy missing in this consortium is a payment processor. I can already do most stuff people do with their smartphones google free (also thanks to the involved partners). However contactless payments or app micro payments are not working and are depending on google or other big tech. Really curious if the future digital euro will work on the foreseen ecosystem

Re: Mobifree – An open-source mobile ecosystem

#174
post #129

Earlier quoted context omitted.

I might be lucky enough to have online banking work with sms and a pre-shared secret. My bank (also in the EU) didn't tell me I could do it automatically, they only mentioned it when I told them I lost my phone (it was true) and that I didn't know when I could buy a new one. Maybe it'll work with yours ?

No, ever since PSD2 came into effect, banks here refuse to do SMS-based verification and have switched to apps. They also don't support hardware authenticators for consumers. I asked.

Fortunately we have competition and possibility to switch to banks that are more private and user friendly.

Re: Mobifree – An open-source mobile ecosystem

#175

Earlier quoted context omitted.

Just to add, F-Droid is not a guarantee against adware. There are definitely adware apps (and by extension, maybe even spyware) on F-Droid.

Adware is marked as an Anti-Feature in the details of an app in F-Droid[1]. Since non-free software is not allowed on F-Droid, and most Ad platforms aren't free software, you're unlikely to find any, though. There's currently only 30 apps with this Anti-Feature[2]. [1]: https://f-droid.org/docs/Anti-Features/#Ads [2]: https://monitor.f-droid.org/anti-feature/Ads

This is probably inaccurate - for instance I use Librera Reader for PDF and it does use ads - annoying video ads that shows up randomly when I close a document. It is not in the list of the 30 apps. And no anti feature is being declared on the app description. That's only one example that I am aware of.

Re: Mobifree – An open-source mobile ecosystem

#176

Nice! I see MicroG is part of this initiative too: https://mobifree.org/ I hope it becomes a bit more mainstream now. Some custom roms like lineage are very hostile to it because they're afraid Google will do more against them if they include it. You can't even mention it in their community or you will get kicked. It's nothing nasty though, it's just a bare minimum implementation of google play services remade in ope…

LineageOS recently included the patch to finally allow signature spoofing for microG. I don't think they're actively hostile and there are obviously people who support it.

Afaik Lineage for microG is independent of the microG project.

Re: Mobifree – An open-source mobile ecosystem

#177

Earlier quoted context omitted.

> That is to say you cannot even connect to IP addresses unless you’re already part of the global whitelist for APs > Try yourself. Get a VPN and then connect from certain regions and to won’t get very far and you’ll be slooooow Connecting to a far away VPN doesn’t prove anything about a “global whitelist” VPN addresses are commonly rate limited and block listed because they’re sources of abusive traffic and therefor…

That's what they said, yes. Only certain access points are whitelisted to access things. If you aren't using one then you're blacklisted. VPNs aren't one. You claim there isn't a global whitelist and then proceed to explain a global whitelist.

> Only certain access points are whitelisted to access things. If you aren't using one then you're blacklisted.

No, this is not how these terms work. Blacklist and whitelist are not just words for opposite sides of a partitioned set. Both blacklists and whitelists are explicitly enumerated lists. If I blacklist a single thing, I have not implicitly created a whitelist containing everything else in the universe. Establishing that VPNs are often blacklisted is not - at all! - the same thing as establishing the existence of a "global whitelist".

Re: Mobifree – An open-source mobile ecosystem

#178

Earlier quoted context omitted.

Adware is marked as an Anti-Feature in the details of an app in F-Droid[1]. Since non-free software is not allowed on F-Droid, and most Ad platforms aren't free software, you're unlikely to find any, though. There's currently only 30 apps with this Anti-Feature[2]. [1]: https://f-droid.org/docs/Anti-Features/#Ads [2]: https://monitor.f-droid.org/anti-feature/Ads

This is probably inaccurate - for instance I use Librera Reader for PDF and it does use ads - annoying video ads that shows up randomly when I close a document. It is not in the list of the 30 apps. And no anti feature is being declared on the app description. That's only one example that I am aware of.

I use librera reader and I have no ads, are you sure you're using the F-Droid version of the app? If you're not, I suggest installing it through F-Droid, as the play store version may have proprietary code in it. Many apps have different builds for Play Store and F-Droid, with slightly different featuresets.

If you are already using the F-Droid version, it should be reported. The list of anti-features is kept accurate by user reports like yours.

https://gitlab.com/fdroid/fdroiddata/-/issues

Re: Mobifree – An open-source mobile ecosystem

#179

Earlier quoted context omitted.

This is probably inaccurate - for instance I use Librera Reader for PDF and it does use ads - annoying video ads that shows up randomly when I close a document. It is not in the list of the 30 apps. And no anti feature is being declared on the app description. That's only one example that I am aware of.

I use librera reader and I have no ads, are you sure you're using the F-Droid version of the app? If you're not, I suggest installing it through F-Droid, as the play store version may have proprietary code in it. Many apps have different builds for Play Store and F-Droid, with slightly different featuresets. If you are already using the F-Droid version, it should be reported. The list of anti-features is kept accurat…

You're correct, turn out it I apparently mistakenly got it from Gplay. Deleted now and reinstalled from Fdroid.

Re: Mobifree – An open-source mobile ecosystem

#180
post #133
post #128

Earlier quoted context omitted.

I have accounts at 1 Swiss bank, 2 German banks, and 2 UK banks. None of them require an app for any functionality. You can get a little hardware thing to generate their OTP codes, as an alternative to apps.

The hardware dongle sounds like it might be TOTP. There are plenty of clients for that for laptops and phones, assuming you can enroll your own secret.

Unfortunately it's not plain TOTP. Most banks in Europe give you a standalone cheap plastic smart card reader into which you put your bank card.

The website shows you a code. You input it into the reader, followed by your card PIN. The reader outputs a code you put into the website.

This is what it looks like:

https://www.post.ch/-/media/portal-opp/k/bilder/postgeschich...

Post reply on HN