Live data from Hacker News

A faster heart for F-Droid

f-droid.org

181–190 of 231 posts

Re: A faster heart for F-Droid

#181

I don't understand why governments haven't started to fund F-Droid, almost all govt. apps are open-source. Countries which fear they could be cut off from the duopoly mobile ecosystem should be forcing android manufacturers to bundle in F-Droid; For the amount of nonsense regulations they force phone manufacturers to adhere to, bundling F-Droid wouldn't be that hard. Google won't be happy, but anti-trust regulations…

Because it's not their responsibility. Why they should care about these kind of stuff? Don't drop everything on governments.

A project like F-Droid is dumb to begin with where they're the one to build the apps.

Re: A faster heart for F-Droid

#182
post #164

I don't understand why governments haven't started to fund F-Droid, almost all govt. apps are open-source. Countries which fear they could be cut off from the duopoly mobile ecosystem should be forcing android manufacturers to bundle in F-Droid; For the amount of nonsense regulations they force phone manufacturers to adhere to, bundling F-Droid wouldn't be that hard. Google won't be happy, but anti-trust regulations…

What did your local politician say when you wrote to them and suggested it? (I've worked with several politicians. You'd be surprised what a well timed letter or meeting can achieve.)

Not much...

I wrote a few times to my local MPs ("député", as we call them in France). I usually got a response, though I suspect it was written by their secretary with no other consequence. In one case (related to privacy against surveillance), they raised a question in the congress, which had just a symbolic impact.

It may be different in other countries. In France, Parliament is de-facto a marginal power against a strong executive power. Even the legal terms are symptomatic of this situation: the government submits a "project of law" while MPs submit a "proposal of law" (which, for members of the governing party, is almost always written by the government then endorsed by some loyal MP).

Re: A faster heart for F-Droid

#183

I don't understand why governments haven't started to fund F-Droid, almost all govt. apps are open-source. Countries which fear they could be cut off from the duopoly mobile ecosystem should be forcing android manufacturers to bundle in F-Droid; For the amount of nonsense regulations they force phone manufacturers to adhere to, bundling F-Droid wouldn't be that hard. Google won't be happy, but anti-trust regulations…

Because it's not their responsibility. Why they should care about these kind of stuff? Don't drop everything on governments. A project like F-Droid is dumb to begin with where they're the one to build the apps.

> A project like F-Droid is dumb to begin with where they're the one to build the apps.

I heartily disagree. Linux distributions also build the packages themselves, and that adds a layer of trust.

It ensures that everything in the fdroid repo is free software, and can be self-built.

Re: A faster heart for F-Droid

#184
post #74

Good. But I wish PostmarketOS supported more devices. On battery, tons of kernel patches could be set per device plus a config package in order to achieve the best settings. On software and security...you will find more malware in Play Store than the repos from PmOS/Alpine. I know it's not a 100% libre (FSF) system, but that's a much greater step towards freedom than Android, where you don't even own your device.

The issue with Linux-based phones is and remains apps. Waydroid works pretty well, but since you need to rely on it so much, you are better off using Graphene or Lineage in the first place.

But Android it's a clusterfuck. Look Lemuroid, a Retroarch based emulator with a nice GUI. With the new SAF related permissions you can't make the emulator work any more.

And that being a libre package from F-Droid. And I noticed several other bugs. Tyr for instance (an Yggmail service which bundles Yggdrasil) doesn't have an armv7a version. Tyr could be really useful with DeltaChat because you could talk with any relative without depending on 3rd party mail services. And because of arbitrary limitations, compiling a 32 bit binary it's damn difficult for maintainers, yet I could compile yggmail for Go under Termux without no issues.

Thus, that's why I prefer PostMarketOS, software would just run once it's installed and for sure I wouldn't need to set an SDK weighting several GB's.

Re: A faster heart for F-Droid

#185
post #62

> this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access. I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argu…

> a $400,000 grant IDK if they could bag this kind of grant every year, but isn't this the scale where cloud hosting starts to make sense?

400k could get you 10 Dell Poweredges with a 128 core CPU, 256GB of RAM and multiple terabytes of storage _multiple times_. 400k easily covers two of these machines, and colocation space is about 2k per year.

Cloud hosting only makes sense at a very, very small scale, or absurdly large ones.

Re: A faster heart for F-Droid

#186
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

It's like ya'll are so eager to crap on a thing that you don't even read tfa. > this server is physically held by a long time contributor with a proven track record of securely hosting services. So you are assuming it's a rando's basement when they never said anything like that. If their way of doing business is so offensive either don't use them, disrupt them or pitch in and help. > I understand this is a volunteer…

> this server is physically held by a long time contributor with a proven track record of securely hosting services.

This is effectively a rando's basement. It doesn't matter that they've been a contributor or whatever. Individuals change, relationships sour. Securely hosting how ? By locking the front door ? By being a random tech company in the midwest ? Or by having proper access control ?

As a little reminder, F-Droid has _all_ the signing keys on its build server. Compromising that is somewhere between "oh that's awful" and "stop the world". These builds go out as automatic updates too. So uh, yeah, I'd like it if it was hosted by someone serious and not my buddy joe who's a sysadmin don't worry

Re: A faster heart for F-Droid

#187

> this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access. I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argu…

> one person had the physical server in their basement

Unless you have even the faintest idea about how F-Droid does it, please stop spreading FUD. All the article says is that it is not a normal contract but a special arrangement where one or a select few have physical access. It could be in a locked basement, it could be in a sealed off cage in a data center, it could be a private research area at a university. We don't know.

A special arrangement with an academic institution providing data center services wouldn't be at all surprising, that has been the case for many large open source projects since long before the term was invented, including Linux, Debian and GNU itself.

Many of these are run by professionals with high standards. The Debian project has done pioneering work with reproducible builds, for example, something the F-Droid project is also very much involved with. Those things are what creates trust in the project.

Re: A faster heart for F-Droid

#188
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

> F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid.

Clearly the GrapheneOS community is clueless then.

You can host F-Droid yourself, which is the opposite of centralized. If the GrapheneOS community actually is concerned about centralization they can host an instance as well.

Futhermore, each author signs their own software, which again is the opposite of centralized. One authority signing everything would be centralized.

So F-Droid is decentralized in authorship and distribution. Google store is only decentralized in authorship.

Re: A faster heart for F-Droid

#189
post #58
post #13

Ugh. This 100% shows how janky and unmaintained their setup is. All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire commodity hardware and shove it in a special someone's basement and they're trying to make it seem like a good thing? F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid. I underst…

Graphene is a great product but their incessant mud slinging at any service that isn't theirs is tiresome at best. Some of their points are valid but way too often they're unable to accept that different services aren't always trying to solve the same problem.

> their incessant mud slinging at any service that isn't theirs is tiresome at best.

100%. But you know, sadly I've noticed that non-experts are impressed by elitism. So you don't have to be good, you just have to shit on others, and passerbys will interpret that as being very competent.

Which is super ironic, from a project which about privacy but only supports hardware built by the biggest surveillance company.

Re: A faster heart for F-Droid

#190
post #37

Earlier quoted context omitted.

> shove it in a special someone's basement They didn't say what conditions it's held in. You're just adding FUD, please stop. It could be under the bed, it could be in a professional server room of the company ran by the mentioned contributor.

100%. Just as an example I have several racks at home, business fiber, battery backup, and a propane generator as a last resort. Also 4th amendment protections so no one gets access without me knowing about it. I host a lot of things at home and trust it more than any DC.

> Also 4th amendment protections so no one gets access without me knowing about it.

Hahaha

at best you're getting a warrant. Slightly better you're getting a warrant _and_ a gag order. Then it escalates, and having your door kicked in at 6AM is about the best you can hope for.

But sure, you'll know about it. Most likely. Maybe.

Just don't keep anything important in there eh ?

(Note, this definitely applies to colocations too. It's just maybe a tiny bit harder to find which rack is yours, and companies of that size generally have lawyers to prevent that from happening. I'll take my chance with the hosting company.)

Post reply on HN