Show more

Gathering technical details of unpatched vulns is dangerous, no matter who is doing it. The Cyber Resilience Act should avoid making this a requirement, it will not make us safer.

More info in the blog post:
guardianproject.info/2023/06/1

way of dealing with work when it is hot: go from super hot subway platform to cold subway to frigid AC offices and keep working away.

way of dealing with work when it is hot: no AC anywhere, if it is too hot to work, go to the nearest body of water and spend the rest of the day swimming.

AI generated music is getting traction because they are basically exploiting a loophole in copyright laws, where AI systems can take human music and make it available in a way that looks like copyright laws do not apply 2/2

Show thread

I don't think I'll ever see a good reason for generated . Music taps directly into emotions and human connection. There is already so much human-composed music out there that could be used instead of AI music. The problem is broken laws e.g. long terms, massive penalties, and applying a commercial regulation to all uses. 1/2

Roaming charges are history! Experience the freedom to travel and stay connected.

Remember when you couldn't activate your mobile #data when you were abroad to avoid high charges? With Roam Like at Home you can enjoy the same benefits wherever you go:

📱 Lightning-fast #5G for seamless connectivity
💰 No unexpected charges, peace of mind
🆘 Improved access to emergency services for safety

The end of #roaming charges has revolutionised #travel and communication, bringing #Europe closer together.

@th_willenbrink@mastodontech.de @mynacol One central goal of my work in is to provide all the tools to give users access to updates and new apps, no matter what the conditions. That means when data is too expensive, the internet is out, when f-droid.org is unjustly blocked or censored, etc. Offline and nearby mirroring provides a failsafe way to get apps and updates.

@grote ah right, I couldn't eat the baby leaves fast enough, so then I had lots of the bigger ones. Any tips on how to stagger arugula planting to get more time to eat the baby leaves?

@lehtimaeki For those who believe that targetSdkVersion is more important than other features, Basic is available, and it targets 33 (the latest). The official alpha is available already, the release will be out any day now f-droid.org/packages/org.fdroi

@mynacol @th_willenbrink@mastodontech.de Off the top of my head, I'm currently struggling to get a decent user experience for offline repo mirrors on USB thumb drives using recent storage APIs. Google has locked out lots of functionality to limit how apps use local folders. If you have invasive apps installed, then that limits the damage. If you have good installed, then that limits the possibilities. There are many other real world examples out there.

@th_willenbrink@mastodontech.de @mynacol What it breaks is well documented, if you're interested, you can find some of it documented in our issue tracker. If Droid-ify works for you, then great! That's in action. I fully support custom clients since that is the only way to deliver certain kinds of user experiences. For the record, the official F-Droid client supports many things that Droid-ify does not, like mirroring. The core logic is available as libraries: f-droid.org/2023/05/02/three-c

@th_willenbrink@mastodontech.de @mynacol I agree that not doing anything about it and complaining would be a bad way to handle this. That is not what is happening in . The targetSdkVersion sandbox literally breaks access to functionality, by design. That is a central design goal. Those who do not understand that do not understand what a sandbox is. The key question here is who gets to decide which functionality remains functional, and which gets banned by the sandbox.

Google made it official that important apps like Messaging and Dialer are no longer maintained in the Android Open Source project. A free Android on its own is pretty much useless now.

android-review.googlesource.co
android-review.googlesource.co

@th_willenbrink@mastodontech.de @doragasu @rolandixor @lehtimaeki Yeah, you pretty much have to trust the developer. Or audit the code. You can use a firewall app, but Google Play doesn't allow most of those anyway. I recommend for this, it has a nice built-in firewall app that actually can fully block internet access on an app-by-app basis, with the user in full control.

@mynacol I agree that bumping targetSdkVersion is good when there is no cost. When there is a cost, then devs should do a cost-benefit analysis. The targetSdkVersion sandbox also breaks features that people rely on, means giving users real choices.

Looking at the new screen, it looks like Google has blocked installing the app. Many users have said as much. That's the monopolistic part.

And F-Droid v1.17 will have a higher targetSdkVersion. That cost a lot of dev time and money.

Currently disassembling an Android malware, where part of the malicious code seems to be in #Flutter app.
Blog post to confirm when I know more.

#JEB #Android #Flutter #malware

I never understood why arugula was a food until I grew it. It is intense and bitter, why would people eat it? When you grow it yourself, you just throw down some seeds where it gets some rain during the winter. Then you get massive amounts of it in the spring, and it is all bug free. Without really doing anything. If I had to grow all my own food, then I think I would probably end up eating a lot of arugula. Plus it tastes better when its freshly picked, not just pure bitterness.

The time between the release of "bullseye" to "bookworm" was 1 year, 9 months, and 28 days. #ReleasingDebianBookworm #Debian12 #Debian

@sergii because you need a team that is all on the same page, since they are working together on building something.

I will go one step further and say that calling an "unsafe app" by this standard is dishonest. It seems that some at also agreed, since the older version of that screen was honest: "Blocked by Play Protect" instead of "Unsafe app blocked". Looks like the team is still focused on protecting their , this time using scare tactics. 2/2

Show thread

This screen that shows on when installing really bugs me. It is purely based on the integer value targetSdkVersion, without considering our security model, public audits results, track record over 10+ years, exclusive use of memory safe languages, or even what our code actually does. It is as if marked anything that comes from Google as containing ads and trackers. 1/2

Show more
image/svg+xml Librem Chat image/svg+xml