The #DigitalCommons #EDIC is forming an advisory board and is looking for experts to join it.
Nominations are due Sept 7th!
https://digital-commons-edic.eu/news/2026-07-01-advisory-board-call-for-experts/
@fedops @ParadeGrotesque I hadn't heard about the French gov mandating Linux workstations for all their Ministries, that's great news!
The Dutch, French and German workspace teams were already working together on a Linux OS within the EDIC's 100 day challenges, but I don't think a choice for a distro has been made yet. 🇪🇺
I'm super impressed with how proactive the French are. Good work @numerique_gouv 👏
A practical way to break #Android #hardware #attestation https://blog.quarkslab.com/bypassing-android-hardware-attestation.html
The "trusted device" debate reminds me of the late 90s debate whether its possible to #trust the #network. Its now clear that good security requires not trusting the network.
From where I sit, the "trusted device" debate is the same. Big companies are lazy and pretend the device can be trusted while companies pushing #DRM and other anti-democratic, anti-user functionality want #finance and #government as allies
‼️⚖️ The #US Supreme Court has declared all independent authorities unconsitutional – effectively blowing up the EU-US deal on data transfers.
👉Click the link below for noyb's full assessment of the situation, and prepare for a #Schrems III case!
🔗 https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-transfers
Your mobile data shouldn't crawl just because you crossed the border.
Under our ‘roam like at home', operators in the EU, Iceland, Liechtenstein, and Norway cannot ‘throttle’ your speed abroad.
If 5G is available in the country you are visiting, you must have access to it at the same quality as at home.
Since January 2026, Ukraine and Moldova have also joined the EU’s ‘roam like at home area.’
Because your connection should be as smooth as your travel plans. 😎
"Should we #OpenSource something that has the ability to kill humanity?"
That is the wrong question, akin to saying: "Should we allow the most powerful #tech to be democratically controlled?". Humans have invented means to #kill #humanity before: #nuclear and biological weapons, and they were used. They are so horrific, basically all countries work to ban them. If #AI leaders believe it also has this power, shouldn't they also be working on non-proliferation?
@stf a couple decades ago, I ran some really long ethernet. I think the slower speeds have longer ranges. I think I did 10mbit at 100m. At the PoE injection point, add a powered switch as a repeater to get another 100m of range.
JBS, see you in court!
Greenpeace Netherlands is taking the world’s biggest meat company to court to force them to hand over information about their secretive business policies and hold their billionaire owners accountable.
Let’s fight back against unchecked corporate power.
Not on our watch.
Sign the People vs Big Ag petition https://act.gp/4wgFMVP
Want to know more? Read our latest explainer on why ePrivacy matters, why cookie banners are only part of the story, and how we can move beyond today’s broken system ➡️ https://edri.org/our-work/cookies-and-consent-why-eprivacy-matters-for-our-browsing-life/
In a major victory for digital rights and common sense, the Court of Justice of the European Union (CJEU) has officially categorized Virtual Private Networks (VPNs) as "lawful technical tools" while establishing new boundaries for online copyright disputes.
The landmark judgment — handed down in July 2026 — stems from a complex legal battle over the online publication of Anne Frank's historical manuscripts. At its core, the case forced Europe's top judges to answer a highly technical question: if a publisher actively tries to block visitors from a specific country, are they still breaking the law if a user sneaks past the digital border using circumvention software?
According to the CJEU, the answer is no. As long as a website employs "state-of-the-art" geo-blocking technology, the publisher cannot be held liable for copyright infringement simply because a determined reader decides to fire up the best VPN to bypass the restrictions.
When I started building with React Native and Expo, it became much harder to write the recipe to be available on #FDroid.
#CastLab was my first one, with the help of maintainers. The last build of #HolosSocial failed (it happens with Expo upgrades). An F-Droid maintainer warned me first on my repo. Before I could act, they made the changes to the recipe so new builds were possible, and silently closed the issue.
Just a thank you to the #FDroid team, they help users and devs alike!
@daniel Oh this is interesting. Does that mean that Google thinks that their LLM scraping might not count as "fair use"? Is there any reporting on this?
Today, July 18 (3:00–5:00 p.m.), we continue our four-part series on the topic:
“Digital Neocolonialism: Data, Resources, Dependencies—Who Benefits?”
This time: Content Moderation at Scale—How Labor Extractivism Powers Platform Models. With SANA AHMAD (https://social.bund.de/@Weizenbaum_Institut)
Event in English more information: https://www.topio.info/digitaler_neokolonialismus.html#3
#ContentModeration #DigitalNeocolonialism #berlin #moabit #mitte
@alsutton @postmarketOS sounds like you are proposing some kind of government ID check, then, albeit via the domain name registrar. Also, there is no natural link between a domain name and an app, that has to be invented.
@mro if the signing key is the root of trust in the developer, then it is important to know that the developer understands that and takes it seriously, and doesn't just give away the keys to the root of trust.
@alsutton @postmarketOS This would specifically link the app and the domain name. That would give the app signer's pseudonym a website/email link, building a more complete pseudonym profile. But I can't see how that would change anything for when the user wants some method of verifying the developer. Linking to someone's government identity does make it easier to track down the actual people who are involved.
@mro I agree, highlighting the role of the signing key seems key. An app signing key is in effect a pseudonym. The hard part is that there is that there is no concrete way for users to verify what the key management practices of the developer are. Judging that from the outside means looking for any signs that the signing key was misused. If a dev wants to hide misuse of their signing key, that is pretty easy to do. For example, they could sign malware and only ship that to targeted users
@jexner your formulation seems like its going the right direction. On one hand, in the world of financial accountability, "know your customer" and showing government ID is normal. Borrowing an established practice makes sense when it works, but it doesn't feel right to apply that to developing software. I don't think the requirements are the same between finance and software, although sometimes similar. I haven't found a good breakdown though that maps that out.
@jexner Can the human be anonymous while the "dev" is public? Clearly, we want the apps we use to be maintained by entities that we can trust. Are given names required for that? I think clearly not. For example, non-profits. People trust #EFF as an entity, even without knowing who everyone works there is, and whether the staff changes. So the entity can be trusted separately from human participants. I think developers are similar. Many trusted FOSS contributors operate under pseudonyms
@rene_mobile @marcprux @fdroidorg @GrapheneOS @lehtimaeki @ottok @grote
You are all people who have specifically thought about this kind of stuff in relation to software distribution, what do you think?