It's pretty unsavory how everybody talks about #MarketPlaces when it comes to platforms for distributing apps. I guess because of #DMA. But it's important to take a step back and appreciate that like many other #FOSS platforms #FDroid is not a maket place, it's a #commons.
We’re excited to share details about STF’s investment in @gnome to improve accessibility, tooling, and security for the Linux desktop ecosystem. Learn more about the comprehensive plan to modernize the platform and support features in the public interest:
Tell the U.S. Senate: RISAA does not reform mass surveillance — it greatly expands who can be surveilled and why. https://act.eff.org/action/tell-the-u-s-senate-stop-risaa-the-fisa-mass-surveillance-expansion
Every time I do tech support for my family I get very angry about people who whine about lacking "tech literacy".
90% of the stuff I have to teach them is how to navigate manipulative software and dark patterns. This has nothing to do with tech, but with capitalism. Tech is not complicated, it is just made maximally confusing on purpose to remove agency.
Better tech ed won't fix this.
We need your help! Call your senators and tell them to vote NO on reauthorizing and expanding Section 702. https://eff.org/risaa
Welcome to Stephen Farrell as #curl commit author 1260: https://github.com/curl/curl/pull/11922
"Just search for 'Linux Foundation Events' in your app store to find our brand new [proprietary?] AI-powered app!"
- Jim Zemlin @ #OSSNA
🕵️🔎🔎📱 The “repackaged” EU Council version of #chatcontrol still includes #MassSurveillance & serious threats to #encryption. Fortunately 🇩🇪🇵🇱🇫🇷🇦🇹🇳🇱🇪🇪🇫🇮 have acknowledged the severe concerns. We call on EU Member States to reject this dangerous position.
https://epicenter.works/content/open-letter-eu-councils-chatcontrol-is-still-mass-surveillance-undermining-encryption
Come work with us at @sovtechfund for a unique job opportunity where you'll be at the intersection of bug bounty programs and public interest.
As the BRP Manager, you'll spearhead our efforts to enhance bug resilience in FOSS projects, leveraging responsible bug bounty programs and more to make a meaningful impact in open source critical infrastructure.
Apply now at https://www.sovereigntechfund.de/jobs/bug-resilience-program-manager
(You're welcome to apply even if you don't meet 100% of the description, it's just a wishlist)
Major push to impose a U.S. site-blocking law. Nothing has changed since SOPA. Of course, lawful content would also be blocked https://arstechnica.com/tech-policy/2024/04/movie-industry-demands-us-law-requiring-isps-to-block-piracy-websites/ #Quad9
Lots of hackers would love to go in an contribute to new projects. If there was a way that people could make a living doing that, we would greatly improve the #FreeSoftware ecosystem. Lots of devs want to improve the code they work on, but so many company ban employees from contributing to #FOSS. One promising new model is maintenance funding from governments and foundations, like @sovtechfund and #LinuxFoundation. Since 93% of codebases use #FOSS, this affects the entire software ecosystem
4/4
This also happens in companies, but the dynamic functions a bit differently. The maintainers will start quitting their jobs, reducing the number of people who know the code. In a number of companies, I've seen this happen where the end result is an essential system that no present employee understands. So no one is allowed to touch it as long as it is working. This happens at mega corps and small companies alike. I experienced it at Merrill Lynch, a wealthy bank that was always cutting costs 3/
This can turn into a downward spiral, because it can drive away contributors, making things worse. Then only the ones who really feel responsible for their user base will continue working on it. Then ultimately they can burnout and the thing goes down in flames. The #XZBackdoor is a version of this dynamic. The #XZUtils maintainer was caught in that dynamic and felt he could not keep up, and was desparate for help since so many essential pieces of software rely on it.
2/
There is a dynamic that arises when there is a growing difference between the amount of maintenance required and available developer time. The maintainers need help to keep up. Until then, they need to ensure that the essentials are maintained. That in turn makes it harder for others to contribute, because the maintainer cannot afford to take any risks that might trigger unexpected work sometime later. So the maintainers have less time to review, less time to help complete merge requests, etc 1/
#Automattic just acquired #Texts and #Beeper, two #matrix chat apps that work with a bunch of bridges to popular apps :
* https://blog.beeper.com/2024/04/09/beeper-is-joining-automattic/
* https://automattic.com/2024/04/09/automattic-acquires-beeper/
I really hope they open source it.
Since they are going for a fee-for-service model like Wordpress, I'm optimistic. This is key for breaking the network effects that #gatekeeper companies rely on: #Apple #Meta #Facebook #WhatsApp #Discord #Telegram #Signal.
PSA: The panic button features built into F-Droid break when targeting newer Android SDK versions (e.g. #targetSdkVersion) due to new restrictions.
It might be possible to get them working again, but we currently do not have the bandwidth to maintain this. We welcome contributions to get it going again. Until then, removing the panic features looks to be our only responsible course of action. #CalyxOS includes built-in panic features like app removal, so that is a recommended replacement.
This week in #FDroid was published again.
You should read it if you're on Android 7 or older. For those on newer versions we have following tl;dr, but you're also welcome to read it all:
- 1.20 is in the making with even better repo handling
- custom Anti-Features will be on by default
- TetheredNet will be a new AF
- our website still has problems with localization
- Bunny Media Editor is new
- Secreto is now known as Sekreto
- 2 removals, 10 additions and 206 updates
Risk of socially engineered backdoors in critical software seems like an indictment of open-source projects, but it could happen anywhere, EFF’s Molly told @theintercept - in fact, this one was found only due to the project’s open nature.
https://theintercept.com/2024/04/03/linux-hack-xz-utils-backdoor/
Bullying in Open Source Software Is a Massive Security Vulnerability https://www.404media.co/xz-backdoor-bullying-in-open-source-software-is-a-massive-security-vulnerability/