We have #ransomware, #AI driving #phishing and #scams abound, #bitcoin being almost all for illicit use cases, #SocialMedia turned to #addictive drugs, #email turned work communications to an endless deluge, and more. What the public discourse lacks is consideration of working to reduce our uses of #DigitalMedia and #software. I believe in the power of software. Given the current directions, some things just worked better without computers involved. We still have the #power to #change that.
Devastating privilege escalation on Linux: https://copy.fail/
Explanation: https://xint.io/blog/copy-fail-linux-distributions
Implementation in Go: https://github.com/badsectorlabs/copyfail-go
... and I learned today that there are AF_ALG socket types, to access cryptographic functions of the kernel.
The App Fair Project has posted our thoughts on the Digital Markets Act review:
https://appfair.org/blog/gatekeeper-paradise/
#DMA #keepandroidopen #appfair
I'm honoured to have been elected to the Board of Directors of F-Droid, the most well-known #opensource alternative to the Google Play Store.
Imagine Microsoft deciding from now on what you can install on your laptop. No internet, you can only download things through the MS app store. Apps that MS has approved. Who wouldn't find that suffocating? Yet that is what Google wants to do on our Android phones (and what Apple already has - a closed ecosystem).
1/3
I am very happy to join the @fdroidorg Board of Directors for the upcoming two years.
F-Droid is in the heart of the Open Source community, which I see as a very important part of the shift away from the US big tech here in Europe. Success of Open Source on mobile is success we all can share.
F-Droid gives visibility to software developers who want to build experiences without predatory practices.
This is important.
Thinking about FOSS, legal advice, and pro bono legal support.
What if there was a fund - be that from a funding body, or donations, or whatever - which paid (at reasonable rates, not Big Law Firm Prices) some lawyers to support FOSS projects.
So that it was free at point of use for those projects, but did not rely on lawyers working for free.
All outputs (subject to sorting issues to do with privilege) would be licensed under suitably open terms, with a goal of maximising re-use.
“Don’t forget international traffic, […] which is one of the fastest growing markets.” –Michael Peterson of Deutschen Bahn
We, as passengers, know that the demand for more and better cross-border rail is there. Now is the time to back it up with policy and offerings that make it possible.
Apparently, #Google has lost track of their goal for #Android "We wanted to make sure that there was no central point of failure, where one industry player could restrict or control the innovations of any other. " https://web.archive.org/web/20120501080416/http://source.android.com/about/philosophy.html
That page is 404 Not Found now...
On #Google's official download page for the #AndroidSDK they list a column "SHA-256 checksum" but then provide a SHA1 value. WTF?
https://developer.android.com/studio#command-line-tools-only
The last third of that is an interesting discussion about whether it actually pays off to use the latest versions of dependencies based on the data that #Sonatype gathers from #MavenCentral and other repositories
https://opensourcesecuritypodcast.libsyn.com/2026-state-of-the-software-supply-chain-with-brian-fox
The last third of that is an interesting discussion about whether it actually pays off to use the #latest versions of dependencies
On a train to #Dagstuhl, I finally got to read the nice write-up about on-device local-web-to-app tracking: https://localmess.github.io/assets/bridges-to-self-localmess-usenix-security-26.pdf
TL;DR summary: You might want to uninstall (or deactivate if pre-loaded) all #Facebook and #Yandex apps from your phone. That kind of behavior is pretty clearly malicious - not even just ethically wrong, but seems actually illegal (at least in the EU, though IANAL).
It appears one or more impersonators have already registered some of the #Android applications that I maintained, including @appmanager. I've reported this to #Google, but not sure what's going to happen. The Android developer verification is still in beta, and it doesn't have a lot of features now to deal with this kind of problems.
#Native #apps have inherent advantages over #web apps, yet an open web is important. #Gatekeepers are abusing its openness. Web apps dominance on #desktop looks like an effect of the gatekeepers pushing for that. Web apps are pushed by #BigTech: #Google #Apple #Facebook #Amazon, partly as a way to break #Microsoft #Windows's dominance. Its good to break Windows' dominance, but now, Big Tech web apps serve as new gatekeepers.
#Government and #military leaders right now are talking a lot about how they need to prepare for the threats they are facing from other countries. But what they basically never talk about is how their own military #buildup makes other countries feel threatened. From what I've seen, this applies everywhere no matter which side they are on. That looks like a clear path to more war. They should be considering #deescalation is also a proven method for avoiding #war, not only #deterrence.
Another case of the #AI #bubble in action: insane #VC funding to create things that corrode the internet and public sphere and that people don't actually really want. #OpenAI's #Sora is no more! It was very expensive to run with hardly any paying customers.
https://www.revolutioninai.com/2026/03/%20chatgpt-gpt-54-mini-silent-switch-march-2026.html
"If that holds at scale, the “#AI coding boom” is not a #productivity #revolution. It is a #debt-acceleration loop wrapped in excellent #UX."
https://medium.com/write-a-catalyst/an-ai-wrote-576-000-lines-to-replace-sqlite-7ea538826d72
Watching two party politics like #Democrat vs #Republican in the #US, it seems like an endless game of "he said she said". With multi-party politics, there are more possibilities. When three differing opposition parties get together to have a hearing to hold the government to account, that sends a pretty clear message that is not possible in two party politics.
Democrats have a hearing, Republics say its just politics. Or vice versa. Then stalemate.
For example:
https://abcnews.com/Politics/follow-law-bondi-after-democrats-storm-epstein-files/story?id=131199517