The success of the free software Android ecosystem relies on contributors like you. Interested in funding to maintain F-Droid or related projects? Let us help you apply to https://nlnet.nl/funding.html, https://prototypefund.de/en/, https://www.sovereign.tech/programs, or https://grayarea.org/initiative/cultural-memory-lab/. We can also mentor you during the grant process to help navigate non-profit funding. please reach out here or via email hans@guardianproject.info
Seven new projects have been selected to contribute to the three NGI Pilots. IzzyOnDroid and OWASP blint will join forces with NGI Mobifree which works on a more ethical mobile ecosystem. Nuxt, Flohmarkt & Open Banking Gateway will work on integrations with Taler, the privacy-preserving digital payment system. And NGI Fediversity - the effort to create a hosting stack in-a-box - will be joined by Drupal & Source-based Nextcloud + Onlyoffice.
https://nlnet.nl/news/2025/20250122-project-selection-pilots.html
#NGI #FOSS
fdroidserver v2.3.5 was released to fix issues with `AllowedAPKSigningKeys` when used in specific configurations. More details in the changelog: https://gitlab.com/fdroid/fdroidserver/-/blob/2.3.5/CHANGELOG.md#235---2025-01-20 #FDroid
Michiel Leenaars (our director of strategy) speaks at #FOSDEM about Europe's ambition to increase its digital sovereignty in relation to the #NextGenerationInternet. Despite its contribution to tech sovereignty with over 1300 Free and Open technologies supported, so far #NGI is not in the EU's future plans. Michiel addresses the question: What should our new EU Commissioner for Tech Sovereignty be working on for the next 5 years from the the vantage point of NGI?
https://fosdem.org/2025/schedule/event/fosdem-2025-6508-next-generation-internet-2025-where-next-/
#FOSS
The gig economy is ground zero for the use of experimental algorithms that use workers' own data against them. Leaving workers playing a game that they don’t know the rules to and that the house always wins.
#TimeToDeliverAnswers
There's a "Signal deanonymized" thing going around:
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
Stay calm. Deep breaths.
👉 while this is a real consideration, the only thing the attacker gets from this is a very rough (kilometers or tens of kilometers radius) location
👉 other communication platforms that use any kind of caching CDN to deliver attachments are just as vulnerable
👉 you almost certainly should continue to use Signal, unless you specifically know that this is a big problem for you.
Reminder: Tech jobs with real impact are rare. At the Sovereign Tech Agency, we work to strengthen digital infrastructure – fostering security, innovation, and resilience to provide a stable foundation for participation and democracy.
You can still apply for our open positions! 📩
Citizens can only trust the 🇪🇺 digital ID if it’s transparent & gives them control over their data. The @EUCommission must protect users from illegal access to their sensitive information & fix loopholes in the upcoming #eID now! ☔
#eIDAS
https://epicenter.works/en/content/civil-society-demands-eu-commission-must-close-e-id-loopholes
🇪🇺 EU Commission's Microsoft 365 reliance raises privacy alarms!
Internal documents reveal the EU Commission's data privacy concerns over dependency on Microsoft.
Should the EU embrace #opensource to prioritize data sovereignty?
Remember that #Facebook's new name #Meta doesn't really refer to the doomed-from-the-start #Metaverse whim, but its much more important reliance on #metadata as the core business model.
#Instagram, #WhatsApp, and the other "products" are primarily metadata collectors. Who communicates with whom, when, how often, how much, through which types of data; which groups are they members of, how do they interact with them; which posts/articles/products do they read, like, or buy? This metadata is sufficiently detailed that the actual content of "what" somebody sent is no longer important - and therefore it doesn't hurt the business model to provide end-to-end encryption in WhatsApp and (more hesitantly) Facebook Messenger. Or, as Gen. Michael Hayden (ex-NSA) infamously once admitted "We kill people based on metadata" (https://abcnews.go.com/blogs/headlines/2014/05/ex-nsa-chief-we-kill-people-based-on-metadata). And #Meta's metadata collection is much more detailed than the mere phone call/message and email and IP packet records the NSA/CIA/etc. use(d).
That metadata is the basis for targeted advertisement and manipulation of individual and public opinion. That's where the money and the power is, not some silly 3D avatars. So the company name #Meta is, actually, interestingly descriptive and honest about the exploitative business model.
Protect yourselves. Use @torproject, @signalapp, @Mastodon, @pixelfed, and other federated services instead of feeding more into the metadata collection.
It is now possible to use #Python as an #ECH client using the DEfO development fork:
https://guardianproject.info/2025/01/10/using-tls-ech-from-python/
I wrote a blog post about using TLS ECH from Python https://guardianproject.info/2025/01/10/using-tls-ech-from-python/
We're starting a sprint to look at all the issues preventing #ReproducibleBuilds in all the apps we ship. Most of the issues are simple fixes in the upstream code, like unsorted outputs or timestamps included in the build.
You can help make the #FreeSoftware #Android ecosystem be more reproducible! See the failures here and help us report them upstream: https://verification.f-droid.org/failed.html
Smartphone Runs Home Server
It’s one of the great tragedies of our technological era. Smartphones that feature an incredible amount of computational power compared to computers the past, are largely locked down by carriers …read more
#hacking #projects
https://hackaday.com/2024/12/09/smartphone-runs-home-server/
🇬🇧Orban insists: First public vote on #ChatControl scheduled for Thursday! https://www.consilium.europa.eu/en/meetings/jha/2024/12/12/ +++ Silence no more: Which countries will support destroying the privacy of correspondence and secure #encryption? +++ Criticism from Austria and Slovenia: https://www.parlament.gv.at/dokument/XXVIII/EU/5949/imfname_11437653.pdf
We wrote a blog post about trust and how to have a verified installation of our client.
One such source for the client could be our CLI tool, that recently got the ability to download the F-Droid.apk.
Read more at
https://f-droid.org/2024/12/11/verified-first-time-installs.html
We are looking for a #Ruby #contractor to work on small #Fastlane and #Jekyll projects for #FDroid, #Android, #Mobifree and #Debian. https://guardianproject.info/2024/12/06/seeking-ruby/jekyll-contractors-to-start-asap/
🎉 PSA: F-Droid users! 🎉 The Tuta Calendar app is now available on F-Droid 🥳
❤️ You can get the Tuta Calendar app here: https://f-droid.org/en/packages/de.tutao.calendar/
We were busy last week!
In short:
- Our DNS entries were finally transferred to us as a legal entity: https://f-droid.org/2024/09/30/dns-security-and-bus-factor-improvements.html
- This week in #FDroid (TWIF) was published again with news about the next F-Droid client update with fixes for TetheredNet and many app news: https://f-droid.org/2024/10/03/twif.html
- And the website is now available in Czech: https://f-droid.org/cs/2024/10/04/czech-language.html
All the details are in the linked blog posts, so please feel free to read them ;)
People, apps and code you can trust