One concrete example of the damage that #BigTech #gatekeeper companies like #Apple and #Google are doing to the mobile ecosystems is clear to see with media codec libraries. Right now, malware companies like #NSOGroup have maintained zero-click exploits in both #iOS and #Android for years. This is mostly via media exploits. iOS and Android have obscene profit margins, meaning both companies have plenty of cash for improving things. Yet where is the big outflow for fixing media codecs?
I installed #Orbot by @torproject roughly two weeks ago to help people circumvent #censorship. In that short time I already helped almost 400 people reach the #internet. You can learn how it works and how to help (it's a click of a button) here: https://snowflake.torproject.org/
We have been running an #FDroid-compatible repository since 2012! Since then, the free software ecosystem on Android has blossomed, meaning @fdroidorg can be properly strict about #FreeSoftware. A couple of our apps still have a couple #proprietary blobs that are requirements. F-Droid no longer includes any third party repos by default, that means our repo is no longer there by default. It is still easy and safe to add it! Read on for more info:
https://guardianproject.info/2024/02/24/the-future-of-our-fdroid-compatible-app-repository/
Journalist Maurits Martijn is writing an article series on his search for a better internet. If that's what you're looking for you'll inevitably end up with free and open source.
In that light he wrote a portrait [1] of NLnet Foundation which financially supports #FOSS projects. Big thanks to Maurits [2] who has been working for many years to inform people about how the internet is broken and ways to make it better.
[In Dutch] [1] https://decorrespondent.nl/15131/deze-nederlandse-club-zorgt-voor-een-internet-dat-wel-voor-iedereen-werkt/14e4d369-934a-04ed-31ed-a3c67bca00e1
[2] https://decorrespondent.nl/mauritsmartijn
It’s finally happening — sideloading is coming to the EU!
We’ve started the process of becoming a legitimate “app marketplace”, allowing our European friends to download @delta and other AltStore apps officially for the first time ever!
See you in March ☘️
Now that we’re here, time for an #introduction!
We’re an open-source app store making it possible to #sideload apps that aren’t allowed in the iOS App Store. We’re just 2 people @rileytestut @shanegillio working on this full-time, alongside a great community that’s motivated to bring new experiences to iOS
We’re solely funded through donations with no interest in VC backing. If you like what we’re doing & want to support a FOSS project, consider joining our Patreon 💚 https://www.patreon.com/rileyshane
I wish the #AndroidSDK team would follow repository best practices and stop silently reissuing binary releases under the same name/version. #MavenCentral does not allow this, for example. The #FDroid transparency log shows the newest violation: two version of sources-34_r01.zip with the file name, version code, and metadata.
Last weekend I co-organised a "EU policy devroom" at #FOSDEM, marking the end of a wild 17 month ride in EU policy land working on the #CyberResilienceAct.
A blog I just published provides an overview of CRA #FOSDEM content, including my personal story starting #FOSS policy engagement in Brussels.
I hope it will contribute to a shared understanding of how the #CRA will most likely affect developers of #opensource software. Feedback welcome.
https://blog.nlnetlabs.nl/what-i-learned-in-brussels-the-cyber-resilience-act/
Think tank funded by Big Tech argues #AI’s climate impact is nothing to worry about - https://www.theregister.com/2024/02/07/ai_climate_impact/ it's the "cryptocurrencies don't use much energy" argument all over again...
As part of #ISRG's work towards memory-safe infrastructure for the internet, @cpu has opened a merge request that implements TLS ECH support on the client side:
https://github.com/rustls/rustls/pull/1718
We agree that "the ECH spec is very challenging to implement and required a lot of trial/error" and we are working with #DEfO to help implementers. Please reach out if that is you:
https://defo.ie/#contact
For people asking why Encrypted Client Hello is so important:
Even if you are using DOH (or ODoH), your ISP can see what websites your visiting (and then sell to NSA) by inspecting the certificate SNI field. Even with Encrypted SNI (ESNI), there are artifacts of the TLS session establishment leaked that can be used for TLS Fingerprinting - things like ALPN, and cipher suite.
Mozilla added scanning of data broker sites to its privacy protecting Mozilla Monitor
The White House just announced visa restrictions on those involved in spyware misuse. Are you a family member of someone misusing or facilitating spyware? You can be sanctioned as well! Great step to further delegitimise the highly invasive surveillance industry!
This week in F-Droid (TWIF) was published again.
Our highlight this week:
F-Droid and F-Droid Basic were updated to the stable version 1.19.0. It brings automatic background updates and a new and better workflow for adding repositories. Please note: this version is not yet the suggested version, so you need to enable beta updates, if you don't want to wait any longer.
Also we talk about notable updates oft some apps and the ongoing spring cleaning.
Do you share F-Droid repos with the NFC feature in our client app?
Background: the support for Android NFC Beam was removed in Android 14, so we probably have to remove this feature in the future. We want to know if anybody is impacted by this.
Hello #FOSDEM, this guy, Alberto Marti, announced 3bn euros for this open source European cloud project with an explicit focus on interoperability.That’s more than 2x the funding announced here back in December. Is there a link online for more info?
Did the other 2bn come from private sector investors?
After #FOSDEM my current understanding of how #EU #CRA and #PLD affects #FDroid and anyone who contributes to it:
* F-Droid org makes the "product" so it would be liable
* F-Droid is currently entirely non-commercial, handles no money
* Volunteer contributors are very clearly exempt from all this
* Donation funded contributions are also exempt
* Contracted contributors are helping build the regulated product, so the legal entities of the contractors would not be liable for F-Droid's "product"
#FOSDEM 2024 will be happening in a bit more than 1 week in Brussels!
Catch my talk "From phone hardware to mobile Linux" on Saturday morning or "Open Source for Sustainable and Long lasting Phones" (together with @agnes007 in the big Janson room!) on Sunday afternoon!
Or come by the postmarketOS (+friends) stand in the AW building!
I hope to see you there!
Links:
https://fosdem.org/2024/schedule/event/fosdem-2024-2234-from-phone-hardware-to-mobile-linux/
https://fosdem.org/2024/schedule/event/fosdem-2024-3362-open-source-for-sustainable-and-long-lasting-phones/
https://fosdem.org/2024/stands/
This week in F-Droid (TWIF) was published again.
We have a lot of information in it, so jump right in: https://f-droid.org/2024/01/25/twif.html
In short:
- FOSDEM is around the corner.
- We specifically talk about the following apps: Money Manager Ex, Open Video Editor, Tachiyomi, Fossify Phone, KOReader, OnionShare, Organic Maps and OsmAnd~.
- The spring-cleaning of our repo is underway, and we have found some proprietary dependencies. The affected versions were removed.
VICTORY! Ring has announced it will no longer facilitate warrantless police requests for footage to Ring’s users. This comes after years of sustained pressure from EFF and other civil liberties and privacy advocates. https://www.eff.org/deeplinks/2024/01/ring-announces-it-will-no-longer-facilitate-police-requests-footage-users
People, apps and code you can trust