[-] refalo@programming.dev 2 points 2 years ago

I would hope the difference is that the f-droid version does not contain any proprietary code.

[-] refalo@programming.dev 2 points 2 years ago

Thank you for your perspective. Yes I think people can find both extremes and everything inbetween depending on where they look, but I don't think that necessarily represents a majority of the population. I do think more can probably be done to reduce waiting times for people on either side though.

[-] refalo@programming.dev 2 points 2 years ago

not from VPN provider and legit websites

Why not? Aren't you worried about either of them selling/leaking your data? I think a lot of people here are.

[-] refalo@programming.dev 2 points 2 years ago

I think it depends on where the bottleneck is, and what they're actually trying to prevent, as to whether or not rate-limiting would actually help anything.

If they are blocking source IP addresses explicitly, it could be for a more specific concern we're not aware of, like trying to limit the amount of email "spam" that would be sent out from automated requests. A rate-limit wouldn't fix that issue, only slow it down.

We're all also assuming any of this is even intentional on their or anyone's part.

[-] refalo@programming.dev 2 points 2 years ago

I think you assume that there is even a contract, and that if it did exist, it wouldn't allow this.

Going to court for this would also cost way more than the product is worth.

[-] refalo@programming.dev 2 points 2 years ago

I disagree, there are many resources for making and distributing android reproducible builds, including third-party F-Droid repos like IzzyOnDroid mentioned in my previous link.

And to my knowledge there is no technical requirement that F-Droid actually needs to build OR sign packages on behalf of anyone... I haven't seen any actual official rationale listed for it, but I assume one of the main reasons is convenience for the developers so they don't have to provide their own builds and deal with signing/losing keys.

I understand that the risk of problems can be somewhat mitigated in F-Droid by using reproducible builds, but I don't consider that sufficient for the most privacy-conscious users because:

  • reproducible builds are not required by F-Droid

  • it is not made clear to the user that a particular package even supports reproducible builds

  • the verification of reproducible builds is not made plainly visible somewhere publicly if at all

  • a user can still easily be misled by a one-off rogue package that is NOT reproducible, due to the previous point

  • independent verifications of those builds reliably made by others are not common

[-] refalo@programming.dev 2 points 2 years ago

Conversely I stay clear of F-Droid as they build and sign packages on behalf of the original developers, adding yet another point of injection for malicious code or supply chain attacks.

[-] refalo@programming.dev 2 points 2 years ago* (last edited 2 years ago)

That's interesting, I've never heard of anyone actually concerned about the power consumption of their PC before, but I guess it makes sense if you live somewhere that it's quite expensive or just don't have much money... or want to be greener I guess.

[-] refalo@programming.dev 2 points 2 years ago

it depends on how much anti-fingerprinting you've setup. I only get endless captchas from every site and ended up just using an extension that blocks all crimeflare sites and redirects to an archive.org version of the page.

[-] refalo@programming.dev 2 points 2 years ago

what scrapers actually go to such lengths? I've never heard of any.

[-] refalo@programming.dev 2 points 2 years ago

Why not just use the built-in bluetooth file sharing?

[-] refalo@programming.dev 2 points 2 years ago* (last edited 2 years ago)

This was a real concern with MEGA back in the day (after Kim said you should no longer trust them) and a big reason why I prefer to use standalone client apps that I can control the source of.

view more: ‹ prev next ›

refalo

0 post score
0 comment score
joined 2 years ago