[-] refalo@programming.dev 2 points 2 years ago

Well it wouldn't be news if it wasn't newsworthy :p

[-] refalo@programming.dev 2 points 2 years ago

I think it depends on where the bottleneck is, and what they're actually trying to prevent, as to whether or not rate-limiting would actually help anything.

If they are blocking source IP addresses explicitly, it could be for a more specific concern we're not aware of, like trying to limit the amount of email "spam" that would be sent out from automated requests. A rate-limit wouldn't fix that issue, only slow it down.

We're all also assuming any of this is even intentional on their or anyone's part.

[-] refalo@programming.dev 2 points 2 years ago

I think you assume that there is even a contract, and that if it did exist, it wouldn't allow this.

Going to court for this would also cost way more than the product is worth.

[-] refalo@programming.dev 2 points 2 years ago

I disagree, there are many resources for making and distributing android reproducible builds, including third-party F-Droid repos like IzzyOnDroid mentioned in my previous link.

And to my knowledge there is no technical requirement that F-Droid actually needs to build OR sign packages on behalf of anyone... I haven't seen any actual official rationale listed for it, but I assume one of the main reasons is convenience for the developers so they don't have to provide their own builds and deal with signing/losing keys.

I understand that the risk of problems can be somewhat mitigated in F-Droid by using reproducible builds, but I don't consider that sufficient for the most privacy-conscious users because:

  • reproducible builds are not required by F-Droid

  • it is not made clear to the user that a particular package even supports reproducible builds

  • the verification of reproducible builds is not made plainly visible somewhere publicly if at all

  • a user can still easily be misled by a one-off rogue package that is NOT reproducible, due to the previous point

  • independent verifications of those builds reliably made by others are not common

[-] refalo@programming.dev 2 points 2 years ago* (last edited 2 years ago)
[-] refalo@programming.dev 2 points 2 years ago

at least if there is a case of mistaken identity, all that surveillance becomes a great alibi /s

[-] refalo@programming.dev 2 points 2 years ago

It doesn't make financial sense to spend money on supporting an entire new platform that's used by <3% of the population.

[-] refalo@programming.dev 2 points 2 years ago

so exactly like kde connect then

[-] refalo@programming.dev 2 points 2 years ago

Unfortunately many banks still require it and have no other methods available. I tried to reason with my bank about it but they just do not care.

[-] refalo@programming.dev 2 points 2 years ago* (last edited 2 years ago)

They don't define what 'compilable' means though (among many other things), and it's pretty easy to come up with several different definitions of it that not everyone will agree with.

[-] refalo@programming.dev 2 points 2 years ago

ask the AI how to make the product better, duh

[-] refalo@programming.dev 2 points 2 years ago

devil's advocate would be calling this a hollow publicity stunt

view more: ‹ prev next ›

refalo

0 post score
0 comment score
joined 2 years ago