GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Hans-Christoph Steiner (eighthave@social.librem.one)

  1. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Thursday, 16-Jul-2026 22:25:33 JST Hans-Christoph Steiner Hans-Christoph Steiner

    At the core of #AndroidDeveloperVerification are a couple potentially useful ideas. #Google has entirely wrapped them in a pile of anti-competitive garbage designed to defend their massive #monopoly profit margins, but nonetheless, those specific technical ideas might still be useful. #iOS's "notarization" is basically the same. That leads me to ask the key question:

    What would a #FOSS-respecting system of #verification look like? What #identity info is useful for trusting the #developer?

    In conversation about 2 months ago from social.librem.one permalink
  2. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Thursday, 12-Feb-2026 01:16:08 JST Hans-Christoph Steiner Hans-Christoph Steiner

    This #PlayIntegrity stuff is really questionable. My banking app won't run on a #GoogleFree #LineageOS running #Android 16 with all the latest security updates. But a #GooglePlay device running Android 10 that was last updated in 2021 is approved. This is not a real #security check. This looks like a #gatekeeper #monopoly check.

    In conversation about 7 months ago from social.librem.one permalink
  3. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Friday, 17-Oct-2025 02:55:25 JST Hans-Christoph Steiner Hans-Christoph Steiner

    Dear tech media, could we please stop using GrapheneOS as the judge on what's secure? I respect very much what GrapheneOS has built, but their stance that free software is not important to security is very short sighted. They literally are willing to call binary blobs secure because someone told them they are? They have no other standard to go on, since they can't inspect them.

    https://www.theregister.com/2025/10/15/fsf_librphone_vs_proprietary_binary_blog/

    #FreeSoftware #FOSS #mobile #LibrePhone #FSF #proprietary

    In conversation about 11 months ago from social.librem.one permalink
  4. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Wednesday, 26-Feb-2025 20:35:22 JST Hans-Christoph Steiner Hans-Christoph Steiner

    We're starting to implement support for split APKs in #FDroid. #Google wants to gather as much data about its users as possible, so trying to hide info about language, country, device specs was not a design concern for them. It is central for us. We want the official client to leak as little data as possible to any server, be it ours, mirrors, or custom repos. We welcome input:

    https://gitlab.com/fdroid/fdroidclient/-/issues/2963

    #Android #APK #privacy #DataEfficiency #efficiency #technology #data #metadata

    In conversation Wednesday, 26-Feb-2025 20:35:22 JST from social.librem.one permalink
  5. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Wednesday, 05-Feb-2025 15:53:48 JST Hans-Christoph Steiner Hans-Christoph Steiner

    The first time I went to FOSDEM, I was constantly explaining what F-Droid was to people who never heard of it. I was introducing it and promoting it.

    Second FOSDEM, people said "oh yeah, I heard of it, what does it do?"

    Third FOSDEM, people said "I'm a user!"

    Fourth FOSDEM, I listened to people tell other people what F-Droid is, and heard groups of people talking about it as the app store that everyone in the group had on their phone.

    It has been quite a ride!

    #FDroid #FOSDEM #FreeSoftware

    In conversation Wednesday, 05-Feb-2025 15:53:48 JST from social.librem.one permalink

    Attachments


  6. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Sunday, 26-Jan-2025 08:08:52 JST Hans-Christoph Steiner Hans-Christoph Steiner
    in reply to
    • Meredith Whittaker
    • Molly

    @Mer__edith Here is one thing Signal could be doing that it is not: the Signal fork @mollyim has already implemented #UnifiedPush support, Signal can help there, or even integrate that work https://github.com/mollyim/mollysocket

    In conversation Sunday, 26-Jan-2025 08:08:52 JST from social.librem.one permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      GitHub - mollyim/mollysocket: MollySocket allows getting Signal notifications via UnifiedPush.
      MollySocket allows getting Signal notifications via UnifiedPush. - GitHub - mollyim/mollysocket: MollySocket allows getting Signal notifications via UnifiedPush.
  7. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Tuesday, 17-Dec-2024 10:22:03 JST Hans-Christoph Steiner Hans-Christoph Steiner
    in reply to
    • Meredith Whittaker

    @Mer__edith seems pretty off base to call that FOSS culture. In my 30 years of working in FOSS, the people who are actually immersed in FOSS are much nicer and more helpful than in general. It is the people who treat FOSS contributors of any kind as some kind of service provider that are the shitty ones. Way back, I worked in corp tech support, and got treated shitty. So often, I see people laying on that kind of crap on volunteer FOSS devs on the internet. That is not FOSS culture.

    In conversation Tuesday, 17-Dec-2024 10:22:03 JST from social.librem.one permalink
  8. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Tuesday, 17-Dec-2024 10:22:01 JST Hans-Christoph Steiner Hans-Christoph Steiner
    in reply to
    • Meredith Whittaker

    @Mer__edith Try to find the stressed out, overworked dev who implemented some piece of macOS or Google that annoys you. You can't, they are hidden within the corp. That doesn't mean they aren't an asshole, it just means you can't interact with them. FOSS devs are vastly more likely to operate in public and respond to feedback from anyone. So there is a data bias at work here.

    In conversation Tuesday, 17-Dec-2024 10:22:01 JST from social.librem.one permalink
  9. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Sunday, 15-Dec-2024 16:22:34 JST Hans-Christoph Steiner Hans-Christoph Steiner
    • Adolph
    • husky
    • F-Droid
    • MortSinyx

    @captainepoch @cnx @fdroidorg @husky hehe you're welcome. That's perfect! If we focus on fixing things upstream as much as possible, many apps will just automatically become #ReproducibleBuilds without the devs even being aware. Your message made me feel like we're on the right track, thanks!

    In conversation Sunday, 15-Dec-2024 16:22:34 JST from social.librem.one permalink
  10. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Sunday, 15-Dec-2024 16:22:21 JST Hans-Christoph Steiner Hans-Christoph Steiner
    in reply to
    • Adolph
    • husky
    • F-Droid
    • MortSinyx

    @cnx @fdroidorg @captainepoch @husky All our rebuilds of Husky from v1.4.0 til v1.5.3 have been reproducible, so most likely, the newer ones still are. We'll see for sure once our rebuilders catch up with the backlog.

    In conversation Sunday, 15-Dec-2024 16:22:21 JST from social.librem.one permalink
  11. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Friday, 17-May-2024 18:23:39 JST Hans-Christoph Steiner Hans-Christoph Steiner
    • Wladimir Palant

    @WPalant Because the submitter deleted their account as a response to the review, I think it could be an deliberate attempt to insert the vuln. Plus all the attention from random new accounts. If it had been a normal review process, I could see how it could have been an honest mistake. But that scenario also makes it more attractive to the attacker, since making a mistake there is quite plausible, and could serve as an easy cover story.

    In conversation Friday, 17-May-2024 18:23:39 JST from social.librem.one permalink
  12. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Monday, 01-Apr-2024 18:13:11 JST Hans-Christoph Steiner Hans-Christoph Steiner

    Three years ago, #FDroid had a similar kind of attempt as the #xz #backdoor. A new contributor submitted a merge request to improve the search, which was oft requested but the maintainers hadn't found time to work on. There was also pressure from other random accounts to merge it. In the end, it became clear that it added a #SQLinjection #vuln. In this case, we managed to catch it before it was merged. Since similar tactics were used, I think its relevant now

    https://gitlab.com/fdroid/fdroidclient/-/merge_requests/889

    In conversation Monday, 01-Apr-2024 18:13:11 JST from social.librem.one permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: gitlab.com
      Search improvements: Sort based on keyword matching and removed alphabetic sort (!889) · Merge requests · F-Droid / Client · GitLab
      The search results are pretty unusable currently. So I've changed it to show apps in this order: App name matches keyword, summary matches keyword, description matches keyword. Also,...
  13. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Friday, 01-Mar-2024 19:04:30 JST Hans-Christoph Steiner Hans-Christoph Steiner

    #Debian has been moving more towards the deb.debian.org mirror which is provided by a single CDN company, #Fastly. It works well, but also feeds an enormous amount of #metadata to a single company, and it can be used to track computers and maybe even people. And the privacy policy in effect is unclear. Fastly says the #privacy policy of the "subscriber" applies, but the privacy policy for deb.debian.org is not listed anywhere I could find. Anyone have any insight here?

    In conversation Friday, 01-Mar-2024 19:04:30 JST from social.librem.one permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Welcome to deb.debian.org (fastly instance)!
  14. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Friday, 07-Jul-2023 21:22:50 JST Hans-Christoph Steiner Hans-Christoph Steiner
    in reply to
    • feld

    @feld 3 vs 10 would make a big different. If I remember correctly, Amnesty Panic Button had a 10 second countdown. Also, Apple designs things in a very integrated way so they would have designed the hardware power button to also work for this use case. That kind of design integration rarely happens in the Android ecosystem. Google Pixel devices do it to some degree, but not nearly as in-depth as Apple does. I would love to see an Android device that applied the same level of polish as Apple does

    In conversation Friday, 07-Jul-2023 21:22:50 JST from social.librem.one permalink
  15. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Thursday, 06-Jul-2023 23:56:09 JST Hans-Christoph Steiner Hans-Christoph Steiner
    in reply to
    • feld

    @feld Apple's PR department is better at shifting blame to other people? My experience with Apple phones is via my mother, whose ringer switch is constantly being accidentally flipped off, so she's rarely reachable. She doesn't know what the switch does, it just gets accidentally switched somehow.

    In conversation Thursday, 06-Jul-2023 23:56:09 JST from social.librem.one permalink
  16. Embed this notice
    Hans-Christoph Steiner (eighthave@social.librem.one)'s status on Saturday, 24-Jun-2023 20:03:10 JST Hans-Christoph Steiner Hans-Christoph Steiner

    A decade ago, #AmnestyInternational did some extensive UX work on #panic buttons using the power button. They used 10 presses as their trigger, and still got far too many false positives. Their conclusion was power button triggers were not workable. #GuardianProject reached a similar conclusion back then. I guess #Google missed that research: they shipped #Android with a 5-press trigger, and now emergency services numbers are receiving record numbers of false calls:

    https://arstechnica.com/gadgets/2023/06/uk-police-blame-android-for-record-number-of-false-emergency-calls/

    In conversation Saturday, 24-Jun-2023 20:03:10 JST from social.librem.one permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.arstechnica.net
      Android’s emergency call shortcut is flooding dispatchers with false calls
      from @RonAmadeo
      Google says it's working on a fix, but as usual, manufacturers will need to update.

User actions

    Hans-Christoph Steiner

    Hans-Christoph Steiner

    FreeSoftware #Privacy #GuardianProject #Debian #FDroid #TorProject #CalyxOS

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          139590
          Member since
          24 Jun 2023
          Notices
          16
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.