• 0 Posts
  • 230 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle
  • Signed developer certificates protect you from MITM attacks, it does not protect you from the sources themselves being compromised.

    Very true, and that’s why f-droid building from source can only guarantee the apk matches the source, but you still need to trust someone else (or yourself) to study the source and confirm nothing shady is going on, which of course isn’t something most people would do for any open source app they install.

    Still, for “high profile” cases it just take one (independent) person to go through the source and publish their findings.


  • Yes, I understand the situation is shady and f-droid maybe didn’t handle it the best way on a human level, and that is important when evaluating trustworthiness.

    What I was focusing on was more on the technical side: As long as I can:

    • trust f-droid to actually build from source and only publish something guaranteed to match the source, and
    • read the source code myself, or trust an independent researcher to study it, and confirm there’s no malware,

    then I don’t need to trust the maintainer of the project at all, and I can ignore all the drama, being assured with a high degree of certainty there is no malware

    I can also ignore any drama involving f-droid as long as I still trust them to build from source. This can also be verified by independent researchers by buulding themselves ans comparing, once again filtering out the drama and noise, though most people probably won’t go this far.


  • I don’t use syncthing (anymore) and didn’t know the story behind this, but one thing I know is, f-droid builds the apk from source and signs it with their keys, or if reproducible builds are available, it verifies the signed apk provided by the maintainer to match bit-for-bit with the source code, so at least even if one doesn’t trust the new maintainer, they should be able to trust f-droid that the apk matches the source, so e.g. no spyware or malware was added for example. Sure, someone still needs to review the source, of course.







  • For all of you that downvoted because “AI”, let’s be clear, this guy does all the processing locally, not in the cloud, so it’s a privacy friendly option:

    Tiiny AI does all of its AI processing right on the device. Nothing leaves this mini supercomputer. If you’re privacy-minded and don’t want all of your data uploaded to the cloud or just don’t want to pay for any more subscriptions, an AI computer is what you want.

    I’m actually quite interested in this. I hate when AI is shoved down my throat, or if it runs in “the cloud” out of my control, but this would be fully under my control.

    My only concern is whether I can run my own OS (i.e. linux) or if I’m locked to theirs.









  • But when Alito referenced a systematic review conducted for the Cass report in England, Strangio conceded the point. “There is no evidence in some—in the studies that this treatment reduces completed suicide,” he said. “And the reason for that is completed suicide, thankfully and admittedly, is rare, and we’re talking about a very small population of individuals with studies that don’t necessarily have completed suicides within them.”

    And then

    Advocates of the open-science movement often talk about “zombie facts”—popular sound bites that persist in public debate, even when they have been repeatedly discredited. Many common political claims made in defense of puberty blockers and hormones for gender-dysphoric minors meet this definition

    Ok, I get the idea that there might be no scientific evidence for gender affirming care reducing suicide rate, but “no evidence” is not the same as “discredited”: it might still be true, and in fact, anectodal evidence probably suggest it’s true, but we don’t have enough data to confirm that.

    The conclusion should be “we need more data” rather than taking about zombie facts.

    And the article continue to conflate “no evidence” with falsehood:

    But the movement has spent the past decade telling gender-nonconforming children that anyone who tries to restrict access to puberty blockers and hormones is, effectively, trying to kill them. This was false, as Strangio’s answer tacitly conceded.

    No, it’s not false, or at least, we can’t conclude that from not enough evidence.




  • I don’t give a shit about Iranian regime, but I do care for their innocent civilians. Just like I don’t care for Israel’s regime (and the … US regime, as well), but I do care for their innocent civilians. The difference with Israel and USA is, though, that they voted for their regime, so, many of them aren’t so innocent.

    Still, as usual, the people who suffer the most are always the ones who never wanted any of this.