fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#moxie_marlinspike

0 posts0 participants0 posts today
Replied in thread

@danie10 @snikket_im

I personally feel that this is the optimal delivery and update methodology for future software distribution.

I've written about this at length in several articles, and more and more service daemons and client software are taking advantage of this form of direct from the developers method of delivery - not just Android apps.

#FairEmail is one such app that even states in the docs that this is the preferred method, although they do support a total of four methods:

- Google PlayStore - crippleware due to google funding source restrictions. In all cases, this is by far the worst distribution point for software, if not with respect for the product that the developers want to deliver, but also with regards for the privacy of the users who are tracked, mined, and themselves repackaged as a quantifiable inventory item.
- F-Droid custom Dev's repo - 2nd best option, because this is built with the developer's keys when the developer decides to push the product, and contain all feature sets that the developer chooses to include.
- F-Droid repo - 3rd best option, since it is signed with F-Droid's keys and typically lags by some measure of time with respect to release dates, considering that F-Droid staff pushes these out on a best effort basis, according to the time they have available to do so.
- Direct from the developers Git repo - This is the best method. They push a release and the next time you open the app you're notified of an update.

This is part of the magic of Slackware's philosophy too - Patrick and team don't church it up like most distro's do (Debian and AlmaLinux quite often, quite heavily wrt customizations, use Apache or Nginx HTTP servers as examples). Slackware tries to package up software as close to how the upstream intends it to be.

In earlier articles I've published on the topic, I've focused at times on a solution to a theme proffered by #Moxie_Marlinspike, who denigrates the open source model somewhat, for being at a great disadvantage when compared to that of proprietary solutions that can update and evolve protocols, APIs, etc., on a whim, because they're centrally managed and controlled by a single dictatorial source. Microsoft is one such classic example. You simply have NO CHOICE as to when you must allow your software to be EOLed, evolve, or update itself.

Using this model, however, where a central repo, or a distributed, CDN type of repo mirroring is deployed at the origin by the development team itself, FOSS has no problem upgrading even things like protocols as they evolve. Of course, it is ultimately up to the operators of the software to allow updates and the prerogative of the developers to establish the level of nags that users of the software will experience until they permit the updates to occur, but that's beyond the scope of the basis of advocating for this type of delivery model.

Okay I think I'm bordering on hijacking this thread, so I'll make a comment about these types of shennigans by Google, and how one one hand it's certainly a huge frustration, if not an impediment to being found and adopted by users, but moreover, a predatory practice by one of the most egregious violators of personal choice in the free market of consumerism and commerce.

It may hurt being pulled like that, but IMO, I don't think there's anything preventing the good folks behind #Snikket from pushing out the kind of crippleware that google wants them to, while at the same time pushing banner splashes in the app that explain just how fricken' useless it is under the terms necessary to distribute it via that medium, and encouraging users to install it instead by following the instructions at the #git_repo for a fully featured, #e2ee secure messaging platform.

IOW, there's always a silver lining - wear this dejection as a badge of honor and as the evidence to support the fact that you're on the right track!

#tallship #FOSS #privacy #crippleware

⛵

.

#Wake_the_fuck_up people!!!

All hail the great #Faceplant :P

I would love to hear what happens to anyone who dares to repost those graphics to their Faceplant or #InstaSPAM pages Muahahaha!

If you do, let us know, m'kay?

https://gizmodo.com/signal-tried-to-run-the-most-honest-facebook-ad-campaig-1846823457

There's plenty of viable de-centralized social and communications platforms (secure too) that shield you from such instrusive raping of your most private secrets, and even what you publicly expound.

#Epicyon, #Pleroma, #Friendica, #Lemmy, #Misskey, #Diaspora, #movim, #matrix, #XMPP, #GNU_Social #Writefreely #jujeune #planetary (#scuttlebutt), and even using your own email services in defiance of what the great Spamming Google gmail engine virtually demands that you not do; are all very viable and privacy respecting opportunities to meet and make new friends, acquaintances, and forge business relationships with others who you'll know are already concerned with privacy respecting communications technologies.

I'll just let that, and the previous advertisements that exposed the private information about people using InstaSPAM and Faceplant users speak for itself.

Kudo's to #Moxie_Marlinspike - You go girl :)

#tallship #Vger #privacy #security #tracking #you_are_the_product

⛵

.
GizmodoSignal Tries to Run the Most Honest Facebook Ad Campaign Ever, Immediately Gets Banned [Updated]By Shoshana Wodinsky
"Let's Crack the Cops!" - is that really what #Moxie_Marlinspike is advocating, or at the very least, implying that devs should consider when it comes to these *Apple pwn3rs?*

I sense there was a need for plausible deniability there in delivering that passive message, due to the #Cellebrite having "Fallen off" a proverbial truck lolz....

Oh you can haz #Cheezburgerz! 🍔

Fell off the truck, Oh that's rich!

https://www.vice.com/en/article/k78q5y/signal-ceo-hacks-cellebrite-iphone-hacking-device-used-by-cops

#tallship #Vger #iPhone #vul #counterinsurgency

⛵

.
www.vice.comSignal CEO Hacks Cellebrite iPhone Hacking Device Used By CopsOne of the biggest encrypted chat apps in the world just showed how a device used to decrypt messages can be hacked and tampered with.