Hacker Newsnew | past | comments | ask | show | jobs | submit | nunobrito's commentslogin

This android distribution is very suspicious because of a lot of bad architectural decisions (that is one of them) and their famous refusal to disclose funding sources which go beyond common logic for open source projects.

There are other Android distributions that run on practically any Android phone you have, look for LineageOS. Even your phone is not explicitly listed as supported, using Claude is easy nowadays to adjust the distro to run on your phone perfectly.


Utter nonsense. GrapheneOS relies on explicit hardware features like MTE, TPM, and secure boot, for its threat model. Most phones don't even have that hardware, fewer still publish enough info to use it (see Samsung). You can debate if GOS is necessary for your personal needs, but the reason they are so picky is they don't want people assuming Graphene security on subpar ports.

Excuses. None of that is a reason to force users into high-profile hardware that is not audited and makes anyone buying them an automatic Person Of Interest.

Furthermore, sound cryptography isn't dependending on specific hardware to function, with that kind of reasoning we'd never get encrypted communications anywhere. So stop inventing excuses and for once in life look deep into how they are financed, which apparently is OK to be as opaque as possible as to whom is paying them so much money.


GrapheneOS is not a cryptography project, like a secure messenger would be. It's goal is practical security, which does depend on practical considerations: without MTE, similar memory security would cost an unreasonable performance penalty, without TPM conventional authentication methods like PIN-code and fingerprint would be vulnerable to bruteforce, without secure boot users would not be able to verify if their phone was physically tampered with in a brief window they were away from it... And if you have closed-source radio chips running their own untrusted software loaded over the air, integrated in such a way they can independently wiretap you, like most phones have, you'd already failed at protecting the user before you start.

Furthermore, Android's ecosystem is structured in a way even the most basic software security concerns, like not running a comically out of date kernel, depend on the vendor's blessing, and sadly most manufacturers, including very desirable ones like Fairphone, hadn't been keeping up with such duties. Porting new kernels to old hardware is an extremely inefficient time-consuming endeavor that will take up most of volunteer time to non-satisfactory results; I can testify to that as a former member of the Ubuntu Touch project, and our standards of security were comically lax.

Again, you CAN lower your standards of security and go for the lesser evil: many people run Lineage or Ubuntu Touch despite known gaps in their security models. But to make that choice, you have to be honest about what you're compromising. If you shut your eyes and plug your ears pretending everything is fine, you'll end up with someone killed because they listened to your uncritical advise.

Also, I struggle to see how it's GrapheneOS's fault choosing the most secure hardware on the consumer market because it might be deemed suspicious to own it. GOS could have chosen the most popular budget Samsung (ignoring the aforementioned security issues) and it would have the same effect. Besides Pixels aren't an obscure unusual hackerphone made in small quantities, shipped from out of the country; it's among the most popular phone brands, advertised from huge billboards I pass on my bus route to university. If they chose something like the PinePhone like Genode, this point would be somewhat defensible.

Finally, what's up with the repeated conspiratorial insinuations about financing? I admit I hadn't looked deeply into this question, even as a one-time small donor, but what are you expecting to find? Is it serious concern about the financial health of a project, or an attempt to manufacture a hysteria around some controversial donor, similar to the Tor Project?


You can downvote my posts as much as you want with your cronies.

It won't change reality, doesn't matter how many paragraphs you write. The fact is that all that security is useless when using hardware that is compromised from the start. And I will repeat this again: any NSA supplier does bug their hardware and they do this for decades until finally admitting, just need to take a look on the NSA museum.

Stop promoting suspiciously funded Android distributions that run on even more suspicious hardware by groups that routinely promote state-sponsored tools on their social media.


Reticulum creates networks but over radio the bandwidth is so limited that what you can realistically send are just messages.

There are more efficient protocols like APRS and more recently XPRS.


Why.. just why..?

What a waste.


When they already mine for ETH, why would any of them be interested in a secondary coin without value?

Value should come from somewhere more than just speculation.


Oh the memories. Took them forever to introduce something as simple as tabs that virtually all other competitors had since years.

File explorer was the same, only recently it got tabs.


It always made more sense to call these tiny texts as "tweets" rather than "toots" (mastodon) or "status update" (generic) so it would be good having the right to use that term as public domain.

There have been worse names for this kind of updates in the past. At some point in time was common to "finger" someone online: https://en.wikipedia.org/wiki/Finger_(protocol)


Mastodon and X both switched to “posts”. Toots was the old name.


Which has been the correct name since before Twitter existed. You can also use "message", or "comment" if its in reply to something else.


Yep, and didn't work.


In what way? I haven’t seen someone say “toot” in a very long time. Tweet I did but that was arguably more entrenched in pop culture over the years.


I guess it depends on what community/bubble are you in. Many fediverse users I know have always been, and will always be tooting.


Some fun history on the origin of ‘tweet’:

https://furbo.org/2013/06/28/the-origin-of-tweet/


Do you have to finger them before you poke them?

<smoking emoji>


Microblogging.

That's the original term.


"did you see what the president just microblogged"?

come now, surely you understand why it would be beneficial to the commons to have a snappy, catchy term that already has purchase in the public imagination be free to use, right?


Okay, what other catchy term instead of "president" would you suggest?


King?


Pedophile?


But people (around me at least) feel bad when they have to compose an entire sentence full of words without any brand names or corporate names inside. They feel like being separated from their mother or like they lost basic orientation when not in each sentence there is "an uber", or "my instagram", or "a youtuber", "a whatsapp", ..., ..., ...

The email signature of my former landlord was like that:

..... Phone: 012345 I-Phone: 543210

Funnily, that wasn't some US girlie, but a German grandma. Maybe she got some bad US food on some journey and it made her brain rot away. Yessss, of course, as a bonus, it's a somewhat uncommon way spelling... But, yeah...


The "phone" is probably landline or old 2G phone, iphone is internet connected smartphone (extra whatsapp etc).

I remember having troubles voice calling iphone users, because of some roaming data bs, their device would not correctly fallback to 2g voice call on bad 4g connection, it tried to use data everywhere (voice call would just get ignored).

Plus imessage does not correctly use sms protocol, instead tries to use internet and apples bs extensions. With bad connectivity it means sms will not reliably work on iphones!

Super relevant in germany and their shitty 4g networks!!!


Heeey, our mobile networks are much less shitty than our railway services! :)

Anyways, in such cases, I would try to get more competent hardware, instead of proudly advertize it in my email signature. Also, yeah, she was as competent as our mobile networks or our railway. When I subscribed the contract, she was making fun of another tenant who failed transferring money and then came with lame excuses like 'the bank account number was invalid'. In a very unfriendly German rich grandma way of making fun. Turned out when I tried to transfer the first rent: The bank account number was invalid... Well... At least she was precise with the mobile phone she had (not so much with its spelling, though). :)


> Heeey, our mobile networks are much less shitty than our railway services! :)

Still mediocre compared to nearby countries.


The brand name version from back in the day was calling them twits.

Let tweeting ring free.


Learn to play piano


On behalf of all pianists, welcome to the fold. The best advice I can give is to get a proper piano teacher for the first few lessons. If you’re in a college town, there might even be performance majors who’d be happy to teach on the cheap.

Even if you’re not going to stick with the teacher and prefer to learn in an autodidactic way, the beginning is the most important part since proper ergonomics, posture, and fingering really set you up for success in the future. It's hard to break bad habits once they've set in.


The novelty is that user accounts and UGC (user generated content) are both verifiable and independent from servers.


That is an unfair judgement. There are people there using LN, just as there are others using Monero, BCH or whatever crypto rocks their boat.

I develop for NOSTR and use zero cryptocurrencies because the communication aspect is what matters, especially the account with npubs which are basically universal entry cards to avoid anyone having to create separate accounts just to use some website or app.


I'm interested in seeing more nostr clients that do not implement cryptocurrency. Can you please share some examples?


From top of my mind would say https://coracle.social/ and on Android the darkwisp from: https://zapstore.dev/apps/com.darkwisp.app

There are so many clients, here is a site that tries to keep up with what exists: https://nostrapps.com/


Try following things you are interested. My topics are radio tech and my feed comes up with things that actually interest me.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: