You know, I think Fossil with its integrated issue management right in the repo is actually a perfect match for the LLM era. Maybe today is the day I migrate to using a Fossil forge with GitHub becoming increasing untenable.
I have wanted to do something similar for a while, but thought that routing would be the toughest part.
In fact, I am surprised that a robust go-to successor to https://www.freerouting.app/ has not appeared in the LLM world. Do you know of a good follow working in the OSS autorouting space?
Look up the English Enclosure acts. They brought about a large-scale robbery of peasants by landowners in the 17th and 18th centuries, and created a proletarian class that needed factory work to survive. Things got a little better in the 19th and especially 20th centuries.
Just downloaded CoMaps. Why does it start with a zoomed out view of the entire world, especially given that I gave it location services and it shows my current location (in North America). The very first UX experience this app gives is "I am primarily for people interested in maps and geography"
Contrast this with Apple Maps - when you open it, there are 4 big tap controls for actions like "Home" "Work", a search bar, and a map that covers a 1-mile radius around you .
I'd encourage your UX flow to go something more like: request location services > if granted, immediately start downloading their local tileset in the background > zoom to a 20-mile radius around the user
Unfortunately I have yet to find an OSM app that offers a properly usable modern interface. Most are passable if you are a nerd who doesn’t mind being inconvenienced and can work around the quirks; my non techy friends open the app once and immediately delete it. We really need an Apple or Google maps clone.
And the online mapping ecosystem is completely fragmented. Half the apps out there demand a $25/month subscription, creating these hermetic, proprietary silos. They are gating and monetizing trails, hikes, and routes that were crowdsourced by the community in the first place. I’m not paying $300 a year to buy back data that I personally contribute to. There are gazillion similar apps, with slight variations, and the more powerful ones look like something straight from 2000s.
Instead of a pay-to-access model, a sustainable consumer map ecosystem could look like Wikipedia, or better yet, a peer-to-peer network like IPFS where you trade compute (route calculation) and storage. It could be a barter: you get to use the collective resources of the network because you are actively hosting tiles, routing data, or contributing metadata back into it. But that requires a critical mass to take off (like bitcoin did).
OpenStreetMap is great, but what we actually need is a modern consumer frontend built on top of an open, distributed layer: decentralized public registry for user-generated content, keeping your routes and trip itineraries discoverable by any client app rather than locked inside VC-backed silos.
Furthermore, current open-source projects miss a lot of quality-of-life features that commercial apps have—things like crowd-sourced opinions and reviews about places, public transit schedules, real-time traffic alerting and reporting, location sharing, street-view, and dependable speed limits during navigation. Without these active, live-data layers, the map looks stale and lagging behind the real world.
The user interface also needs to shift from a passive viewport to a high-contribution editor. Right now, if you want to make serious geometry edits, you’re forced into JOSM. It’s hard to boot, clunky, and quite clearly has never seen a proper UI/UX designer, scaring away everyone but the most hardcore power users. I'm a person who doesn't give up easily, but when I tried adding parking zone regions for the city I gave up after 2 days of trying to make some sense of this software. A modern mobile UI should let you freehand draw a route that snaps to paths, edit regions on the fly, or drop advanced metadata — like parking restrictions — in just three obvious taps, without a steep technical learning curve.
Finally, the client app itself should be a pluggable core. Instead of building every feature from scratch, it should allow users to plug in open modules for whatever they need, whether that's live public transit routing, traffic estimates, location sharing, or advanced 3D metro overlays. The data is there, and the rendering tech is there; we just need a shared, distributed network structure so companies can't charge us a premium to gate the social and metadata layers. I wish there was an EU initiative to have a fully featured app like that, unifying all the existing ones in place of N abhorrent, barely functional implementations in all of the different local public transport apps (looking at you italian AMT genova or you, french IDF mobilites).
When I downloaded it via F-Droid earlier today it did what wanted. Unfortunately Android Auto is only enabled in the Play Store Version, so I downloaded that and there it went the same as for you. At least it immediately prompted me to download my local tile set when I tapped the geolocation button to zoom in.
Only functional startups I've seen solve actual customer problem and don't try to solve all problems. Usually they have tried several things before they found one that actually is worth solving.
But everyone makes mistakes and bad deals in product development or they go out of business.
What always gets me about these red team attacks is the same thing that gets me about internal phishing test emails.
My company sent an internal phishing test last week. Several people immediately reported it to a cybersecurity engineer, posted about it in Slack, saying they were surprised that such a sophisticated phishing attack was happening.
I too was surprised - Google is usually much better about catching these kinds of things in the GMail filter before they get through. Oh well, sometimes one slips though. Reported it and moved on
Come to learn that the only reason it made it through is because we let it through _on purpose_.
By analogy to these red team attacks: _theoretically_ someone could rent a car, pose as an employee, and set up a Raspberry Pi in the network.
But who would go to all that trouble?
Theoretically, someone could craft a perfect phishing attack, but who would go to all that trouble?
Spray-and-pray, low precision, high surface area, attacks are the ones I end up reading about.
The only reason this attack vector was open is because the red team stood to gain a massive benefit from succeeding in the attack. What real-world actor would go to the trouble and stand to benefit as much?
Imaginary country called Nicha can’t buy lithography machine from imaginary company called SAML. Nicha can kidnap some scientists and torture them to get all the secrets. But it’s not elegant. Nicha can pay a lot for hacking and get the result in anonymous way. I guess 8 figures can be paid easily for these secrets. With that money “red team” can launch very nice multifaceted social hacking attack.
> Theoretically, someone could craft a perfect phishing attack, but who would go to all that trouble? Spray-and-pray, low precision, high surface area, attacks are the ones I end up reading about.
I've been at a company that was well targetted. I forget which group it was, but they were got into a lot of customer service sites that week; not ours, but we had some near misses. Almost got me, sent me an email from the boss with 'The blog is down' and a link ... I was checking my mail on mobile as I was out the door, but of course mobile doesn't show any useful headers like from address.
"Theoretical" becomes "pretty much guaranteed" if standards sink low enough - the more effort you put in, the more problems you ward off.
Sort of like how a lock can be picked in 30 seconds, but still deters 90% of crime - a lot of criminals are just searching around to find out who is vulnerable, and most every company has something that's worth at least a bit (even if it's just stealing $500 laptops instead of breaching the network)
I mean, a company I worked at had a significant amount of money stolen after the attackers spent 6 months sitting on their access waiting for the right moment to fake an (expected) reply to an email exchange. The original breach (or at least the breach of this executives account) involved a very targeted phish. When the potential payout is millions it justifies a lot of effort.