• 0 Posts
  • 81 Comments
Joined 3 years ago
cake
Cake day: January 26th, 2024

help-circle
  • One thing I really dislike about the Mobile ecosystem is how much different each device is to each other.

    I thought you were sarcastic when I first read this part, since way back when phones used to be innovative in both hardware and software. The current market offerings are all carbon copies of eachother with a strong trend towards converging into the exact same lineup.

    Multiple cameras, one in front, 2+ in back. A power button and two for volume. Reader apps may hijack it for scroll. Gesture movements. Fingerprint and face id. Less and less conusmer freedom in software choice. Irremovable battery. No removable back plate. A rectangular brick. A near-100% display area. No headphone jack or SD card, with SIM on the way out.

    Covers the vast majority of offerings on the market, with a few slight adds/subtracts. Dumbphones are a rounding error.

    This definition covers even tablets, and it isn’t even deliverately vague.

    Without much experimentation and development on the hardware front, no wonder software’s behaving exactly the same.

    There just isn’t enough interest for proper innovation and experimentation.


  • That’s nice to have. For both GIMP and the industry’s sake, priorities should be:

    • good UX
    • feature-wise competitiveness
    • in any (sensible) format

    GIMP is an alternative to Photoshop. It isn’t a psd reader.

    Being the format jack of all trades yet master of none isn’t too great of an idea. It’ll just exacerbate GIMP’s main current problem: an ancient UI Photoshop enthusiasts dread. A lot might consider switching if the bad GIMP UX was better than the also-bad Photoshop UX.

    If I had to say what my main design gripe with gimp is, that’d be modularity. Seperate the ui (skins) from the tools, effects and rendering (formats). The UI is especially egregious in its hard-codedness while effects are pretty well-supported.

    A few more apis would go a long way. Hell, even the closed Photoshop has open(ish) apis, since even Adobe know the value of an ecosystem and not just their internal r&d department!


  • Maybe that’s what it was. It doesn’t necessarily need to be that going forward, as project putlooks anf goals change with time.

    Also editing is quite a lot of more work to support than mere viewing. As all tools and actions need to behave correctly - not jusbt the renderer.

    And something proprietary can hadly be a “industry standard”. It can be “most common” or a “de facto standard”. But all “industry standards” are by definition open as any industry worth its weight doesn’t rely on or include a single point of failure anywhere within itself.


  • Honestly, Chromium seems to have the basic features like history and passwords figured out way better than Firefox (or rather, Chrome does), while stripping most of the junk away, as it luckily happens to be proprietary Google bullshit.

    Firefox has a bunch of telemetry and bloat, but the fact that my only real dealbreaker for a browser is quality adblock makes Firefox pretty much my only “vanilla” choice.




  • Not only that…

    They use this fucking incredible argument:

    “We destroy the book because when we scan it - that’s a new copy. If we destroy the oroginal - only one copy (the scan) remains”

    As if the model doesn’t get copied over and rented out in bajillions of instances. Its product - by all AI service ToS’s made free to use and copy royalty free (unlike say, every single library in this world, which universally forbid the photocopying of lent out books). Meaning - copyright infringement of the worst kind in any sane interpretation. Shame this world is insane.

    Such an incredible spin on the rules. Using them as the excuse to go against the core cultural, civilizational and moral imperative of archiving, while going against the spirit of the concept of what copyright was initially made to do - give authors the path to a livelihood from their work and denying it to parasites such as publishers.

    Copyright truly is dead. Indeed - the global copyright rules were on their last legs before AI and used only as anti-consumer protection for publishers (not authors!), but now they’re a sinked ship - the mask is off. It’s all plainly visible what they’re here to do now.


  • Late to reply, but

    Imagine if, like how app publishers can seemingly magically deploy arbitrary code and send data at a high speed to and from your devices, society and technology went in a similar way with appliances:

    Due to the obvious fire risk, all appliances need to be recorded. The recordings: accessible real-time to the fire department and yore utility suppliers. Don’t worry, installation of the beeded equipment is covered by the Stop The Spread of Fire association. You only pay a symbolic part of the real cost.

    Sounds dystopian, and it is.

    Hell, with the way some cashier-free stores are using solely scale-equipped shelves (no camera needed), a conclusion of "Why don’t we do that in OUR fridges by Samsung isn’t impossible. Give an eextended warranty and some bonus functionality like expiry tracking if the user registers their produce in the device’s built-in display. Then sell the data and profit.




  • Probably not. AFAIK docker isn’t a virtual machine in the traditional sense that it has its reserved storage other apps on the machine can’t access. And even if it were, it’s the same physical drive.

    Now I’m not too versed myself in SSD firmware so maybe the large file size really is like a wide net, or maybe the file size isn’t important - only the fact you’re doing read operations on a small space on the SSD may give enough volatility in the read speed to infer the exact app that decided to spin up at that moment.

    The simplest fix that comes to mind is to have multiple drives (e.g. install and data) and put the browser on the data one. Maybe this added complexity can throw off some naive attacks. Also, a HDD “naturally” has some variability in the access time (since it needs to physically locate the sector with its read heads).

    So in essence, laptops with a single SSD are by far the most vulnerable.

    However, adding sane limits on the vulnerable API mentioned and throttling read/write speeds (ideally with randomization) seems like a fix good even for single-drive laptops.

    What’d probably work with Docker is a similar read speed throttling setup.

    Spoofing identifying information won’t help much since read time variability is what matters here. It may make it take more info to infer performance rather than having the transparent information, but a good model is bound to infer pretty well after some initial data.





  • They are. It’s a step in the right direction and I absolutely welcome it.

    However, it’s way overdue in my book, and the harm is im the waiting. It’s much better to strike while the iron’s still hot and avoid these issues. As is not waiting on improving accessibility.

    I’m also intrigued by the fact Google makes such custom devices for the market. I think I came across some explanations lurking (and sometimes popping my head out and commenting) here on Lemmy (and on Reddit before the API apocalypse), but I don’t really have anywhere to point you in your search other than Libredirect+Reddit since searching Lemmy has always proven an uncatchable golden goose to me.


  • Sure.

    Using community-vetted software doesn’t have any security or privacy benefits over proprietary.

    Neither will proprietary software arbitrarily be able to remove features, lock out certain users or raise prices dramatically.

    Would you rather buy vetted cruelty-free foods or not?

    There’s surely no benefits in doing so.

    What about clothing?

    Would you rather buy a shirt that has some guarantee of not using underpaid or child labor?

    What about energy?

    Would you rather your electricity comes from a local coal plant poisoning you and others with its toxic fumes, or from a solar+hydro mix?

    What about furniture?

    Woukd you rather get an item made from recycled materials and with well-paid labour, made locally and to high quality or get the not-so-cheap alternative from IKEA?


    All the options above are morally superior. And so is FOSS software.

    And there is a multitude of reasons.

    But there’s two things I’d like to point out right away, regardless of FOSS specificalky

    1. sometimes, these pros from above don’t even come at a higher price.

    Hell, oftentimes they’re cheaper (for example, storebrand is vastly more moral than Nestle and it’s cheaper).

    1. There’s a positive-feedback loop regarding standards.

    First standards don’t exist formally and any “standard” (quality or otherwise) is pure coincidence. Pay is high because the market said so. Quality is high because machines are good enough. Privacy of our maiking list is high because our director chose to use a free (FOSS) local app instead of a paid cloud service.

    Then ad-hoc (informal) standards form. Companies voluntarily do things in order to stay competitive. For example most every site uses hashing and salting, meaning your passwords are pretty safe.

    Then real standards form. Still voluntary, but formal. They’re still voluntary, but you can’t half-ass things anymore abd say you did them. You’ve gotta meet real demands.

    Then these standards get made a requirement by the legislature, so Nestle actually has to do some ethics now.

    This exact same progression is present in multiple otherwise disjunct domains. Labor rights, pollution, quality standards. And yes, software freedom is one of them.

    But what even is software freedom?

    It’s the ability to vett code. The ability to switch providers. The ability to play a game after servers shut down. The ability to export data. The ability to not pay an hourly rate of $15 for your dial-up use. Interoperability. And a lot of other things.

    Free as in freedom is much more than gratis (free as in no need for money).

    Free software is the one that pushes this feedback loop forward the most.

    And that’s why it’s a moral imperative.

    Ironically, it’s free software that often times creates competition (and therefore lowers the price of) proprietary software.

    It sets quality standards. Proprietary can’t be that worse than free - people’d find out soon enough.

    It acts as competition (albeit oftebtimes unequal).

    It expands accessibility by giving a gratis alterbative.

    It drives change. Much more so than proprietary bullshit.

    Using FOSS software isn’t easy in this day and age. But without it, using proprietary software would be way, way harder than the FOSS from decades ago.

    No Internet/WorldWideWeb. No networking. No encryption.

    Most of the infrastructure is FOSS. It’s too expensive to make well even for the big players - some 25% of Windows (as in the bloated mess) is made up of free software. 90% of Edge is.

    You’re using free software even if you’re not trying to much more than you realize.

    And that’s the result of small victories from ages ago. Victories which set standards and expectations.

    Maximizing your use of FOSS software maximizes the amount of these victories. It speeds them up.

    And it makes a difference way bigger than you may realize.


  • There are a few issues with there being… a single ideal privacy option line of devices (the Pixels):

    • the pixel isn’t available for sale in all regions
    • there are only so much Pixels out there… Meaning less options to choose from and potentially higher prices
    • people using them stand out… So much so some agencies treat Pixel users like criminals even if they don’t have Graphene on it
    • Google may choose to end the Pixel line, drastically limit production or remove some feature Graphene relies upon any time they feel like

    Having more vendor choice drastically lowers these negatives. And I can’t really think of any negatives for the other side than increased dev time and operating costs.

    Having the privacy features trickle down to other devices is great since some already landed in AOSP.

    However, the trickle down is slow (and often a myth). And some protection is better than no protection.

    Why are a multitude of poor options better than a few good options?

    Is anything other than a Pixel a poor option?

    They may be suboptimal but… Some hardening is definitely better than no hardening any day of the week.

    What actively blocking “okay” or even “good” options when “the perfect” one exists should be plainly obvious.

    Privacy-consciousness will never spread. Which also has negative effects on the privacy-conscious. Namely point 3 of my little list.



  • Yeah.

    Edge still has its problems, but it’s nowhere near the hot mess it wass in 2015 when it was basically a reskinned IE. Once they switched to Chromium it was still a hot mess, butit did get polished and has all the features you’d expect of a modern browser.

    That being said, Edge is the main innovator behind built-in AI chats and similar bloat, which Chrome also likes to shove down people’s throats.

    And although the feature has existed as a Firefox addon for ages, I think the first browser to support tab groups and horizontal tabs was Edge.

    So since both are pretty on-par feature (and bloat) wise, run the same engine and are made and maintained by billion-dollar corpos gobbling user data, both seem like two sides of the same coin.

    So for ‘normies’, it pretty much boils down to which ecosystem you’re more ingrained - that will make you prefer Edge or Chrome.

    Us lunatics on Linux and/or ActivityPub prefer an independent option.


  • Security wise Fairphone isn’t up to GOS standards, so a collaboration wasn’t on the table either way.

    I don’t know the situation, but if it’s as this part of your comment implies, then that’s clear bridge-burning on Graphene’s part.

    If the current phones don’t have a chip or whatever, that doesn’t mean they can’t reach out to Fairphone and say “Hey, we’d like to promote our OS and join up! However, we requure such-and-such hardware. Are you interested?”

    Saying “It doesn’t have the chip, a deal with them will never work” without reaching out isn’t productive.

    I assume that Fairphone has quite the problems competing with more established markets and the OS is an afterthought, so they went with /e/. But hey, I might be wrong, and it’s all a conspiracy to maie an illusion of choice with Fairphone+/e/.

    But if the mission of Fairphone is fair production and repairability, the fact that security and privacy are afterthoughts seems like a reasonable (but foolish) standpoint. They should care.

    However, since the mission of Graphene is security and privacy, that seems like they should be the ones to reach out and try to provide their world-class software to as many people as possible. This probably includes supporting more than one make of phone.