@ueeu well, @monocles do #ReproduceableBuilds as that's necessary to get their apps on @fdroidorg / #FDroid!
@ueeu well, @monocles do #ReproduceableBuilds as that's necessary to get their apps on @fdroidorg / #FDroid!
@ueeu I think crucial parts is looking at it's components, dependencies, size and for apps permissions.
#ReproduceableBuilds for example are important, so the actually released source code is what people actually get served as basis.
Plus in terms of #security, choose *real #E2EE with #SelfCustody of all the #Keys!
@centopus well, feel free to port @AsahiLinux 's patches to #C.
As for #Rust, IDGAF in general.
@lispi314 @enigmatico @bunnybeam @kimapr
nodds in agreement
And I do prefer #FLOSS as it works fine for an ever increasing audience!
Personally, I think that everything people are expected to use if not forced to use should be #OpenSource as licensed in a #OSI accredited license and be released with #SourceCode and #documentation to make #reproduceableBuilds and thus facilitate #audits by truly independent parties...
A unsarcastically good example is #S3, even tho I hate #amazon, they wanted #developers to integrate their #ObjectStorage which necessitated an #open source'd API to the point that it's #backend is inherently reproduceable, and now every halfassing #Webhoster offers S3 #storage, sometimes with bit & second-precise billing.
@dragonarchitect @Siph also just using #Rust isn't automatically make shit good.
But then again I care more about #ReproduceableBuilds and #Maintainablility than the languague.
@ai6yr nodds in agreement whereas the "akshual coding" is "relatively simple" if one doesn't mind #readability, #maintainability or using understandable variablr names...
Testing can be automated if one builds and documebts the tests that is...
"#AI" can't do this because those #LLM|s don't learn organically but merely act as "#StochasticParrot" and not as intelligent beings that is able or even willing to transfer * exchange information freely...
@lucasmz @estelle It is proprietary in that to this day there are neither #ReproduceableBuilds nor is it #SelfHosting-capable...
Which makes @signalapp a #liability and #incapable of complying with #GDPR & #BDSG due to #CloudAct making that impossible!
@eemmaa personally, I do intent to copy that with @OS1337 because #ReproduceableBuilds are as much of an important step in having an #auditable system as having unrestricted (#opensource licensed!) #sourcecode availability & access...
THIS is where I disagree...
You may think it's elitist, but if people are too lazy to learn even fundamentals like how to use #Tails then maybe they should just not do #tech at all?
I'll gladly teach #TechIlliterates but I won't waste my time on people that spread disinfo...
It's 2024: @tails_live / @tails has been out for over a decade and there are a shitload of guides ranging from written documentation to Zoomer-friendly TikTok-Style shorts on how to get started.
I don't expect people to do #airgapped pffline-PGP but with @thunderbird including #Enigmail and not requiring any external dependencies like the god-awful #GPG4Win stuff's easier than ever.
Same with #mobile: #Appls like @monocles / #monoclesChat are so easy, I've been able to onboard literal tech-illiterates remotely with few steps and simple instructions.
FOR THE LAST TIME:
*STOP MAKING EXCUSES TO JUSTIFY ESCALATING COMMITMENT TO EVIDENTLY BAD SOLUTIONS!"
Whereas with #SelfCustody of all the keys as well as #ReproduceableBuilds and real #decentralization, this would be evidently impossible even if all the devs wanted to comply honestly and not just because they could be held at gunpoint.
Compare that to #monocles where you do pay like €2 p.m. but in return get #standard #protocols like #IMAP, #SMTP & #XMPP and can pay anonymously and not have to provide any PII whatsoever!
Make of that what you will, but just like allowing flatearthers to roam freely without caretaker supervision doesn't make the world less round, so won't the facts change about #ITsec, #InfoSec, #OpSec & #ComSec.
Because all #centralized, #SingleVendor & #SingleProvider solutions are bad, and if they don't even allow for #SelfCustody then they are just a #grift to #scam tech-illiterates that don't know and/or don't care!
@bananapi Q: How about you get proper #drivers amd #support going for your existing #products?
Cuz that's what makes #RaspberryPi better!
https://www.youtube.com/watch?v=51OMXTElStM
@renan nodds in agreement
Tho #SimpleX, like #Threema, is also a #centralized, #proprietary, #SingleVendor & #SingleProvider solution with neither #SelfCustody of keys nor any means to #SelfHost and have #reproduceableBuilds.
Granted, @OS1337 has a different target mission, which is to be a #KISS-principled, easy to build, extent and adapt basis for #Firmware and #Embedded Systems...
Or to power some #security-focussed #EmbeddedSystems where having #ReproduceableBuilds is part of the #transparency culture I aim for.