Avatar
unSATiated
55a450c3ee08a05be16c9e5b0e3d5102aa0d42b54e0d10971979bb98e1898a33
n00b maxi

Yes, trust in Supergovernment Daddy Overlord to manage you money, work, thoughts, and the rest of your life for you. No need to concern yourself with pesky ideas like autonomy, privacy, or freedom. They've got this. You just keep doom scrolling, get scared/outraged when it suits them, keep gaming/streaming to get that dopamine hit, and ignore anything that distracts you from those distractions. Everything will be just fine.

That's true, but it's also possible for an attacker to compromise a GH account and publish a new "release", without even changing any source code. Only you have all the accounts to secure, and only one F-Droid.

I use Obtainium too, but it's unclear to me how to weigh up these risks.

I've officially migrated all of my most important apps over to Obtainium and marked them as ignored in F-Droid. Previously I had used F-Droid for the majority of my apps (Aurora Store for everything else), but following some recent controversies regarding them misclassifying the sacred text of my Christisn faith as "not safe for work" and "pornographic", I decided that it was time to start moving away from them and just start grabbing apps from source directly.

This was also inspired in part by nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd68yvfwvdhk6tcpz9mhxue69uhkummnw3ezuamfdejj7qgswaehxw309ahx7um5wghx6mmd9u2mk7fe. In a conversation, he mentioned that something like F-Droid centralizes all authority to one group of people, whereas Obtainium allows you to be fully in charge of what apps you use and when you download them. F-Droid compiles apps themselves, based on the original source code. Meanwhile, Obtainium allows you to grab the apps direct from their repositories, without any middle men.

There's still a place for F-Droid. Because of the fact that they do compile things themselves, that means you're less likely to download a malicious app if it's something you never used before. But if you know the app and it's important to you, you should just download through Obtanium directly.

#decentralization #obtaining #opensource

I wonder which of F-Droid or individual projects' GitHub profiles are more likely to be used in a supply chain attack. How does one mitigate against that from either source?

What are those prices in sats?

Replying to Avatar Richard

Well said nostr:nprofile1qqsrhuxx8l9ex335q7he0f09aej04zpazpl0ne2cgukyawd24mayt8gprdmhxue69uhhyetvv9ujuam9wd6x2unwvf6xxtnrdakj7qg6waehxw309ac8junpd45kgtnxd9shg6npvchxxmmd9u6gptxa

While I don’t want my RaspberryPi node relaying and storing what I consider as spam on bitcoin, I can appreciate these users of the network paying _elevated transaction fees_ to help secure my savings.

It’s not worth getting your #KnickersInAKnot

That's knot funny

You're 💯% correct, but it goes so much further. We're not socially evolved enough for (especially mainstream) social media. Our bodies aren't evolved to sit still for this long every day. Our communities aren't evolved enough to comprehend a state ruling over millions. Our primitive trade brains aren't evolved to understand global flows of wealth.

We must fight against the centralization/globalization of all these things.

nostr:nprofile1qqs9xtvrphl7p8qnua0gk9zusft33lqjkqqr7cwkr6g8wusu0lle8jcpzamhxue69uhkummnw3ezuurpwfjhgmeww3hhwmspr9mhxue69uhkummnw3exx6r9vd4jumt99aex2mrp0yn7plng Why do I need to KYC to be able to zap posts? Is there a way I can connect an external wallet that doesn't require any KYC?

With NFTs like BAYC you don't even own the images you "bought". You only own a URL to an image (that could change too!). Even if OpenSea was unaffected by the AWS outage, the server hosting "your NFT" could still be down. Scam all around.