I can't report on percentage improvement, but after a long time localsend recently pushed out a version that claims to be much better (to be read as faster) for the transfer of large/many files.
For a long time the issue was blocked because of an upstream library, maybe LLMs finally unblocked the devs to push the fixes through.
But alongside the marketing blitz they also offer certifications for people who are supposed to execute these projects. Even the most foundational certification exam -- which simply tests your recall on what AWS service is for compute versus networking -- teaches and tests you about "Shared Responsibility Model" that draws the line at what the customer is still responsible for when they use cloud bases IaaS / PaaS / SaaS services.
If businesses are going to cloud but without engaging / listening to competent people who know these basics -- then the blame needs to be somewhat pointed back at those very business leaders I feel.
This is not obscure magical knowledge either that is tightly controlled. Any cloud vendor will freely teach you that. Or even a google search would.
Who is a CEO going to believe? Amazon, Microsoft and the entire IT infra division or that lone SRE who disagrees with them?
I mean, every time cloud comes up on HN we see legions of techies posting strowman arguments about why you should offload everything onto AWS, GCP, Azure, etc.
Aws cto is basically opening every presentation with a everything breaks all the time slide, idk where you get that idea they oversell the cloud resilience
They could offer controlled "failure of service" service where they randomly take stuff offline and you have to pay to get it back if you don't have a backup/recovery strategy.
You just have to take a look at the Rube Goldberg-esque abomination that is the AWS web interface for a few minutes to realize that it's not that simple. Granted, most executives won't do that...
Or encounter their CLI and it's lovecraftian combination of positional arguments, named arguments, piping, json documents, etc, distributed largely by random lot, as far as I can tell.
The "Kompromat" angle should not be ignored in this day and age.
"In cases of kompromat during the early 21st century, Russian operatives have been suspected or accused of placing child pornography on the personal computers of individuals they were attempting to discredit." https://en.wikipedia.org/wiki/Kompromat
The only real question is how easy it would be to target the undesired via the ad placement targetting options on social media platforms. On the one on which I've run ads (LinkedIn), pretty hard. At least on a technical level, because if your audience size is too small it asks you to expand your criteria. Maybe other platforms are less strict?
For sure would be a more comfortable approach for state operatives than physical access.
--
Aside. Watch the movie with the same name. Use an ad blocker, religiously.
I've seen people in real life still pushing for crypto. Believe it or not they already got burned a couple of times, but somehow they think that with the next crypto they'll be at the top of the pyramid chain and able to cash out. They don't understand crypto currencies technically, nor that they are always going to be at the bottom of the pyramid no matter how many times they are burned.
Some of these people with the moral integrity of "quick buck at everyone else's expense" maybe won't stop until they go bankrupt or severly in debt. Might be a self-selective environment at this point.
Great suggestion, there is real value in these lists. Options are always good. I like the freshness transparency and that helps impart confidence going forward as it's easy to see when it was last updated but the suggested alternatives don't seem as deeply researched and subsequently there is less categories.
Fairphone makes their fair share of blunders. Software updates are a big issue, especially around the times that critical vulnerabilities need to be patched.
With the hardware I'm not impressed, and on their own forum I've seen plenty of people reporting issues with overheating on the Gen 6. Hopefully kinks have been ironed out on their 6+.
The current CEO also has a persona that would stir up any community (read a few of his AI-gened posts on their blog, if interested of context).
Still holding on to my FP4, but they are not of consideration on my future phone purchase, unless there is some kind of reality check over there and improvements materialize beyond words.
Ultimately, a lot of the “fairness”
of the Fairphone is offered by “just buy a really popular manufacturer.”
Everyone and their dog can repair an iPhone because it’s the most popular phone on the planet. Are those repairs accessible to the consumer at home with amateur skills? No, not really. However, newer iPhone models are significantly easier to repair and come along with lower repair costs direct from the manufacturer compared to previous models.
You want years of software updates? Yeah, an iPhone has you covered there, too.
And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Who is the Fairphone for exactly? Who is buying it and why?
I think the fairbuds are their best product, but I also imagine AirPods Pro 3 are on a whole different level of sound quality, noise cancelation, voice quality/voice isolation, and firmware/software polish.
And let’s be honest about repairability with tiny earbuds: being able to replace the battery is has such a tiny impact on their footprint. If I have to throw out my
AirPods Pro 3 every 5 years due to battery degradation, that’s such an insignificant quantity of material being wasted, so it’s probably worth it to get a better product. I could offset my environmental impact by eating a little less beef or riding my bike instead of driving a few times. You drive 30 miles and that’s an entire gallon of refined petroleum product, how much material and energy is used to make one pair of AirPods? I can’t imagine it’s a lot.
I don’t say any of this to be a big corporate or Apple shill. I am rooting for the little guys. But the little guys need to be realistic. You look at products like the Framework 13 Pro and you can actually say, okay, here’s a product with really legitimate benefits over its incumbent competition. There is a reason to buy this product for a certain buyer. I just don’t see that with Fairphone. I can’t think of a customer profile where that person is getting a better ownership experience with Fairphone products.
I'm not big on this general line on argument, but one point in particular:
> And of course, fairphone’s hardware and OS are nothing to write home about. For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included. The Murena e/OS offering in particular is simple enough that the non-nerds that (perhaps less outspokenly) care about freedom can just pick it up with little change in habits.
I guess that’s true, although we could possibly split that camp into two sides: the folks who believe that Play Store sandboxing is going to be more functional, and the folks who prefer microG are willing to accept the issues that come along with it.
To be fair on either side of that debate, getting a phone that comes with /e/OS installed from the factory is going to be easier than flashing GrapheneOS on a Pixel or LineageOS with microG on another device.
Devices are sold with GrapheneOS installed. Installing it with the web installer is very easy and safe so that's the recommendation for nearly everyone.
> For the "freedom nerds", FP is one of the only (if not the only?) vendor to have official support for microG-based operating systems, seamless OTA updates and everything included.
I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want?
As for microG, I think it's debatable. Is it better to have microG contacting the Google servers or sandboxed Play Services going through a Graphene-powered proxy? And say you have microG going through a Murena proxy (do they do that?), is that significantly better than sandboxed Play Services? At the end of the day, your system is made mostly of code written by Google (AOSP).
> The Murena e/OS offering in particular is simple enough that the non-nerds
Yes, I think it's what makes Murena successful. It's surprisingly simple to install GrapheneOS on a Pixel (you follow a wizard on a Chromium browser and click "next" a bunch of times), but many people are scare just by the idea.
> I am not sure what you are trying to say here. I have never had an Android system that did not have OTA updates. Everything included... I usually like to install the apps I want?
The last bit of my sentence could easily be misread as an enumeration of three things ("microG", "OTA updates", "everything included"), but it was actually an elaboration: FP is the only vendor to support microG, and (in contrast to "unofficial" microG setups) it doesn't require sacrifices in convenience because standard features like OTA updates work just like with your average Android. Perhaps that's clearer?
(Notably "Everything included" does not mean it ships a thousand apps or something. To the contrary, FP stock OS is mostly vanilla Android)
Point being: I could install LineageOS on my last phone, but it was a poorly documented process, updates were a hassle (having to flash through custom recovery for lack of OTA), and I had virtually no confidence in data integrity when running major updates.
> Is it better to have microG contacting the Google servers or sandboxed Play Services going through a Graphene-powered proxy?
How about microG not contacting Google servers at all?
In any case you're presenting an unnecessarily binary argument though. Letting Google handle push notifications is different from using them as your location provider, and both are different from letting all Play Services lose on your system.
> How about microG not contacting Google servers at all?
I already addressed that in my comment, right after the line you quoted.
> Letting Google handle push notifications is different from using them as your location provider, and both are different from letting all Play Services lose on your system.
And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse there?
> I already addressed that in my comment, right after the line you quoted.
Where? You suggested it would go through Murena instead, but you can fully disable third party services by disabling external push providers and by using on-device databases for GPS. e/OS directly offers this configuration during initial setup.
> And what would you say GrapheneOS does of those? Do you know, or do you just assume that GrapheneOS does the worse there?
I'm not necessarily trying to present either as "better" or "worse" since they both have their merits depending what exactly you're after (which I don't feel this is the right time/place to have a detailed rundown of). It was the root comment that posited e/OS was strictly inferior for people who care about freedom.
isn't the main point of Fairphone to not use conflict minerals?
by using FOSS only myself and hating monopolies like Apple etc., i still pretty much convinced that being "green" or "ethical" is more about participating/volunteering/doing-something towards a better world than off-loading your duty to other companies... one could easily make a point that Apple products despite locked down, are still green (Apple has a bunch of zero-emission and whatever policies) and much more if one uses their devices for a long while. i had a 2° hand iPhone SE 1° gen. till 2021? if stuff breaks despite your not being able to fix it's not like you can't hop into a specialized shop to change batteries or even pay the expensive service Apple offers... sure that allows exploitation and it's always nice to get rid of it, that's why somehow these emerging companies are important and/or policies like the right of repair will make them obsolete
I have been wondering and I first got a Fairphone 3+ because I thought, among others, it was "greener".
Then I realised that:
- Fairphone 3 was already "slow" when it was released in 2019
- Fairphone 3+ was pretty much exactly the same hardware, but I bought it 2.5 years later
- My Fairphone 3+ was annoyingly slow from the moment I bought it (I was using it less than a normal phone because of that, and I just completely gave up on using the camera and asked other people to take photos instead).
- My Fairphone 3+ became painfully after 1.5 - 2 years.
I did not change phone because the hardware was not running anymore. I changed because I just couldn't use the few apps I needed because they were unusable (lagging and crashing). I don't mean games: banking apps, weather forecasts, public transports. Pretty much only Signal/WhatsApp were fine (slow, but fine).
So I painfully kept my Fairphone 3+ for a little more than 4 years.
Then I realised that people who buy an iPhone routinely keep it 6-8 years, without it being painful at all. Is it "greener" if I buy one iPhone/Pixel, or 2 Fairphones? I'm not so sure anymore. What I know is that the iPhone/Pixel are not painful to use.
I think your story also points to the idea that business ethics or other tertiary benefits will only sell a product to a limited extent. They help, but the product being fit for its core purpose is still most important.
> For the freedom and security nerds they’re better off with GrapheneOS on Pixel or whatever upcoming Motorola phones will support it.
Not quite. The people who care about security first are better off with GOS, yes. However, GOS's threat model very specifically treats the user as a thing to defend against; the freedom-first crowd should avoid them.
> However, GOS's threat model very specifically treats the user as a thing to defend against
Can you elaborate?
GOS mostly honours the Android security model, which many alternatives don't do (many times they don't have a choice because the device doesn't allow them to relock the bootloader, so they just defeat the whole security model from the moment you install).
There is absolutely nothing that can be done on a Stock Android and that I cannot do on GrapheneOS. Or at least I haven't found it.
Yes, GOS is probably a direct improvement over stock android; I would also describe that as suboptimal from a user freedom perspective. Really, most of my beef with GOS is that its developers strongly object to user-controlled root. On my phone, I can run a backup app, give it root access, and backup/restore any app at will. Or, I can run a file manager with root access and inspect any data in the system. The GOS devs object to this on the grounds that any user-installed app getting root undermines their entire security model (and some other arguments that I'm going to skip because I'm trying to steel-man). And that's actually a perfectly valid argument; handing root access to apps does break their security model, but if the user doesn't have root then I'd contest the idea that the user is in control. And of course there is the fact that I have actual uses for root that GOS doesn't provide. (There are some other variants of this basic tension, like bootloader locking, but I think root is the biggest instance and representative.)
> And that's actually a perfectly valid argument; handing root access to apps does break their security model, but if the user doesn't have root then I'd contest the idea that the user is in control.
First, "protecting against an app running with user permissions" does not mean "considering that the human owning the device is malevolent", right?
The idea is that if the human installs a malware, we don't want that malware to own the system. I think it is completely fair, and for most people it is the better deal.
Second, your complaint about GOS is that you want root access, and they don't provide it. You want a feature they don't provide, sure, but that happens. And that's probably a good reason to use an alternative system. But turning "I want feature X" into "if you don't provide the feature I want, then you are not free software" is manipulative IMO. GrapheneOS is as open source as it gets, you can fork it and install it on your Pixel. It is free software. Maybe not the software you want (that's okay, different people have different preferences), but free software nonetheless.
Since we're steelmanning, I would like to add a bit more.
GrapheneOS will never be closed source/proprietary because they believe code freedom (and user freedom by extension) is paramount. They have repeatedly said they don't have the resources to build a ChromeOS-esque firmware authentication and warning flow for ephemeral user-accessible root and support those builds alongside the existing production environment. They have NOT said it is something they have no interest in even discussing. They have also repeatedly said that where the utility is clearly demonstrated and can be architected in a maintainable way, they are open to contributions (and continued maintenance) that properly enable functions that people unnecessarily need to abuse root privileges for.
The main goal of their project is a system that can protect your personal thoughts, associations and memories to the best of its ability (against thieves, attackers, surveillance etc.) while preserving your interaction with the world. Current OSes (including GrapheneOS and iOS) are already far behind where they should be given the wealth of privacy enhancing technology, computer hardware security, systems engineering and OS design knowledge that has existed for decades- so their work is cut out for them and they are putting everything they have into leading the industry. Their hands are already full. For clear use cases the path of least resistance would be to contribute and commit to maintaining features everyone would benefit from.
If it is a feature/function someone understands they would benefit from personally but do not see the value to impose on others, we can circle back to the original fact which is that GrapheneOS is open source and can be bent/built to your will.
That doesn't come across as steelmanning our position at all but rather the opposite. It omits the most important points.
Providing app accessible root in the OS greatly reduces security without people ever using it. It gives root access to a huge portion of the OS by having it around as a feature even if it's never used. It fundamentally breaks a large portion of the security model for verified boot, which can no longer defend against attackers maintaining privileged access after a compromise
In addition to the inherent reduction in security from providing it, nearly all apps built around using full unconstrained root access don't need anywhere close to that. In nearly all cases, it's used as a shortcut instead of doing things securely. Following the principle of least privilege by only granting the required privileges is a core part of security. For example, an app for managing low-level firewall rules only needs an API for doing so in netd and netd only needs CAP_NET_ADMIN rather than full root. Doing this by giving full root access to a graphical application which is not properly integrated into the standard firewall management is not a secure approach. Giving full root access to a large portion of the rest of the OS in a way that can be hijacked in many attack vectors to make it possible to dynamically grant it makes it a lot worse.
GrapheneOS does have user-accessible root access in userdebug builds. Those aren't the main production builds of the OS but people who believe they know better and want to have it can build, sign and use those instead. Building the OS also gives an opportunity to include safe implementations of features instead of insecure hacks.
Every app can be backed up as part of the baseline. Apps can exclude specific data but are nearly all doing so because that data is a cache or can't be used elsewhere. For example, Signal encrypts their database with the hardware keystore and bypassing them excluding it from backups to back up all the files for it will not result in the data being possible to restore elsewhere.
How about having full access to /data? Or full system backups GrapheneOS still lacks? One might object granting root access to apps, but the device owner should at least have full FS access via adb.
That's available in userdebug builds of GrapheneOS via ADB. A userdebug build can be done with ro.adb.secure=1 to keep the ADB authentication model intact which is disabled in userdebug builds by default for early boot debugging.
Well said. I would say in general there isn't "the best" OS for everyone and never will be, because each OS makes different trade-offs. I for one want primarily what is understood to be "general purpose computer". Other people rightly don't care about that and want a maximum security device, one that even protects users from their own mistakes (of course putting more trust in the makers of the OS). What we should care about is that people have a choice and can get whatever they prefer.
To answer GPs point, I think Fairphone doesn't primarily target either of the two audiences. I think they primarily target the people that care about the ethics of the creation of the hardware. Basically people who would like to minimize the invisible human cost that their phone creates.
The new Sennheiser earbuds have replaceable batteries too so the fairbuds are no longer unique in that regard. I haven't read comparisons on sound quality though
And of course, wired headphones still exist as an alternative for those who really don’t like the battery aspect, and it’s not even terribly inconvenient for phones without a headphone jack.
I suspect that the venn diagram of the kind of person who takes issue with Bluetooth audio batteries and the kind of person willing to use wired headphones or prefers them outright has a lot of overlap.
Fair enough, but note that it does not concern GrapheneOS. Hopefully soon available on Motorola phones :-). That would be my next phone (assuming it's not too expensive of course).
As someone reading much of what Molly White publishes, there is no short supply of people in crypto that give of the same aura and are f̵i̵n̵a̵n̵c̵i̵n̵g̵ donating to someone that will push their crypto regulation agenda https://hachyderm.io/@molly0xfff/117191164732599820
If not directly through what is offered there, under the DSA (eu citizens and residents) have further ways to appeal their decision, and also Google takeout should be a last option even for banned accounts.
If you have any luck post a followup on HN to guide other users having a similar issue.
For a long time the issue was blocked because of an upstream library, maybe LLMs finally unblocked the devs to push the fixes through.
reply