• 0 Posts
  • 32 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle







  • It’s a matter of exposure and attack surface vs rewards for the attacker, and risk in companies are evaluated by the trio: freqency of occurrence, severity of occurrence (how large), severity of the occurrence. Banks can spend a lot because severity quickly gets very high in money.

    What’s the incentive again for the next gov to properly fund the system? Oh yes: they would have to say “sorry! shit happens! that’s all because of the previous admin!!” and maybe throw one guy under the bus.









  • The kernel update issue on Android is going to be exactly the same for PostmarketOS and for the exact same reason: proprietary firmwares and/or drivers.

    There is a huge ecosystem for Android today, including apps for so many EU companies, that they would have to re-develop to port them to Linux, or they’ll just rely on Waydroid, so you still have to follow Google somewhat, and now you need to maintain both a GNU/systemd/Linux AND a compatibility layer with Android. With a fork of AOSP, you need only the last.

    From a security and privacy standpoint, Linux was never designed to handle hostile apps designed to aquire as much data as possible. Android has a sandboxing system: an app cannot go and check what other apps you have. A Linux app can pretty much access everything on your system. GrapheneOS adds on top of that storage and contact scopes: you can define a subset of each per app, and they won’t see anything else.

    In an ideal world, it wouldn’t matter: everything would be opensource and developed in good faith. In the real world, you still have tons of malevolent apps that people will want to use anyway, so better take that in account.




  • Because like absolutely all public companies, they need to grow their revenues every year without ever a pause, and once you have reached the maximum number of subscribers you think you can get, the only path left to increase your revenues is to increase the revenues per subscriber.

    Besides, these companies have been enshittifying their services so badly over the years that there is no one left among managers who can imagine they wouldn’t get away with it.

    I don’t give them 5 years before they resolve to shady tactics like phone calls during which they trick you in agreeing to upgrade to a higher grade subscription, or make the cancellation so difficult that you end up paying a few more months, etc.