28 comments

  • utopiah9 hours ago
    I think there are quite some misconceptions about F-Droid in the comments :<p>- you can be your own F-Droid server<p>In fact it&#x27;s a basic static HTTP(S) server that is generated with the list of .apk and meta-data so it rely doesn&#x27;t require much.<p>I think what is concerning to people is that the most popular INSTANCE of F-Droid, the one that is by default when one downloads the F-Droid CLIENT, is &quot;centralized&quot; but again that&#x27;s a misconception. It&#x27;s only popular, it&#x27;s not really central to F-Droid itself. Adding another repository in the F-Droid parlance is just a simple option of changing or adding a URL to more instances.<p>That being said if anybody here would like to volunteer to be provider a fallback to the build system to that popular instance, I imagine the F-Droid team would welcome that with open arms.
    • ptx1 hour ago
      I don&#x27;t think it&#x27;s necessarily a misconception but rather people having different conceptions of what the term &quot;F-Droid&quot; refers to. It could refer to the client, the server tools, a specific server instance, the project, the collection of applications, or possibly other things.<p>Some people might use &quot;F-Droid&quot; in the same sense as the main page [1] does, to mean &quot;an installable catalogue of FOSS (Free and Open Source Software) applications&quot; but others in the sense the about page [2] uses it, referring to the &quot;non-profit volunteer project&quot;, which is consistent with the project statues [3]:<p>&gt; <i>F-Droid is the name of a not-for-profit technical, scientific and creative community effort serving the public benefit.</i><p>The documentation start page [4] makes it a bit more clear:<p>&gt; <i>F-Droid is both a repository of verified free software Android apps as well as a whole “app store kit”, providing all the tools needed to setup and run an app store. It is a community-run free software project developed by a wide range of contributors. It also includes complete build and release tools for managing the process of turning app source code into published builds.</i><p>[1] <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;</a><p>[2] <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;about&#x2F;" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;about&#x2F;</a><p>[3] <a href="https:&#x2F;&#x2F;commonsconservancy.org&#x2F;dracc&#x2F;0039&#x2F;" rel="nofollow">https:&#x2F;&#x2F;commonsconservancy.org&#x2F;dracc&#x2F;0039&#x2F;</a><p>[4] <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;docs&#x2F;" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;docs&#x2F;</a>
    • 1vuio0pswjnm72 hours ago
      &quot;It&#x27;s only popular, it&#x27;s not really central to F-Droid itself.&quot;<p>I&#x27;ve used F-Droid for years and I&#x27;ve never used the client (&quot;the F-Droid app&quot;)<p>For me the value of F-Droid is as a list of open-source software with (a) pointers to source code and (b) sample binaries<p>The goal of F-Droid could be to enable Android users to read, edit and compile the software they choose to run on their &quot;phones&quot;<p>But F-Droid promotes their own app (&quot;the client&quot;) so maybe the project&#x27;s goal is something more like an &quot;app store&quot;
      • herewulf1 hour ago
        Likely they are trying to make said list of open-source software easily accessible. The vast majority of users are incapable of compiling their own software. Probably it&#x27;s better (for users&#x27; freedom, privacy, and a healthy Android FOSS ecosystem) to have these users obtaining software through an F-Droid &quot;app store&quot; than through Google Play.<p>The goal that you suggest is interesting. It reminds me of Guix, where one can obtain binaries or one can build the entirety of packages oneself. All from the same system.<p>Perhaps you could share how you are currently building software from source and&#x2F;or F-Droid?
  • kasabali22 hours ago
    Context: &quot;F-Droid build servers can&#x27;t build modern Android apps due to outdated CPUs&quot; (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44884709">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44884709</a>)
  • Aurornis18 hours ago
    &gt; this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access.<p>I can’t be the only one who read this and had flashbacks to projects that fell apart because one person had the physical server in their basement or a rack at their workplace and it became a sticking point when an argument arose.<p>I know self-hosting is held as a point of pride by many, but in my experience you’re still better off putting lower cost hardware in a cheap colo with the contract going to the business entity which has defined ownership and procedures. Sending it over to a single member to put somewhere puts a lot of control into that one person’s domain.<p>I hope for the best for this team and I’m leaning toward believing that this person really is trusted and capable, but I would strongly recommend against these arrangements in any form in general.<p>EDIT: F-Droid received a $400,000 grant from a single source this year ( <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;2025&#x2F;02&#x2F;05&#x2F;f-droid-awarded-otf-grant.html" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;2025&#x2F;02&#x2F;05&#x2F;f-droid-awarded-otf-grant.htm...</a> ) so now I’m even more confused about how they decided to hand this server to a single team member to host in unspoken conditions instead of paying basic colocation expenses.
    • moelf14 hours ago
      &gt;We worked out a special arrangement so that this server is physically held by a long time contributor with a proven track record of securely hosting services.<p>Not clear if &quot;contributor&quot; is a person or an entity. The &quot;hosting services&quot; part make it sound more like a company rather than a natural person.
    • briffle17 hours ago
      The OSU Open Source Lab gives machines to groups in their datacenter: <a href="https:&#x2F;&#x2F;osuosl.org&#x2F;services&#x2F;hosting&#x2F;" rel="nofollow">https:&#x2F;&#x2F;osuosl.org&#x2F;services&#x2F;hosting&#x2F;</a><p>It has hosted quite a few famous services.
      • petcat15 hours ago
        Which famous services?<p>I doubt OSU is going to host F-Droid. It doesn&#x27;t even sound like F-Droid would want them to host it.
        • wtallis14 hours ago
          <a href="https:&#x2F;&#x2F;osuosl.org&#x2F;blog&#x2F;osl-moving-to-state-data-center&#x2F;" rel="nofollow">https:&#x2F;&#x2F;osuosl.org&#x2F;blog&#x2F;osl-moving-to-state-data-center&#x2F;</a> mentions several major, famous services&#x2F;projects that OSUOSL either has hosted in the past or is still hosting: kernel.org, Debian, Gentoo, Drupal, OpenWRT, OSGEO. <a href="https:&#x2F;&#x2F;osuosl.org&#x2F;blog&#x2F;osl-future&#x2F;" rel="nofollow">https:&#x2F;&#x2F;osuosl.org&#x2F;blog&#x2F;osl-future&#x2F;</a> also mentions hosting Mozilla at the time of the Firefox 1.0 release, and having previously hosted Apache Software Foundation. Closer in relevance to F-Droid, OSUOSL hosts the GitLab instance used by postmarketOS: <a href="https:&#x2F;&#x2F;postmarketos.org&#x2F;blog&#x2F;2024&#x2F;10&#x2F;14&#x2F;gitlab-migration&#x2F;" rel="nofollow">https:&#x2F;&#x2F;postmarketos.org&#x2F;blog&#x2F;2024&#x2F;10&#x2F;14&#x2F;gitlab-migration&#x2F;</a>
        • spoaceman777714 hours ago
          F-Droid is the best known non-corporate Android App Store... Why wouldn&#x27;t they be willing to host it?<p>It&#x27;s a critical load-bearing component of FOSS on Android.
    • vachina9 hours ago
      There is nothing wrong with hosting prod at home. A free and open source project needs to be as sustainable and low maintenance as possible. Better to have a service up and running than down when the funds run out.
    • xorcist5 hours ago
      &gt; one person had the physical server in their basement<p>Unless you have even the faintest idea about how F-Droid does it, please stop spreading FUD. All the article says is that it is not a normal contract but a special arrangement where one or a select few have physical access. It could be in a locked basement, it could be in a sealed off cage in a data center, it could be a private research area at a university. We don&#x27;t know.<p>A special arrangement with an academic institution providing data center services wouldn&#x27;t be at all surprising, that has been the case for many large open source projects since long before the term was invented, including Linux, Debian and GNU itself.<p>Many of these are run by professionals with high standards. The Debian project has done pioneering work with reproducible builds, for example, something the F-Droid project is also very much involved with. Those things are what creates trust in the project.
    • autoexec11 hours ago
      &gt; I know self-hosting is held as a point of pride by many, but in my experience you’re still better off putting lower cost hardware in a cheap colo with the contract going to the business entity which has defined ownership and procedures. Sending it over to a single member to put somewhere puts a lot of control into that one person’s domain.<p>If they really want to run it out of a computer in their living room they should at least keep a couple servers on standby at different locations. Trusting a single person to manage the whole thing is fragile, but trusting a few people with boxes that are kept up to date seems pretty safe. What are the odds they&#x27;d all die together? Paying a colo or cloud provider is probably better if you care about more 9s of uptime, but do they really need it?
    • silisili18 hours ago
      Yup. But the same can happen in shared hosting&#x2F;colo&#x2F;aws just as easily if only one person controls the keys to the kingdom. I know of at least a handful of open source projects that had to essentially start over because the leader went AWOL or a big fight happened.<p>That said, I still think that hosting a server in a member&#x27;s house is a terrible decision for a project.
      • Aurornis18 hours ago
        &gt; if only one person controls the keys to the kingdom<p>True, which is why I said the important parts need to be held by the legal entity representing the organization. If one person tries to hold it hostage, it becomes a matter of demonstrating that person doesn’t legally have access any more.<p>I’ve also seen projects fall apart because they forgot to transfer some key element into the legal entity. A common one is the domain name, which might have been registered by one person and then just never transferred over. Nobody notices until that person has a falling out and starts holding the domain name hostage.
      • olyjohn10 hours ago
        It doesn&#x27;t say it&#x27;s in someone&#x27;s house. Maybe the guy runs a business doing this.<p>At least they know where it is. They can go knock on the door.
    • prmoustache3 hours ago
      Ultimately hosting is not the most critical part as long as backups are stored in places other members of the projects have access to (and one copy could be in their own home, I don&#x27;t think the f-droid repos have grown to be that big they can&#x27;t be hosted on commodity NAS).<p>What is usually more critical is who has the credentials for the domain management.
    • ycombinatrix7 hours ago
      Is colocation not considered to be &quot;self-hosting&quot; in the cloud era?
    • eulgro16 hours ago
      It&#x27;s just a build server no? If that&#x27;s the case it&#x27;s not the end of the world.<p>Or does it also serve the APKs?
      • lytedev15 hours ago
        depending on how you view it, the build server _does_ serve the APKs, right?
    • lrvick18 hours ago
      400K would go -fast- if they stuck to a traditional colo setup. Donations like this are rare and it may be all they get for a decade.<p>Personally I would feel better about round robin across multiple maintainer-home-hosted machines.
      • Aurornis18 hours ago
        &gt; 400K would go -fast- if they stuck to a traditional colo setup.<p>I don’t know where you’re pricing coloration, but I could host a single server indefinitely from the interest alone on $400K at the (very nice) data centers I’ve used.<p>Collocation is not <i>that</i> expensive. I’m not understanding how you think $400K would disappear “fast” unless you think it’s thousands of dollars per month?
      • arjie10 hours ago
        I, personally, have a cabinet in a colo. With $400k, I can host it at that datacentre with the income from risk-free return never exercising the capital with 10 GigE, 3 kW of power. If I can do it, they can do it.<p>Modern computers are super efficient. A 9755 has 128 cores and you can get it for cheap. If you&#x27;ve been doing this for a while you&#x27;d have gotten the RAM for cheap too.<p>If I, a normie, can have terabytes of RAM and hundreds of cores in a colo, I&#x27;m pretty sure they can unless they have some specific requests.<p>And dude, I&#x27;m in the Bay Area. Think about that. I&#x27;m in one of the highest cost localities and I can do this. I bet there are Colorado or Washington DCs that are even cheaper.
        • lrvick8 hours ago
          I to am in the bay area, and clearly I have been shopping at the wrong colos. I expected to find nothing with unlimited bandwidth for under $1k&#x2F;mo given past experience with what may have been higher end DCs.<p>In any event if I was the volunteer sysadmin that had to babysit the box, I would rather have it at my home with business fiber where I am on premises most of the time because getting in and out of a colo is always a whole thing if their security is worth a damn.<p>Even given a frugal and accessible setup like that I can imagine 400k lasting 5 years tops especially if paying for the volunteers business fiber and much more especially given I expect some of it is to provide a sustainable compensation to key team members as well. Every cent will count.
      • pilif18 hours ago
        400k would last me 13 years for a rack, power and 10Gbit&#x2F;s bandwidth at my colo place (Switzerland, traditionally high prices)
        • dotancohen18 hours ago
          Yes, but that&#x27;s not their only expense.
          • throwaway20376 hours ago
            Stupid question from me: What are their other costs? I&#x27;m a total newbie about data center colo setups, but as I understand, it includes: power and internet access with ingress and egress. Are you thinking their egress will be very high, thus thus need to pay additional bandwidth charges?
          • Aurornis18 hours ago
            Yes, but that’s not the last or only donation they’re receiving either.
            • LoganDark17 hours ago
              Don&#x27;t bet on receiving money in the future.
              • Aurornis17 hours ago
                It&#x27;s a community donation-supported project. That&#x27;s kind of the whole deal.<p>Regardless, the ongoing interest on $400K alone would be enough to pay colo fees.
                • fragmede17 hours ago
                  Since you&#x27;ve already done the math, what&#x27;s the interest on $400k pay for the colo costs?
                  • serf16 hours ago
                    at a (fairly modest) 3.3 its like 1100&#x2F;month.<p>I don&#x27;t know what kind of rates are available to non-profits, but with 400k in hand you can find nicer rates than 3.3 (as of today, at least).<p>that covers quite a few colo possibilities.
                    • throwaway20379 hours ago
                      USD money market funds from Vanguard pay about 3.7% now. Personally, I would recommend a 50&#x2F;50 split between a Bloomberg Agg bond ETF and a high-yield bond ETF. You can easily boost that yield by 100bps with a modest increase in risk.<p>Another thing overlooked in this debate: Data center costs normally increase at the rate of inflation. This is not included in most estimates. That said, I still agree with the broad sentiment here: 400K USD is plenty of money to run a colo server for 10+ years from the risk-free interest rate.
          • Craighead18 hours ago
            [dead]
      • silisili15 hours ago
        For reference, in the US at least, there was&#x2F;is a company called Joes Data Center in KC who would colo a 1U for $30 or $40 a month. I&#x27;d used them for years before not needing it anymore, so not some fly by night company(despite the name).<p>At that rate, that would buy you nearly 1000 years of hosting.
        • Aurornis14 hours ago
          I was trying to avoid naming exact prices because it becomes argument fodder, but locally I can get good quality colo for $50&#x2F;month and excellent quality coloration with high bandwidth and good interconnects for under $100 for 1U<p>I really don’t know where the commenter above was getting the idea that $400K wouldn’t last very long
          • esseph13 hours ago
            Alaska. Dollars per Mbit + reliable power in colo.
        • throwaway20376 hours ago
          Those prices are rock bottom! For that price, what do you get for (a) power budget, (b) Internet connectivity, (c) ingress and egress per month?<p>I Googled for that brand and got a few hits:<p><pre><code> - https:&#x2F;&#x2F;inflect.com&#x2F;building&#x2F;1325-tracy-avenue-kansas-city&#x2F;joes-datacenter&#x2F;datacenter&#x2F;joes-datacenter - https:&#x2F;&#x2F;www.linkedin.com&#x2F;company&#x2F;joesdatacenter&#x2F; - https:&#x2F;&#x2F;www.facebook.com&#x2F;joesdatacenter&#x2F; </code></pre> The homepage now redirects here: <a href="https:&#x2F;&#x2F;patmos.tech&#x2F;" rel="nofollow">https:&#x2F;&#x2F;patmos.tech&#x2F;</a><p>Another under appreciated point about that data center: It has excellent geographical location to cover North America.
        • stackghost14 hours ago
          Joe&#x27;s got bought out by Patmos.<p>The jury&#x27;s still out on whether or not this is a good thing.
      • kube-system17 hours ago
        For <i>a</i> server? The going rate for a 1&#x2F;4 cabinet is $300-500&#x2F;month.
      • jeltz3 hours ago
        If 100 years is fast, yes. You can get pretty sweet colo for 4k per year. I know cheaper places too.
      • shrubble15 hours ago
        A full rack, 10 gigabits bandwidth and 1920W of power is available for as little as $800&#x2F;month: <a href="https:&#x2F;&#x2F;1530swift.com&#x2F;colocation.php" rel="nofollow">https:&#x2F;&#x2F;1530swift.com&#x2F;colocation.php</a><p>Of course you have to buy the switches and servers…
    • 1f60c18 hours ago
      &gt; a $400,000 grant<p>IDK if they could bag this kind of grant every year, but isn&#x27;t this the scale where cloud hosting starts to make sense?
      • well_ackshually5 hours ago
        400k could get you 10 Dell Poweredges with a 128 core CPU, 256GB of RAM and multiple terabytes of storage _multiple times_. 400k easily covers two of these machines, and colocation space is about 2k per year.<p>Cloud hosting only makes sense at a very, very small scale, or absurdly large ones.
      • 0x1ch17 hours ago
        You have two options. Colo if you still want physical access to your devices, or cloud, where you get access to nothing beyond some online portals.
        • LoganDark17 hours ago
          Colo is when you want to bring your own hardware, not when you want physical access to your devices. Many (most?) colo datacenters are still secure sites that you can&#x27;t visit.
          • kube-system16 hours ago
            I&#x27;ve only ever seen that at data centers that offer colo as more of a side service or cater to little guys who are coloing by the rack unit. All of the serious colocation services I&#x27;ve used or quoted from offer 24&#x2F;7 site access.<p>Basically anywhere with cage or cabinet colocation is going to have site access, because those delineations only make sense to restrict on-site human access.
          • 0x1ch16 hours ago
            Every colo I&#x27;ve visited has a system for allowing physical access for our equipment, generally during specific operating hours with secure access card.
            • immibis3 hours ago
              While this is true, you stated a tautology: of course every colo you visited allows visiting.
            • calvinmorrison12 hours ago
              secure access cards, IDing, bag check, and a tech following you around. Of course cabinets are all locked up as well.<p>A lot of these places are like fortresses
          • jcrawfordor16 hours ago
            To be quite honest I&#x27;ve never seen a colo that didn&#x27;t offer access at all. The cheapest locations may require a prearranged escort because they don&#x27;t have any way to restrict access on the floors, but by the time you get to 1&#x2F;4 rack scale you should expect 24&#x2F;7 access as standard.
            • firesteelrain15 hours ago
              Same. We would colo and had racks behind chain link fencing that was locked behind cipher locks
          • olyjohn10 hours ago
            I don&#x27;t think so. I don&#x27;t think anybody is going to hand off their server and ask someone else to hook it up. Also, you need access so you can troubleshoot hardware issues.
      • stefan_14 hours ago
        So that they can pay 100x more expenses for.. no gain? They would pay an arm just for traffic.
        • kevin_thibedeau42 minutes ago
          It&#x27;s OpEx. MBAs will pour unlimited money into OpEx to avoid CapEx.
          • somehnguy3 minutes ago
            Clearly I don&#x27;t have an MBA because this mindset doesn&#x27;t make sense to me. Burning money unnecessarily is burning money unnecessarily, no matter where it&#x27;s burned.
        • arcfour13 hours ago
          CloudFlare is free&#x2F;cheap and hey presto, no servers to manage!
          • herewulf12 hours ago
            And when your Cloudflare site is down, most of the Internet is down too! There&#x27;s no downside!
          • encrypted_bird12 hours ago
            Counterpoint: that would require using CloudFlare.
            • arcfour12 hours ago
              That is, in my opinion, far superior to using a single server ran by &quot;someone&quot;.
              • encrypted_bird11 hours ago
                I guess that is the beauty of opinions: they can be different from person to person. In my case, I would rather avoid CloudFlare if possible.
  • mcsniff19 hours ago
    Ugh. This 100% shows how janky and unmaintained their setup is.<p>All the hand waving and excuses around global supply chains, quotes, etc...it took pretty long for them to acquire <i>commodity</i> hardware and shove it in a special someone&#x27;s basement and they&#x27;re trying to make it seem like a good thing?<p>F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid.<p>I understand this is a volunteer effort, but it&#x27;s not a good look.
    • lrvick19 hours ago
      As someone that has run many volunteer open source communities and projects for more than 2 decades, I totally get how big &quot;small&quot; wins like this are.<p>The internet is run on binaries compiled in servers in random basements and you should be thankful for those basements because the corpos are never going to actually help fund any of it.
      • pydry17 hours ago
        It&#x27;s a shame mozilla wont step up to fund it. They&#x27;ve spunked way more money on way dumber things.
        • quantummagic15 hours ago
          Imagine the good they could do if they didn&#x27;t pay their CEO 6 million a year.
          • jeltz3 hours ago
            6 million is 30 really good senior software devs in Stockholm, or I think 10 in SF. American CEO salaries are crazy.
          • wongarsu6 hours ago
            They&#x27;d probably burn it without much to show for, like the rest of their funds
    • lukan19 hours ago
      &quot;I understand this is a volunteer effort, but it&#x27;s not a good look.&quot;<p>I would agree, that it is not a good look for this society, to lament so much about the big evil corporations and invest so little in the free alternatives.
      • fruitworks17 hours ago
        You can&#x27;t just host servers in your own basement! You need to pay out the ass to host servers in some big company&#x27;s basement!
        • JuniperMesos16 hours ago
          I don&#x27;t have a problem with an open source project I use (and I do use F-Froid) hosting a server in a basement. I do have a problem with having the entire project hosted on one server in a basement, because it means that the entire project goes down if that basement gets flooded or the house burns down or the power goes out for an extended period of time, etc.<p>Having two servers in two basements not near each other would be good, having five would be better, and honestly paying money to put them in colo facilities to have more reliable power, cooling, etc. would be better still. Computer hardware is very cheap today and it doesn&#x27;t cost that much money to get a substantial amount of redundancy, without being dependent on any single big company.
          • nine_k12 hours ago
            This sounds reasonable. But this is a build server, not the entire project infrastructure.<p>I bet the server should be quite powerful, with tons of CPU, RAM and SSD&#x2F;NVMe to allow for fast builds. Memory of all kinds was getting more and more expensive this year, so the prolonged sourcing is understandable.<p>The trusted contributor, as the text says, is considered more trustworthy than an average colocation company. Maybe they have an adequate &quot;basement&quot;, e.g. run their own colo company, or something.<p>It would be great to have a spare server, but likely it&#x27;s not that simple, including the organization and the trust. A build server would be a very juicy attack target to clandestinely implant spyware.
          • schubidubiduba15 hours ago
            What do you think would happen if that server went down? People can&#x27;t get app updates, or install new ones. That is all. That is not critical.<p>They can then probably whip up a new hosted server to take over within a few days, at most. Big deal.<p>They are not hosting a critical service, and running on donations. They are doing everything right.
            • tisdadd12 hours ago
              I concur, and given the amount of apps they build it makes sense to spend the money on a good build server to me, especially if it is someone with experience hosting trusted servers as mentioned as well as a contributor already. If people do not want to use it, the source code to build yourself is still available for the apps they supply.
          • prmoustache2 hours ago
            It is not your bank. You don&#x27;t need 99.999999999999999% availability of the build server of an app store. Especially if the apps packages can still be downloaded from regular https servers.
          • autoexec11 hours ago
            &gt; Computer hardware is very cheap today<p>As long as you don&#x27;t need RAM or hard drives. It&#x27;s getting more expensive all the time too. This isn&#x27;t the ideal moment to replace a laptop let alone a server.
    • troyvit12 hours ago
      It&#x27;s like ya&#x27;ll are so eager to crap on a thing that you don&#x27;t even read tfa.<p>&gt; this server is physically held by a long time contributor with a proven track record of securely hosting services.<p>So you are assuming it&#x27;s a rando&#x27;s basement when they never said anything like that.<p>If their way of doing business is so offensive either don&#x27;t use them, disrupt them or pitch in and help.<p>&gt; I understand this is a volunteer effort, but it&#x27;s not a good look.<p>What does make a &quot;good look&quot; for a volunteer project?
      • wtallis12 hours ago
        &gt; What does make a &quot;good look&quot; for a volunteer project?<p>It&#x27;s an open-source project. It should be... <i>open</i>. Not mysterious or secretive about overdue replacements of critical infrastructure.
        • ptx57 minutes ago
          What would that look like in this case?
      • well_ackshually5 hours ago
        &gt; this server is physically held by a long time contributor with a proven track record of securely hosting services.<p>This is effectively a rando&#x27;s basement. It doesn&#x27;t matter that they&#x27;ve been a contributor or whatever. Individuals change, relationships sour. Securely hosting how ? By locking the front door ? By being a random tech company in the midwest ? Or by having proper access control ?<p>As a little reminder, F-Droid has _all_ the signing keys on its build server. Compromising that is somewhere between &quot;oh that&#x27;s awful&quot; and &quot;stop the world&quot;. These builds go out as automatic updates too. So uh, yeah, I&#x27;d like it if it was hosted by someone serious and not my buddy joe who&#x27;s a sysadmin don&#x27;t worry
        • jabwd4 hours ago
          &gt; This is effectively a rando&#x27;s basement. You. Do. Not. Know. Stop straw-manning stuff its so pointless.
          • herewulf1 hour ago
            The not knowing is the point. From a security perspective, you have to assume the worst.<p>And maybe that is F-Droid&#x27;s point: Security through obscurity. If the build infrastructure with the signing keys is unknown, then it&#x27;s that much harder for Bad Actor to do things like backdoor E2E encrypted communication apps. This is, of course, the weakness in E2E encryption in apps obtained from mainstream&#x2F;commercial app stores. For all we know, these may already be backdoored depending on where it came from.<p>However, the obscurity makes F-Droid hard to trust as an outsider to the project.
    • magguzu18 hours ago
      Graphene is a great product but their <i>incessant</i> mud slinging at any service that isn&#x27;t theirs is tiresome at best.<p>Some of their points are valid but way too often they&#x27;re unable to accept that different services aren&#x27;t always trying to solve the same problem.
      • ekjhgkejhgk5 hours ago
        &gt; their incessant mud slinging at any service that isn&#x27;t theirs is tiresome at best.<p>100%. But you know, sadly I&#x27;ve noticed that non-experts are impressed by elitism. So you don&#x27;t have to be good, you just have to shit on others, and passerbys will interpret that as being very competent.<p>Which is super ironic, from a project which about privacy but only supports hardware built by the biggest surveillance company.
    • ekjhgkejhgk5 hours ago
      &gt; F-Droid is often discussed in the GrapheneOS community, the concerns around centralization and signing are valid.<p>Clearly the GrapheneOS community is clueless then.<p>You can host F-Droid yourself, which is the opposite of centralized. If the GrapheneOS community actually is concerned about centralization they can host an instance as well.<p>Futhermore, each author signs their own software, which again is the opposite of centralized. One authority signing everything would be centralized.<p>So F-Droid is decentralized in authorship <i>and</i> distribution. Google store is only decentralized in authorship.
    • xandrius19 hours ago
      &quot;Nothing is ever good enough&quot; (tm)
      • orthecreedence16 hours ago
        If <i>I</i> were running a volunteer project, I would be dumping thousands a month into top-tier hosting across multiple datacenters around the world with global failover.
        • amrit312812 hours ago
          the _if_ is doing a lot of heavy lifting there. You&#x27;re free to complain about it but Fdroid has been running fine for years and I&#x27;d rather have a volunteer manage the servers than some big corporation
          • wtallis11 hours ago
            They quite notably <i>haven&#x27;t</i> been running fine for years: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44884709">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44884709</a> Their recent public embarrassment resulting from having such an outdated build server is likely what triggered them to finally start the process of obtaining a replacement for their 12 year old server (that was apparently already 7 years old when they started using it?).
            • ndriscoll2 hours ago
              In what world is it embarrassing to not buy hardware you don&#x27;t need? The servers worked fine for years. When there was an actual reason to spend money, they bought something new. Sounds like good stewardship of the donations they receive.<p>I finally just upgraded my 9 year old computer with an i5-6600k to a Ryzen 9 5950x because I wanted to be able to edit home videos. I already rarely even used 1 core on the old CPU, the new one is 7x more powerful, and it&#x27;s an ebay part from 5 years ago. I don&#x27;t foresee needing to upgrade again for another decade. I probably would&#x27;ve been good for another 15-20 years if I had upgraded to a DDR5 platform, but RAM prices had already spiked, so I just swapped the motherboard and CPU.
            • pabs310 hours ago
              Its embarrassing that Google binaries don&#x27;t even use runtime instruction selection.<p><a href="https:&#x2F;&#x2F;wiki.debian.org&#x2F;InstructionSelection" rel="nofollow">https:&#x2F;&#x2F;wiki.debian.org&#x2F;InstructionSelection</a>
              • wtallis10 hours ago
                Nah, if you actually read into what&#x27;s available there, it&#x27;s clear that the <i>compilers</i> have never implemented features to make this broadly usable. You only get runtime instruction selection if you&#x27;ve manually tagged <i>each individual function</i> that uses SIMD to be compiled with function multi-versioning, so that&#x27;s only really useful for known hot spots that are intended to use autovectorization. If you just want to enable the latest SIMD across the whole program, GCC and clang can&#x27;t automatically generate fallback versions of every function they end up deciding could use AVX or whatever.<p>The alternative is to make big changes to your build system and packaging to compile N different versions of the executable&#x2F;library. There&#x27;s no easy way to just add a compiler flag that means &quot;use AXV512 and generate SSE2 fallbacks where necessary&quot;.<p>The people that want to keep running new third-party binaries on 12+ year old CPUs might want to work with the compiler teams to make it feasible for those third parties to automatically generate the necessary fallback code paths. Otherwise, there will just be more and more instances of companies like Google deciding to start using the hardware features they&#x27;ve been deploying for 15+ years.<p>But you already know all that, since we discussed it four months ago. So why are you pretending like what you&#x27;re asking for is easy when you <i>know</i> the tools that exist today aren&#x27;t up to the task?
    • gnufx17 hours ago
      &gt; commodity hardware<p>Apart from the &quot;someone&#x27;s basement&quot;, as objected to in this thread, it also doesn&#x27;t say they acquired &quot;commodity hardware&quot;; I took it to suggest the opposite, presumably for good reason.
      • wtallis10 hours ago
        &gt; it also doesn&#x27;t say they acquired &quot;commodity hardware&quot;; I took it to suggest the opposite, presumably for good reason.<p>This seems entirely like wishful thinking. They were using a 12 year old server that was increasingly unfit for the day-to-day task of building Android applications. It doesn&#x27;t seem like they were in a position to acquire and deploy any exotic hardware (except to the extent that <i>really old</i> hardware can be considered exotic and no longer a commodity). I&#x27;d be surprised if the new server is anything other than off the shelf x86 hardware, and if we&#x27;re lucky then <i>maybe</i> they know how to do something useful with a TPM or other hardware root of trust to secure the OS they&#x27;re running on this server and protect the keys they&#x27;re signing builds with.
        • gnufx7 hours ago
          I&#x27;m just reading what was written, especially &quot;the specific components we needed&quot;, and assuming they&#x27;re not as incompetent as is being suggested, given they&#x27;ve served me well. Perhaps you haven&#x27;t been tendering for server hardware recently, even bog-standard stuff, and seen the responses that even say they can&#x27;t quote a fixed price currently. At least, that&#x27;s in my part of the world, in an operation buying a good deal of hardware. We also have systems over ten years old running.
    • viraptor19 hours ago
      &gt; shove it in a special someone&#x27;s basement<p>They didn&#x27;t say what conditions it&#x27;s held in. You&#x27;re just adding FUD, please stop. It could be under the bed, it could be in a professional server room of the company ran by the mentioned contributor.
      • lrvick18 hours ago
        100%. Just as an example I have several racks at home, business fiber, battery backup, and a propane generator as a last resort. Also 4th amendment protections so no one gets access without me knowing about it. I host a lot of things at home and trust it more than any DC.
        • Aurornis17 hours ago
          &gt; Also 4th amendment protections so no one gets access without me knowing about it.<p>If there&#x27;s ever a need for a warrant for any of the projects, the warrant would likely involve seizure of every computer and data storage device in the home. Without a 3rd party handling billing and resource allocation they can&#x27;t tell which specific device contains the relevant data, so everything goes.<p>So having something hosted at home comes with downsides, too. Especially if you don&#x27;t control all of the data that goes into the servers on your property.
        • hypeatei18 hours ago
          Isn&#x27;t a business line quite expensive to maintain per month along with a hefty upfront cost? For a smaller team with a tight budget, just going somewhere with all of that stuff included is probably cheaper and easier like a colo DC.<p>&gt; Also 4th amendment protections so no one gets access without me knowing about it<p><i>laughs in FISA</i>
        • well_ackshually4 hours ago
          &gt; Also 4th amendment protections so no one gets access without me knowing about it.<p>Hahaha<p>at best you&#x27;re getting a warrant. Slightly better you&#x27;re getting a warrant _and_ a gag order. Then it escalates, and having your door kicked in at 6AM is about the best you can hope for.<p>But sure, you&#x27;ll know about it. Most likely. Maybe.<p>Just don&#x27;t keep anything important in there eh ?<p>(Note, this definitely applies to colocations too. It&#x27;s just maybe a tiny bit harder to find which rack is yours, and companies of that size generally have lawyers to prevent that from happening. I&#x27;ll take my chance with the hosting company.)
        • kube-system16 hours ago
          Which one of those things do you think you can&#x27;t get in a datacenter?
          • drnick114 hours ago
            That&#x27;s not the point. The point is that a &quot;home&quot; setup can basically replicate or exceed a &quot;professional&quot; setup when done right.
            • kube-system14 hours ago
              A home setup might be able to rival or beat an “edge” enterprise network closet.<p>It’s not going to even remotely rival a tier 3&#x2F;4 data center in any way.<p>The physical security, infrastructure, and connectivity will never come close. E.g. nobody is doing full 2N electrical and environmental in their homelab. And they certainly aren’t building attack resistant perimeter fences and gates around their homes, unless they’re home labbing on a compound in a war torn country.
              • drnick12 hours ago
                &gt; The physical security, infrastructure, and connectivity will never come close. E.g. nobody is doing full 2N electrical and environmental in their homelab. And they certainly aren’t building attack resistant perimeter fences and gates around their homes, unless they’re home labbing on a compound in a war torn country.<p>Why would you need all of that if what they have works? Nobody is going to raid a repo of open source software, you can just download everything for free.
    • cyberax18 hours ago
      I read it a bit differently: you don&#x27;t need to be a mega-corp with millions of servers to actually make a difference for the better. It really doesn&#x27;t take much!<p>Also, even 12-year-old hardware is wicked fast.
      • Aurornis18 hours ago
        The issue isn’t the hardware, it’s the fact that it’s hosted somewhere private in conditions they wont name under the control of a single member. Typically colo providers are used for this.
        • unethical_ban9 hours ago
          Is it one person? Is it an organization&#x2F;professional company with close ties to F-Droid? There are a lot of worst-case assumptions in this thread.
        • cyberax17 hours ago
          Eh. It&#x27;s just a different set of trade-offs unless you start doing things super-seriously like Let&#x27;s Encrypt.<p>With f-droid their main strength has always been replicable builds. We ideally just need to start hosting a second f-droid server somewhere else and then compare the results.
  • amake8 hours ago
    I publish an app to the App Store, Google Play, and F-Droid. For years, F-Droid took absolute <i>ages</i> to reflect a new release.<p>People used to criticize the walled gardens for having capricious reviewers and slow review times, but I found F-Droid much more frustrating to get approval from and <i>much</i> slower to get a release out.<p>So this development is much appreciated. In fact I had an inkling that build times had improved recently when an update made it out to F-Droid in only a day or two.
  • ZiiS18 hours ago
    Let&#x27;s focus on how they have done so much with such simple hardware, rather then comparing them to companies that do so little with so much more.
  • Abishek_Muthian12 hours ago
    I don&#x27;t understand why governments haven&#x27;t started to fund F-Droid, almost all govt. apps are open-source.<p>Countries which fear they could be cut off from the duopoly mobile ecosystem should be forcing android manufacturers to bundle in F-Droid; For the amount of nonsense regulations they force phone manufacturers to adhere to, bundling F-Droid wouldn&#x27;t be that hard.<p>Google won&#x27;t be happy, but anti-trust regulations would take care of it.
    • edent9 hours ago
      What did your local politician say when you wrote to them and suggested it?<p>(I&#x27;ve worked with several politicians. You&#x27;d be surprised what a well timed letter or meeting can achieve.)
      • idoubtit5 hours ago
        Not much...<p>I wrote a few times to my local MPs (&quot;député&quot;, as we call them in France). I usually got a response, though I suspect it was written by their secretary with no other consequence. In one case (related to privacy against surveillance), they raised a question in the congress, which had just a symbolic impact.<p>It may be different in other countries. In France, Parliament is de-facto a marginal power against a strong executive power. Even the legal terms are symptomatic of this situation: the government submits a &quot;project of law&quot; while MPs submit a &quot;proposal of law&quot; (which, for members of the governing party, is almost always written by the government then endorsed by some loyal MP).
    • worldsavior5 hours ago
      Because it&#x27;s not their responsibility. Why they should care about these kind of stuff? Don&#x27;t drop everything on governments.<p>A project like F-Droid is dumb to begin with where they&#x27;re the one to build the apps.
      • MYEUHD5 hours ago
        &gt; A project like F-Droid is dumb to begin with where they&#x27;re the one to build the apps.<p>I heartily disagree. Linux distributions also build the packages themselves, and that adds a layer of trust.<p>It ensures that everything in the fdroid repo is free software, and can be self-built.
        • worldsavior4 hours ago
          They don&#x27;t. The community builds the packages.<p>There are other ways to ensure something is free software and can be self built. Their approach is highly inefficient.
  • valgaze20 hours ago
    Hmm:<p>“F-Droid is not hosted in just any data center where commodity hardware is managed by some unknown staff. We worked out a special arrangement so that this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access.”
    • kube-system18 hours ago
      Yikes. They don&#x27;t need a &quot;special arrangement&quot; for those requirements. This is the bare minimum at many professionally run colocation data centers. There is not a security requirement that can&#x27;t be met by a data center -- being secure to customer requirements is a critical part of their business.<p>Maybe the person who wrote that is only familiar with web hosting services or colo-by-the-rack-unit type services where remote-hands services are more commonly relied on. But they don&#x27;t need to use these services. They can easily get a locked cabinet (or even just a 1&#x2F;4 cabinet) only they could access.
      • fruitworks17 hours ago
        A super duper secure locked cabinet acessible only to them or anyone with a bolt cutter.<p>You want to host servers on your own hardare? Uh yikes. Let&#x27;s unpack this. As a certified AWS Kubernetes professional time &amp; money waster, I can say with authority that this goes against professional standards (?) and is therefore not a good look. Furthermore, I can confirm that this isn&#x27;t it chief.
        • kube-system17 hours ago
          Colocation <i>is</i> when you use your own hardware. That&#x27;s what the word means.<p>And you&#x27;re not going to even get close to the cabinet in a data center with a set of bolt cutters. But even if you did, you brought the wrong tool, because they&#x27;re not padlocked.
          • toast015 hours ago
            Bolt cutters will probably cut through the cabinet door or side if you can find a spot to get them started and you have a lot of time.<p>Otoh, maybe you&#x27;ve got a cabinet in a DC with very secure locks from europe.... But all are keyed alike. Whoops.<p>A drill would be easier to bring in (especially if it just looks like a power screwdriver) and probably get in faster though. Drill around the locks&#x2F;hinges until the door wiggles off.
            • kube-system15 hours ago
              I&#x27;d go with a drill -- but I&#x27;m not sure what possible threat vector would have access to the cabinet who would be able to get to the cabinet in any decent data center.
        • fragmede16 hours ago
          Because it&#x27;s a secret, we don&#x27;t know if it&#x27;s mom&#x27;s basement where the door doesn&#x27;t really lock anyways, just pull it real hard, or if it&#x27;s at Uncle Joey&#x27;s with the compound and the man trap and laser sensors he bought at government auction through a buddy who really actually works at the CIA.
    • IshKebab20 hours ago
      &quot;F-Droid is not hosted in a data centre with proper procedures, access controls, and people whose jobs are on the line. Instead it&#x27;s in some guy&#x27;s bedroom.&quot;<p>Not reassuring.
      • PaulKeeble19 hours ago
        It could just be a colo, there are still plenty of data centres around the globe that will sell you a space in a shared rack with a certain power density per U of space. The list of people who can access that shared locked rack is likely a known quantity with most such organisations and I know in the past we had some details of the people who were responsible for it
      • TomatoCo20 hours ago
        In some respects, having your entire reputation on the line matters just as much. And sure, someone might have a server cage in their residence, or maybe they run their own small business and it&#x27;s there. But the vagueness is troubling, I agree.<p>A picture of the &quot;living conditions&quot; for the server would go a long way.
      • a3w19 hours ago
        Depends on the thread model, which one is worse.<p>State actor? Gets into data centre, or has to break into a privately owned apartment.<p>Criminal&#x2F;3rd party state intelligence service? Could get into both, at a risk or with blackmail, threats, or violence.<p>Dumb accidents? Well, all buildings can burn or have an power outage.
        • Aurornis18 hours ago
          &gt; State actor? Gets into data centre, or has to break into a privately owned apartment.<p>I don’t think a state actor would actually break in to either in this case, but if they did then breaking into the private apartment would be a dream come true. Breaking into a data center requires coordination and ensuring a lot of people with access and visibility stay quiet. Breaking into someone’s apartment means waiting until they’re away from the premises for a while and then going in.<p>Getting a warrant for a private residence also would likely give them access to all electronic devices there as no 3rd party is keeping billing records of which hardware is used for the service.<p>&gt; Dumb accidents? Well, all buildings can burn or have an power outage.<p>Data centers are built with redundant network connectivity, backup power, and fire suppression. Accidents can happen at both, but that’s not the question. The question is their relative frequency, which is where the data center is far superior.
          • pbhjpbhj16 hours ago
            &gt;Breaking into a data center requires coordination and ensuring a lot of people with access and visibility stay quiet<p>Or just a warrant and a phone call to set up remote access? In the UK under RIPA you might not even need a warrant. In USA you can probably bribe someone to get a National Security Letter issued.<p>Depending on the sympathies of the hosting company&#x27;s management you might be able to get access with promises.<p>I dare say F-Droid trust their friends&#x2F;colleagues more than they trust randos at a hosting company.<p>As an F-Droid user, I think I might too? It&#x27;s a tough call.
          • u80807 hours ago
            &gt;I don’t think a state actor would actually break in to either in this case<p>Read Jabber.ru Hetzner accident: <a href="https:&#x2F;&#x2F;notes.valdikss.org.ru&#x2F;jabber.ru-mitm&#x2F;" rel="nofollow">https:&#x2F;&#x2F;notes.valdikss.org.ru&#x2F;jabber.ru-mitm&#x2F;</a>
          • Calzifer16 hours ago
            &gt; Data centers are built with redundant network connectivity, backup power, and fire suppression. [...] The question is their relative frequency, which is where the data center is far superior.<p>Well, I remember one incident were a &#x27;professional&#x27; data center burned down including the backups.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;OVHcloud#Incidents" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;OVHcloud#Incidents</a><p>I know no such incident for some basement hosting.<p>Doesn&#x27;t mean much. I&#x27;m just a bit surprised so many people are worried because of the server location and no one had mentioned yet the quite outstanding OVH incident.
            • arjie10 hours ago
              I&#x27;m not going to pretend datacenters are magical places immune to damage. I worked at a company where the 630 Third Street datacenter couldn&#x27;t keep temperatures stable during a San Francisco heatwave and the Okex crypto exchange has experienced downtime because the Alibaba Zone C datacenter their matching engine is on experienced A&#x2F;C failure. So it&#x27;s not all magic, but if you didn&#x27;t encounter home-lab failure it&#x27;s because you did not sample the population appropriately.<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;homelab&#x2F;comments&#x2F;wvqxs7&#x2F;my_homelab_burned_down&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;homelab&#x2F;comments&#x2F;wvqxs7&#x2F;my_homelab_...</a><p>I don&#x27;t have a bone to pick here. If F-Droid wants to free-ball it I think that&#x27;s fine. You can usually run things for max cheap by just sticking them on a residential Google Fiber line in one of the cheap power states and then just making sure your software can quickly be deployed elsewhere in times of outage. It&#x27;s not a huge deal unless you need always-on.<p>But the arguments being made here are not correct.
            • Bridged775610 hours ago
              Surely &quot;Juan&#x27;s home server in basement burns down&quot; would make the headlines. You&#x27;re totally right.
          • tcfhgj18 hours ago
            &gt; The question is their relative frequency, which is where the data center is far superior.<p>as a year long f-droid user I can&#x27;t complain
      • pwndByDeath19 hours ago
        I think there are countless examples of worse failures by organisations that meet your criteria for far more valuable assets than some free apps.
      • ugh12320 hours ago
        The &#x27;cloud&#x27; has come full circle
      • gpm19 hours ago
        Eh...<p>The set of people who can maliciously modify it is the people who run f-droid, instead of the cloud provider <i>and</i> the people who run f-droid.<p>It&#x27;d be nice if we didn&#x27;t have to trust the people who run f-droid, but given we do I see an argument that it&#x27;s better for them to run the hardware so we only have to trust them and not someone else as well.
        • lrvick19 hours ago
          You actually do not have to trust the people who run f-droid for those apps whose maintainers enroll in reproducible builds and multi-party signing, which only f-droid supports unlike any alternatives.
          • gpm19 hours ago
            That looks cool, which might just be the point of your comment, but I don&#x27;t think it actually changes the argument here.<p>You still have to trust the app store to some extent. On first use, you&#x27;re trusting f-droid to give you the copy of the app with appropriate signatures. Running in someone else&#x27;s data-center still means you need to trust that data-center plus the people setting up the app store, instead of just the app store. It&#x27;s just a breach of trust is less consequential since the attacker needs to catch the first install (of apps that even use that technology).
            • lrvick18 hours ago
              F-droid makes the most sense when shipped as the system appstore, along with pinned CA keychains as Calyxos did. Ideally f-droid was compiled from source and validated by the rom devs.<p>The F-droid app itself can then verify signatures from both third party developers and first party builds on an f-droid machine.<p>For all its faults (of which there are many) it is still a leaps and bounds better trust story than say Google Play. Developers can only publish code, and optional signatures, but not binaries.<p>Combine that with distributed reproducible builds with signed evidence validated by the app and you end up not having to trust anything but the f-droid app itself on your device.
              • gpm15 hours ago
                None of this mitigates the fact that apriori you don&#x27;t know if you&#x27;re being served the same package manifest&#x2F;packages as everyone else - and as such you don&#x27;t know how many signatures any given package you are installing should have.<p>Yes, theoretically you can personally rebuild every package and check hashes or whatever, but that&#x27;s preventative steps that no reasonable threat model assumes you are doing.
          • imiric16 hours ago
            Why have we normalized &quot;app stores&quot; that build software whose authors likely already provide packages of?<p>I&#x27;ve been using Obtainium more recently, and the idea is simple: a friendly UI that pulls packages directly from the original source. If I already trust the authors with the source code, then I&#x27;m inclined to trust them to provide safe binaries for me to use. Involving a middleman is just asking for trouble.<p>App stores should only be distributors of binaries uploaded and signed by the original authors. When they&#x27;re also maintainers, it not only significantly increases their operational burden, but requires an additional layer of trust from users.
        • ejj2819 hours ago
          The cloud isn&#x27;t the only other option, they could still own and run their own hardware but do it in a proper colocation datacenter.
    • skiing_crawling19 hours ago
      I never questioned or thought twice about F-Droid&#x27;s trustworthiness until I read that. It makes it sound like a very amateurish operation.<p>I had passively assumed something like this would be a Cloud VM + DB + buckets. The &quot;hardware upgrade&quot; they are talking about would have been a couple clicks to change the VM type, a total nothingburger. Now I can only imagine a janky setup in some random (to me) guy&#x27;s closet.<p>In any case, I&#x27;m more curious to know exactly what kind hardware is required for F-Droid, they didn&#x27;t mention any specifics about CPU, Memory, Storage etc.
      • AndrewDucker19 hours ago
        For a single server why would you use cloud services rather than go the self-owned route?
        • skiing_crawling19 hours ago
          A &quot;single server&quot; covers a pretty large range of scale, its more about how F-droid is used and perceived. Package repos are infrastructure, and reliability is important. A server behind someone&#x27;s TV is much more susceptible to power outages, network issues, accidents, and tampering. Again, I don&#x27;t know that&#x27;s the case since they didn&#x27;t really say anything specific.<p>&gt; not hosted in just any data center where commodity hardware is managed by some unknown staff<p>I took this to mean it&#x27;s not in a colo facility either, assumed it mean&#x27;t someone&#x27;s home, AKA residential power and internet.
          • secabeen15 hours ago
            The F-Droid repos are provided by redundant mirrors: <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;docs&#x2F;Running_a_Mirror&#x2F;" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;docs&#x2F;Running_a_Mirror&#x2F;</a><p>If this is the hidden master server that only the mirrors talk to, then it&#x27;s redundancy is largely irrelevant. Yes, if it&#x27;s down, new packages can&#x27;t be uploaded, but that doesn&#x27;t affect downloads at all. We also know nothing about the backup setup they have.<p>A lot depends on the threat model they&#x27;re operating under. If state-level actors and supply chain attacks are the primary threats, they may be better off having their system under the control of a few trusted contributors versus a large corporation that they have little to no influence over.
          • AndrewDucker19 hours ago
            Ah. I took &quot;not just any data center&quot; to mean &quot;in a specific co-location facility where they trust the person responsible for it&quot;.<p>I agree that &quot;behind someone&#x27;s TV&quot; would be a terrible idea.
      • lrvick18 hours ago
        &gt; It makes it sound like a very amateurish operation.<p>Wait until you find out how every major Linux distributions and software that powers the internet is maintained. It is all a wildly under-funded shit show, and yet we do it anyway because letting the corpos run it all is even worse.
        • kube-system16 hours ago
          What do you mean by &quot;major distribution&quot;?<p>e.g. AS41231 has upstreams with Cogent, HE, Lumen, etc... they&#x27;re definitely not running a shoestring operation in a basement. <a href="https:&#x2F;&#x2F;bgp.tools&#x2F;as&#x2F;41231" rel="nofollow">https:&#x2F;&#x2F;bgp.tools&#x2F;as&#x2F;41231</a>
        • goodpoint3 hours ago
          This is 100% false.
        • Craighead18 hours ago
          [dead]
  • Johnny55511 hours ago
    Does anyone know what the server is? I don&#x27;t see it on their site.<p>I&#x27;m curious why supply chain issues got in the way and why they couldn&#x27;t just configure a Dell Poweredge and get delivery in a couple weeks.<p>I&#x27;m assuming they have some special requirements that weren&#x27;t met by an off-the-shelf server, so I&#x27;m just curious what those requirements are.
  • PaulKeeble19 hours ago
    Modern machines go up to really mental levels of performance when you think about it and for a lot of small scale things like F droid I doubt it takes a lot of hardware to actually host it. A lot of its going to be static files so a basic web server could put through 100s of thousands of requests and even on a modest machine saturate 10 gbps which I suspect is enough for what they do.<p>This just reads to me like they have racked a box in a colo with a known person running the shared rack rather than someone’s basement but who really knows they aren&#x27;t exactly handing out details.
    • wtallis19 hours ago
      This isn&#x27;t about a server for hosting the website or package repo, it&#x27;s about the server <i>building</i> all the packages.
    • JuniperMesos16 hours ago
      Which is itself kind of suspicious - why can&#x27;t they say &quot;yeah we pay for Colo in such-and-such region&quot; if that is what they are doing? Why should that be a secret?
  • debugnik18 hours ago
    &gt; not hosted in just any data center [...] a long time contributor with a proven track record of securely hosting services<p>This is ambiguous, it could mean either a contributor&#x27;s rack in a colocation centre or their home lab in their basement. I&#x27;d like to think they meant the former, but I can&#x27;t deny I understood the latter in my first read.<p>Also, no details on the hardware?
  • NoiseBert6920 hours ago
    So.. what kind of hardware did they buy?
    • IshKebab20 hours ago
      Yeah kind of conspicuously absent! They said<p>&gt; The previous server was 12 year old hardware<p>which is pretty mad. You can buy a second hand system with tons of ram and a 16-core Ryzen for like $400. 12-year old hardware is only marginally faster than a RPi 5.
      • lucb1e15 hours ago
        &gt; 12-year old hardware is only marginally faster than a RPi 5<p>My 14yo laptop-used-as-server disagrees. Also keep in mind that CPU speeds barely improved between about 2012 and 2017, and 2025 is again a lull <a href="https:&#x2F;&#x2F;www.cpubenchmark.net&#x2F;year-on-year.html" rel="nofollow">https:&#x2F;&#x2F;www.cpubenchmark.net&#x2F;year-on-year.html</a><p>I&#x27;m also factoring in the ability to use battery bypass in phones I buy now because they are so powerful, I might want to use them as free noiseless server in the future. You can do a heck of a lot on phone hardware nowadays, paying next to nothing for power and no additional cost on your existing internet connection. A RPi 5 is that same ballpark
      • DaSHacka19 hours ago
        &gt; 12-year old hardware is only marginally faster than a RPi 5.<p>A Dell R620 is over 12 years old and WAY faster than a RPi 5 though...<p>Sure, it&#x27;ll be way less power efficient, but I&#x27;d definitely trust it to serve more concurrent users than a RPi.
      • phantom78419 hours ago
        Plus the fact that it&#x27;s been running for 5 years. Does that mean they bought 7 year old hardware back then? Or is that just when it was last restarted?
      • cvwright19 hours ago
        Unfortunately you can’t even get the RAM for $400 anymore.
        • neogodless19 hours ago
          I was able to find 2 x 16GB DDR4 for $150...<p>Building a budget AM4 system for roughly $500 would be within the realm of reason. ($150 mobo, $100 cpu, $150 RAM, that leaves $100 for storage, still likely need power and case.)<p><a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;Timetec-Premium-PC4-19200-Unbuffered-Computer&#x2F;dp&#x2F;B0FZTN2381" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;Timetec-Premium-PC4-19200-Unbuffered-...</a><p><a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;MSI-MAG-B550-TOMAHAWK-Motherboard&#x2F;dp&#x2F;B089CWDHFZ" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;MSI-MAG-B550-TOMAHAWK-Motherboard&#x2F;dp&#x2F;...</a><p>For a server that&#x27;s replacing a 12 year old system, you don&#x27;t need DDR5 and other bleeding edge hardware.
          • kiddico19 hours ago
            I don&#x27;t think 32GB is going to be enough lol
            • calgoo19 hours ago
              Also, you would want ECC for something this important.
              • krautsauer9 hours ago
                I seriously wonder if doing the same build twice by two people in two locations wouldn&#x27;t provide the same benefit and others for less money.<p>(I might be spoiled by sane reproducible build systems. Maybe F-droid isn&#x27;t.)
  • JimBlackwood19 hours ago
    While I get their setup is amateurish, it&#x27;s also a good reminder of how simple setups can be.<p>Saying this on HN, of course.
  • basilgohar18 hours ago
    I think all the criticism of what F-Droid is doing here (or perceived as doing) reflects more on the ones criticising than the ones being criticised.<p>How many things went upside down and all the &quot;right&quot; things were done (corporate governance, cloud native deployment, automation, etc.). The truth is none of these processes are actually going to make things more secure, and many projects went belly up despite following these kinds of recommendations.<p>That being said, I am grateful to F-Droid fighting the good fight. They are providing an invaluable service and I, for one, am even more grateful that they are doing it as uncompromisingly as possible (well into discomfort) according to their principles.
    • dugite-code15 hours ago
      Not to mention this is a build server, its uptime isn&#x27;t actually all that critical, assuming they then mirror the artifacts out from there.<p>Not to mention it also simplifies the security of controlling signing keys significantly.
    • vachina9 hours ago
      Exactly, if you run out of money, processes meant jackshit.
  • anthk17 hours ago
    Good. But I wish PostmarketOS supported more devices. On battery, tons of kernel patches could be set per device plus a config package in order to achieve the best settings. On software and security...you will find more malware in Play Store than the repos from PmOS&#x2F;Alpine. I know it&#x27;s not a 100% libre (FSF) system, but that&#x27;s a much greater step towards freedom than Android, where you don&#x27;t even own your device.
    • drnick114 hours ago
      The issue with Linux-based phones is and remains apps. Waydroid works pretty well, but since you need to rely on it so much, you are better off using Graphene or Lineage in the first place.
      • anthk5 hours ago
        But Android it&#x27;s a clusterfuck. Look Lemuroid, a Retroarch based emulator with a nice GUI. With the new SAF related permissions you can&#x27;t make the emulator work any more.<p>And that being a libre package from F-Droid. And I noticed several other bugs. Tyr for instance (an Yggmail service which bundles Yggdrasil) doesn&#x27;t have an armv7a version. Tyr could be really useful with DeltaChat because you could talk with any relative without depending on 3rd party mail services. And because of arbitrary limitations, compiling a 32 bit binary it&#x27;s damn difficult for maintainers, yet I could compile yggmail for Go under Termux without no issues.<p>Thus, that&#x27;s why I prefer PostMarketOS, software would just run once it&#x27;s installed and for sure I wouldn&#x27;t need to set an SDK weighting several GB&#x27;s.
        • drnick12 hours ago
          Those are valid criticisms of Android, but I see at least two problems that prevent wider adoption of PostmarketOS (even among HN readers). First, it only supports what seems to be ancient hardware. Contrast this with Graphene and latest-gen Pixel support. Second, compatibility with Android is critical. People just want to run their Starbucks app and expect it to work.
  • j1elo18 hours ago
    I wonder if anyone knows about Droid-ify. Whether it it a safe option, or better to stay away of it?<p>It showed up one day while I searched about why F-Droid was always so extremely slow to update and download... then trying Droid-ify, that was never a problem any more, it clearly had much better connectivity (or simply less users?)
    • kasabali18 hours ago
      it&#x27;s a different client using same servers. fdroid official client is just super buggy.
  • anticorporate18 hours ago
    It&#x27;s frankly embarrassing how many of the comments on this thread are some version of looking at the XKCD &quot;dependency&quot; meme and deciding the best course of action is to throw spitballs at the maintainers of the critical project holding everything else up.
    • charcircuit15 hours ago
      F Droid is no where near being a critical project holding Android up. The Play Store, and the Play Services themselves are much more critical. Being open source doesn&#x27;t make you immune from criticism for not following industry standards or being called out for poor security.
      • drnick114 hours ago
        &gt; The Play Store, and the Play Services themselves are much more critical.<p>Critical for serving malware and spyware to the masses, yes. GrapheneOS is based on Android and is <i>far better</i> than a Googled Android variant precisely because it is free of Google junk and OEM crapware.
        • charcircuit8 hours ago
          The internet itself is also critical for serving malware and spyware, but that doesn&#x27;t mean that the internet is garbage. Google invests much more into removing malicous apps from the app store than fdroid does.
      • lucb1e15 hours ago
        If you have nothing to install on your device, what&#x27;s the point of being able to? For me, f-droid is a cornerstone in the android ecosystem. I could source apks elsewhere but it would be much more of a hassle and not necessarily have automatic updates. iOS would become a lot more attractive to me if Android didn&#x27;t have the ecosystem that&#x27;s centered around the open apps that you can find on f-droid
        • charcircuit8 hours ago
          &gt;If you have nothing to install on your device<p>&gt;I could source apks elsewhere<p>Do you or do you not have apps you want to install?
    • wtallis18 hours ago
      At the very least, it&#x27;s reasonable to expect the maintainers of such a project to be open about their situation when it&#x27;s that precarious. Why <i>wouldn&#x27;t</i> you take every opportunity to let your users and downstream projects know that the dependency you&#x27;re providing is operating with no redundancy and barely enough resources to carry on when things <i>aren&#x27;t</i> breaking? Why <i>wouldn&#x27;t</i> they want to share with a highly technical audience any details about how their infrastructure operates?
      • tcfhgj17 hours ago
        &gt; when it&#x27;s that precarious<p>assumptions
        • wtallis17 hours ago
          They&#x27;re building all the software on a single server, and at best their fallback is a 12 year old server they might be able to put back in production. I&#x27;m not making any unreasonable assumptions, and they&#x27;re not being forthcoming with any reassuring details.
    • stefan_14 hours ago
      I think both of those POVs are wrong. The whole thing about F-Droid is that they have worked hard on not being a central point of trust and failure. The apps in their store are all in a repo (<a href="https:&#x2F;&#x2F;gitlab.com&#x2F;fdroid&#x2F;fdroiddata" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;fdroid&#x2F;fdroiddata</a>) and they are reproducibly built from source. You could replicate it with not too much effort, and clients just need to add the new repository.
  • user2057387 hours ago
    Disappointed in HN because of these comments
    • Xunjin6 hours ago
      Criticism is good when it comes with feasible suggestions or even a little help.<p>I wonder how many of HN audience does know someone, or a guy who knows a guy, which works in a data center able to manage the hardware and a simple email&#x2F;message&#x2F;hello there could open a new opportunity.
  • ilaksh15 hours ago
    Is it possible to add some kind of hardware detection to the build process of a project submitted and inspect the details?
  • whalesalad18 hours ago
    Absolutely zero details on the old or new server.
  • SuperNinKenDo14 hours ago
    Christ, comment sections like this make me never want to do anything that might gain widespread adoption, ever.<p>Brought to you by the helpful folks who managed to bully WinAmp into retreating from open source. Very productive.
    • wolpoli12 hours ago
      A lot of people here are used to working for companies with a larger infrastructure budget.
  • vjay1513 hours ago
    I wish they could give more clarity on whether its hosted in a professional server or someone&#x27;s bedroom, because just saying that &quot;it&#x27;s held by a long time contributor with a proven track record of securely hosting services&quot; is not very reassuring.
  • Gelob14 hours ago
    so uhhh what are the specs of said server?
  • hindustanuday8 hours ago
    [dead]
  • trusttrusttrust16 hours ago
    [flagged]
  • alexnewman17 hours ago
    i&#x27;m glad we have a wing that&#x27;s against gab app store. Can we have one that&#x27;s for them for balance?
  • websiteapi19 hours ago
    &gt; Another important part of this story is where the server lives and how it is managed. F-Droid is not hosted in just any data center where commodity hardware is managed by some unknown staff.<p>&gt; The previous server was 12 year old hardware and had been running for about five years. In infrastructure terms, that is a lifetime. It served F-Droid well, but it was reaching the point where speed and maintenance overhead were becoming a daily burden.<p>lol. if they&#x27;re gonna use gitlab just use a proper setup - bigco is already in the critical path...