This is the elephant in the room regarding the big "digital sovereignty" talks in the EU.
For the moment in the EU institutions the focus is mostly at the post-acceptance stage that everything must eventually migrate off US clouds. There is still some denial and hope that things will go back to "before" because it's going to be extremely costly to migrate, but at least high level EU civil servants start to see the strategic value of moving out.
However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.
So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...
"zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU."
Complete public datasheets on how to program the hardware should be a requirement fit a DMA2.0.
This is not entirely true. I don't have much details but I know people who started to work on two separate free software projects aiming to make supported mobile OS.
These projects couldn't get funding before but they do now. Afaik it's still a battle with AI companies lobbying that soverign AI is much more important than mobile OS but there is some growing interest.
Imho i don't even think some linux based alternative to Android would be that hard to pull off but it's the hw companies that will be skeptical to build hw for such OS. I would have to be some govs puahing it as secure gov devices first.
It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.
> there's nothing preventing those new OSes form providing proper security signals.
A network effect, far from being nothing, is a barrier the height of a mountain.
The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.
Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.
And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.
What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.
It requires a government-authorised "age verification" "app", but it does not require that it is accessible through standard protocols, so that it can work on any platform. In practice, the governments will only make it available for Android and iOS. Plus, you cannot have a free OS providing "attestation"; "attestation" is incompatible with root access and modifying the OS.
See, you’re just saying what they’re saying, but with emotive, thought-terminating language. Again, it’s easier to complain. Have you been living under a rock for your entire life? Have never ever been involved in a decision being made about certain “blessed” vendors, and the decision is being made for legitimate technical reasons, not “ridiculous” ones.
If you’re the sort of person that’s unable to distinguish between something that’s legitimately unjustifiable/ridiculous, and something that just upsets you, then you do you, but don’t bring this here pretending that it suffices as a discussion, because it doesn’t.
I think the asumption being if there is gov backed mobile OS govs would also support their app ecosystem there. That's kinda the point of funding alternative free mobile OS?
That wont help anything. Then you are just force to use Android, iOS, or Sailfish. It need to be a platform agnostic thing, else you're just hitching the fulcrum of civil society on private company.
Exactly. The app is only inclusive if it is accessible over a standard protocol (Web) without "attestation", so that it works for any platform. If I release a GNU/Linux distribution tomorrow, I should be able to use the app on it with only some work on my part.
I don't disagree, but the eu needs their own mobile OS alternative in general so if they absolutely need to rely on a private company, it isn't an american one
This doesn't follow. Why is public infrastructure no longer a possibility as soon as computers get involved? We aren't talking about cutting edge innovation here anymore, mobile phones are boring standard devices.
Because this is all a political move. This so-called "EU sovereignty" drive is in fact aimed at further reducing sovereignty of the member states via further transfer of power and control to the EU.
These digital ID wallets do exactly that. Member states lose control of the ID infrastructure, which will now be controlled by the EU. There isn't much sovereignty left at national level...
The US federal government has been doing that to the states for a while now. They don't have the constitutional authority to do something, so instead they shove a lever under something they nominally are allowed to do and tell the states "do the thing we're not allowed to, the way we tell you to, or else." Where the "or else" is something like, they collect billions of tax dollars from your constituents that you then can't use to provide them with services, and return them to only the states that bend the knee.
(The US constitution originally required federal taxes to be apportioned for exactly that reason.)
Moreover, it's ignoring the context of the thread. The relevance is obviously that coercing someone to do something against their will and then saying they're still in charge because they're the ones doing it is a sham.
US federal laws are also a thing. In both cases, they're supposed to be limited to specific categories.
In the EU this appears to be classified into "exclusive", "shared" and "support" "competencies":
> the EU has competence to support, coordinate or supplement the actions of the Member States (article 6 TFEU) – in these areas, the EU may not adopt legally binding acts that require the Member States to harmonise their laws and regulations.
So for example, one of the areas in that category is industry.
The common trick to look out for in cases like that is that when they want to regulate something like "industry" they instead categorize the rules as something else, e.g. the US infamously regulates non-interstate non-commerce as "interstate commerce".
A major example is the US drinking age. Federal highway funds, which provide money for interstate highways, major US routes, etc, are partially contingent on states (who are given authority over alcohol laws both by the general police power and the 21st Amendment) setting the minimum age for the legal purchase of alcohol at 21. The National Minimum Drinking Age Act withheld 10 percent of highway funds from states that didn't comply. The fact that it wasn't 100% let the Supreme Court allow it to slide, but eventually all the states did comply, and effectively the US has a drinking age set by the Federal government instead of the states even though the states technically have the power to set an age themselves.
The Federal government using the withholding of funds to get the states to do what it wants is a well-documented phenomenon.
As an obvious example, regulating education isn't one of the enumerated powers of the US federal government, but there are numerous -- often controversial (e.g. NCLB) -- federal laws that take tax revenue from every state's constituents and return it to the state only if they comply with federal requirements the federal government has no power to impose on its own.
Where is control in being mandated to implement and EU-wide, EU-defined system? This is a net loss.
My previous comment should be taken in its entirety. The loss of sovereignty of individual countries is comprehensive across all domains and this is just one brick in the wall.
This is nothing new, this is what "European integration" means. I wanted to point out the very newspeak-esque use of the term "sovereignty" in Europe at the moment.
The spec/design leaves a lot for the member states to decide on their own. You do understand how the EU and the member states roles work?
I would think the idea is to make services and ID documents more uniform across the union. I don’t see what the individual members state lose here? Apart from the cost of implementation. The individual EU citizen would seem to benefit from standardized documents accepted by all companies and governments, do you disagree?
This is totally not the EU version of China's social credit score system and WeChat SSO system.
It will totally not be used to sanction you the moment you become a nuisance to the EU elites by saying "wrong speech" that goes against their mandated doctrine or pointing out their acts of corruption or dismantling of democracy.
The EU building in Brussels even has the word "DEMOCRACY" plastered on the front in large bold letters[1], in case you forgot.
China made its own linux distros almost immediately. And as far as I know it is widely in use (Kylin etc.?).
Some nations in the western sphere seem to gladly outsource such critical infrastructure. Thinking about the Korean defence manufacturer whose contact mail was something@gmail.com in an advert I saw a few days ago. Perhaps Google will integrate some fast reply function for some instant AA ordnance delivery?
The sovereignty thing is a theater. Many french unis use Google cloud because they're broke and can't maintain in-house services, and none gives a damn.
In fact, it requires attestation: even if you install Google Play on some Android in an emulator/container/VM, on an alternative Android distro or in a rooted device, the app will not accept it.
Wth. Does it at least have the decency to use aosp attestation? Or are they just happy to give the keys to the kingdom to Google and require Play Protect?
GrapheneOS guy went on a very extensive rant on Mastodon when someone wanted to create an independent, European, list that could be used by apps to verify attestation. They want apps to hardcode theirs specifically.
Which makes sense for them - after all, that makes their competitors break and their ROM doens't.
It is true that Google (de facto) controls the platform and made themselves (de facto) essential to utilizing the platform by integrating their proprietary services so deeply into the OS that you need to be a behemoth of Samsungs caliber to even attempt to meaningfully re-purpose the AOSP, and this was a brilliant strategy because it has allowed Google to solidify their spot in the duopoly / oligarchy while seeming "open". But. I do believe that Google will continue to publish the AOSP source code under a permissive license and that this code will be indispensible to a European Manhattan project for tech sovereignty, should policymakers ever see the light.
Yes, I remember feeling that way in 1995-2005 about Microsoft. Imagine my surprise to learn that people still to this day trust and believe in Microsoft.
(because you still need the hardware made, and it's not like the EU commission is even prepared to fix BSPs for that hardware)
The EU has endlessly sold critical infrastructure to US, India and China while actively sabotaging efforts to rebuild it and now want it back - for free. This is criticized as having a low chance of success, as well as being a pretty unreasonable demand.
Mobile is the UI/UX equivalent of… I don’t even know… a moon landing? A wonder of the world?
I’m not saying it can’t be duplicated. I’m saying if you want to build a mobile platform you need to approach it with appropriate respect for the incredible difficulty of making something that usable.
Indeed. Power management alone is a massive research area with never-ending complexity across a bunch of domains. And nailing the ecosystem correctly is very hard (both devices and software). Security is another bottomless pit of research and improvement. When trillion-dollar companies like Amazon and Microsoft ceded mobile to Google and Apple, it was a good demonstration of how hard a successful mobile platform is to get off the ground.
Ok we get new HN articles every week now about migrating to EU solutions and digital sovereignty. At this point EU should just do as China, please: have EU their own cloud providers, softwares, hardwares, phones and also its own closed-EU only mini-internet barrier by a big EU digital policy border. Just like China, NKorea and Russia. They would be finally at peace with themselves.
I use syncthing to automatically sync my dotfiles git directory across PC/laptops, and stow to manually update symlinks when I add a new dotfile (the content of existing dotfiles is synced by syncthing already)
That way I don't have to remember to commit+push+pull changes to existing dotfiles (like bashrc or vimrc which I edit often) to sync them to other machines, it happens automatically in almost real time as soon as the file is saved on one of my machines (syncthing uses inotify to detect changes on monitored directories)
This is what I did too. My dotfiles used a custom install process that didn't really handle ~/.config very well, so I switched to stow, and then added syncthing because the push + pull dance got too annoying. Really happy with it.
looks like LLMs aren't mature enough yet to play long-game xz-style attacks without detection... Scary stuff though :( These supply chain attacks are getting really wild
Well I don't know if you wrote this in a sarcastic way or not, but when you write a new message in Thunderbird just turn on `Options -> Delivery Status Notification` and your mail server will email you back with a delivery status message (success or failure, although failure can take some days if the receiving server doesn't outright reject your message)
I was not sarcastic. I just tried this by sending from my gmail account to one of my other accounts. Didn't get any email back even though the email was immediately delivered.
ah sorry, I thought you wanted a delivery notification when you are sending an email via your own SMTP server (i.e. when thunderbird is configured to use your own outbound SMTP gateway)
As my main desktop computers I've been using Fedora and Windows (for gaming only) virtualised on top of a single proxmox host with 2 GPUs passed through for more than 10 years... Upgraded all the way to latest versions (guests and hosts) without ever having to reinstall from scratch. I upgraded the hardware a few times (just cloned the disks), and since the desktops are virtualised, Windows always worked fine without complaining about new hardware drivers (only thing to change was GPU driver)
Another benefit is block-level backups of the VMs (either with qcow2 disks files or ZFS block storage, which both support snapshots and easy incremental backups of changed block data only)
Proxmox is great for this, although maybe not on a laptop unless you're ready to do a lot of tweaks for sleep, etc.
I think people like using makefile as a simple task runner because it's pretty much ubiquitous and also a kind of auto-descriptive standard. Interactive shells usually do autocompletion on makefile targets so it's easy to see what you can run on a project (more so on old or foreign projects)
- about 20TB per day, around 100PB expected for the whole survey
- 0.5PB ceph cluster for local data
- workloads on 20 nodes kubernetes cluster/argocd
- physical infra managed with puppet/ansible
- 100Gbs(+40Gs backup) fiber connection to US-based datacenter for further processing
I wonder if they could reduce the data size at rest by using specialized compressing techniques. Your probably could build an averaged "model" of the sky observed by the telescope (probably with account for stellar parallax and bright planets) and store only compressed diffs, not full images.
But I guess, since storage is relatively cheap, it's simply impractical to bother with such complexity.
The usual lossless image compression algorithms is the given. I am talking about compressing it further since the telescope observes the same (or largely overlapping) patches of the sky and the most significant signal is stars, which are more or less "constant". At the very least, they probably could use the lossless "animation" compression algorithms like APNG or FLIF for consequent images of the same sky patch.
If you think this is insanity I encourage you to look up the expected data to come out of the SKA. Even after several processing steps they expect several hundred PB/year (the raw data which is not being archived is several orders of magnitude more). That is only SKA-low I think for SKA-mid we are talking Exabyte/year. I recall that their chief scientist said once they are operational they will process more data than google and facebook combined.
At least with keepassDX on android there is no internet access permission needed by default, but if a compromised update suddenly required it I don't know if Android would prompt about it since all apps have internet access granted without prompting :(
I also wish it was possible to block automatic updates of specific apps on the play store... So at least we could be in control over updating critical apps such as these without having to micromanage updates for all apps.
On GrapheneOS there is a prompt when installing an app that asks if you would like to grant network access. I am not sure if that pop up displays if network access is added later in an app update though.
Restic supports a similar feature set to Borg (open source, locally encrypted backups, content-addressed snapshots instead separate incremental+full backups, etc) but also works with dumb file hosts (S3, Backblaze B2, a local drive, etc).
Indeed, and it's a powerful combination. With "autorestic" as a bit of a front end, I have backups going to a local SSD, home NAS, and Backblaze B2. My B2 storage is under 200 GB so far, but has also cost basically nothing. For that, I have at least some chance of getting data back if the house burns down.
Nebula is great!
From what I found after testing other solutions (headscale, netbird, netmaker) It's also the only completely open source mesh vpn that can be configured with a highly available control plane (just run multiple lighthouses, nothing is shared) and also supports multiple root CAs for nodes, relays and control planes (and each node can be a relay too)
I just wish there was a kubernetes operator to easily set up mesh sidecars like with tailscale and it would be perfect!
FYI, the Nebula mobile client is source-available but not open-source. The devs from Defined Networking have been cagey about this and don't make this fact obvious, which makes me wary of Nebula.
Fair enough about the android mobile client... My use case only involves meshing linux appliances across various networks so we only need the nebula core binaries which are under MIT license
They could have just added a LICENSE file which stated you are not allowed to use to software without a commercial license. Instead they chose to be vague about it. Doesn't really inspire confidence.
However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.
So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...