54 pointsby kasabali2 hours ago3 comments
  • kasabali2 hours ago
    Context: "F-Droid build servers can't build modern Android apps due to outdated CPUs" (https://news.ycombinator.com/item?id=44884709)
  • valgaze34 minutes ago
    Hmm:

    “F-Droid is not hosted in just any data center where commodity hardware is managed by some unknown staff. We worked out a special arrangement so that this server is physically held by a long time contributor with a proven track record of securely hosting services. We can control it remotely, we know exactly where it is, and we know who has access.”

    • skiing_crawling10 minutes ago
      I never questioned or thought twice about F-Droid's trustworthiness until I read that. It makes it sound like a very amateurish operation.

      I had passively assumed something like this would be a Cloud VM + DB + buckets. The "hardware upgrade" they are talking about would have been a couple clicks to change the VM type, a total nothingburger. Now I can only imagine a janky setup in some random (to me) guy's closet.

      In any case, I'm more curious to know exactly what kind hardware is required for F-Droid, they didn't mention any specifics about CPU, Memory, Storage etc.

    • IshKebab29 minutes ago
      "F-Droid is not hosted in a data centre with proper procedures, access controls, and people whose jobs are on the line. Instead it's in some guy's bedroom."

      Not reassuring.

      • TomatoCo18 minutes ago
        In some respects, having your entire reputation on the line matters just as much. And sure, someone might have a server cage in their residence, or maybe they run their own small business and it's there. But the vagueness is troubling, I agree.

        A picture of the "living conditions" for the server would go a long way.

      • gpm5 minutes ago
        Eh...

        The set of people who can maliciously modify it is the people who run f-droid, instead of the cloud provider and the people who run f-droid.

        It'd be nice if we didn't have to trust the people who run f-droid, but given we do I see an argument that it's better for them to run the hardware so we only have to trust them and not someone else as well.

      • ugh12321 minutes ago
        The 'cloud' has come full circle
  • NoiseBert6940 minutes ago
    So.. what kind of hardware did they buy?
    • IshKebab26 minutes ago
      Yeah kind of conspicuously absent! They said

      > The previous server was 12 year old hardware

      which is pretty mad. You can buy a second hand system with tons of ram and a 16-core Ryzen for like $400. 12-year old hardware is only marginally faster than a RPi 5.

      • cvwright2 minutes ago
        Unfortunately you can’t even get the RAM for $400 anymore.