reshared this
Google has news on what you will need to do for still being able to sideload apps:
* enable developer options
* confirm that you are not tricked
* restart phone and re-authenticate
* wait one day
* confirm with biometrics that you know what you are doing
* decide if you only want unrestricted installs for 1 week or forever
* confirm that you accept the risks
* enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
Android developer verification: Balancing openness and choice with safety
News and insights on the Android platform, developer tools, and events.Android Developers Blog
reshared this
Jiří Eischmann, Justin Macleod, Peter Vágner, Hubert Figuière, Jonathan and Mathijs reshared this.

they're stepping back a lot so the pushback is clearly working, keep it up until we get rid of this entirely 
i must admit, this is a lot better than what i thought their "advanced flow" would be. don't give them a single inch though, if this is implemented it'll be the first step towards fully killing off installing the apps you want to use on your device that you paid for 
@dusk chaos.social/@grote/1162577421…
@millihertz for all apps you will ever want from F-Droid? And their updates?
Sensitive content
I'm very thankful to google for covering the incredibly common case where I'm forced at gunpoint to install a malicious apk. Now such attacks will require attackers to kidnap me for a couple of days, which severely limits their options.
We can finally break the cycle of coercion where after being scammed into installing an apk, I started scamming people into installing apks.
Sensitive content
"In these scenarios, scammers exploit fear – using threats of financial ruin, legal trouble, or harm to a loved one – to create a sense of extreme urgency."
In these scenarios, Google exploits fear – using threats of financial ruin, legal trouble, or harm to a loved one – to justify taking control over your phone.
"According to a 2025 report from the Global Anti-Scam Alliance (GASA), 57% of surveyed adults experienced a scam in the past year, resulting in a global consumer loss of $442 billion."
We don't have any data on harm being caused specifically by sideloading apps, so here is some completely unrelated data that is very worrying.
wow. for a second i thought this was satire, but then i clicked on the link and it's literally as you say.
why do i have a feeling this is not really about security?
@LexYeen it's almost possible to make up a definition which would let someone pretend it has historical roots:
"it's called 'sideloading' because you used to install software by sticking floppy disks into the side of the computer."
maybe Google just doesn’t like developing android anymore and want an excuse to stop having to update it (no more userbase)
how long before banking apps refuse to run with app freedom ("side loading") enabled.
Watch 'Damn your drunk tests are hard.' | The Man with Two Brains Clip
Watch the clip 'Damn your drunk tests are hard.' from the movie The Man with Two Brains on Clip.Cafe. Dr. Michael Hfuhruhurr: Damn your drunk tests are hard.Clip.Cafe
Sensitive content
Sensitive content
Long live DuckDuckGo. Long live Vivaldi.
The open sources are out there . . .
(Also, big praise for Lenovo's ThinkPad, who said to Microsoft, "let's call the whole thing off.")
linkedin.com/posts/stevenstone…
Lenovo Switches to Ubuntu or RedHat on Thinkpads | Steven Stone posted on the topic | LinkedIn
Lenovo is switching the default OS on Thinkpads and Thinkcentres to either Ubuntu or RedHat. You can pay more for the Windows 11 option if you want. Personally, I think that this is the most beautiful and hilarious thing ever.Steven Stone (LinkedIn)
This is still bad, and I don't want to downplay that, but it's a one-time thing users of F-Droid or other non-Play app sources will do once when setting up their phones and be done with. It's what I expected, and nowhere near as bad as being completely locked out or forced to go thru a waiting period/exemption process each time.
Still, we should continue to push back for a better outcome. Like dropping this nonsense entirely.
Yeah, yeah . . . Facebook said META would rule too.
Meanwhile, Lenovo, a major player, says 'Nuh-Uh" to Legacy defaults for Microsoft— with detailed performance reasons.
Ubuntu is their default OS, now . . .
ok, what's freaking funny is this act is required UPON TURNING ON DEVELOPER MODE. Imagine if you need to do this every time you need to turn off developer mode because some banking apps check for developer mode. THIS IS HORRIBLE.
If you want to limit app installation, don't limit developer mode. Adb is borderline not ok but still, something else. Maybe this is only required if you need to enable app install from untrusted sources apk.
wow that wording feels so much bullshitty
removing all the bullshit would probably leave you with “… a … a … a …” removing also spaces would summarise my feelings about this: aaaaaaaaaaaaaaaaaaaaaaa!

youtube.com/watch?v=Urixf-E6SW…
DS9 Scenes - Allamaraine!
S01E09 - Move Along HomeCopyrighted material used without permission and without monetary gain. Any potential ads on this clip are not mine.Count to four. T...ManticoreEscapee (YouTube)
2. Make it look like a security and safety feature
@grote
taking the freedom slice by slice.
Somehow reminds me Xiaomi phone "e-waste" laying in the shelf, where I needed to wait 3 weeks, with SIM card in it, but it doesn't unlock anyway because "unknown reason". I'm sure it's intended to make me more safe!
For the first phase, one day wait is good start to get there.
we're voting with our wallets, invest some of your time into checking out alternatives to Android and iOS, look at what mobile Linux can offer, good potral to get overview is linmob.net/
If you develop app, there are lot of ways to easily port apps to (mobile) Linux too.
#MobileLinux #LinuxMobile #Mobian #postmarketOS #NixOS
LINux on MOBile
LINMOB.net is a blog about LINux on MOBile devices. With the PinePhone (Pro) and Librem 5 shipping it is back to report on GNU+Linux on mobile devices.LINux on MOBile
I don't know, the one big annoying hoop seems like the one day wait, the rest is a bunch of "are you sure" style confirmations to make sure you're the one that wants this and not the scammer on the phone, and I understand what the day wait is for.
If I want to use F-Droid, waiting a day during initial set up sucks badly but after that I can use it indefinitely.
It sucks ass that we have this flow put in front of app installation but for what it is I feel it's pretty low friction.
wait an entire day??? confirm that you only trust it for one week???
holy fuck it's actually worse than iOS. I didn't think it could get worse than iOS
Google is getting close to being as shitty though!
Moving the goalposts. Then in Android 21, they'll expire sideloaded apps not used weekly and delete them for security purposes, Android 24 they'll require users to legally identify themselves to even kick this off, Android 26 even looking at this process means your phone will do a factory reset in 3 months, and Android 28 you can sideload three apps in your entire account's lifetime before it is unavailable to you ...forever.
Fingers crossed, we're looking at a timeline where even this gets monetized: Android will instead sell developer kit devices for $20,000 a year by Android 30, restricted only for use to registered developers.
At that point, Apple will be a more open ecosystem, who is already eating their lunch today.
Let's work towards good Android app support for #LinuxMobile 📱 so we can benefit from the nice #FreeSoftware apps that are there and being developed without having to worry about what Google does.
this seems fine to me. You can use this to essentially side load 3rd party app stores like F-Droid.
And then use those stores to install apps via those.
So developers make apps for those stores, users side load the stores themselves.
Of course the developers for the actual stores will still have to juggle this. But I don't see why it needs to be an issue for most android developers, when they can just develop their apps and have them put on places like F-Droid and others.
@r3spawndbae It's not okay. Because how exactly do you install F-Droid in the first place without waiting 24 hours?
Even unlocking the boot loader of a phone is faster than this, and all just to prevent people from installing software on the devices they own...
ahah what ? ><
This shows that Google is either a) ignorant to how scams work or b) playing dumb to mislead people into thinking this isn't about them tighting their control over distribution.
I also feel like the 24 hour wait is a DMA violation so wouldn't fly in the EU.
Does this help, though? Because the moment someone makes a “Android improvements self-guide” app and puts that in the playstore, the attackers can just link to that and let the victim follow the instructions.
Note how that app doesn't even need to get malicious – the process is tricky and lengthy, I think there could be some value in having an app to remind you that you can now continue with step 3 (or even show a countdown).
In case the app is permitted to exist, someone would abuse it / embed a similar thing in an actually malicious app. If it is forbidden to exist, then (a) google would be censoring apps without warrant, which feels to violate antitrust laws, and (b) given that playstore has a record of malicious apps, that app would exist on playstore probably anyway, solving nothing.
This feels like a security theatre play noone should buy tickets for…
#marschine 19 Under a New Moon. New Moon in Pisces on the spring equinox. Trap drums, bells, a vocal offering, and a reverse synth that opens like a door with no handle. Something begins tonight whether you're ready or not. #trap #hiphop #beats #maschine #instrumental
Peter Vágner likes this.
Peter Vágner reshared this.
Episode 14: Press Start to play: Levelling up Gaming through Accessibility | EBU in action
The videogame industry has grown massively during the last decades. Bearing in mind all the developments in this domain, we ask ourselves: how can blind and partially sighted people enjoy Gaming on an equal basis with others? We explore this subject…Podbean
reshared this
Peter Vágner, Andre Louis, Jason Fayre, Oskar, Pitermach, Jonathan and Patryk Mojsiewicz reshared this.
Episode 14 of (EBU in Action) "Press Start to play: Levelling up Gaming through Accessibility." ebuinaction.podbean.com/e/pres…
Transcript: euroblind.org/sites/default/fi…
#Gaming #Accessibility
Episode 14: Press Start to play: Levelling up Gaming through Accessibility | EBU in action
The videogame industry has grown massively during the last decades. Bearing in mind all the developments in this domain, we ask ourselves: how can blind and partially sighted people enjoy Gaming on an equal basis with others? We explore this subject…Podbean
reshared this
Peter Vágner reshared this.
What's that sound? Darude - Sandstorm
🎛️ Get our Ableton devices here:https://buymeacoffee.com/mixedsignals/extras☕️Support our channel:https://www.patreon.com/mixedsignalshttps://www.buymeacoff...Mixed Signals (YouTube)
Peter Vágner likes this.
Peter Vágner reshared this.
GitHub - amanKG777/Quizzy: code for the quizzy project
code for the quizzy project. Contribute to amanKG777/Quizzy development by creating an account on GitHub.GitHub
reshared this
Peter Vágner, Keao Wright and Zach Bennoui reshared this.
windows, installer: github.com/amanKG777/Quizzy/re…
windows, zip: github.com/amanKG777/Quizzy/re…
android: github.com/amanKG777/Quizzy/re…
GitHub - IhorShevchuk/piper-app: The original Piper, now on iOS and macOS
The original Piper, now on iOS and macOS. Contribute to IhorShevchuk/piper-app development by creating an account on GitHub.GitHub
reshared this
🇨🇦Samuel Proulx🇨🇦 and Peter Vágner reshared this.
Piper - Neural TTS | AppleVis
Bring clearer, more natural voices to VoiceOver with modern neural speech technology. Piper – High-Quality VoiceOver Voices Piper is a modern text-to-speech solution that brings natural, expressive neural voices to your device.www.applevis.com
reshared this
Peter Vágner and Andre Louis reshared this.
Actually, even if you don’t care about #UnifiedPush, having this minimal #Prosody server that just accepts messages via a simple REST API and sends them out via #XMPP is great alternative to the various sendxmpp scripts out there.
gultsch.de/posts/xmpp-via-http…
Sending Jabber/XMPP messages via HTTP
The goal of this tutorial is to set up a simple REST API that allows you to send XMPP messages to an existing XMPP account. This can be easily integrated into monitoring solutions or other scripts that send out status information.Daniel Gultsch
Peter Vágner likes this.
Peter Vágner reshared this.
GitHub - matterbridge-org/matterbridge: Multi-protocol chat bridge (IRC, Matrix, XMPP, Discord, Telegram, etc…)
Multi-protocol chat bridge (IRC, Matrix, XMPP, Discord, Telegram, etc…) - matterbridge-org/matterbridgeGitHub
The great Andre Louis @FreakyFwoof takes us on a tour of Move and its accessibility features.
Who should watch this: everyone. Sighted people, to understand these needs. Move fans, to check out Andre's awesome demo of Move Everything features. Sighted developers of hardware and software, to understand needs of the visually impaired.
cdm.link/move-everything-visua…
With everything else going on in the world, making music more open to everybody seems even more valuable.
Video guide to accessibility in Ableton Move, Move Everything - Andre Louis - CDM Create Digital Music
Unofficial screen reader support in Ableton Move may be new, but it's already a revelation. Andre Louis, a visually impaired musician and technologist/artist extraordinaire, takes us on a tour of Move Everything.Peter Kirn (CDM Create Digital Music)
reshared this
Peter Vágner, Andre Louis, johann, Derek Lane and Zach Bennoui reshared this.
Pushed #nvdaComposer 1.5.1 to fix an error with exporting very large.rng compositions such as the fantastic one done by @batworx which is now in the demos folder accessed with CTRL+Shift+O. You must check out his version of 'Bouncing Round The Classroom' which I wrote many years ago.
Update 1.6.0:
• Added F8 to cycle the live playback engine while in the composer window.
• Playback modes now cycle through NVDA tones, smooth local audio, and Nokia-style local audio.
• The selected playback engine is stored persistently in NVDA’s configuration, so your last choice is remembered.
Playback engine toggle: Press F8 in the composer window to switch between the three live playback modes. The default remains NVDA tones.
This allows you to hear what your composition should sound like with the two export options before you do so.
Download: onj.me/nvda/nvdaComposer.nvda-…
Github: github.com/OnjLouis/nvdaCompos…
reshared this
Peter Vágner, johann and Onj 🎶 reshared this.
There is a little discrepancy with the #Foobar2000 mobile v2.26 beta that it display url encoded file names when browsing webdav shares that are not indexed into its media library. I am using it like this when playing my audio books / audio drama. If you are using Foobar 2000 mobile on android for playing media from webdav remotes, perhaps you can support my wish so this will be looked into at some point.
When browsing webdav shares folder names and file names are displayed correctly, url decoding is applied again.
The fifty year old Talking Clock Radio
In 1971 Panasonic Introduced the first consumer Talking Alarm Clock Radio, the RC-6900.Let's open it up and find out how it worked. --------------- SUBSCRIBE...Techmoan (YouTube)
reshared this
Peter Vágner reshared this.
Unbelievable, #Nextcloud seems to be finally getting repeated tasks feature. 🎉
Nextcloud's backend had no problem with repeated tasks. Syncing with webdav was completely OK.
But the web fronted couldn't reschedule and edit repeating tasks. It seems it will be fixed now.
Peter Vágner reshared this.
#marschine 07 They Flipped the Call, featuring @FreakyFwoof and @raywonder on the sample chop, which is a derivative of the Nokia ringtone. The iconic Nokia tune is based on a 19th-century guitar piece by Francisco Tárrega. Nokia licensed it in 1994, and it debuted on the Nokia 2110. By the late ‘90s, it was the world’s most-heard melody, ringing billions of times daily. Now it will ring in your head all day.
reshared this
Andre Louis and Peter Vágner reshared this.
Maschine From A Blindness Perspective
Sdílejte svá videa s přáteli, rodinou a celým světem.Izzie G (YouTube)
My colleague Tiago posted about some of his recent work at @igalia on PDF accessibility:
vignatti.com/posts/accessibili…
Accessibility and PDF documents
Accessibility # When we think of accessibility, we tend to picture it as something designed for a small minority. The reality is much broader: 16% of the world’s population — 1.3 billion people — live with a significant disability¹.Tiago Vignatti
reshared this
Peter Vágner reshared this.
Unison is an open-source file synchronization tool that keeps two folders on different devices in sync.
Unlike traditional backups, it supports two-way synchronization, so changes on either side can be safely propagated.
Works across Linux, macOS, and Windows, and typically syncs data securely over SSH.
👉 github.com/bcpierce00/unison
More privacy-friendly tools curated at : digital-escape-tools-phi.verce…
#OpenSource #Privacy #SelfHosting #FileSync #FOSS
Digital Escape Tools – Privacy & Security Software 2026
Discover the best privacy tools and secure software in 2026. Open-source apps, encrypted services, and guides to protect your online privacy and fight surveillance.digital-escape-tools-phi.vercel.app
reshared this
Jonathan, Izzie G 🌕♾️, Tissman, johann and Peter Vágner reshared this.
I see a lot of posts on my feed expressing various ethical and pragmatic concerns about AI. And I see quite a few posts from other disabled people along the lines of "stop telling us not to use AI when it's helping me fix accessibility issues that you've never done anything to fix."
I worry about the ecological effects of AI's need for resources in the aggregate, but a few disabled people making use of it isn't going to make a meaningful difference, and I get the argument that we need all the help we can get. So I am not going to tell someone else whether to use it or not.
Whether it is helpful is a more complicated and nuanced question, and I think that it will depend on the context.
I've been avoiding it mostly for reasons specific to me--I just vaguely feel like I don't know how, and it normally wouldn't occur to me to use it. I feel like I wouldn't know what to give it for a prompt. So, admittedly, I'm not the best person to be giving opinions.
I wrote about it at the time, but, a few months ago, someone gave me an AI-assisted patch for a bug in my module. At first I was impressed, and I still am to some extent, but the patch was later found to have problems, and the person came back with a revised patch. That, too, caused problems. I eventually removed all of the complicated code that the AI added and solved the bug with just a few lines of code. To be fair, the AI patch helped me to figure out how to think about the problem. So that was my first impression.
reshared this
Matt Campbell and Peter Vágner reshared this.
reshared this
Mike Gorse, Matt Campbell and Marek Macko reshared this.
@Thumper1964
I guess what most bothers me is when people, purposefully or otherwise, underestimate/misstate the amount of work they themselves are putting in to get a particular result,
e.g., ignoring how many prompts they had to try, or ignoring the effort they themselves had to put into cleaning up what the agent produced in order that it would actually work...
... and maybe it's indeed better than having to write from scratch -- just like when I find something on search that gets me 30% of the way there, that's better than nothing -- or maybe the agent inspired something they wouldn't have thought to try otherwise,
but they're still having to do work, and when they credit it *all* to the agent, that's a problem.
@Thumper1964
> but they're still having to do work
and I'd even go so far as to say they're doing *all* of the work that involves actual thought, because the agent is inherently incapable of that part.
Mike Gorse reshared this.
@ppatel Having used AI to build a cognitive support system for AuDHD* and cPTSD - I am absolutely not going to be down on it. It's all about appropriate use.
*AuDHD = autism + ADHD
This blog post recently crossed my timeline. blogs.gentoo.org/mgorny/2026/0… It talks about burnout among FOSS maintainers, which is an important subject.
It saddens me, though, that the author called out Rust alongside generative AI as a contributor to their own burnout as a distro maintainer, going back to the Python cryptography package's adoption of Rust in 2021. Is there anything that we who use and promote Rust can do about this, or is Rust just too at odds with the norms of Linux distros?
Money isn’t going to solve the burnout problem
The xz-utils backdoor situation brought the problem of FLOSS maintained burnout into the daylight. This in turn lead to numerous discussion on how to solve the problem, and the recurring theme was …Michał Górny
Peter Vágner reshared this.
Matt Campbell reshared this.
Rust has basically two things that make it "controversial".
One half is an artificial cotnroversy coming from the right-wing circles. It's purely political; I don't think anything can really be done about it.
The other thing is its particularly unusual handling of 'pointers'. That, something can be done against — just steal this neat idea for use in other contexts, and other programming languages. The more widely used it becomes, the less unusual it will be perceived as, and the lower adoption barrier it will be.
Remember when lambda expressions were highly unusual and "weird", until JavaScript put them into every browser?
Some distros also value long-time stability, and try to support old devices for as long as possible. This is something that the Rust community could address at the compiler level, but unless it shares the same concerns, this is unlikely to happen.
This value conflict is exacerbated by (a part of?) the Rust community aggressively wanting to re-write everything, even in the absence of issues. The coreutils debate is a good example.
Fix screen readers reading the wrong line on blank lines in textboxes (closes #7190) by trypsynth · Pull Request #11509 · dotnet/wpf
Fixes #7190 Description When navigating a TextBox or RichTextBox line-by-line with a screen reader (e.g. Narrator, NVDA), blank lines caused the next line's content to be announced instead of &...GitHub
Peter Vágner reshared this.
Just played around a little with ish (it's a Linux emulator for the IPhone).
For the moment, I wanted to be able to use the screen reader of my choice, even if I'm doing it remotely from another computer. So I successfully got a ssh server set up, following the instructions here: medium.com/@der.loste.kitkat/g…
My ssh connection goes away as soon as my phone locks. I haven't tried the workarounds described in that post for running things in the background; maybe that would have helped.
I wanted to see if sound was emulated. So I got amixer installed, but it didn't appear to detect any sound cards. So I'm guessing not.
So I would have to use VoiceOver I guess.
And, with VoiceOver, when I type a key, I get a lag of approximately a second before the key is echoed. (And it is not because I'm using a bluetooth keyboard--that might be a small part of it, but I don't get nearly as much lag if I'm, say, typing in the messages app).
So I don't really see myself using it, but trying it out has been interesting.
Peter Vágner reshared this.
Peter Vágner reshared this.
reshared this
victor tsaran, Andre Louis, Jonathan, johann, Peter Vágner and Zach Bennoui reshared this.
Project Load Warning dialog There were 3 elements in the project that were not understood. If this project was created in a newer version of REAPER, this version may not preserve all of the settings of the project.
Project tokens not recognized:
RULERHEIGHT
RULERLANE
youtu.be/Pkh2KaFy5M0?is=NMJcfy…
How a joke sound defined 90s rave
🎛️ Get our Ableton devices here:https://buymeacoffee.com/mixedsignals/extras☕️Support our channel:https://www.patreon.com/mixedsignalshttps://www.buymeacoff...Mixed Signals (YouTube)
Peter Vágner likes this.
Peter Vágner reshared this.
The official microG OS project (lineage.microg.org/) leaked their private keys for logging into their servers and signing releases:
github.com/lineageos4microg/l4…
We make our official builds on local machines. Our signing machine's keys aren't ever on any storage unencrypted.
December 2025 security issues
Contribute to lineageos4microg/l4m-wiki development by creating an account on GitHub.GitHub
reshared this
Jonathan and Peter Vágner reshared this.
@packet @alwayscurious See grapheneos.social/@GrapheneOS/… where we gave an explanation.
Our roadmap for improving security of verifying updates is based on taking advantage of the reproducible builds. We plan to have multiple official build locations and a configurable signoff verification system in the update clients also usable with third party signoff providers.
GrapheneOS (@GrapheneOS@grapheneos.social)
@eloy@hsnl.social We're going to be using the secure element on Pixels rather than the smartphone itself. Unlike commercial HSM products, the secure element on Pixels is heavily battle tested against a bunch of exploit development companies.GrapheneOS (GrapheneOS Mastodon)
@alwayscurious In addition to those 2 replies in that thread, here's another relevant one:
grapheneos.social/@GrapheneOS/…
@Canine3625 We have very little faith in the security of products from Yubico and other HSM vendors. We would consider it to be a downgrade from having the keys stored encrypted at rest on the primary build machine. The primary build machine being exploited would already be a disaster and needs to be protected against. Signing keys aren't actually super special compared to the security of the builds. We don't want to create a weak point for signing keys through an attempt at improving things.
@TheAlgorythm No, since Android's signing system trusts the output of the build so the only way to secure them more is running them in a container or VM with restricted access.
Android Open Source Project has an upstream container system for the build process although the intended purpose is not security. The purpose of their build sandbox is avoiding build determinism issues and also avoiding accidental damage being done to the host system or account.
Hi,
This is a new account, so I wasn’t sure where to ask this.
I noticed the NFC APK signing key was only recently added to the build scripts (a7b69d9). From what I understand, it was previously signed with the AOSP public test key.
Since those keys are publicly available, wouldn’t that be a security issue for a system component like NFC?
Was this communicated or i missed it, also to update ASAP?
github.com/GrapheneOS/script/c…
github.com/GrapheneOS/graphene…
Thanks.
add nfc key to generate release signing keys step · GrapheneOS/grapheneos.org@ecc26ba
Servers for our website, HTTP/HTTPS connectivity checks, HTTPS network time, NTP (for Qualcomm XTRA), Broadcom PSDS cache, Samsung PSDS cache, Qualcomm PSDS (XTRA) cache, SUPL proxy, attestation key provisioning proxy, Vanadium component update check…GitHub
@Occasion_Antique GrapheneOS blocks system app updates not done via OS updates or App Store. Android has a recent protection which stops this from being a serious issue itself too.
Handling the changes adding new keys for signing components within APEX modules was included in the release notes for 2026021200 and documented on the build page:
grapheneos.org/releases#202602…
> update release signing to handle AOSP APEX changes
We also made changes to prevent further added keys in AOSP regressing it.
GrapheneOS releases
Official releases of GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.GrapheneOS
Thanks for the clarification.
I was just worried after noticing the change.
You mentioned GrapheneOS blocks system app updates not done via OS updates or the App Store. Could you point to where this is enforced (code or docs)?
If someone got ADB access, would `adb install` still be blocked from updating a system component like the NFC APK?
A link would be helpful.
Thanks.
@Occasion_Antique Why would you be worried about this of all things that you could worry about? There are Critical and High severity issues being fixed on a regular basis. Why worry about a lightly privileged app?
> If someone got ADB access, would `adb install` still be blocked from updating a system component like the NFC APK?
No, but then they already have a lot more privileges than this app already. Android began blocking apps like this hijacking privileged permissions via shared UID.
github.com/GrapheneOS/platform…
It's only possible to update system components via App Store or ADB.
Android doesn't have verified boot for system APK updates but rather that's a feature added by GrapheneOS, so it only weakened a protection we added rather than a standard one.
github.com/GrapheneOS/platform…
This is a standard protection which prevents it from becoming far more privileged.
It was a minor issue and won't happen again when they quietly add more within-APEX APK keys again.
platform_frameworks_base/services/core/java/com/android/server/pm/InstallPackageHelper.java at 8209fe0ab30eaf097c380bb373bc6433b29c3556 · GrapheneOS/platform_frameworks_base
Contribute to GrapheneOS/platform_frameworks_base development by creating an account on GitHub.GitHub
Thanks, so its safe to use any recent builds right. I noticed the NFC key has been in AOSP for a while, More than 2 years.
Is there a reason this wasn’t handled earlier and only addressed recently? Even if its a minor issue.
This was never a practical issue. It's strange that you keep questioning whether releases are safe to use due to a minor issue which was present for a months and addressed a month ago.
We've been signing the NFC APEX with the main releasekey since it was introduced and it was still being properly signed. We didn't need to make a dedicated key for it until recently.
This only recently became an issue after Android 16. We now have detection for future AOSP key changes.
Since the NFC key has existed for a while, what changed in Android 16 that made this start being treated as an issue?
I’m curious about the technical reason for the delay in enforcing the dedicated key. Was this intentional, or was it simply missed until the changes in Android 16?
Reposted, as I see my messages are locked.
I appreciate the precautions already in place to prevent such APKs from being installed accidentally. Was it mainly missed because the AOSP signing script didn’t error when the key was missing and the build completed successfully?
I noticed bluetooth was handled earlier and NFC was added in the next Android version, how was Bluetooth noticed but not NFC?
github.com/GrapheneOS/platform…
I'm not trying to raise an issue or controversy. I’m just trying to understand how it was missed.
add bluetooth to standard key mapping · GrapheneOS/platform_build@c70f942
Make Build System (being phased out upstream). Contribute to GrapheneOS/platform_build development by creating an account on GitHub.GitHub
Also I saw the release notes, but the NFC signing change isn’t mentioned specifically. Is there a reason it wasn’t listed?
Thanks
That's one part of the change we listed. We determined it wasn't a serious issue and couldn't think of any relevant attack vector beyond a minor reduction in our added verified boot security. There are other cases where our added security features were found to have holes in them which we resolved. There's a fix for one of them in the latest release via closing an upstream hole in the INTERNET permission which impacts Network.
The NFC app is not the more privileged NFC code.
@Occasion_Antique There are Critical and High severity issues being fixed upstream on a regular basis. We also often have to patch issues we find in the AOSP code ourselves.
The NFC APEX itself was properly signed already prior to this. This was about a specific APK inside of the NFC APEX which they started signing with a new key. The way the signing scripts work doesn't result in them failing if more keys get added but not replaced which is something we've addressed for them now.
@Canine3625 For that purpose, you don’t need it to be more secure, or even for the key to be unexportable. The only requirement is that the key not be accessible through normal filesystem operations, so that things like a full filesystem backup don’t expose it.
The idea I had was not to mitigate a build machine compromise. It was to prevent the key from being leaked from an uncompromised build machine due to human error.
@alwayscurious @Canine3625 Trezor Safe 7 includes both their own open source secure element and an additional proprietary one where an attacker would need to compromise both:
SLIP39 is a very nice way to handle deriving keys with backups but it isn't really what we want for the release signing keys for the OS and apps. We want the flexibility to be able to use a different approach rather than being locked into the SLIP39 key derivation approach among other things.
Trezor Safe 7 | Hardware Wallet with TROPIC01 Secure Element
Secure your crypto with Trezor Safe 7—Bluetooth, high-res color touchscreen, and quantum-ready security.Trezor
Depending on how the system as a whole is designed, which I don't have details on, the concern I have with storing the keys on disk on a build server vs on a HSM attached to that server is that while compromising the build machine lets you make a build in either case. In the no HSM scenario you can run exfiltrate the key much more easily and then have a better shot at hiding the compromise.
Assuming that HSMs are perfect and nothing will ever go wrong is a bad idea, but if you assume they make compromise harder or more expensive then they still add security.
I don't find a lack of updatable firmware to be a particular issue on a device inexpensive enough to replace, especially when that replacement also means key rotation. Replacement isn't cheap, but it's also not that bad at least for a corporate environment.
@alwayscurious @Canine3625 the CEO of Ledger was kidnapped and maimed in an attempt to get to his cryptocurrency:
@idkrn @gravepapaya why? They get to sell new keys…
The last one, caused by bugs in an Infineon library, my former employer considered it low risk and did not replace the Yubikeys. I replaced my personal ones, despite not being a trillion-dollar company.
2. Users aren't not going to be happy about buying new keys when other keys allow for free updates
reshared this
D Whatson and Peter Vágner reshared this.
GrapheneOS Foundation Reporting On MicroG OS Project Leaking Private Keys
The official microG OS project (lineage.microg.org/) leaked their private keys for logging into their servers and signing releases:
github.com/lineageos4microg/l4…
We make our official builds on local machines. Our signing machine's keys aren't ever on any storage unencrypted.
Our roadmap for improving security of verifying updates is based on taking advantage of the reproducible builds. We plan to have multiple official build locations and a configurable signoff verification system in the update clients also usable with third party signoff providers.
We don't have faith in any available commercial HSM products being more secure than keeping keys encrypted at rest on the primary local build machine. Instead, we're planning to develop software for using the secure element on GrapheneOS phones as an HSM for signing our releases.
December 2025 security issues
Contribute to lineageos4microg/l4m-wiki development by creating an account on GitHub.GitHub
We don't have faith in any available commercial HSM products being more secure than keeping keys encrypted at rest on the primary local build machine. Instead, we're planning to develop software for using the secure element on GrapheneOS phones as an HSM for signing our releases.
reshared this
Peter Vágner reshared this.
Our response was, as it is in most cases to help educate people who use it and the OS ecommended by microG themselves since they have deeper microG integration than what's available in official LineageOS. It's an official part of the microG project and it reveals a lot about their overall approach to privacy and security in the project.
We are often asked why we don't implement it instead of sandboxed Play Services and this just goes to further reinforce that position.
reshared this
Peter Vágner and Matt Campbell reshared this.
Nah. It stopped sucking when Unicode became variable-width even in a 32-bit encoding. Or at least it no longer became valid to correctly point out that it sucks, since there now isn't anything that doesn't.
Every now and then the Cambridge CST exam papers include a question like "explain why even experienced programmers sometimes have problems with character codes".
You could write pretty well anything you liked.
Originally what was expected was an essay about things like escape sequences on Flexowriter tapes; in my day it was about conversion between EBCDIC and ASCII; these days it might be about obscure characters in URLs.
No hacking, no 3rd party software required. I had to do the upgrade in multiple steps for each major version upgrade seperate but still I am seeing this as a huge surprise.
I can run up to date software on par with todays security standards, even run services that were not available at the time of producing that device e.g. #wireguard. #tech #networking
😬.
Looks like abandoned. It won't be federating with many servers now since it doesn't support the new letsencrypt certs.
Peter Vágner likes this.
Peter Vágner likes this.
Peter Vágner likes this.
I've been using Linux on my personal machines since I was a teenager. Twenty-five years of desktops, from GNOME 2 to Sway. I felt the need to write about it.
tarakiyee.com/for-the-love-of-…
#Linux #Wayland #FOSS #OpenSource
For the Love of the Linux Desktop
🖼️Cover Photo: "Woman with wax tablets and stylus," commonly called Sappho. 1st century AD fresco from Pompeii. National Archaeological Museum, Naples.Tara Tarakiyee (Do Flamingos Know They're Pink)
reshared this
Peter Vágner reshared this.
reshared this
johann, Peter Vágner and Kaveinthran reshared this.
+421 918 123 456 Richard profylaktest_lumen_whatsapp_vysielanie 10:52 Pre viac možností stlačte kláves so šípkou doľava alebo doprava, čím otvoríte kontextovú ponuku 
#marschine 06 Coffee Beans. This one I made for a friend to chop up in to a different beat, and he did a good job doing so. Won’t post his with out asking, and I'd probably have to wait until #aprilton to post anyway, since he uses Live.
Peter Vágner reshared this.
For screen reader users, text-based multiplayer games (MUDs) are often easier to access than graphical games.
So why can playing one from a web browser feel harder instead of easier?
Brandon Cross (aka bscross) explains it all in this interview:
writing-games.org/accessibilit…
#MUDs #Accessibility #TextGames
Accessibility in a changing MU* landscape: an interview with bscross -
Long-time MU* enthusiast Brandon Cross talks about how far the hobby has come - and some of the accessibility hurdles that still remain.Andruid (Writing Games)
reshared this
Peter Vágner reshared this.
#marschine 04 Son of a Ghost Bitch! This is on the shorter side. This was made because I wanted to sample some random thing, and @Millerd16 was the random recording.
Peter Vágner reshared this.
reshared this
Zach Bennoui, Pitermach and Peter Vágner reshared this.
In case anyone wants an offline version, @jcsteh makes it very easy to save it, and you can go into the ssource and download the java script this depends on if you want that offline as well.
Ah, that's a good reason as any. I just left the version number out and it works a treat still, in case that is of any difference to you.
alternatives, I found markdownlivepreview.com/
and dillinger.io/
Online Markdown Editor - Dillinger, the Last Markdown Editor ever.
Dillinger is an online cloud based HTML5 filled Markdown Editor. Sync with Dropbox, Github, Google Drive or OneDrive. Convert HTML to Markdown. 100% Open Source!dillinger.io
WebRTC VST for VDO.Ninja
Audio-first VST3 bridge for VDO.Ninja. Stream or monitor live audio directly from your DAW.VDO.Ninja
Peter Vágner reshared this.
reshared this
Pitermach, Peter Vágner and Patryk Mojsiewicz reshared this.
ocean, earthquake / sea, earthquake. ign.com/wikis/little-alchemy/L…
Little Alchemy Cheats - List of All Combinations - Little Alchemy Guide - IGN
Stuck and need some Little Alchemy hints? IGN's Little Alchemy Cheats guide has you sorted with a massive list of more than 500 Little AlchemyIGN
Web #accessibility / #a11y people — any good resources I can link to on the problems with relying on LLMs for accessibility reviews?
I have concerns but I can't find a good summary. Initial searches have only found pages that support the idea more-or-less uncritically.
(Not saying absolutely that there *are* no potential positives — but the target audience already believes in the positives, so I'd like to introduce some balance.)
reshared this
Peter Vágner reshared this.
With the proviso that I think LLMs have important and possibly irreplaceable (with current technology) accessibility uses:

Kaveinthran
in reply to Elijah Massey • • •Would you willing to host them if I can send you? The creators are giving it for free, or I can give you the creators username for you to get it from them and host it for our Blind community
Orrock LXXXVI XLVII
in reply to Elijah Massey • • •Elijah Massey
Unknown parent • • •Kajetan Hundhammer
in reply to Elijah Massey • • •While I was making the kids' lunch boxes and dropping off the middle one at work, I gave it a listen.
And I have to say: Guys, this is really good! If you like audiobooks and/or The Lord of the Rings, give it a listen.
Thank you @emassey0135
#lotr
Jane
in reply to Elijah Massey • • •bazbt3 🦣
in reply to Elijah Massey • • •@WeirdWriter Thankyou. I just need to make the time.
(Only listened to the first minute, but for me it's enough).
Elijah Massey
in reply to Elijah Massey • • •The Silmarillion Musical Study Guide : Tolkien : Free Download, Borrow, and Streaming : Internet Archive
Internet Archive