Remix.run Logo
troyvit 8 hours ago

It's like ya'll are so eager to crap on a thing that you don't even read tfa.

> this server is physically held by a long time contributor with a proven track record of securely hosting services.

So you are assuming it's a rando's basement when they never said anything like that.

If their way of doing business is so offensive either don't use them, disrupt them or pitch in and help.

> I understand this is a volunteer effort, but it's not a good look.

What does make a "good look" for a volunteer project?

well_ackshually an hour ago | parent | next [-]

> this server is physically held by a long time contributor with a proven track record of securely hosting services.

This is effectively a rando's basement. It doesn't matter that they've been a contributor or whatever. Individuals change, relationships sour. Securely hosting how ? By locking the front door ? By being a random tech company in the midwest ? Or by having proper access control ?

As a little reminder, F-Droid has _all_ the signing keys on its build server. Compromising that is somewhere between "oh that's awful" and "stop the world". These builds go out as automatic updates too. So uh, yeah, I'd like it if it was hosted by someone serious and not my buddy joe who's a sysadmin don't worry

jabwd an hour ago | parent [-]

> This is effectively a rando's basement. You. Do. Not. Know. Stop straw-manning stuff its so pointless.

wtallis 8 hours ago | parent | prev [-]

> What does make a "good look" for a volunteer project?

It's an open-source project. It should be... open. Not mysterious or secretive about overdue replacements of critical infrastructure.