Hacker Newsnew | past | comments | ask | show | jobs | submit | dmantis's commentslogin

What's wrong with having more sovereignty over your data and infrastructure? You don't need to stop working on the mentioned issues together but cutting foreign spies the access to your citizens data and reducing their leverage.

That's life, spies going to spy, state psychopaths from the military and the three-latter agencies exist regardless whether you see them or not and they don't care about the "common good". They must be taken into the account.

The less power humans have over each other - the better. Instead of pressuring each other to bring profits people would be able to speak like equals.


Sometimes you just can't.

For example, the banking app I have refuses to be installed from the Play Store on GrapheneOS due to "not-certified" device, but works perfectly fine when installed by Aurora.

The check seems to be purely store-based and never enforced later.


I have similar problems installing region locked apps as someone who's fairly frequently in different regions.

This is exactly why I switched to Aurora. I couldn't even install Balatro from the Play Store.

Same. Twint (basically the Swiss Venmo) insists that my phone is not compatible with it.

But using Aurora I can install it just fine and it works flawlessly.


Do you trust the banking app installed from Aurora enough to do your online banking? I don't, and I really wish there would be a decent way to verify that the installed/provided apps are legit. For me this is the biggest downside of using GrapheneOS, which I'm otherwise extremely happy with.

(for me, the whole point of using GrapheneOS is privacy and not sending data to Google, so using the PlayStore is not an option)


Android apps are signed. Can't you verify the signature?

Can you?

I'm pretty sure if I try calling my bank or searching the website to confirm the developer's public key fingerprint, there's not going to be any answer. You have to ask Google's servers to give you the APK and trust what it gives you, either via the front-end called Aurora or the front-end called Play Store


Privacy Guides is building a database of signing keys with a verifier app:

https://github.com/privacyguides/verified-apps-android

https://github.com/privacyguides/verified-apps/

I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.


Maybe not in practice, but in theory, it works. I don't think there's a better way of handling this without relying on some centralised authority (Google) to validate the authorship of an app, which is hardly desirable.

Doesn't AppVerifier allow you to do just that?

Doesn't Aurora download the packages directly from Google?

Presumably the parent does not want to have to trust Aurora to do that

> Single developer projects can build to the caliber and consistency of large development teams.

Yet the simple blog website static page saying that looks very weird and broken on the desktop firefox.

How large should be a development team to make proper margins in 2026?


I was a little "what a weird nitpick" then I opened it on FF and yeah... that's awful.

Normally I'd just switch into FF reader view when it's that badly done but that doesn't work either.


I looked at it on my out of date FF and it looks fine.


I looked at it on firefox and it looks fine. I wonder why it's off for some people


Looks fine in my Firefox. The text size is smaller than in Safari, but it’s fine.


Could this be an extension? I already have a <meta tag name="darkreader-lock">, but I'm not sure what extensions are common in firefox


Large development team... that is exactly the problem. The more effort and code put into it the worse it gets. Peak web was one webmaster per site, doing it by hand.


Looks fine on ff, and the same as other browsers. You sure the issue isn't in your end?


Well, who knows, but in brave it looks alright, and ff for me has extremely narrow text with disproportionately huge images. I see a few upvotes so I assume at least some other users have the same.


Direct Actionable feedback. Thank you. The text is trying to folow the seven to ten words per line rule.

This is my first blog post with graphics. so your comment helps me guage proportions


> weird and broken

Weird, yes. Broken, I don't think so. Seems to just be a matter of taste.


If it's not rendering as intended across all browsers, I'd call that broken. If it renders as intended and just look bad, that's taste.


It's hard to say since the gp didn't specify what they thought was broken.

The overall layout is fairly odd & weird - but it's the same in Chrome & Firefox. There is one technical bug with the main body font-size - it uses some invalid syntax (should be invalid in both Chrome & Firefox) & Chrome seems to be accepting it (against spec). The rule:

  font-size: clamp( 1.125rem, 1.125rem + (1.333rem - 1.125rem) * (100dvw - 24rem) / (80rem - 24rem), 1.333rem );
Firefox drops it & falls back to the default body font, making the article text slightly smaller. But it's definitely not a layout-breaking bug.


Whats wrong with the font size exactly? Im not a desktop to check it but its look fine? A bit unusual but I wouldn’t say a clamp with a bunch of math is invalid.


for me it's just a slight reduction in the font size due to firefox ignoring the above - which doesn't seem enough of a difference to warrant folk calling it outright "broken"

It's entirely possible I'm misreading the spec on clamp() but as far as I understood it, clamp() performs math on a bunch of comma separated fixed values, calc() handles arithmetic operators - this seems to be combining those without a calc invocation, but maybe I misread & overlooked clamp arithmetic operators. Firefox just says it's invalid, no detail on why.


This problem is easily solved. "Check that the blog looks the same in XYZ browsers".

I have LLMs align stuff for me all the time because I'm too lazy. It takes the screenshot, changes the code, code auto reloads and boom, done.


Sure. However I have a strange feeling when I read all AI praises and how productive everyone is while seeing more and more broken things everywhere. Sometimes from the same very productive people. Otherwise we might have said that maybe broken stuff goes from AI-deniers.

If everyone is doing the job of hundreds, extremely productive and everything is so easily fixed, why everything feels so slow and broken, even so basic things? That's kind of the point. I'd expect nearly perfect websites everywhere, especially from "productivity" people who mastered the flow.


> If everyone is doing the job of hundreds, extremely productive and everything is so easily fixed, why everything feels so slow and broken, even so basic things?

This doesn't make sense. There were slow and broken things before AI. This was true even when the things were made by hundreds or thousands of engineers.

If an organization doesn't care about making their app or site fast or correct, then unless they have a truly ludicrous amount of free manpower (more than is available now with AI, because review and architecture are still bottlenecks), it probably won't happen.

AI doesn't change this. AI doesn't change the priorities of an organization, it just changes how quickly and cheaply they can build. And every org has a point in their priority queue where things are no longer worth it to spend resources on.

If Venmo didn't care about making their login page work well with Firefox (which, in my experience, they don't) before AI, why would you expect it to be better with AI?


I think what you're seeing is A LOT of moving fast that wasn't possible before. When you move fast, you break things.

Where it would take 6 hours to make a first cut of a static site, you can now do that in 15 minutes. Obviously that's not going to be perfect.


Yes, something like this is a good skill for me to add to the critic phase. This is my first post with the blog redesign, and I will admit I am 100% using hacker news as QA.

Excellent feedback, Thank you.


please upvote then, people are downvoting because they don't like that it works.

Do large development teams care about Firefox?


Article literally says it adds a guid, not a binary field indicating that the image is ai generated.


A guid isn’t a user id, if it is in this case, it’s an abuse of how guid is used, at least colloquially. I haven’t read enough to understand if it is user / machine id, I.e. only globally unique in the sense it’s a globally unique entity identifier.


Microsoft Can Track Users via a Windows Device ID https://news.ycombinator.com/item?id=48815196

Microsoft GDID telemetry includes full browsing and gaming history https://news.ycombinator.com/item?id=48787239


They stated the GUID is used to identify the prompt used to generate the image. How are you confused as to not being able to identify the user?

"I haven’t read enough to understand". Oh, now I know the answer to my question


It became much easier to make open source too.

The current biggest problem is reputation and QA. Ie I see hundreds of same kind of apps when I search for open source stuff on F-Droid, but I can't really say whether it was properly audited with current influx of vibe-coded stuff, whether it contains malware, is it fully vibe-coded or human evaluated the result, etc. which one of those hundreds is actually good?

When we solve the slop recognition problem, we can actually see a positive turn from enshittification, because copying products overnight without spyware became almost trivial.


LinkedIn users made slop long before LLMs, what would be left if the platform removes such a content?


They'd still have a job board with the world's most useless search algorithm


I have a good experience with Huawei Band. Huawei doesn't even require to pair the watch with an official app! So I never connected it to the Internet or installed their app, paired directly with gadgetbridge from the first day.


Amazfit required a one time registration to get a one time code to unlock things, but I used a throwaway email id, and then deleted their app immediately. After that point the watch only syncs with gadgetbridge. The best part is that the watch has no internet capabilities, and gadgetbridge itself doesn't have internet permissions either so you know that absolutely no data can leave your device


I haven't encountered such a thing on private trackers for a very long time. Like, for years.

They usually have a very decent moderation and if they say that an entry has some particular resolution/subs/audio then it has it.

Sure, you have to stay as a seeder for some ratio/period in such trackers and can't hit-and-run, but it gives a warm feeling of contributions anyway.


The API behaves this way:

> To request a user's age range and sharing status, you call the Play Age Signals API (beta) from your app at runtime. The default age ranges the API returns are 0-12, 13-15, 16-17, and 18+, but you can receive custom age ranges.

https://developer.android.com/google/play/age-signals/use-ag...

But I don't find it any better. I don't see any viable reason to provide identification to my phone's OS. If a parent buys a phone for their child, they can already set up parental controls before handing it over.

I wish Motorola all the best with their GrapheneOS partnership.


You can also get GrapheneOS right now on Google-branded hardware, which is expensive but not enshittified.


True. Though I have mixed feelings buying new pixel from Google after all these actions.


Then buy a used or open box one. There's plenty of people who try switching to Android and buy Pixels, but go back to their iPhones in a week.


I don't. When they start making shit hardware, stop buying their hardware. As long as it's good, buy it. That's a free market price signal.


I don't think there's enough GrapheneOS users to make a 'free market price signal' here


I'm going to stop visiting the restaurant that makes the best food to spite them because I don't like their delivery policies, even though I'm going to eat inside.


>which is expensive

The rumored Motorola devices are even more expensive. It's the signature and some foldables, all in the 1000+ MSRP range. At least with pixels you can get the a series for as little as 400 on sale.


If you buy one of the Motorola Grapheneos phones, you're gonna be marked. You will stand out in the crowd. It has happened before and will happen more frequently as the world becomes more authoritarian.


Oh but “the government already knows everything” as all the other privacy doomers like to say. “They” can probably already predict what phone you’re going to buy and what you’re going to eat for lunch, right? So why worry about this?


On the other hand, privacy becomes a luxury. People love signaling their status and standing out from the crowd. Entire car and clothing brands exist solely because of that.

And if enough people stand out, it doesn't matter anymore.


Yes, people can tell a phone is running Graphene. They just can't get in.


LineageOS is still a thing too.


But not in the same league as GrapheneOS.


Apparently, looking at Iraq and Vietnam, US citizens only believe in "personal freedom, freedom of speech, freedom of religion and the value of human life" when it comes to US citizens, not to humans in general.

Even on HN, I saw a lot, that when people discuss surveillance topics, they argue whether ie NSA can spy on Americans, not on everyone. Mostly, nobody even question the human rights of those inferior humans abroad.

That's a very long wiki page, I must say: https://en.wikipedia.org/wiki/United_States_war_crimes

So the question stays open.


Vietnam and Iraq were both unpopular wars in their own ways, so they don't seem like good examples if you're trying to find examples of what US citizens support.

Also, a country surveilling its own citizens has unique and different implications compared to surveilling other countries. Citizens need to be able to influence their own government, but mass control can nullify citizen power entirely which becomes its own problem.

Then, on a US website, you link to another US website which keeps track of various war crimes. Try finding an equivalent website for China in China, or for Iran in Iran. This is part of the asymmetric freedom issue on the internet that many people ignore. There are a lot of lies and propaganda spread within other countries that censor and deny some types of information from even existing, then they use that as a springboard to spread it around the world.

In the US, we can criticize ourselves which is important, since it helps us improve.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: