Would you trust an open source software maintained by a developer who you disagree with politically (or otherwise don't like the developer)?
-
Well, you may be surprised then to find it's being funded by NLnet, which apparently gets its money from the EU.
That doesn't mean it's not also funded by China or Russia. They've been able to work on Lemmy for a while without much public funding.
-
I kinda doubt it. Let's not forget this is a global community, and Marxism-Leninism has different levels of support in different parts of the world.
If this was a state-funded project, I think the development would have gone a lot more swiftly, and the leads would be even more puritanical in pushing their beliefs. As it is, I've argued pretty extensively from a liberal perspective on .ml before, even personally with dessalines, and while they don't exactly love me over there, I'm careful to respect their rules and they haven't banned me.
I think they really are just idealistic supporters of communism, mostly from places where that's a little more common.
wrote last edited by [email protected]If it was state funded by a functioning state I would agree with you, but I wouldn't be surprised if Russia was kicking these guys a modest living to undermine American social media companies.
I mean, I got banned personally by Dessalines from lemmy.ml for mildly suggesting that a meme felt like it was a Chinese op designed to provoke in-fighting in western countries.
Not rudely, not aggressively, literally just questioning whether it could be in the comments below.
-
I kinda doubt it. Let's not forget this is a global community, and Marxism-Leninism has different levels of support in different parts of the world.
If this was a state-funded project, I think the development would have gone a lot more swiftly, and the leads would be even more puritanical in pushing their beliefs. As it is, I've argued pretty extensively from a liberal perspective on .ml before, even personally with dessalines, and while they don't exactly love me over there, I'm careful to respect their rules and they haven't banned me.
I think they really are just idealistic supporters of communism, mostly from places where that's a little more common.
Not to mention wheres all the disinformation campaigns? It only started to get bad recently on Lemmy.
-
"Trust" as in: trust it enough to run it on your machine.
(And assuming that you can't understand code yourself)
If I know someone's political affiliation prior to using their software I'll likely find an alternative if their views are harmful.
-
jdupes: it's great software. The author left GitHub not because of Microsoft, but because he refused to implement 2fa on his account, which GitHub made mandatory.
His website has some wild ranting about codeberg too. I've been tempted to stop using jdupes.
-
If it was state funded by a functioning state I would agree with you, but I wouldn't be surprised if Russia was kicking these guys a modest living to undermine American social media companies.
I mean, I got banned personally by Dessalines from lemmy.ml for mildly suggesting that a meme felt like it was a Chinese op designed to provoke in-fighting in western countries.
Not rudely, not aggressively, literally just questioning whether it could be in the comments below.
Yeah, I won't say it's impossible or anything. I just think there's other reasonable explanations too.
Personally I just avoid mentioning China when I'm over there. lol It's easier to keep everything civil if you avoid naming names, and China is a particularly sore spot for them. You also can't forget that free speech is not a foundational part of their ideology like it is ours. They're more about seizing the means of production than the free contesting of ideas.
It does feel a little like walking on eggshells.
-
He lied about stopping use of GrapheneOS. He can be seen in videos long after still using GrapheneOS on his Pixel. Also, the reasons he stated for not using/trusting it were nonsense. There was not, and is not, a technical way to target a user with malicious OTA updates.
He was also one of 3 owners of a for-profit telecom that included Nick Merrill (Founder of Calyx). https://sec.gov/Archives/edgar/data/2009536/000200953624000001/xslFormDX01/primary_doc.xml is the SEC filing for shares issued in February 2024 .
Ok first of all: GrapheneOS is great, probably the best alternative Android OS, but their PR skills are rock bottom. Still, many ignore that due to how good it is.
With that said, I don't believe their claim that it's impossible for them to target a user with a malicious OTA: their reason is basically that the update server never even knows who is downloading, and so it can't send a different file to just one user. That's true, but thet could, in theory, make a single OTA that everybody gets, but checks for a specific IMEI or other device ID and only there enables some malicious payload.
I trust them not to do it, for many reasons, but technically they could. I also don't think they'd do it to Louis, despite the beef they have with him.
-
While I am... suspicious of what the CEO (?) has spouted recently, I am unaware of how that connects to user data. Can you ELI5/summarize/point me in a direction?
Not OP, but I left for similar reasons. The CEO publically supported the Republican admin (mildly, but even at the time, stupidly). The statement sent out about it after the fact was also sus, but not really super bad.
I left anyway. I'd rather not pay a CEO to publically support the administration that is specifically targeting my family for political points.
I also heard a lot of fear mongering on the fediverse about how their new AI conversations can't be private because it gets to their servers directly, but I couldn't find anyone reasonable online who actually looked into it and confirmed that.
So like, they've got all the ingredients for more stupidity, and as we've seen time and again, everything pressuring them to fuck up/enshitify is also there in the background too.
-
The developer is kind of just a sack of shit. I'm 90% sure Lemmy development is funded by either Russia or China, and I suspect Russia.
It's funded mostly by the Netherlands lol
-
"Trust" as in: trust it enough to run it on your machine.
(And assuming that you can't understand code yourself)
I know you do.
Well, you're here, aren't you?
-
The developer is kind of just a sack of shit. I'm 90% sure Lemmy development is funded by either Russia or China, and I suspect Russia.
I'm 90% sure Lemmy development is funded by either Russia or China
Why do you think so?
-
Ok first of all: GrapheneOS is great, probably the best alternative Android OS, but their PR skills are rock bottom. Still, many ignore that due to how good it is.
With that said, I don't believe their claim that it's impossible for them to target a user with a malicious OTA: their reason is basically that the update server never even knows who is downloading, and so it can't send a different file to just one user. That's true, but thet could, in theory, make a single OTA that everybody gets, but checks for a specific IMEI or other device ID and only there enables some malicious payload.
I trust them not to do it, for many reasons, but technically they could. I also don't think they'd do it to Louis, despite the beef they have with him.
Well, the fact is it is impossible to target someone with a modified update. The update client sends no IDs to the server, it just fetches static files and determines whether it needs to update or not. The server only has static files.
thet could, in theory, make a single OTA that everybody gets, but checks for a specific IMEI or other device ID and only there enables some malicious payload.
That would be very obvious in the code. And how would devices be targeted if GrapheneOS project members don't know the unique IDs because they're not sent in the first place? There are also community members who build GrapheneOS on their own and check if the builds match because GrapheneOS builds are reproducible. It just isn't possible. But even if people don't believe all of that, they can still disable the updater app and sideload updates manually. Instructions are on the website.
-
That doesn't mean it's not also funded by China or Russia. They've been able to work on Lemmy for a while without much public funding.
They get donations, and people can just do stuff on the side
-
You always have to trust others. If a key person can not be trusted anymore, the option to constantly check the code is not really an option.
At this point GrapheneOS is big enough that there are people who do pay attention to changes and forks that would notice as well.
-
"Trust" as in: trust it enough to run it on your machine.
(And assuming that you can't understand code yourself)
for me, it generally boils down to "show me the work, then i decide".
some works are more influenced by politics like art pieces and written works. some, like architecture, plumbing and network stacks, much less so.
in this case, even if you don't know code but can be a good appraiser of political taint then you can decide on your own what to endorse or not.
-
I don't "trust" tankies, because no authoritarian can ever be trusted, nor do I trust lemmy. I just prefer to vote with my content/wallet, and Reddit showed the world they don't deserve their user base, or any of their content.
This is an open non-profit platform anyone can scrape. That's good enough for me, until something with a better value proposition comes along.
i'm so excited about the progress piefed is making and my home instance's plans to migrate
-
The developer is kind of just a sack of shit. I'm 90% sure Lemmy development is funded by either Russia or China, and I suspect Russia.
Even It is I'd be okay with it since its opensource meaning I can see if its doing something bad and I can fork ifbit goes sideways.
-
"Trust" as in: trust it enough to run it on your machine.
(And assuming that you can't understand code yourself)
Depends on the software. I'd not trust a vpn that was made in an authoritarian state. I'll play a game made in one.
As for the developer if they are more famous for their political views than the software I'd probably not install it.
-
I know you do.
Well, you're here, aren't you?
Tbf, accessing a a software running on some server (which is not my machine) over Tor isn't exactly the same as, say, installing a software with admin privileges on my computer.
-
While I am... suspicious of what the CEO (?) has spouted recently, I am unaware of how that connects to user data. Can you ELI5/summarize/point me in a direction?
That was largely gut-level analysis for my personal decision-making but here are a few of the things I considered:
- Value proposition in the context of acquisition, featuring a heavily-marketed privacy brand and a base of privacy-conscious users (harder to profile, more expensive data)
- Obfuscation of funding sources via ‘venture philanthropy’ non-profit (a la OpenAI) housing closed-doors for-profit operations
- Rapid expansion to full-coverage consumer productivity cloud platform alternatives (vpn, mail, drive, calendar, wallet, passwords, etc)
- Weird pattern of being blocked then let through without future contest by numerous data-hungry entities including thiel, and generally just allowed in a few too many privacy-unfriendly places for my taste
- And the usual reservations re: privatized privacy and commercial OSS
Again sorry that’s all hand-wavy. Probably shouldn’t have thrown shade without something more concrete.