It seems that there is something very wrong with the entire Android privacy community, because fighting between different open-source projects in this space never stops.
From the technical point of view, only Daniel Micay's GrapheneOS currently takes security really seriously by providing constant system updates. It seems that you either have to use GrapheneOS, or buy an iPhone, if you care about both – security and privacy.
The people who are attacking Daniel Micay often incorporate a lot of his work into their own projects. And, naturally, that might make many of them feel inferior or even incompetent – if they are doing this for years to stay in the competition.
> When a custom ROM, even a "degoogled" one, is made, you include a customized kernel and custom drivers, and the AGPS URLs are part of this "driver".
Thanks, this should be the top comment.
Both, Sony and Google, provide driver downloads for their smartphones[1][2].
In this case, the tested "de-Googled" OS (/e/OS) did exactly what it promised to do: removed all network connections made by Google – and not by Qualcomm or anybody else.
Since Pixel smartphones now use Google's own Tensor chips (which are based on Samsung Exynos), they obviously don't make any connections to Qualcomm servers.
This blog post is clearly an ad for NitroPhone, which is simply a Google Pixel smartphone with a different open-source OS pre-installed.
GrapheneOS[3] is only targeting Google Pixel line-up at the moment, and therefore is able to make sure that even A-GPS URLs are "de-Googled" on the latest models.
But the older Google Pixel models with Qualcomm chips make exactly the same connections – from the driver, not from the firmware[4]:
> GrapheneOS has modified all references to these servers to use HTTPS rather than a mix of HTTP and HTTPS. No query / data is sent to the server.
I see Rust and Go as the best high-performance high-concurrency programming languages today, and choose between Rust and Go depending on the bottleneck (Rust – CPU / RAM, Go – I/O).
Rust and Go are very much alike, when Java is not an option because of the JVM startup time and memory requirements (GraalVM Native Image solves this, but at the expense of highly reduced performance).
That's true, and Clojure (when used with metosin/malli) is probably the only reasonable alternative to statically typed programming languages in terms of long-term maintainability.
Essentially, it's like two completely different reasoning models: inside-the-box (ALGOL / SQL), and outside-the-box (LISP / Datalog).
The first model (ALGOL / SQL) is about designing for machines to better understand, and the second model (LISP / Datalog) is about designing for humans to better understand.
I think that the main issue with dynamically typed programming languages is the lack of robust enforcement.
I believe that many people from Ruby on Rails and Django communities moved on to Clojure, Elixir, and Kotlin.
Others chose between Rust and Go, if performance was the most important thing.
The thing about dynamically typed languages and their expressiveness, is that you are sacrificing the ease of long-term maintenance for the ease of short-term prototyping.
Personally, I am a big fan of Clojure as a tool for designing software, but I would prefer having to maintain a code base written in Rust.
I am a big fan of Alphabet as a company, but this is how I read the first two paragraphs...
> When Shane Legg and I launched DeepMind back in 2010, many people thought general AI was a farfetched science fiction technology that was decades away from being a reality.
Translation: "We were not able to see what the founders of OpenAI saw back in 2015".
> Now, we live in a time in which AI research and technology is advancing exponentially. In the coming years, AI - and ultimately AGI - has the potential to drive one of the greatest social, economic and scientific transformations in history.
Translation: "Now we live in a time in which AI research and technology has advanced exponentially thanks to the great achievements by our competitors – and we clearly feel left behind."
> Retailers wont take me because of my accomplished work history.
Can't you just remove it from your CV then? I thought that CV is like personal marketing material: you only list things there that help you to get a specific job – and skip everything else that doesn't.
EDIT: It's possible to list your previous employers without listing your work accomplishments.
> Well ok, but was EY less competent than McKinsey or did they just get unlucky that they're the poor bastards who stepped on the landmine?
I have asked myself the same question, before I noticed that EY is basically the Credit Suisse and the SoftBank of the audit world[1]:
> EY has been involved in many accounting scandals: Bank of Credit and Commerce International (1991), Informix Corporation (1996), Sybase (1997), Cendant (1998), One.Tel (2001), AOL (2002), HealthSouth Corporation (2003), Chiquita Brands International (2004), Lehman Brothers (2010), Sino-Forest Corporation (2011), Olympus Corporation (2011), Stagecoach Group (2017), Wirecard (2020), Luckin Coffee (2020) and NMC Health (2020).
In fact, Wirecard managed to partner with EY, Credit Suisse, and SoftBank simultaneously just before going bankrupt.
Maybe because no reputable companies wanted to touch it?
There was an interesting comment exchange on FT.com a few hours ago[1].
One person wrote:
> Lee’s former company, Block, is currently under investigation by the SEC after the app that he founded (Cash App) was alleged to have been facilitating money laundering. Wonder if there is a connection?
And another responded:
> A hitman isn't going to use a knife.
But when you think about it: if you didn't want something to look like a hit job, that's exactly what you would do – use a knife in downtown San Francisco at 2 AM – and nobody will be surprised.
Personally, I find it a little suspicious, that an important individual could have been murdered accidentally in a city with an average of 4 murders per month, just 2 weeks after the SEC opened an investigation into the platform he created[2].
Also, the place of the murder wasn't described as particularly dangerous at night by multiple locals[3][4].
> Toshin found Pinduoduo to have exploited about 50 Android system vulnerabilities. Most of the exploits were tailor made for customized parts known as the original equipment manufacturer (OEM) code, which tends to be audited less often than AOSP and is therefore more prone to vulnerabilities, he said.
> Pinduoduo also exploited a number of AOSP vulnerabilities, including one which was flagged by Toshin to Google in February 2022. Google fixed the bug this March, he said.
That's probably a good enough reason to stick with Pixel smartphones, if choosing Android.
We would need to see the "inflation adjusted" numbers here, because Hacker News has certainly had a lot of growth since 2011.