

have you ever used Gentoo? if you do, you know how long it takes to build updated software from source code.
vetting all that, even just the changes would take a lot more time. and it’s a constant effort.


have you ever used Gentoo? if you do, you know how long it takes to build updated software from source code.
vetting all that, even just the changes would take a lot more time. and it’s a constant effort.


that’s not “alive next to it”. you can’t see both at the same time


Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.
what does that mean? are you not running any programs at all? you cannot know just by looking at the name if a program reads such sensitive info. and its not unlikely that some developer figured it would be a good idea to include it in automatic crash reports
yes, this is sensitive information. its like your fingerprint, you cannot change it. I think its quite obvious. web browsers firefox is fighting to hide more and more that even indirectly could lead to identification. websites can’t read this ID, this is just a comparison.


Yeah but XMPP sounds so techy you know.… /s
the trick is to not mention XMPP to the end users. if they dig deep in the app settings they can find it out, but otherwise all that end users need to know is just, download the app named conversations, and use this domain and username. the domain could likely be hidden from them by deep linking, and sending the link in a company email. then they just need to log in as anywhere else.
yes, git is a godsend. but who will you trust that they checked the new code, and found nothing bad? different people have different expectations too.