[HN Gopher] Turn your old, cracked Android phone into a backup s...
       ___________________________________________________________________
        
       Turn your old, cracked Android phone into a backup server
        
       Author : thunderbong
       Score  : 211 points
       Date   : 2021-06-21 03:47 UTC (19 hours ago)
        
 (HTM) web link (www.hannahtech.co)
 (TXT) w3m dump (www.hannahtech.co)
        
       | jablan wrote:
       | Another cheap solution is buying a used router and then
       | installing OpenWRT on it. Get one with USB.
        
         | CTOSian wrote:
         | used routers?!
         | 
         | someone can find 10+ yrs NAS really cheap nowadays.. I ve got a
         | ..bucket of Netgear's (most of them ReadyNAS Duo v2) for PS5
         | each!!!
        
           | gattilorenz wrote:
           | > ReadyNAS Duo v2
           | 
           | don't you have problems with SSL certificates and accessing
           | the interface via browser?
           | 
           | In general, both a router and a NAS do lack the backup
           | battery, unless an UPS is also used...
        
       | HPsquared wrote:
       | It's possible to install Debian on an Android phone without root,
       | by using Termux.
       | 
       | Would this software also work in that environment?
        
         | OJFord wrote:
         | If you have Debian why would you choose.. 'UrBackup Server'
         | when you could use anything?
        
           | HPsquared wrote:
           | Step 1 of TFA is basically "install Debian using Linux Deploy
           | on a rooted phone", I was asking whether I can use Debian
           | installed via Termux, on a non-rooted phone.
        
       | justusthane wrote:
       | Somewhat off-topic, but the article uses UrBackup. I came across
       | UrBackup a couple years ago when I was looking for a free
       | workstation backup solution with centralized control.
       | 
       | It's pretty neat! Check it out if you have a need for it.
        
       | fulafel wrote:
       | Unfortunately this is also a recipe of dropping an unpatched
       | unmaintainable Linux machine on the network to provide
       | interesting security challenges in the future.
        
         | atatatat wrote:
         | So...most Android phones?
        
         | mattowen_uk wrote:
         | Aren't most dedicated home NAS units basically 'an unpatched
         | unmaintainable Linux machine' also ?
        
           | Wronnay wrote:
           | I think most ppl here have something like a Synology which
           | isn't too bad with updates...
           | 
           | Of course, my Buffalo NAS can't compete with that and got
           | fewer updates than my old phone...
        
             | techrat wrote:
             | My Lenovo NAS, despite continuing to be sold well past when
             | Linux Kernel v4.19 was released... is still on 2.6.32
             | 
             | It is no longer connected to an internet facing network.
        
         | BelenusMordred wrote:
         | Something like PostmarketOS is likely a better choice if it is
         | supported for your device.
        
           | cookiengineer wrote:
           | For people that are not aware: ArchLinuxARM [1] is an
           | unofficial Arch based distro for all kinds of ARM devices.
           | 
           | Using it for my router, firewall and NAS hardware - and can
           | totally recommend it.
           | 
           | [1] https://archlinuxarm.org/platforms
        
             | cunidev wrote:
             | postmarketOS has much more active mainline work though
        
           | outsomnia wrote:
           | Right, they are at least trying to use current, updatable
           | kernels.
           | 
           | Vendor kernels are a continual security apocalypse that never
           | ends.
           | 
           | https://source.android.com/security/bulletin
        
       | ProtoAES256 wrote:
       | The first thing that come to my mind is: "How will this fare for
       | a long term daily backup?" A few of my old phones and SD cards
       | died due to the flash being used up(can't write new data, ro
       | only).
       | 
       | That said, with some magic linux command sauce, external drives
       | can be used(part 2 of link), then software RAID, offloading data
       | to them to prolong flash writes lifetime, then more stuffs like
       | AnLinux can instead be used to add functionality to it.
       | 
       | Interesting read indeed.
        
       | imvetri wrote:
       | How to make the ports available in internet ?
        
         | pmlnr wrote:
         | Get on your router and follow the instructions for port
         | forwarding.
         | 
         | READ the documentation though, because opening devices up for
         | the internet can be nasty, especially when it's your first time
         | doing so.
        
       | omginternets wrote:
       | This is a bit of a tangent, but is there a way to get low-level
       | access to an Android phone's radio without installing Android? I
       | have an old OnePlus One and I'd really like to use it as an SDR
       | for weekend projects. Ideally, I'd have it run some sort of
       | minimal linux installation. If such a thing exists, I'm betting
       | someone on HN knows about it.
        
         | schrijver wrote:
         | I think PostmarketOS intends to be that linux installation: "a
         | sustainable, privacy and security focused free software mobile
         | OS that is modeled after traditional Linux distributions."
         | https://postmarketos.org/ No idea how easy it would be to
         | access that radio though.
        
           | omginternets wrote:
           | This is a fine start. Many thanks.
        
         | moftz wrote:
         | With the right USB adapter, you can plug an RTLSDR into an
         | android phone.
        
       | ev1 wrote:
       | What's keeping a plugged in unremovable battery charging on power
       | 24/7 like
        
         | pmlnr wrote:
         | Depends. If the power source is decent enough, it's fine. If
         | not, you'll end up with a swollen battery, like I did, and
         | you'll get rid of it as fast as possible.
        
         | rollcat wrote:
         | You don't need to continue charging the battery past given
         | percentage. It just happens that by default batteries don't
         | charge past 100%, you can tell the firmware to stop at e.g. 40%
         | which is a perfect compromise between having a bit of backup
         | power and considerably extending its lifespan.
        
           | dendriti wrote:
           | Charge your battery to 40%, so that it will be able to charge
           | to 100% for more charging cycles...
           | 
           | I know you're joking, but I've seen this logic at play
           | elsewhere.
        
           | jeroenhd wrote:
           | Is there a standardised way to do that on old Android
           | devices? I've got a tablet that I'd like to run continuously
           | at some point as a touch interface to my house but I'm wary
           | if hooking up the battery 24/7 after seeing what happened to
           | other people's devices when they did that.
        
             | e3bc54b2 wrote:
             | I've been using this fantastic work for years without side
             | effects
             | 
             | https://github.com/Magisk-Modules-Repo/acc
             | 
             | I had my phone plugged in for almost 3 years, and the
             | battery still lasts for 3 days on its own. Highly
             | recommended.
             | 
             | As a side note, can someone tell me if something like this
             | can be made for postmarketOS? I installed it couple months
             | back and this is really bugging me. Apart from constant
             | vibrations.
        
               | MayeulC wrote:
               | > As a side note, can someone tell me if something like
               | this can be made for postmarketOS? I installed it couple
               | months back and this is really bugging me.
               | 
               | In theory, if changing charge thresholds is supported by
               | the PMIC (power-management IC) driver, it should be
               | exposed in the sysfs. It is device-specific though, and
               | might not be exposed by the driver.
        
         | hypertele-Xii wrote:
         | Doesn't the battery controller bypass the battery once it's
         | full and supply power directly from cable?
        
           | lmns wrote:
           | I've never heard of a phone that does this.
        
             | ev1 wrote:
             | I wish I could find a power bank for USB devices that will
             | just pass through power when the battery is full.
        
       | develatio wrote:
       | While, from a technical POV, this sounds fun, I'd really
       | recommend against using an old and cracked phone (which, to add
       | insult to injury, is probably running very outdated and
       | vulnerable software) for backup purposes.
       | 
       | Please, run your backup servers on machines designed to do so,
       | capable of receiving regular software updates, etc...
        
         | Anunayj wrote:
         | if one backup is no backup, a backup on a old cracked phone is
         | a backup with a timebomb.
        
       | notjulianjaynes wrote:
       | Root required, darn. I have 2 or 3 android phones with bad
       | screens sitting in a drawer I'd like to do something with.
       | Unfortunately they a.) don't have USB debugging enabled and b.)
       | don't support any sort of external display.
       | 
       | If anyone had some tips on how I could get into these machines it
       | would be much appreciated.
        
         | rjzzleep wrote:
         | I have a rooted phone that I use to get information I need root
         | for with a broken touchscreen. The other day I was stupid
         | enough to try to reset it to see if I could part of the screen
         | working. Obviously that didn't work.
         | 
         | Re-enabling USB debugging was the following process:
         | 
         | 1. use USB-OTG to go into the bluetooth menu to connect a
         | bluetooth device to.
         | 
         | 2. enable usb debugging using mouse
         | 
         | 3. connect to PC and use the bluetooth keyboard to allow USB
         | debugging
         | 
         | 4. use scrcpy to control the device
         | 
         | Obviously this only works reasonably well if you can see at
         | least some portion of the screen.
        
           | sippeangelo wrote:
           | It also only works if your phone is on an old enough Android
           | version where they haven't put OTG behind a manual toggle
           | yet.
        
             | yjftsjthsd-h wrote:
             | What versions of Android have a toggle to allow USB OTG?
        
         | HPsquared wrote:
         | Look up Termux, it doesn't require root.
        
         | ce4 wrote:
         | You could order replacement screens and try to fix it yourself.
         | Depending on the model it's often cheaply available on
         | Aliexpress or ebay.
        
         | Aulig wrote:
         | Not sure if it helps you to get root, but to enable debugging
         | you could use something like this guide:
         | https://www.youtube.com/watch?v=GPJcR_Iosm4
         | 
         | Once you have usb debugging, I can recommend Vysor, super easy
         | to use to control your phone from the pc.
         | 
         | I'd also recommend turning on Talkback (assistive technology)
         | and VoiceAccess as that can help you use the device even if you
         | cant see anything on your screen. That helped me a lot with my
         | phone that has a broken screen where nothing but the
         | touchscreen works.
        
           | khimaros wrote:
           | also scrcpy
        
         | butz wrote:
         | Depending on device you have, you might be able to build a
         | serial cable for it:
         | https://wiki.postmarketos.org/wiki/Serial_debugging
        
         | BelenusMordred wrote:
         | Not sure about this guide but you should be able to install a
         | linux rom through fastboot instead of a recovery. You won't
         | need a working screen to do that.
        
         | MayeulC wrote:
         | If they have their bootloaders unlocked, I'd look into
         | postmarketos. If not... well, I guess you really need to fix
         | the screen up first, unless you had enabled adb. It could even
         | be a temporary fix (for instance, a single screen if the 3
         | devices are the same.
        
         | dehrmann wrote:
         | You're better off getting a single-board computer for this.
         | You'll be able to install your own mSATA drive, and it'll run
         | most distros without any fuss. That said, this quickly
         | escalates to just set up a real NAS box. You don't really want
         | to use an SSD for backup because they can lose data when not
         | used. Alternatively, just go with a cloud provider.
        
           | KronisLV wrote:
           | As funnny as this is, i never really go the whole concept of
           | a "real NAS box" - do people usually mean specialized
           | hardware in combination with something like the FreeNAS OS?
           | 
           | Because right now i'm just using consumer hardware (an Athlon
           | 200GE for its low 35W TDP, some cheapo RAM and a number of
           | Seagate BarraCuda HDDs) in combination with Debian, which
           | also runs on my other cloud servers. It's all mounted on my
           | other devices either through SFTP or a Nextcloud instance
           | that's also running on them for easier file replication. I
           | don't even have RAID or ZFS/XFS/Btrfs file systems, just ext4
           | because any sort of clustering would introduce unneeded
           | complexity to the setup - instead, a cron job with rsync
           | backs the data from the "primary" HDDs to "secondary" ones
           | every day in an incremental manner (well there's also
           | BackupPC that does network rsync backups across servers).
           | 
           | What purpose would running a NAS oriented OS distro even
           | serve, for simple uses cases like that? It feels like the
           | current "ad hoc" setup is really affordable and easy to
           | operate.
           | 
           | I think a SoC would also be nicely suited for this, as long
           | as there is sufficient I/O capability. In regards to phones,
           | however, i feel like drivers for obscure devices could
           | probably become problematic quickly.
        
             | pjmlp wrote:
             | Regular people usually buy something like a Western Digital
             | NAS from the shopping mall on the neighbourhood.
        
             | makeitdouble wrote:
             | To me choosing a specialized hardware was motivated by
             | these two factors:
             | 
             | - power management
             | 
             | - semi-closed source applications
             | 
             | On power management, I don't use the NAS box continuously,
             | and there can be long gaps between accesses. Having the box
             | "sleep" for 95% of the day, and wake up the disks only for
             | one or two bursts of activity is interesting to me.
             | 
             | I tried doing that with DIY solutions, including Raspberry
             | Pi+SATA disk type of arrangements. Overall it didn't work
             | great and was a PITA.
             | 
             | On the semi-proprietary apps, I am thinking about
             | Synology's apps. I could totally live without them, but
             | it's a nice addition to the package, they're easy to
             | install, seem to be well maintained and work decently well.
        
               | dkarp wrote:
               | As someone who normally rolls their own and has a half
               | dozen raspberry pis around the house, I have a Synology
               | NAS.
               | 
               | As you said, it's very low energy and zero noise (rubber
               | feet and quiet fan).
               | 
               | It's also effortless to set up and run with their RAID
               | system and syncing etc is very good. It'll let me know if
               | there is a problem with a drive, it keeps itself updated
               | and I've never had to reboot it.
               | 
               | I do not use it for Plex as it wouldn't be able to handle
               | it. They are a bit under powered but they're very
               | optimised for their main purpose, Network Attached
               | Storage, and that's the most important thing for me.
               | 
               | It is also very neat and tidy, unlike most home made
               | solutions.
        
               | NortySpock wrote:
               | Would OpenMediaVault on a Raspberry Pi have met your RAID
               | and sync needs?
               | 
               | I keep eyeing OMV but haven't splurged on running a NAS
               | with multiply-redundant drives separate from my
               | application server; currently it's just an RPi4 as a
               | docker host, with rsync keeping two USB drives in sync
               | with each other.
        
               | dkarp wrote:
               | Probably, at least on the software side!
               | 
               | But then I'd need to find a RAID enclosure and a
               | something to run OMV on. The NAS was around PS150 with
               | all that built in
        
               | makeitdouble wrote:
               | I'm obviously not very good at this, but my issue with
               | OpenMediaVault was less the software side than finding
               | hardware to reliably work with it.
               | 
               | For instance trying with an old low profile PC, wake on
               | lan didn't work half of the time so I gave up, and just
               | let the drives sleep. But they would also fail to wake up
               | sometimes.
               | 
               | All in all a NAS is not that expensive (I have one I
               | bought for 400 or so, and it's lasting for 15 years
               | now...), so it's hard to justify the endless tweaking of
               | a solution that could work the same if done well.
               | 
               | BTW even with a commercial NAS , ssh access is
               | configurable, major scripting languages are there, and
               | recent ones have docker I think. For the really custom
               | stuff, like you I use Raspberry Pis that mount the NAS
               | files as needed.
        
               | rob74 wrote:
               | > _Having the box "sleep" for 95% of the day, and wake up
               | the disks only for one or two bursts of activity is
               | interesting to me._
               | 
               | Have you really managed to get that to work? I got a QNAP
               | TS-230 a few months ago hoping I could do just that, but
               | it turns out that even this smallest NAS box they are
               | offering isn't really designed with this "occasional use"
               | in mind. There are so many user questions about this
               | (https://www.qnap.com/en-us/how-to/faq/article/why-are-
               | my-nas...) that they even built a half-baked utility
               | that's supposed to give you a hint which process is
               | preventing the drives from going into sleep mode, but
               | it's not a great help. I have disabled all services
               | (photo indexing with face recognition and other such
               | crap) except for the most basic ones, but still the
               | drives are happily chugging along, flashing their LED
               | every few minutes, not spinning down. I know that it's
               | basically a Linux computer, and there are probably
               | utilities I can install to diagnose the issue better than
               | with the above-mentioned software, but isn't this
               | something that's supposed to work out of the box, or at
               | least be easy for an average user to accomplish?!
        
               | makeitdouble wrote:
               | I have an old Synology, so it miht be different.
               | 
               | I run relatively few stuff on it too, with no client that
               | consistently access the shares though samba/nfs (I
               | cluster the scripts that run automaticaly around the same
               | range of time, and they unmount after they're done).
               | 
               | I wonder if your system is not writing logs from a
               | monitoring service (something checking your dynamic DNS,
               | or waiting for remote connections, or pinging the
               | internal servers to see if they're alive).
               | 
               | I stopped most default services, including sync (it's
               | done more rarely via a user script instead), and yes, it
               | can be a PITA to understand what's running out of the
               | box.
        
             | hansel_der wrote:
             | yea, normies do just buy a ready-built nas appliance, if
             | you know what you are doing or like to tinker, use old
             | consumer hardware.
             | 
             | just one nitpick with your setup:
             | 
             | if your primary hdd corrupts, rsync will not notice/care
             | and corrupt your backup as well. zfs is all the rage
             | because it aims to have two sources for the data aswell as
             | a checksum, so it can tell which data-source is flawed AND
             | fix it.
        
               | KronisLV wrote:
               | Oh, another person also mentioned using ECC memory, which
               | may not be awfully important until it suddenly is.
               | 
               | Right now i have incremental backups over the network
               | with BackupPC: https://backuppc.github.io/backuppc/
               | 
               | That software solution sort of dances around the issue,
               | because if any files were to become corrupted, i could
               | just go back in time to their older versions, though that
               | approach isn't necessarily good either - since that means
               | having to store the original "full" backups for a long
               | time and also takes up more storage, which i do for the
               | essential data, but not the stuff that i'm willing to
               | lose. And, since the data stored can be arbitrary and
               | therefore checking for corruption would have to be done
               | manually, there are serious drawbacks to that, in regards
               | to even knowing when things have gone wrong.
               | 
               | Of course, there's also the possibility to use additional
               | sources of redundancy, like versions within Nextcloud
               | should the actual file contents of a particular version
               | become corrupt, however for certain scenarios file
               | systems like you've described indeed do become the way to
               | go. Maybe not for every homelab out there, though.
        
             | neartheplain wrote:
             | To me, a real NAS box means:
             | 
             | - ECC RAM, to avoid corruption on write
             | 
             | - Software RAID, to avoid data loss due to drive failure
             | 
             | - Some kind of checksumming and error-correcting
             | filesystem, e.g. ZFS, to prevent data loss due to bad
             | sectors
             | 
             | - Enough CPU to transcode media in real-time
             | 
             | - Vanilla distro with SSH, SMB filesharing, Plex, and
             | networked printing
             | 
             | - A spare PSU in the closet
             | 
             | I explicitly avoid:
             | 
             | - Hardware RAID (unnecessary, expensive, harder to fix)
             | 
             | - Any OEM prebuilt NAS products (more expensive, less
             | capable, less user control)
             | 
             | - Any specialty NAS-oriented distros or OSes (more feature
             | bloat, bigger attack surfaces)
             | 
             | I use plain old Debian for my home NAS. I'd switch to
             | OpenBSD in a heartbeat if it supported a checksumming and
             | error-correcting filesystem.
        
               | Miraste wrote:
               | > Any specialty NAS-oriented distros or OSes (more
               | feature bloat, bigger attack surfaces)
               | 
               | So you recommend ZFS but not TrueNAS? It more or less is
               | FreeBSD with zfs and NAS-oriented defaults+utils. There's
               | not much I'd count as bloat.
        
               | nottorp wrote:
               | > Software RAID, to avoid data loss due to drive failure
               | 
               | Ok it's old but: raid is not backup.
               | 
               | I've personally worked for a small online shop that was
               | selling digital items and shut down when their raid
               | failed. Of course, they had ignored my warnings to build
               | a mirror system or do copies on removable drives or ...
               | anything resembling an actual backup.
               | 
               | Edit: that said, I do have a box that's pretty similar to
               | what you're describing.
        
               | neartheplain wrote:
               | Yes, for actual backups I have M-DISC BluRays [0] which I
               | keep in a fireproof box. They're limited in capacity
               | compared to the full NAS, but big enough for really
               | important stuff like photos and scanned documents (which
               | conveniently are intrinsically write-once).
               | 
               | [0] https://en.wikipedia.org/wiki/M-DISC
        
               | khimaros wrote:
               | encrypted, deduplicated offsite backups are another
               | approach. borgbackup on free tier cloud services can be
               | useful for this.
        
               | syntheticnature wrote:
               | Serious question: are there free tier cloud services with
               | enough storage to be worthwhile?
        
               | justin_oaks wrote:
               | It probably depends on how much you need to store. But if
               | you need ongoing backup that will get larger and larger
               | then the answer is probably "No".
               | 
               | I back up my family photos and other important files to
               | Amazon S3 using Restic. My 150GB of data ends up costing
               | me about $1.50/month. I could get the price down lower if
               | I use, say, the Infrequent Access storage tier, but at
               | that price point I just can't be bothered to deal with
               | it.
               | 
               | A free tier often isn't worth it if you have to put any
               | time into thinking about whether you'll exceed the limit.
               | I'd just go with a cheap pay-as-you-go service and not
               | worry about it.
        
           | poisonborz wrote:
           | > You don't really want to use an SSD for backup because they
           | can lose data when not used
           | 
           | Not (really) true, there is not much hard data backing this
           | up as I see it, and for what there is, the retention would be
           | 1+ year. The thread is not about offline backups, but an
           | always powered backup server anyway. And SSD does make sense
           | for a lot of reasons: HDD speeds are likely slower than local
           | CAT cable, the higher IOPS helps on parallel workload cases,
           | not to mention the way lower power draw and zero noise (no
           | moving parts for the rest of the setup), compared to a
           | chirping HDD.
        
           | hungryforcodes wrote:
           | Obviously solid advice, but I think the point here is about
           | reusing old electronics. I also have a couple of old phones
           | I'd like to try this with.
        
         | rawbot wrote:
         | Depending on how broken the screen is, you could navigate
         | Android with a USB keyboard/mouse.
        
       | anilgulecha wrote:
       | This is over-engineering IMO. If you want to use an old phone,
       | simply setup syncthing, and add in the folder from the connected
       | hard disk. Instantly available synced folders from other places.
       | 
       | No root, no fuss.
        
         | tolbish wrote:
         | Looks promising, thanks for the info!
        
       | jeroenhd wrote:
       | For those looking for backup servers on Linux, using the backup
       | tool built into many Linux distros (Deja-Dup or Duplicity) you
       | can make file level backups without setting up backup software at
       | the server side by using SFTP. Backups are encrypted and through
       | a few (admittedly hidden) settings you can enforce a period after
       | which full backups are made rather than diffed backups.
       | 
       | That's the system in currently using, at least. I'd be happy to
       | read about other open source solutions if anyone has a better
       | solution. My backup system is geared towards a service that
       | exposes nothing more than SFTP or WebDav as a backup location
       | because of a cheap cloud storage subscription I've managed to
       | get.
        
         | khimaros wrote:
         | i personally recommend borgbackup
        
         | mananaysiempre wrote:
         | I have two gripes with Deja Dup (or rather had, the last time I
         | reviewed my backup setup several years ago):
         | 
         | - It can only do one set of backup settings and consequently
         | only one backup destination without additional tooling, which
         | is not Right(tm).
         | 
         | - It cannot add different prefixes to the names of index and
         | data files, making it impossible to set up S3 lifecycle rules
         | for dumping the latter to Glacier. (Duplicity requires the
         | former to be hot for some reason, I don't know why.)
         | 
         | Both of those are things you can do with the underlying
         | Duplicity tool and a scheduler, but the UI does not expose
         | them. Thus I sadly had to discard Deja Dup's shiny GNOME UI,
         | and I know of no other backup tool with a shiny GNOME UI (and
         | am too lazy to write one so far).
         | 
         | Have any parts of this become false?
        
       | teddyh wrote:
       | Any Internet-connected device is, in fact, a server, and must be
       | seen and managed as one. This means strict control of installed
       | services and, first and foremost, regular _updates_ of all its
       | software components (including firmware). If you acquire and
       | install such a server which either can't be updated or one which
       | you know, realistically, won't get any updates six months after
       | installation, that's asking to lose.
       | 
       | -- Me, 21/2 years ago:
       | https://news.ycombinator.com/item?id=18019343
        
         | pmlnr wrote:
         | > regular updates of all its software
         | 
         | NO.
         | 
         | You need security patches. The current "regular updates"
         | bullshit where the Play Store wants to update and app I updated
         | an hour ago is insane.
        
           | orf wrote:
           | We've discovered that backporting security fixes to a large
           | matrix of (outdated) versions isn't generally sustainable
           | outside of a few specific cases.
           | 
           | So... YES. Regular updates to all of its software is how you
           | stay on top of security updates.
        
             | Black101 wrote:
             | Yes and that is really bad... hopefully someone, one day,
             | will solve this problem. I don't auto-update Android apps
             | that what I need, because as a rule of thumb, app quality
             | declines over time...
        
               | orf wrote:
               | Then by definition you are not receiving security
               | updates. Android sandboxing obviously helps here, but
               | it's still not a sensible position to take in the general
               | case and definitely not an idea you want to give to your
               | less technical friends or family.
        
               | anonymousab wrote:
               | Then it is unfortunate that the general behavior of (some
               | big?) app developers has made it so necessary to eschew
               | updates by default to avoid change-for-the-sake-of-change
               | workflow breakages (e.g. how Mozilla went about rolling
               | out Fenix) and to dodge the threat of user hostile
               | changes (e.g. the ad and tracking nonsense we see so
               | often on Windows updates).
               | 
               | This is a problem of their own creation, trying to tell
               | users to accept it anyways is a non-starter for many.
        
               | vagrantJin wrote:
               | > definitely not an idea you want to give to your less
               | technical friends or family.
               | 
               | That's a load of garbage.
               | 
               | I don't do updates and zapped all google services except
               | the playstore. Been looking good since.only whatsapp is
               | the only culprit that demands me to update by force.
        
               | Black101 wrote:
               | > Then by definition you are not receiving security
               | updates.
               | 
               | There are certain apps that I will update though, like
               | Element, but I don't even update Firefox because the new
               | engine breaks too many things for me, like extensions and
               | bookmarklets. IE: Last time I checked you could only
               | choose between 12 extensions on the latest Firefox
               | Mobile.
        
             | birdyrooster wrote:
             | Of course... IT DEPENDS on the type of app, if the app
             | doesn't share user input with other users and doesn't
             | download or run untrusted code, then you probably don't
             | need to update it.
        
             | tarsinge wrote:
             | And that's how you introduce new vulnerabilities too.
        
             | pmlnr wrote:
             | > isn't generally sustainable outside of a few specific
             | cases.
             | 
             | WordPress can do it. Others also could, if they wanted to.
        
               | orf wrote:
               | > if they wanted to.
               | 
               | But for various reasons they don't, and that's the
               | problem.
        
         | slim wrote:
         | I'd add any system with an uptime of more than one month is a
         | decent server. Android has nothing to shy of
        
           | teddyh wrote:
           | Uptime is not the only gauge of significance. Security is one
           | of the most important ones, as is reliability.
        
       | 1vuio0pswjnm7 wrote:
       | Without needing to "root" the "phone", the user can install
       | primitive ftpd from f-droid. Works great.
        
         | slim wrote:
         | Also termux is the best software you can have for android
        
           | 1vuio0pswjnm7 wrote:
           | Earliest version of termux on f-droid in the internet archive
           | requires android 5.0 or later. Current versions require
           | andoid 7.0 or later. How does the user with old android
           | phone, e.g., 4.x, use termux. Current versions of primitive
           | ftpd will work with android 4.0.3 or later.
        
             | seniorivn wrote:
             | if your old phone has no unofficial support for more or
             | less modern on version, either forget about it or go all in
             | native linux route postmarketos etc
        
               | 1vuio0pswjnm7 wrote:
               | "... either forget about it or..."
               | 
               | Will forget about it. Not really that interested in
               | wireless anyway.
        
       | fnord77 wrote:
       | what's a good phone to try this with?
        
       | pmlnr wrote:
       | The lesson of the cracked screen is: always pair you phone for
       | adb as one of the first steps in setting it up, and if possible,
       | root it.
       | 
       | You might need it if the screen cracks and you want to save data
       | off it.
       | 
       | Sometimes there are ways around it by dirty booting a recovery
       | image, but it's not as simple as it sounds, and you'd need an
       | unlocked bootloader to do so:
       | https://petermolnar.net/article/save-files-from-a-dead-scree...
        
         | techrat wrote:
         | Probably unnecessary at this point.
         | 
         | Nearly every phone today is sold with a USB C port.
         | 
         | "But this phone is older than..."
         | 
         | My Moto Z Play was released in 2016. That phone is now 5 years
         | old. It came with Nougat... and I can mirror the screen with a
         | USB C hub with Built in HDMI. Plug in a mouse and you're done.
         | 
         | No need to leave adb enabled, which is a security hole that can
         | be exploited by unsafe USB ports and bad actors. (Also,
         | police.)
        
           | fulafel wrote:
           | A lot of phones don't have video over the USB C port (eg
           | Google Pixels).
        
             | lkois wrote:
             | Pixel 5 does. I tried with one recently and noted it only
             | does mirroring, unlike Samsung and Huawei which launch some
             | pseudo desktop OS when plugged in.
        
               | comeonseriously wrote:
               | Pixel 4a does not.
        
           | pmlnr wrote:
           | Moto E series doesn't have MHL.
           | 
           | No, adb is still needed.
        
             | techrat wrote:
             | MHL largely was for MicroUSB. Chances are what you need is
             | a USB to DP or USB to HDMI adapter. Some work in one but
             | not the other and vise versa. In the end however, Moto Es
             | ARE designed to be the most cut down, least featured phone
             | in the Moto line.
             | 
             | You would still be able to use a mouse or keyboard to input
             | a pin or passphrase if the screen was still semi readable.
        
             | silon42 wrote:
             | Also the Pixel ones don't have it (or DP alternate mode), I
             | think. This is why Nexus 5 is still the best Google phone
             | so far.
        
               | pmlnr wrote:
               | The Nexus 5 years produced good phones.
        
               | techrat wrote:
               | Pixels support DisplayLink mode.
               | 
               | https://www.youtube.com/watch?v=2iw4YJpiBVo
               | 
               | https://www.youtube.com/watch?v=2iw4YJpiBVo
        
           | qkqk wrote:
           | Why does a USB C port mean you don't need ADB or help with a
           | cracked screen?
        
             | Evidlo wrote:
             | I think the implication is that video output is usually
             | available on these devices.
        
             | techrat wrote:
             | It's bad to leave ADB enabled in general.
             | 
             | With a USB C port, there's a near absolute certainty that
             | you can simply plug in a USB hub with HDMI built in to hook
             | your phone up to a mouse and monitor to get around the
             | cracked screen issue.
        
               | ufmace wrote:
               | The recent versions of Android seem to have gotten way
               | better on ADB security. It seems to generate a keypair on
               | every computer with ADB and require a user with the
               | unlocked phone to authorize the keypair for each device
               | manually. It also auto-revokes authorization if you
               | haven't connected that device with ADB in 7 days by
               | default.
        
           | goda90 wrote:
           | I had a double whammy of a corroded display connection and a
           | loose usb-c port, meaning recovering data from the phone was
           | a very sensitive and frustrating affair.
        
           | OJFord wrote:
           | Can you unlock it (pin/password I mean, not finger/face) with
           | a keyboard and mouse though?
        
             | techrat wrote:
             | Yep.
             | 
             | Even did a video:
             | https://www.youtube.com/watch?v=Qkh4oagFfb8
             | 
             | Got out my old Moto Z Play which was retired. Restarted the
             | phone so I couldn't use fingerprint to unlock.
             | 
             | Plugged in a mouse, clicked pin. Unlocked.
             | 
             | Moto Z Play runs Nougat, stock but rooted. You don't need
             | root to be able to do this nor do you need ADB to be
             | enabled.
             | 
             | Also confirmed to be working on Razer Phone (stock, 9/Pie)
             | and Essential Phone (stock, 10). Also works with Keyboard
             | instead of mouse. Just type in the pin and hit enter.
             | 
             | Pattern unlock will have to be done with the mouse for
             | obvious reasons.
             | 
             | So if your digitizer is completely busted, you can still
             | use a mouse and keyboard. If your display is completely
             | busted, you likely will be able to get video alt mode with
             | USB C out.
             | 
             | I tried it on a few other devices that I had in my pile.
             | Chances are, if it's Micro USB, you won't get video on
             | boot, even with a proper MHL adapter.
             | 
             | * Sony Xperia J (Jelly Bean): Nothing, Micro USB
             | 
             | * Sony Xperia Play (Gingerbread): Nothing, Micro USB
             | 
             | * Marshall London (Lollipop): Mouse and Keyboard Works,
             | Micro USB
             | 
             | * Asus Zenphone 3 Zoom (Nougat): Mouse and keyboard works,
             | USB C
             | 
             | IIRC, Displaylink and OTG support was officially added in
             | Lollipop, so that kind of jives with my experience here. As
             | always, YMMV.
        
             | wongarsu wrote:
             | On my android I can enter pin/password per keyboard, or the
             | swipe pattern per mouse. Some early android phones had
             | slide-out keyboards (like a Blackberry), so good support
             | for physical keyboards isn't that surprising. I wasn't
             | expecting the mouse support tough.
        
               | megous wrote:
               | It's all standard HID interface these days.
        
         | [deleted]
        
         | salawat wrote:
         | See I did that, but got the one-two punch of death.
         | 
         | Cracked screen AND USB-C port failure. No charging or data
         | transfer possible.
         | 
         | Apparently at one time google opted me in for Google Photos, so
         | I have a backup of those, but recent contacts were totally
         | lost.
         | 
         | Still have the board lying around and am tempted to continue
         | tinkering with it... Or would be if I had any clue where to get
         | insight on how to do advanced debugging on why a mobile phone
         | wouldn't even register as connected over USB-C. Assuming some
         | sort of handshake failure.
        
         | sp332 wrote:
         | And set a password as soon as you root it for cryin' out loud.
        
         | LMYahooTFY wrote:
         | Isn't rooting it blowing a giant hole in the security model?
         | 
         | There's obviously benefits to doing so, but it has some big
         | costs?
        
           | pmlnr wrote:
           | Isn't no root a giant scam for not allowing you to actually
           | own your device?
           | 
           | All arguments have multiple sides to them.
        
           | gruez wrote:
           | Rooting a phone doesn't give all apps root access. You still
           | need to approve each app.
        
             | ufmace wrote:
             | At the level of running apps, yes. But unless I'm way
             | behind on my rooting tech, all of the usual methods leave
             | the phone in a state where anyone who connects it to a
             | computer via USB can access everything on it. AFAIK,
             | Android has gotten way better at having phones with the
             | stock OS locked down hard, with signed bootloaders, OS
             | level encryption keys stored in secure media, etc, and
             | rooting blows that all away.
        
               | pmlnr wrote:
               | > Android has gotten way better at having phones with the
               | stock OS locked down hard
               | 
               | eeeeerm, no. It didn't get better at all. It basically
               | wiped out a vibrant 3rd party android development culture
               | by making it extremely hard for them.
        
       ___________________________________________________________________
       (page generated 2021-06-21 23:02 UTC)