<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Open-Source on digikar's microblog</title><link>http://digikar.online/microblog/tags/open-source/</link><description>Recent content in Open-Source on digikar's microblog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 20:09:09 +0200</lastBuildDate><atom:link href="http://digikar.online/microblog/tags/open-source/index.xml" rel="self" type="application/rss+xml"/><item><title>Performance Comparison of Stan on Intel 228V vs Apple Air M4</title><link>http://digikar.online/microblog/p/stan-performance-m4-228v/</link><pubDate>Fri, 28 Aug 2026 20:09:09 +0200</pubDate><guid>http://digikar.online/microblog/p/stan-performance-m4-228v/</guid><description>&lt;p&gt;Apple Silicon is definitely impressive in benchmarks. For real world tasks, however, they recommend running testing against real applications. Now, I&amp;rsquo;m not running any rigorous tests. Just some informal tests and eye-balling the times.&lt;/p&gt;
&lt;p&gt;The most intensive task I&amp;rsquo;ve been doing this month is building and running stan models. For those not in the know, &lt;a class="link" href="https://mc-stan.org/" target="_blank" rel="noopener"
&gt;Stan&lt;/a&gt; is a software for bayesian data analysis. The documentation is really good. It essentially provides a rich C-like DSL (minus the memory management) to write bayesian models. It then transpiles this to C++, compiles it, and then runs it. For small datasets, both compilation and runtime become comparable.&lt;/p&gt;
&lt;p&gt;As against my earlier announcement about the &lt;a class="link" href="../macos-dislike/" &gt;use of macbook&lt;/a&gt;, I eventually returned to Linux as a found a good deal on a T14 Thinkpad with Intel 228V, which has very reasonable battery life to get me through full conference days and long journeys. But I have the M4 Macbook Air lying around that I don&amp;rsquo;t want to give, because I want to use it for occasionally testing &lt;a class="link" href="https://github.com/digikar99" target="_blank" rel="noopener"
&gt;my libraries&lt;/a&gt; on MacOS. Cloud-hosted solutions for MacOS cost on the order of 60 USD/month, which basically means you can get a full macbook in a few months. Very unaffordable.&lt;/p&gt;
&lt;p&gt;But more recently, I found some time and peace of mind to dive into &lt;a class="link" href="https://github.com/anderspitman/awesome-tunneling" target="_blank" rel="noopener"
&gt;tunneling&lt;/a&gt; and set up a &lt;a class="link" href="https://developers.cloudflare.com/tunnel/" target="_blank" rel="noopener"
&gt;cloudflared tunnel&lt;/a&gt; to access my macbook through a public domain. This means I can now access my dormant macbook from anywhere even if I don&amp;rsquo;t have a public-facing static IP.&lt;/p&gt;
&lt;p&gt;But is it any useful? Apple M4 packs a punch. Depending on the metric, &lt;a class="link" href="https://www.cpu-monkey.com/en/compare_cpu-intel_core_ultra_5_228v-vs-apple_m4" target="_blank" rel="noopener"
&gt;it is about 25-50% faster than Intel 228V&lt;/a&gt;. I also noticed that while 228V has a peak of 4.5GHz, in reality, it only spends a minute or two above 3GHz, and often settles down to 2.5GHz. I don&amp;rsquo;t know how all the benchmark numbers compare against thermal throttlings. &lt;a class="link" href="https://www.reddit.com/r/hardware/comments/pitid6/eli5_why_does_it_seem_like_cinebench_is_now_the/" target="_blank" rel="noopener"
&gt;Benchmark numbers also don&amp;rsquo;t have strong cross-domain correlations.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So, the question then becomes, for my particular use case, which is compiling and running Stan Models, how do Intel 228V and Apple M4 compare? I also found an officially maintained &lt;a class="link" href="https://github.com/stan-dev/performance-tests-cmdstan" target="_blank" rel="noopener"
&gt;stan-dev/performance-tests-cmdstan&lt;/a&gt; repository that I hope is representative of my usage. So, [depending on how lucky you are], the following should allow you to benchmark stan on your computer. As of this writing, I&amp;rsquo;m on commit &lt;code&gt;b329e269&lt;/code&gt; of the repository.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sh" data-lang="sh"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;git clone --recursive https://github.com/stan-dev/performance-tests-cmdstan.git
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;python3 runPerformanceTests.py -j N -runj N stat_comp_benchmarks &lt;span class="c1"&gt;# N is the number of cores&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;You might want to prefix that last command with &lt;code&gt;time&lt;/code&gt; which is what I do for obtaining the below numbers. They represent duration in minutes; thus lower the better. For whatever reason, Intel 228V did not throttle while running this workload. It consistently had at least one core above 4GHz.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Test \ Platform&lt;/th&gt;
&lt;th&gt;Intel 228V&lt;/th&gt;
&lt;th&gt;Apple M4 (Powersave)&lt;/th&gt;
&lt;th&gt;Apple M4 (Full)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;4 cores compile + run&lt;/td&gt;
&lt;td&gt;2:25&lt;/td&gt;
&lt;td&gt;4:10&lt;/td&gt;
&lt;td&gt;2:07&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 core compile + run&lt;/td&gt;
&lt;td&gt;2:40&lt;/td&gt;
&lt;td&gt;3:55&lt;/td&gt;
&lt;td&gt;1:57&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4 cores run&lt;/td&gt;
&lt;td&gt;0:35&lt;/td&gt;
&lt;td&gt;2:10&lt;/td&gt;
&lt;td&gt;1:05&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 core run&lt;/td&gt;
&lt;td&gt;0:55&lt;/td&gt;
&lt;td&gt;1:55&lt;/td&gt;
&lt;td&gt;1:00&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;4 cores compile (diff)&lt;/td&gt;
&lt;td&gt;1:50&lt;/td&gt;
&lt;td&gt;2:00&lt;/td&gt;
&lt;td&gt;1:07&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;1 core compile (diff)&lt;/td&gt;
&lt;td&gt;1:45&lt;/td&gt;
&lt;td&gt;2:00&lt;/td&gt;
&lt;td&gt;0:57&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Well, these were obtained by eye-balling about 2 runs each, just to check if they differ. Often, the difference between subsequent runs was less than 1 second. So, nothing rigorous, but nothing totally off either. It does seem that multiple cores has negligible impact on the runs. If anything, on MacOS, the multiple cores actually degraded the run! It&amp;rsquo;s also possible that difference in compilation times are due to the difference between g++ on Linux and clang++ on MacOS; I could not trivially get the system to compile with clang++. There could also be a bunch of different optimization flags that are not being used.&lt;/p&gt;
&lt;p&gt;That said, it seems this is not the workload where I will get any significant benefits from Apple Silicon in the immediate future. There are similar reports and discussions &lt;a class="link" href="https://github.com/tuhdo/tuhdo.github.io/blob/8a26ccfea91c1e5fea7b18c110bf11746a37ee5a/emacs-tutor/zen3_vs_m1.org" target="_blank" rel="noopener"
&gt;here&lt;/a&gt;, &lt;a class="link" href="https://discourse.mc-stan.org/t/anyone-planning-on-getting-an-m1-machine-to-benchmark/19344/3" target="_blank" rel="noopener"
&gt;here&lt;/a&gt; and &lt;a class="link" href="https://discourse.mc-stan.org/t/stan-on-m4-mac/37240/16" target="_blank" rel="noopener"
&gt;here&lt;/a&gt;. Most of the reported gains seem to be from testing a 2018-era CPU to the M-series Apple Silicon :/. That&amp;rsquo;s not to dismiss the energy efficiency of Apple Silicon. M4 gets me about 2 conference days(!) on a single charge. Its standby time is also something that might put smartphones to shame. But at least for this particular workload, it doesn&amp;rsquo;t seem it&amp;rsquo;s a great fit.&lt;/p&gt;</description></item><item><title>Nostr: The next step to decentralized social media</title><link>http://digikar.online/microblog/p/nostr/</link><pubDate>Sat, 18 Jul 2026 18:25:34 +0200</pubDate><guid>http://digikar.online/microblog/p/nostr/</guid><description>&lt;p&gt;In 2005, Huffman and Ohanian got together and launched what they called the &lt;a class="link" href="https://www.britannica.com/money/Reddit" target="_blank" rel="noopener"
&gt;&amp;ldquo;front page of the internet&amp;rdquo;&lt;/a&gt;. Here, users could post the best articles from news outlets, journals, or even images and just text posts with each other, upvote what they liked and help others find good content. This platform was called &lt;a class="link" href="https://www.reddit.com/" target="_blank" rel="noopener"
&gt;Reddit&lt;/a&gt;. In 2026, &lt;a class="link" href="https://en.wikipedia.org/wiki/List_of_most-visited_websites" target="_blank" rel="noopener"
&gt;reddit is still the 8th most popular website on the entire internet&lt;/a&gt; even more popular than WhatsApp(!)&lt;/p&gt;
&lt;p&gt;Around the same time, in 2006, &lt;a class="link" href="https://en.wikipedia.org/wiki/History_of_Twitter" target="_blank" rel="noopener"
&gt;Dorsey and others&lt;/a&gt; launched another platform that allowed people to share SMS-sized chunks of text with each other. This was Twitter, also known as &lt;a class="link" href="https://x.com" target="_blank" rel="noopener"
&gt;X&lt;/a&gt; in recent times. In 2026, X is even more popular than Reddit!&lt;/p&gt;
&lt;p&gt;Likewise, the other top websites include Google, YouTube, Facebook, Instagram, ChatGPT(!), WhatsApp, and TikTok. Each is owned by some or other private corporation.&lt;/p&gt;
&lt;p&gt;The open source enthusiasts amongst us are not very happy with this state of the internet.&lt;/p&gt;
&lt;p&gt;First, the public internet is supposed to be &lt;em&gt;public&lt;/em&gt;. Anyone who has access to the internet, should be able to view the content they want to view without barriers. Platforms like X, Facebook, Instagram, WhatsApp, TikTok, and to a lesser extent also Reddit and YouTube forbid non-users from viewing the content. In other words, every time you visit one of these platforms, you need to have an account with them to view content. Ever been annoyed by the constant popups for log ins or location-based restrictions? Well, it doesn&amp;rsquo;t have to be this way!&lt;/p&gt;
&lt;p&gt;Secondly, if some content does not comply with the policies of platform moderators, it gets removed. &lt;a class="link" href="https://en.wikipedia.org/wiki/Censorship_by_X" target="_blank" rel="noopener"
&gt;For X, this takes the form of centralized moderation by X sometimes following government orders and sometimes mistakes.&lt;/a&gt; On reddit, the story is slightly more complex. While Reddit as a whole has some policies, the actual moderation is performed by volunteer users &amp;ndash; known as moderators &amp;ndash; so long as the content still agrees with the top-level policies. Until 2023, reddit moderators had access to third party tools that made moderation relatively doable. These tools also provided various other accessibility services. However, &lt;a class="link" href="https://en.wikipedia.org/wiki/Reddit_API_controversy" target="_blank" rel="noopener"
&gt;in 2023, Reddit introduced changes that made third party tools either non-free or impossible&lt;/a&gt;. After Reddit did not budge to appeals, many users and moderators quit reddit. Though, before deleting, they also deleted their comments, accounts, and also made their subreddits inaccessible. If you came across &amp;ldquo;deleted&amp;rdquo; or &amp;ldquo;unintelligible&amp;rdquo; comments on reddit, this was the context under which this happened. I myself cannot stand the &amp;ldquo;official&amp;rdquo; [android] reddit app to this day, and limit myself to its webapp.&lt;/p&gt;
&lt;p&gt;Were moderators just shitty humans for protesting and had no brains? Well, I&amp;rsquo;d perhaps be displeased at the content deletion, which has AI and content disattribution to blame too. But more importantly, reddit moderators are volunteers. They moderate out of their own time and passion, and without any monetary compensation. And &lt;a class="link" href="https://arstechnica.com/gadgets/2023/07/reddit-calls-for-a-few-new-mods-after-axing-polarizing-some-of-its-best/" target="_blank" rel="noopener"
&gt;subreddit moderation can be tough and also require actual qualification!&lt;/a&gt; And yet, what reddit offered them in return was a ban of the moderation tools themselves!&lt;/p&gt;
&lt;p&gt;What has open source to do with all this? Open source means you have access to the software and the source code that runs the software. If you don&amp;rsquo;t want a certain change to happen, or if you want a certain change to happen, you are completely free to make that change. Though, indeed you still need your own computers, servers and devices to run the modified software! In other words, if reddit were open source, this mishap could have been avoided!&lt;/p&gt;
&lt;p&gt;Well, not quite, there was still the possibility that moderators and admins of open source reddit of this counterfactual universe might still have went ahead with the API changes. What is needed then is the ability for multiple &amp;ldquo;reddit instances&amp;rdquo; to talk to each other, so that if you disagreed with the moderation policies and tools of one instance you could switch to another. Turns out this actually exists! People have been working on this &amp;ndash; &lt;a class="link" href="https://fediverse.party/en/fediverse/" target="_blank" rel="noopener"
&gt;Fediverse&lt;/a&gt; &amp;ndash; since the 2010s. The idea is exactly that multiple &amp;ldquo;instances&amp;rdquo; or &amp;ldquo;versions&amp;rdquo; of reddits &amp;ndash; and even &lt;a class="link" href="https://jointhefediverse.net/join?lang=en-us" target="_blank" rel="noopener"
&gt;instagrams, youtubes, Xs, mediums and goodreads&lt;/a&gt; &amp;ndash; can freely talk to each other. Users can sign up on one instance and use that same account on other instances. They can &amp;ldquo;subscribe&amp;rdquo; to as well as post content on other instances.&lt;/p&gt;
&lt;p&gt;That sounds very good. &lt;em&gt;Sounds.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;In practice, there are &lt;a class="link" href="https://join-lemmy.org/instances" target="_blank" rel="noopener"
&gt;494 lemmy instances&lt;/a&gt; alone. I won&amp;rsquo;t even start to count Mastodon and others. Several problems arise:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;It&amp;rsquo;s &lt;em&gt;supposed to&lt;/em&gt; not matter which lemmy instance you sign up for. However, it &lt;em&gt;actually matters&lt;/em&gt;, because if the instance you sign up for goes down &amp;ndash; say, because the admins ran out of funds or there were some server issues, etc &amp;ndash; &lt;em&gt;your account&lt;/em&gt; goes down with that instance!&lt;/li&gt;
&lt;li&gt;Each lemmy instance has its own set of communities. So, c/programming on lemmy.world is a &amp;ldquo;different&amp;rdquo; community than c/programming on lemmy.ml. In principle, you can subscribe to both of them. In principle, different lemmy instances and communities can subscribe to each other. But are all the 494 lemmy instances going to do that for all the 493 other lemmy instances? That simply does not scale!&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;And there are all different kinds of bugs arising from database duplication and what not.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;.&lt;/p&gt;
&lt;p&gt;But, there is an alternative!&lt;/p&gt;
&lt;p&gt;Enter the &lt;a class="link" href="https://nostr.org/" target="_blank" rel="noopener"
&gt;Nostr&lt;/a&gt; protocol - which literally stands for &lt;em&gt;Notes and Other Stuff Transmitted by Relays&lt;/em&gt; &amp;ndash; that was developed as recently as 2020.&lt;/p&gt;
&lt;p&gt;The elements of Nostr map quite straightforwardly onto the real world. In the real world, our identities are owned by us. When we talk, a &lt;em&gt;medium&lt;/em&gt; &amp;ndash; air or something else &amp;ndash; transmits our message to another user. In Nostr, similarly, the identities are owned by us. These identities can write messages that are transmitted to others via what are called relays. This is in contrast to Lemmy and Fediverse, where identities belong to the server-instance. Thus, it can appear quite strange when one views Nostr through the lens of existing social media. On the other hand, when one views Nostr through the lens of the real world, it seems very straightforward. This separation of Nostr identities from relays also means that when a relay goes down, even when &lt;em&gt;all relays&lt;/em&gt; go down, that identity still remains with you!&lt;/p&gt;
&lt;p&gt;Using concepts from cryptography, a Nostr identity takes the form of a public key called &lt;em&gt;npub&lt;/em&gt; and a private key called &lt;em&gt;nsec&lt;/em&gt;. Both of these are essentially long sequences of random characters. These keys are used by &lt;a class="link" href="https://nostrapps.com/" target="_blank" rel="noopener"
&gt;Nostr clients&lt;/a&gt;. As its name suggests, an &lt;em&gt;nsec&lt;/em&gt; is something you should never share with other people or Nostr clients you don&amp;rsquo;t trust!&lt;/p&gt;
&lt;p&gt;Whenever you write a &lt;em&gt;note&lt;/em&gt; using a Nostr client such as &lt;a class="link" href="https://amethyst.social/" target="_blank" rel="noopener"
&gt;Amethyst&lt;/a&gt;, this &lt;em&gt;nsec&lt;/em&gt; is used to &lt;em&gt;sign&lt;/em&gt; your note. Other users can then use their own Nostr clients to verify using your public key &lt;em&gt;npub&lt;/em&gt; that, indeed, the note was actually written by you, and not someone else falsely claiming to be you.&lt;/p&gt;
&lt;p&gt;Note that, in verifying that a note was actually written by you, no server or central system is necessary! Some kind of &lt;em&gt;relay&lt;/em&gt; is still necessary for transmission. But it is a relatively dumb software that simply transmits notes from some clients to other clients. This is as good as &lt;em&gt;air&lt;/em&gt;. Air does nothing. It just transmits my voice to you!&lt;/p&gt;
&lt;p&gt;A relay can still filter out notes. However, it is ultimately the client who decides which other users&amp;rsquo; notes to actually show you. Most clients do this in two ways. Firstly, you can &amp;ldquo;follow&amp;rdquo; other users npubs. By doing this, you should get the notes they write or reshare in &lt;em&gt;your feed&lt;/em&gt;. Secondly, you can browse content from some relays and also filter them out on the basis of various criterion. For example, if you dig a bit into Nostr, you might notice that it is surrounded by bitcoin and cryptocurrency &lt;del&gt;enthusiasts&lt;/del&gt; freaks. I usually have a preference for content other than bitcoin. So, I have set &amp;ldquo;bitcoin&amp;rdquo; as a filter term in my client. This means I don&amp;rsquo;t see anything mentioning bitcoin in the first place!&lt;/p&gt;
&lt;p&gt;You can probably start out with &lt;a class="link" href="https://nostr.org/" target="_blank" rel="noopener"
&gt;nostr.org&lt;/a&gt; or &lt;a class="link" href="https://nostr.how/en/what-is-nostr" target="_blank" rel="noopener"
&gt;nostr.how&lt;/a&gt; and then explore the internet to learn more. The &amp;ldquo;Join Nostr&amp;rdquo; on nostr.org should already get you a pair of npub and nsec that you can use for posting.&lt;/p&gt;
&lt;p&gt;&lt;img src="nostr-org.png"&gt;&lt;/img&gt;&lt;/p&gt;
&lt;p&gt;More importantly, for merely reading, you don&amp;rsquo;t need any keys or install any software at all! You can just use a &lt;a class="link" href="https://nostrapps.com/#microblogging#web" target="_blank" rel="noopener"
&gt;Nostr webclient&lt;/a&gt; &amp;ndash; &lt;a class="link" href="https://primal.net/reads" target="_blank" rel="noopener"
&gt;Primal&lt;/a&gt; is usually a recommended choice. &lt;a class="link" href="https://amethyst.social/" target="_blank" rel="noopener"
&gt;Amethyst&lt;/a&gt; is a reasonable android app.&lt;/p&gt;
&lt;p&gt;If you decide to give Nostr a try, do follow me! &lt;a class="link" href="https://primal.nprofile1qqs2540j8qjkjpelcun94e0j8jg7lsgwztvsxvsp9dd4hydq72v4gzclzxztk" target="_blank" rel="noopener"
&gt;digikar&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a class="link" href="https://primal.net/p/nprofile1qqspyca37sznlgx4jvdqrnn2nj5uj5mxmxa6me5elxgmtgmwd9g4atckj0nmw" target="_blank" rel="noopener"
&gt;HackerNews 250&lt;/a&gt; is another interesting poster to follow!&lt;/p&gt;
&lt;p&gt;All that said, I wouldn&amp;rsquo;t say Nostr is as smooth as Instagram 👀. So, expect some friction. More importantly, there is the &lt;a class="link" href="https://en.wikipedia.org/wiki/Network_effect" target="_blank" rel="noopener"
&gt;Network effect&lt;/a&gt; which means Nostr won&amp;rsquo;t provide much value until there are enough users in one&amp;rsquo;s own circle using it. It is probably a decade too early to advocate Nostr.&lt;/p&gt;
&lt;p&gt;I myself am passively looking for bot tools to automate content posting to Nostr from other platforms. But I currently have my hands on a bit too many things, so I&amp;rsquo;ll relegate that, perhaps, to 2027 or later.&lt;/p&gt;</description></item><item><title>The role of Open Source and Data Privacy for Security</title><link>http://digikar.online/microblog/p/data-security/</link><pubDate>Tue, 13 Jan 2026 18:08:32 +0100</pubDate><guid>http://digikar.online/microblog/p/data-security/</guid><description>&lt;p&gt;Internet has been amazing. You send a message. And it reaches the other end of the Earth in seconds. Even more, you can communicate with live video and audio! It seems magical.&lt;/p&gt;
&lt;p&gt;Yet it is not. All communication is transmission of energy. Energy travels through space &amp;ndash; which may be occupied by matter or may not. Most space through which communications travel is openly available to everyone. The same space is used by multiple communicators. Does that mean everyone can access the messages I send over the internet?&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s a scary thought. All your bank account details, passwords, private messages, your voice, your tone, your looks*, all travel over the internet. Are these all available to the public at large? (*You know now with generative AI, your voice and looks are sufficient to prepare videos as if you had done or said things you hadn&amp;rsquo;t!)&lt;/p&gt;
&lt;p&gt;Unfortunately, in an unencrypted world, it would be true that everyone can see everyone&amp;rsquo;s messages. You can read malicious users&amp;rsquo; messages, and they can read yours. Furthermore, what even determines that a message your messaging app says was sent by your friend was really sent by your friend? And not someone else disguised as your friend?&lt;/p&gt;
&lt;p&gt;Humans, some of them, are smart. These problems have been known since the dawn of the internet in the 20th century, possibly before. Solutions have been devised against them. Today, for most communication problems in the general, we know that&lt;/p&gt;
&lt;center&gt;
If communications satisfy certain assumptions, then certain particular security benefits are &lt;em&gt;guaranteed&lt;/em&gt;.
&lt;/center&gt;
&lt;p&gt;In other words,&lt;/p&gt;
&lt;center&gt;
If we build communication softwares that satisfy certain assumptions, then we get certain particular security benefits.
&lt;/center&gt;
&lt;p&gt;These benefits include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Knowing that the message your messaging app says was sent by a friend was really sent by your friend&amp;rsquo;s device.&lt;/li&gt;
&lt;li&gt;Ensuring that only you and your friend can read messages sent to each other. That is, your messages are inaccessible to anyone else.&lt;/li&gt;
&lt;li&gt;&amp;hellip; and many more &amp;hellip;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In general, the &amp;ldquo;friend&amp;rdquo; may be any other communication end-point, such as your bank, where security is just as important if not more. However,&lt;/p&gt;
&lt;center&gt;
How do we know that communication softwares actually satisfy the assumptions required for security?
&lt;/center&gt;
&lt;p&gt;Three methods:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;We trust the word of the person or institute who developed the software &lt;em&gt;and make profits from the software&lt;/em&gt;. In general, the greater motive here is making monetary profits, since that is a very essential aspect of livelihood of the person or institute.&lt;/li&gt;
&lt;li&gt;We trust the word of the person or institute who is &lt;em&gt;motivated to study and develop the software and ensure the software satisfies the assumptions required for security&lt;/em&gt;. In general, monetary profit as a motive is either absent or very much secondary.&lt;/li&gt;
&lt;li&gt;We study the workings of the software ourselves.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Both 2nd and 3rd methods require that how the software works is publicly accessible. This means the source code (but also the infrastructure details) are publicly available. In other words,&lt;/p&gt;
&lt;center&gt;
Trusting the claim that a particular software is secure becomes easier when the workings of the software are publicly known, that is, it is open source.
&lt;/center&gt;
&lt;p&gt;How to find open source softwares?&lt;/p&gt;
&lt;center&gt;
An easy method to find the open source alternative for a software is to simply google "open source alternative to &lt;em&gt;software that interests you&lt;/em&gt;". You can also append the search by "site:reddit.com" or "site:stackexchange.com" or you can also consult one of your tech-geek friends or family-members.
&lt;/center&gt;
&lt;p&gt;It is trivial to see that between two people or institutes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;One who is motivated by monetary profits&lt;/li&gt;
&lt;li&gt;Another who is motivated by software security&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The second category of people or institutes would end up with more secure softwares in any particular class of softwares in the longer run. In other words, in the longer run, the first category of people or institutes are likely to make mistakes even if, besides making money, they too want to make their softwares secure. This is simply because, for the software developers, motivation for software security drives learning and brings in the time to spend on the software and make changes that may go against the monetary motivation.&lt;/p&gt;
&lt;p&gt;That people and software developers can make mistakes brings us to the second point of this blog post. Your data includes - your name, phone numbers, email addresses, passwords, bank account numbers, people or institutes you send messages to or receive messages from, what messages you send, which websites you access, how frequently, at what time, for how long, your phone location, when do you leave your home, office or visit a friend, and much more.&lt;/p&gt;
&lt;center&gt;
You would &lt;em&gt;WISH&lt;/em&gt; that the banks, institutes, and messaging softwares that have access to your data are actually storing them securely, in a manner that does not permit thieves and malicious actors from misusing your data.
&lt;/center&gt;
&lt;p&gt;This is also called a data breach. In 2025 alone, there were &lt;a class="link" href="https://www.cybersecurity-insiders.com/top-5-banking-data-breaches-of-2025-2/" target="_blank" rel="noopener"
&gt;at least 5 data breaches with banking softwares&lt;/a&gt; resulting in millions of individuals losing their banking details to malicious hackers. It is not just banking softwares. Data breaches can happen with &lt;a class="link" href="https://therecord.media/8-million-affected-zoomcar-data-breach" target="_blank" rel="noopener"
&gt;car companies&lt;/a&gt;, &lt;a class="link" href="https://en.wikipedia.org/wiki/Kido_International_cyberattack" target="_blank" rel="noopener"
&gt;education providers&lt;/a&gt;, &lt;a class="link" href="https://www.computing.co.uk/news/2025/security/asahi-breach-exposes-customers-details" target="_blank" rel="noopener"
&gt;beer companies&lt;/a&gt;, &lt;a class="link" href="https://www.scworld.com/brief/almost-27m-sk-telecom-sim-records-compromised" target="_blank" rel="noopener"
&gt;sim providers&lt;/a&gt;, &lt;a class="link" href="https://www.yahoo.com/news/articles/kering-confirms-data-breach-192611717.html" target="_blank" rel="noopener"
&gt;luxury brands&lt;/a&gt;, and pretty much everything that is connected to internet.&lt;/p&gt;
&lt;p&gt;If the softwares were open source, it would be easier to ensure security. However, the next best thing to open source might be data privacy. How do you prevent your data from being misused?&lt;/p&gt;
&lt;center&gt;
To prevent your data from being misused, you restrict your data from being accessible. That is, you keep your data &lt;em&gt;private&lt;/em&gt;.
&lt;/center&gt;
&lt;p&gt;How do you make your data more private? This is a bit like asking &lt;em&gt;How do I make myself more healthy?&lt;/em&gt; There&amp;rsquo;s no simple answer, although one can try some guidelines! See &lt;a class="link" href="https://www.reddit.com/r/privacy/wiki/index/#wiki_what_can_i_do_to_protect_my_privacy.3F" target="_blank" rel="noopener"
&gt;here&lt;/a&gt; or &lt;a class="link" href="https://www.reddit.com/r/privacy/comments/1cposnq/starting_from_scratch_how_to_delete_my_online/" target="_blank" rel="noopener"
&gt;here&lt;/a&gt; for a detailed guide. Here&amp;rsquo;s an attempt at some guidelines:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Reduce reliance on closed source softwares for information processing. This includes Microsoft Word, Powerpoint, Excel, as well as Google Docs, Slides, and Sheets, and also Apple. Of course, you may be forced to use these apps &lt;em&gt;because your colleague uses them&lt;/em&gt;. In that case, either convince them to shift to open source alternatives or use the open source alternatives for your personal use cases. Simple alternatives include &lt;a class="link" href="https://www.markdownguide.org/getting-started/" target="_blank" rel="noopener"
&gt;markdown&lt;/a&gt;, &lt;a class="link" href="https://www.overleaf.com/learn/latex/Learn_LaTeX_in_30_minutes" target="_blank" rel="noopener"
&gt;latex&lt;/a&gt;, and &lt;a class="link" href="https://blog.documentfoundation.org/blog/2025/05/16/what-is-odf/" target="_blank" rel="noopener"
&gt;open document formats&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Try out &lt;a class="link" href="https://www.youtube.com/watch?v=2W7Pi26ZHm8" target="_blank" rel="noopener"
&gt;Kubuntu&lt;/a&gt; on newer laptops or &lt;a class="link" href="https://www.youtube.com/watch?v=lnzMl7BFM0Q" target="_blank" rel="noopener"
&gt;Xubuntu&lt;/a&gt; to renew old laptops. Be sure to use the &amp;ldquo;Long-Term Support (LTS)&amp;rdquo; versions, currently 24.04. You can also try it as a &lt;a class="link" href="https://www.youtube.com/watch?v=2uxX0UtInhQ" target="_blank" rel="noopener"
&gt;virtual machine&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Switch to secure open-source messaging softwares:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class="link" href="https://signal.org/" target="_blank" rel="noopener"
&gt;Signal&lt;/a&gt; or &lt;a class="link" href="https://molly.im/" target="_blank" rel="noopener"
&gt;Molly&lt;/a&gt; &lt;em&gt;in addition to&lt;/em&gt; Whatsapp, Messenger, Instagram.&lt;/li&gt;
&lt;li&gt;&lt;a class="link" href="https://jitsi.guide/blog/jitsi-vs-zoom/" target="_blank" rel="noopener"
&gt;Jitsi&lt;/a&gt; &lt;em&gt;in addition to&lt;/em&gt; Zoom or Google Meet or Teams&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use &lt;a class="link" href="https://www.pcmag.com/explainers/why-you-need-a-password-manager-and-how-to-choose-the-right-one" target="_blank" rel="noopener"
&gt;password managers&lt;/a&gt; like &lt;a class="link" href="https://bitwarden.com/" target="_blank" rel="noopener"
&gt;Bitwarden&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&amp;hellip; You are motivated enough. Read one of those detailed guides now :)&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="to-sum-up"&gt;To sum up
&lt;/h3&gt;&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Open source aids security. You can find open source alternatives by simply googling &amp;ldquo;open source alternatives to &amp;lt;app you want&amp;gt;&amp;rdquo;. Optionally, you can append the search with &amp;ldquo;site:reddit.com&amp;rdquo; or &amp;ldquo;site:stackexchange.com&amp;rdquo;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Privacy aids security. Privacy is a bit like moving towards a healthy lifestyle. There are lots of small changes in the way. See &lt;a class="link" href="https://www.reddit.com/r/privacy/wiki/index/#wiki_what_can_i_do_to_protect_my_privacy.3F" target="_blank" rel="noopener"
&gt;this&lt;/a&gt; or &lt;a class="link" href="https://www.reddit.com/r/privacy/comments/1cposnq/starting_from_scratch_how_to_delete_my_online/" target="_blank" rel="noopener"
&gt;this&lt;/a&gt; for a detailed guide.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;</description></item></channel></rss>