Can We Route Around the App Stores?
Hackers have long understood that networks are resilient. We can bootstrap anonymity and routing layers like Tor, I2P, and Nym with relative ease, and move traffic across hostile environments with surprising flexibility. In many ways, the network layer is the least of our problems. The real challenge begins next layer up, where applications, platforms, and distribution channels impose control over how that network can actually be used. Over the past year, the presenters built and deployed a working suite of desktop applications for communication, identity, and storage, and put them in the hands of real users in classroom environments. This gave a clear view into what happens when people try to use privacy-first tools in practice. You will see what worked, what broke, and how user expectations shaped by mainstream platforms collide with systems designed for autonomy and control. These applications also include an independent software delivery and verification model, allowing updates and dependencies to be distributed and validated without relying on centralized app stores. These ideas are now being brought to mobile devices, where the constraints are far more severe. This talk focuses on the practical challenges of running user-controlled software on phones: app store restrictions, packaging and distribution barriers, Android limitations, and Apple policies that restrict apps which resemble alternative software ecosystems. This talk will also address sideloading, UI constraints, and the current state of hardware, including experiments with PinePhone, Fairphone, and GrapheneOS. The core question is simple: how can we build trustworthy applications that route around the app stores?
Sunday 1600 Crystal Ballroom