The future of selfhosted services is going to be… Android?

Wait, what?

Think about it. At some point everyone has had an old phone lying around. They are designed to be constantly connected, constantly on… and even have a battery and potentially still a SIM card to survive power outages.

We just need to make it easy to create APK packaged servers that can avoid battery-optimization kills and automatically configure an outbound tunnel like ngrok, zerotrust, etc…

The goal: hosting services like #nextcloud, #syncthing, #mastodon!? should be as easy as installing an APK and leaving an old phone connected to a spare charger / outlet.

It would be tempting to have an optimized ROM, but if self-hosting is meant to become more commonplace, installing an APK should be all that’s needed. #Android can do SSH, VPN and other tunnels without the need for root, so there should be no problem in using tunnels to publicly expose a phone/server in a secure manner.

In regards to the suitability of home-grade broadband, I believe that it should not be a huge problem at least in Europe where home connections are most often unmetered: “At the end of June 2021, 70.2% of EU homes were passed by either FTTP or cable DOCSIS
3.1 networks, i.e. those technologies currently capable of supporting gigabit speeds.”

Source: https://digital-strategy.ec.europa.eu/en/library/broadband-coverage-europe-2021

PS. syncthing actually already has an APK and is easy to use. Although I had to sort out some battery optimization stuff, it’s a good example of what should become much more commonplace.

cc: @selfhosted
#selfhosted #selfhosting

  • @RegalPotoo@lemmy.world
    link
    fedilink
    English
    938 months ago

    Running web services on a device that hasn’t seen a security patch in 3 years seems like a bad idea.

    Also, unless you can mount a real hard drive, you are going to very quickly run into I/O bandwidth issues and flash longevity limits

    • Wander ΘΔ :verified_paw:OP
      link
      fedilink
      168 months ago

      @RegalPotoo Maybe I should have been more specific in the wording of my title.

      No one planning on hosting public multi-user service that would see some serious traffic would probably benefit from hosting on a phone.

      Someone who wants to simply run a single-user instance or their personal nextcloud? I think that’s a real possibility.

      • @RegalPotoo@lemmy.world
        link
        fedilink
        English
        108 months ago

        It’s a really cool idea, and the internet would probably be a better place if more people took ownership of their infrastructure rather than relying on ad-supported “free” services, and it’s easy to criticise an approach that I’ve spent maybe 10 minutes actually thinking about - I’ve got my reservations, but if you can make it work it would be awesome

      • @knF@lemmy.world
        link
        fedilink
        English
        58 months ago

        It is possible nowadays: I’m hosting quite a few services on an 5 years old Android. Just with Termux, no root required. Of course connectef it’s just to the internal network due to all the security concerns mentioned in the post.

        To solve all the bandwidth/connection issues, I’ve bought a usbc-ethernet dongle that works like a charm.

        To mitigate battery issues I’ve limited the charging to 85%.

        I would never host Jellyfin there, but with webdav and Kodi I can get my media served easily to all my devices at home

      • @krash@lemmy.ml
        link
        fedilink
        English
        48 months ago

        The risk that @regalpotoo mentioned is still unmitigated though, single user instance or not. At worst, the personal data can be exfiltrated. At best, the server can be used as a part of a botnet. Even if the software (nextcloud) would be patched, that doesn’t help against exploits on a OS level.

        Granted, one could run services inside a vpn and have some kind of preventive / monitoring controls, but you’re still need to implement some kind of defense in depth in order to protect it.

    • Otter
      link
      fedilink
      English
      108 months ago

      I’d also be worried about battery issues

      Don’t want to find it having overheated / turned into a pufferfish

      • chiisana
        link
        fedilink
        English
        118 months ago

        Future news headline: “The web server literally exploded under the DDOS attack.”

  • southsamurai
    link
    fedilink
    English
    428 months ago

    I mean, android is fine I guess, but it’s being pushed to be less and less able to be separated from Google. I think for a lot of people interested in self hosting, there’s a low amount of interest in it because of that.

    • Wander ΘΔ :verified_paw:OP
      link
      fedilink
      5
      edit-2
      8 months ago

      @southsamurai Oh that’s definitely a huge concern, but not just for self-hosting but for privacy in general.

      But still, if the average joe wants to self-host something using an old phone is probably the easiest way to get them to try self-hosted alternatives and drop corporate / commercial services.

      Maybe not the ‘average average joe’ such as my parents, but anyone who is minimally curious enough to do stuff such as registering a domain, setting up a game server for friends and maybe has opened the CMD windows console once or twice in the past following a tutorial. That kind of demographic (IDK if it has a name) might be much more inclined to self-host if it was as easy as installing an APK and letting your phone one somewhere at home.

      Overall as long as Android doesn’t become straight out malicious spyware itself, the benefit of dropping commercial alternatives might very well be a net positive. In a worst-case scenario, any tunnel / vpn configuration necessary to expose a service to the internet could also add an automated step to blackhole requests to google’s tracking servers.

        • Wander ΘΔ :verified_paw:OP
          link
          fedilink
          4
          edit-2
          8 months ago

          @Omniraptor ah yes! Probably that’s why.
          Actually the whole original post was sent via Mastodon.

          I tend to write posts that I share to my Mastodon followers and then at the end I mention a Lemmy community if I believe the community would also find it interesting.

          • @Omniraptor@lemm.ee
            link
            fedilink
            English
            4
            edit-2
            8 months ago

            That is so cool I didn’t realize lemmy and mastodon were different views into the same database, assumed they were different services with no overlap except some underlying tech (I don’t know much about fediverse structure). But how does that work with like, character limits? Iirc lemmy can have much longer comments

            • Wander ΘΔ :verified_paw:OP
              link
              fedilink
              28 months ago

              @Omniraptor in theory Mastodon will show a “read more” button for longer comments. Top level posts sent from Lemmy often require clicking the link to view them in full and content isn’t ordered by votes because they don’t exist.

              So, it’s a bit messy to read Lemmy from Mastodon, but posting something and then replying to comments on that thread is really easy.

            • @Omniraptor @Wander Probably user is limited during writing by own instance limit and longer posts of others could be displayed. I saw this between mastodon/misskey instances with various limits, probably it could be similar for lemmy/kbin federation. Currently I am writing this on small mastodon server with 20k limit (never used this fully yet…)

  • @onlinepersona@programming.dev
    link
    fedilink
    English
    218 months ago

    IMO, more like Linux. Android for such old devices is unmaintained, but if you’re able to run Linux on it you’ll still be able to apply kernel updates and security updates for software will continue to exist. Many things are opensource too and you should be able to recompile them on the android device to make it run.

  • @Moonrise2473@feddit.it
    link
    fedilink
    English
    188 months ago

    Big problem: updates for something that is directly exposed to internet

    Some low end devices will stop getting security updates 6 months after launch because the OEM launches a new model every two weeks and obviously doesn’t have resources to dedicate to it

    In some cases, even high end devices don’t get updates and are discontinued internally shortly after launch, for example the Xiaomi mix 3 5g

    Yes, root and custom ROMs could solve the problem, but not as easy as regular Linux where you just use a package manager to update. First issue is needing to wipe after updates and you have to reinstall and reconfigure everything

  • @awooo@pawb.social
    link
    fedilink
    English
    188 months ago

    Hmm I think my main concern would be lack of kernel/firmware updates, running something like postmarketOS could partly solve that and still be nearly as easy to set up (just unlock and flash a prebuilt image)

    But firmware is still almost entirely dependent on the vendor, since it’s all signed and unpatchable.

    Next issue would be lack of connectivity on a lot of phones, which have gone backwards and include USB 2.0 now. WiFi is an option, but less stable, I personally decided to just go 100Mbps and suffer.

    As for the battery, it would help a lot if phones were designed to boot without one and they were removable, it all worked well for about half a year until I found out I had a spicy pillow and had to replace it with direct power to the board, which made the whole setup much less elegant and required soldering.

    It all comes down to how devices are designed in the end. If someone took the time to make a computer instead of just a phone, and included features that make it useful past its initial life that aren’t that popular (display output, microsd, headphone jack), mainlined all the drivers and maintained firmware, that would be a different story.

    But that’s not a very profitable model, because it’s all about reducing waste and thus selling less. A lot needs to change.

  • Benjohn
    link
    fedilink
    178 months ago

    @Wander @selfhosted this whole “We are walking about with entirely reasonable servers in our pockets for reasonable scales - why doesn’t it feel like that?” thing is in my brain quite a bit.

  • Björn Tantau
    link
    fedilink
    English
    178 months ago

    I feel like Android is adding some new power saving “feature” with every version to kill all the useful stuff I want to keep running in the background.

    Last stupid thing I remember was when it removed my CalDAV synchronisation because I haven’t been “using” the CalDAV app for some months.

    Not to mention all the times it decides to kill something you want to use because it thinks the RAM would be more needed elsewhere. Honestly my 128 MB RAM Nokia N900 could run more apps at the same time than my 4 GB RAM Fairphone.

    • @Buddahriffic@lemmy.world
      link
      fedilink
      English
      108 months ago

      Yeah, android is a lot like Windows in that they make choices that might benefit users who don’t know what’s going on but interrupts or harms things power users are doing. They are just better at not being as annoying with it and don’t beg people to use their default programs.

    • @trolololol@lemmy.world
      link
      fedilink
      English
      68 months ago

      You’re right, that’s a feature if you’re a regular phone user and a bug if you want it as a server.

      Also, even if the application is still running you can have the os almost fully shutdown even if it’s charging. Again, it’s a behavior tuned for a typical user.

  • @MonkCanatella@sh.itjust.works
    link
    fedilink
    English
    168 months ago

    Pretty cool concept actually. upcycling old tech does seem to be a selfhosting hobby. I see a lot of criticism that I think doesn’t really see the value proposition. You should be able to root the device and install a new OS. I wonder how limited the bandwidth would be though, and whether it’d be worth the cost to get adapters, if they exist, to allow more throughput. I do like the concept though.

    • @elscallr@lemmy.world
      link
      fedilink
      English
      38 months ago

      If I’m just using them as a glorified small Linux box it could work pretty well. If you’re going to host services that don’t require a ton of bandwidth you don’t need a hard line or anything. Hell my Plex server is using WiFi (802.11ax but still) and it delivers 4K just fine.

      • @MonkCanatella@sh.itjust.works
        link
        fedilink
        English
        38 months ago

        Shit, I run plex of my synology ds1621+ and it chokes on 4k regularly. This is with a cabled connection. It’s almost certainly the CPU though. These things are weak as hell. What’re you running plex on ?

        • @elscallr@lemmy.world
          link
          fedilink
          English
          38 months ago

          Admittedly the server on which it’s running is pretty beefy and I don’t let it transcode. I’ve got enough disk space that if something spends time transcoding I just optimize it to a new version of the file.

          By bandwidth I was speaking in terms of network only, but if you were to run it on a simple server that didn’t do any transcoding it might be ok.

          • @MonkCanatella@sh.itjust.works
            link
            fedilink
            English
            28 months ago

            Ah ok makes sense. Yeah it’s definitely not latency or throughput causing stuttering for me. Gonna definitely be the anemic CPU. Luckily I have an extra laptop that I haven’t used in years that would make a perfect addition to the homelab. Can just through linux on it and use it as a plex/roon server

            • @elscallr@lemmy.world
              link
              fedilink
              English
              28 months ago

              Yeah my server is an i5 using an onboard GPU so it’s nothing crazy but it’s got 80TB of drive space, so I optimize for what I put my money into.

              Hell, sometimes it’s even easier to copy the data to my gaming rig, transcode it, and rsync it back. If I’m done playing for the night and about to go to bed and I have like a TV show or something I know has to be transcoded, I’ll just queue up a job and let it run while I’m sleeping and script it so it rsyncs everything back when it’s done transcoding.

              • @MonkCanatella@sh.itjust.works
                link
                fedilink
                English
                28 months ago

                That’s definitely a good call. Before I even had a NAS, I’d just throw some movies and stuff on my macbook when I had to travel. Problem is that when you’re loading it up, you think you know what you’ll want to watch and then later you just wish you had different choices.

  • @PieMePlenty@lemmy.world
    link
    fedilink
    English
    158 months ago

    Android? No. It’s not made for it. You are using a hammer to paint a wall.

    Phones? With a different Linux based distro? I can see it happening. For a small niche at least.

  • @Appoxo@lemmy.dbzer0.com
    link
    fedilink
    English
    148 months ago

    Who provides the software and firmware updates for my antique Samsung S4 and Galaxy young?
    I hope you will give me some firmware for the old snapdragon.
    Don’t forget the loads of Exynos CPUs and loads of GPUs from different vendors.

  • @CarbonatedPastaSauce@lemmy.world
    link
    fedilink
    English
    138 months ago

    The future? No. A useful niche? Sure.

    I run 4 mail servers, 2 game servers, 3 directory/auth servers, a firewall/router, a NAS, a security system server, a media server, a monitoring server, and a couple others. Android ain’t gonna cut it.

  • @TCB13@lemmy.world
    link
    fedilink
    English
    12
    edit-2
    8 months ago

    The future of selfhosted services might includes phones yes, Android most likely not.

    Think about it, those phones might work right now but in 10 years their Android versions will not support anything, they wont even have root certificate updates breaking SSL, the kernel will be missing support for whatever people need and whatnot. Maybe the phones won’t even boot because some key will expire somewhere… let alone security vulnerabilities.

    People selfhost on 10-year old hardware right now, but they do install modern Linux distros that are well supported and up to date. I believe the most likely scenario is that at some point the “security” of most of that hardware will be broken and you’ll be able to run some version of AOSP for older hardware and/or a generic Linux.

    But that might not ever happen, those phones are built like hell and we’ve another category of hardware with similar characteristics that was never repurposed for anything after a decade - routers. It’s common to see older routers that are now too slow when it comes to wifi or even CPU and although they’re way more open and primitive than modern smartphones when it comes to software we usually can’t even repurpose them as dumb switches with alternative / open software. OpenWRT and DD-WRT might work in some case but those are exceptions and usually those models were already supported by those firmwares. For instance there are enough Thomson / Technicolor TG784n ISP provided routers to create a second moon and the effort to break their security and create a usual firmware is so much that nobody did it. It’s just easier to pay 30€ for a cheap router/switch and move on.

    • @TCB13@lemmy.world
      link
      fedilink
      English
      18 months ago

      People who downvote, care to explain? You clearly never tried to access the Internet / install modern software on a Windows XP computer :)

      • @Wander@yiffit.net
        link
        fedilink
        English
        38 months ago

        Am curious. Are you able to run a modern windows 10 virtual machine / virtualbox vm on XP?

        • @TCB13@lemmy.world
          link
          fedilink
          English
          3
          edit-2
          8 months ago

          I just talking about that: https://lemmy.world/comment/4731273

          It doesn’t appear to be possible. The Vmware version that supports the latest Windows 10/11 won’t support a host system older than Windows 8. The same applies to VirtualBox.

          The usual issue with that is that the modern OS requires drivers for the virtual devices and if you get a modern version of Vmware it won’t run on Windows XP (https://kb.vmware.com/s/article/90060) if you get an older version of Vmware that does run on XP it won’t have / be compatible with the drivers required for Windows 11 to work.

    • Wander ΘΔ :verified_paw:OP
      link
      fedilink
      08 months ago

      @TCB13 I’m not an expert in the matter but I wonder how large the attack surface actually is for a web service that has a single port exposed via a tunnel which can even contribute to doing some security filtering.

      The application / server component can actually be updated since it’s just an APK. And someone else in this thread actually linked to whole linux distros that can be installed and run without root. In theory even if the underlying OS is insecure, more secure OSes can be installed on top, or risk can be severely limited by only exposing a single port.

      Basically, while flashing a new ROM would be ideal, I think there’s likely a way in which a sandboxed and possibly even updated environment with updated TLS cyphers, CA stores, etc… can be run in a secure manner on top of a stock Android ROM.

      Furthermore, developers packaging their apps into APKs could run security checks and by the time it says “your OS is insecure” you’re already on your third phone and can host stuff on your second. I mean… Android phones are in their prime for two/three years at most in my experience :P

      • @TCB13@lemmy.world
        link
        fedilink
        English
        2
        edit-2
        8 months ago

        The application / server component can actually be updated since it’s just an APK. And someone else in this thread actually linked to whole linux distros that can be installed and run without root. In theory even if the underlying OS is insecure, more secure OSes can be installed on top, or risk can be severely limited by only exposing a single port.

        When you install another one “on top” you’re essentially speaking about a very thin layer above the base OS. In most cases that’s simply a container that uses the base OS kernel. This is what happens today and it works for a while but it comes a point (way less than 10 years) when you won’t be able to have a modern top layer OS sitting on such older base OS because the kernel is way too old to support the requirements of the new OS.

        Even if go through the trouble of virtualization in order to have the top layer running a modern kernel it will most likely fail. It would require a LOT more effort coding the support for the old hardware and a ton of other virtualization pains to just end with a very slow system. We’ve examples of this: it is next to impossible to virtualize Windows 11 in a Pentium 4 that runs Windows XP, for instance a versions of Vmware that supports Windows 11 won’t support a host system older than Windows 8. The same applies to VirtualBox.

        Basically, while flashing a new ROM would be ideal,

        Yes it would but for that you would have to completely break the phone’s boot security and that isn’t feasible in all cases. Most phones doesn’t allow you to unlock the bootloader thus you can’t install another ROM/OS. Even on those you can some will only accept software that was signed by the manufacturer so unless there’s a leak of the key they use or it gets bruteforced in some way you won’t be able to do it.

        Take older routers as examples, those don’t even protect the firmware, nothing is signed, and yet the time and effort (weeks/months) required to make a simple open firmware to turn a SINGLE model into a dumb switches / routers that it isn’t worth it - after all you can get a < 30€ device today that is faster and more power efficient than those old units.

        With phones things are considerable worse as modern day devices are way more locked down than those router ever were. There’s also way more fragmentation (hundreds of phone models all running very specific hardware and software hacks). It’s very likely that in 10 years you’ll be able to buy some ARM / RISC board, such as a raspberry pi, that is open, run a modern OS out of the box and most likely cost you 30€.

  • Wander ΘΔ :verified_paw:OP
    link
    fedilink
    9
    edit-2
    8 months ago

    @selfhosted Update:

    1. Just to clarify, the the whole point is that Android makes it easy for less tech oriented people to host small single user / family services.

    It does not need to be perfect, have massive throughput or allow for massive amounts of read/write cycles.

    If people can host their own media server like Jellyfin or note taking apps like Joplin instead of using commercial services by simply installing an APK on an old phone they can leave connected at home, that’s already a big win.

    1. Regarding device longevity, Android 13 apparently supports / will support full KVM emulation. Windows can be run if you have root while android based VMs are expected to be possible without the need for root. Since this type of virtualization allows VMs to run their own kernel, keeping the “server app” updated should allow the user to be protected even if the host OS is outdated as long as these server-app-VMs are trustworthy themselves.
    • Lav
      link
      fedilink
      48 months ago

      @Wander @selfhosted digging into the updates or running linux instead of android that other comments are mentioning feels like missing the point a bit.

      the accessibility that this would provide could easily surmount the hurdle that prevents most from being able to get off big central services. self hosting, or even any alternative that doesn’t hold your hand 100% of the way (cough, mastodon) is beyond most people.

      even if it’s wrapped up nicely and not precisely long term, it would do a lot for the learned helplessness that big tech trains and to bridge that accessibility gap. even if the typical end user doesn’t get that involved, it could be an easy way in to understand how you might manage your own data.

      not like it’s much less safe having a limited security patch lifespan than (insert big company data breach here) :vlpn_happy_blep:

        • Lav
          link
          fedilink
          58 months ago

          @Wander @selfhosted more folks need to read this https://www.nngroup.com/articles/computer-skill-levels/

          it’s kinda easy to overlook this in techy circles. it’s why web 2.0 was able to reach most of the world, and why the old ways of building your site / hosting your services from scratch will always be limited in reach. most people just… don’t even know that’s an option, never mind have the background to know where to begin.

          unless you want to tell everyone to stop using the internet (fat chance), or continue to support the centralized corpo hellscape, we need easy ways for people to spin up their own digital infrastructure, and build platforms for themselves without a profit driven middleman.

          /rant
          sorry, this is a bit of a personal crusade to me, i love this idea :ms_awoo:

    • @TCB13@lemmy.world
      link
      fedilink
      English
      1
      edit-2
      8 months ago

      Regarding device longevity, Android 13 apparently supports / will support full KVM emulation. Windows can be run if you have root while android based VMs are expected to be possible without the need for root. Since this type of virtualization allows VMs to run their own kernel, keeping the “server app” updated should allow the user to be protected even if the host OS is outdated as long as these server-app-VMs are trustworthy themselves

      Guess you missed this: https://lemmy.world/comment/4731273

      Having virtualization doesn’t ensure future success. Not when the timeframe is something like more than 8 years.

      • @bustrpoindextr@lemmy.world
        link
        fedilink
        English
        -28 months ago

        Pass, I’ll take the cluster of raspberry pis for the same cost… For the purpose of self hosting my cluster is going to out perform your x86. Like why are you going to spend hundreds of dollars for an x86 that will do fine when you can spend $50 for a pi that will also do fine?

        Then you can just cluster those pis and get redundancy

        • Encrypt-Keeper
          link
          fedilink
          English
          138 months ago

          You’ve got it backwards, a small x86 box is more cost effective for better performance. With a raspberry pi you’re paying for the form factor (and often scarcity)

          • @bustrpoindextr@lemmy.world
            link
            fedilink
            English
            -6
            edit-2
            8 months ago

            You’ve got it backwards. A small x86 is a hundreds, and a rpi is 50… Like come on… Cost for performance isn’t even a question…

            Y’all… I thought you’d be better at tech than Reddit… this is sad

            • @AbidanYre@lemmy.world
              link
              fedilink
              English
              58 months ago

              You can get a wyse thin client on eBay for $50, and if you’re clustering the pis it’s not $50 anymore, so you can get a real computer on woot in the $150 range.

              Either of those options will run circles around a pi/pi cluster.

              • @MonkCanatella@sh.itjust.works
                link
                fedilink
                English
                18 months ago

                holy shit I haven’t thought about that webside in over a decade. Do you have personal experience purchasing self hosting stuff from there?

                • @AbidanYre@lemmy.world
                  link
                  fedilink
                  English
                  18 months ago

                  I’ve bought a couple old SFF PCs and tablets from there for low powered workstation stuff.

                  For self hosting I end up with rack mount dell servers when the prices fall off a cliff; right now it’s the 13th gen stuff that’s super cheap.

              • @bustrpoindextr@lemmy.world
                link
                fedilink
                English
                -58 months ago

                Please learn to read. Again. I thought I wasn’t on Reddit anymore.

                $50 for a pi. Not for clustering. For one. That’s it.

                An X86 PC is gonna cost you hundreds. That’s how I can cluster rpi, for the same cost. I hope you now know how to do basic math.

                • @AbidanYre@lemmy.world
                  link
                  fedilink
                  English
                  38 months ago

                  Insulting my reading ability and math skills would work better if you weren’t making a fool of yourself.

                  I gave you an example of a $50 x86 PC and mentioned the more expensive options because you brought up building a pi cluster in your first response to me, at which point you’re not talking about spending $50 anymore.

                  The main point is that either the thin client or the slightly more expensive computer will runs circles around your pi(s) for the same price.

                • @TCB13@lemmy.world
                  link
                  fedilink
                  English
                  28 months ago

                  This isn’t even true. A Pi sells for 50$ yes, + USB cable for power + USB power adapter + case + whatever else money grab.

                  A second hand HP mini with an i5 7th gen CPU that is WAY faster comes with everything including 8 GB of RAM and 256GB of SSD (or better if you get a good deal) for around 80$. Tell me about your math again…