If you want to keep a spare phone plugged in all the time in your closet, connected to Wifi/Ethernet, and hack it to be a webserver, then go ahead. But webservers on mobile devices, being used in a mobile way, are a terrible idea.
If you want to keep a spare phone plugged in all the time in your closet, connected to Wifi/Ethernet, and hack it to be a webserver, then go ahead. But webservers on mobile devices, being used in a mobile way, are a terrible idea.
You can't hack a web server in your closet to run on port 80 without jailbreaking your phone/unlocking the bootloader and rooting your phone, and I can't really think of a reason why that should be. It's not as it Android and iOS come with important http(s) servers out of the box, why shouldn't port 80/443 be available to apps?
Because they're < 1024, I guess. Anywhere I've seen besides windows needs you to be root, or have some other specific permission to listen on that port.
Not that I agree with it, but it is the existing status quo.
These days, computers are used by one, maybe two or three people. If I, the only user of my phone, decide I want to use port 80, why can't I? Put this stuff behind a special privilege for all I care.
Yeah, IPv6 isn't everywhere, but if you have it on your phone and everywhere you want to access you phone from...
I had some experience getting yelled at by a carrier for something like this. If your “server” is mobile, they get testy.
I have previously used carriers that did expose (IPv6) addresses, though. Port 25/53/etc were blocked but I could host a web server on there if I wanted to drain the 2GB of mobile data I had at the time.
NAT isn't a problem with IPv6 support. Of course there's the network firewall, but adding a rule to accept ports 1714-1764 isn't that hard.
Right now I've solved the problem with a VPN tunnel, but that's not really that permanent a solution.
Even on a phone (that's not a "server" in the traditional sense), e.g. listening on UDP port 5353 is needed to show up in mDNS.
There should be a separate permission for listening on standard, reserved ports (anything in the IANA docs for all I care) that should require manual consent, like with location access. In fact, I think there should be a retractable permission for any kind of remotely accessible port binding. The fact any calculator app can start a VPN server on my phone without my knowledge isn't good! That doesn't mean providing any type of service is inherently bad, though.
For instance, there are tons of phone <=> desktop sync apps (My Phone on Windows, KDE Connect on Linux/Windows/Mac) that constantly communicate between each other. Why should your phone always be the one to initiate that direct connection? Why should we rely on cloud servers when mutually authenticated SSH is already doing every bit of protection we could possibly need? My phone is half a meter away from my computer, it shouldn't need to be this difficult!
Can you tell me more about that?
I know about SRV records from Minecraft (of all things!) for a similar purpose, can you point me towards a reference of what is this about? Wikipedia fails me.
[1]: https://blog.cloudflare.com/speeding-up-https-and-http-3-neg...
[2]: Current version is https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-svcb-...
FWIW, that's possible today on Android (not necessarily tomorrow, not necessarily on iOS) - I can and do regularly move files around with rsync/scp courtesy of termux, either by running the command on the phone or just running sshd on the phone (which does, in my setup, need to be manually started; I don't know if that's inherent or could be changed) and then running the transfer from another machine.
Otherwise they're competing with a lot of other people interested in what the phone should and should not do.
If they own a hammer, they can do what they like with a hammer, but a phone is not a hammer. It's a complex arrangement of molecules, licenses and competing group interests.
I'm sure if someone found a way to shove ads and place restrictions on the use of your hammer they would.
People make a big deal out of those differences though, go figure!
Otherwise your line of reasoning boils down to “it exists.”
1. When discussing human rights (which apply to technological freedoms) reducing a need to "an edge case" is the basis of marginalization, defined as "treatment of a person, group, or concept as insignificant or peripheral". Therefore, it is never appropriate to rely on such language to prove a point, especially when we are discussing software which had to go out of its way to restrict freedoms.
2. It's an incredibly slippery slope to use "crapware" as a justification for reducing the freedoms of the individual. Criminals will find a way, do not create a hostile user experience.
Since it's inception smart phones have been a consumer platform, used for consuming content. The platform for tinkerers already exists. It's called a PC with Linux installed. Every platform does not need to cater to your needs.
Are you familiar with the false dilemma?
https://en.wikipedia.org/wiki/False_dilemma
> The platform for tinkerers already exists. It's called a PC with Linux installed
I would love for you to make the case that a modern touch screen phone is not a Personal Computer. And you fail to address the very real scenario in which companies are conspiring to provide fully locked-down hardware and software ecosystems.
I'm always up for a challenge, so here you go.
I'd argue that a PC is a general purpose personal computer. I wouldn't count a game console such as Xbox, PS or Switch as a PC because it is vendor controlled and locked down. I'd also not consider a car with an entertainment system a general purpose computing device.
Similarly phones are bought with the knowledge that they are more similar to game consoles than general purpose computers. They are bought with the knowledge that they are locked down by the vendor and that your use of the device is going to be limited. The right to install custom software that does whatever you want has never been part of the contract.
I do support the people's right to attempt to hack these devices to do whatever they want, but I do think expecting vendor support for their wacky antics is a step too far.
The Xbox was built primarily from standard components used in personal computers.
The PlayStation 2 and 3 ran Linux as alternative operating systems, officially supported by Sony.
The Nintendo Wii series is heralded as some of the most hackable and therefore versatile consoles in history, not for Nintendo's lack of trying.
> Similarly phones are bought with the knowledge that they are more similar to game consoles than general purpose computers
My phone in my pocket has more capability than my old laptops. Touchscreen interaction and the ability to make calls over a cell network do not suddenly make this thing not a personal computer. The hardware is completely capable of supporting this.
> They are bought with the knowledge that they are locked down by the vendor and that your use of the device is going to be limited.
This is just circular reasoning. The entire point is that this "knowledge" is simply consumer conditioning, and people are being taken advantage of by being fed this bullshit narrative.
> The right to install custom software that does whatever you want has never been part of the contract.
My friend, there is no contract. That is the point. I buy the hardware, and then I have the right to do whatever the fuck I want with it. Full stop. Anything less restricts my right to modify my personal items as I see fit.
> I do think expecting vendor support for their wacky antics is a step too far.
What? My phone runs a heavily-modified Linux and can do literally anything I need regarding personal computing, including hook up to external monitors and make use of peripheral devices like a mouse and keyboard. It is objectively a full-blown computer, regardless of if you can't understand that.
The premise of this thread is simply that, despite all of this, ports are arbitrarily locked down. This requires extra vendor intervention to implement, so your argument makes no sense. There is nothing wacky about using my personal computing device for.... personal computing. It's either disingenuous or ignorant to suggest this is not something which should be considered.
i understand that you want to own the stack on your tech, and i would argue that if custom OSes were allowed, that fulfils that need. it’s not apple or google’s responsibility to let you do anything with their OS, in the same vein that you often are limited by stock router firmware or what’s on your ps5.
as phones are hyper-personal it makes sense people want more control, but most average users do not. and as someone who works closely with smartphone tech, i want it to just work and i don’t want to worry about whatever nonsense is enabled by disabling security or os-level by guarantees.
just get a fairphone or whatever. it’s not a human right to force tech companies to embrace your vision of computing
Now that you have, will you say that it has more merit if discussed in future?
You can argue all you want about what the normal joe shmoe should be able to do but most joes shmoes will use that to hurt themselves more than help.
Limitiations are essentially OSHA of computing, by making it hard to do the wrong stuff it makes most people least likely to hurt themselves.
Well, it's not reasonably available. The number of android phone manufacturers that still allow bootloaders to be unlocked without significant friction is pretty small, and hardware attestation is slowly killing the whole rooting/custom rom scene since phones with unlocked bootloaders can't run many apps.
The option is there on some phones, and that with caveats; lots of phones don't let you root them, and even if you can they'll artificially break things (like sony degrading the camera, or any app that refuses to run if it realizes it's on a rooted phone)
Personal computers should be able to run a web server > Phones are personal computers > Phones should be able to run webservers.
Is this line supposed to be ironic or something?
I'm sorry, but what are you doing right now if not this?
It's a legit security issue. Not protecting people from these things is far more user hostile.
I've never heard an argument before that the ability to host a personal website on a cellphone is a human right. But, by using this phrase, you seem to be assuming your readers already agree with you that human rights is what we are discussing. As a rhetorical device, that may be effective at getting someone to back down for fear of being labeled as anti-human-rights, but it is not effective at persuading someone of your implied thesis. I'd very much like to hear such an argument connecting cellphone websites to human rights.
Hence, freedom is the default position, the default human right. What needs to be justified is the restriction, not the freedom. Without good justification the restriction should be removed. An example of unjustifiable restriction is "criminals may use it", as:
a) your freedom should not be impinged on by the actions of others, especially malicious ones, and
b) you are presumed innocent (the second, perhaps only in order of mention here, great principle of English law, if not culture. One that is sadly being undermined).
The argument is that individuals must have the right to modify their devices as they see fit, barring some reasonable FTC radio restrictions which are necessary to enable fair use.
You can argue that nothing should compel a company, in a free market, to provide such a device. But the nature of human rights is that they must be defended vigilantly, or the entire industry and government will slowly move to exploit people.
If you do not guarantee freedom of speech, companies will restrict it. If you do not guarantee freedom to repair or modify a device, companies will restrict it. At some point, these practices become inescapable for the end user and they effectively lose these freedoms while entirely skipping due process and the court of law.
Rights must be enforced, not left up to corporate goodwill.
Humans rights pov to this were not remotely part of the discussion. If you have one you think is relevant to the discussion then introduce it. The way you have tried to do so here is in the tone of “I know you think you’re trying to help but clearly your attitude is part of the problem.”
This might be acceptable if phone-hosted websites were already a well-known humanitarian & human rights issue and therefore marginalization a potential problem. As it stand though it just seems like you’re twisting the meaning of “edge case” into something that it is not.
You could argue John Deere shouldn't be required to sell you a tractor which you can repair at home. But if you don't require that, they won't, and you've chosen to prioritize corporate needs over individual needs.
Calling this a human rights issue is like calling your ability to order a sandwich for lunch a human rights issue
Exactly. If we established all law based only on what we currently observe, without considering future implications, then we would fundamentally only be a reactive legislative system and not proactive.
> Calling this a human rights issue is like calling your ability to order a sandwich for lunch a human rights issue
No, that is a gross misrepresentation. The simple fact is that if you don't require the right for a user to modify their general computing hardware, that right will never be awarded systematically, and will in fact be repressed. It's the definition of a slippery slope, because anything can be justified from that point.
Your concern is about an intellectual ideal of full freedom to utilize a device as you see fit.
That is an ideal that I am philosophically attracted to. But… you have to balance harms when dealing with the public. Security risk management for mobile is difficult and even professional practitioners fail badly at it. A billion little servers with a trillion little bugs are a physical safety risk for thousands of people that they cannot effectively manage.
We live in an era where publishing is easier than it has been since society consisted of a bunch of cavemen in a few small bands. This idea is technically interesting but a bad one.
This is a category error. The use is marginal, not the people. You can't just uprate the severity of something because it suits your wants.
Thankfully, nobody will be forcing you to use this feature; it shouldn't bother someone who ignores it. It is a feature of your phone though, unless you're daily-driving a pager or 2G Nokia. Hopefully this helps you make peace with the "utterly cringey" reality of modern computing.
Actually, trying to argue against something that you will not use, but others would use, that has no other effect on you, harms yourself (you might change your mind later) and harms others.
2003:
[Cueball approaches a bearded fellow.]
Cueball: Did you get my essay?
Bearded Fellow: Yeah, it was good! But it was a .doc; You should really use a more open-
Cueball: Give it a rest already. Maybe we just want to live our lives and use software that works, not get wrapped up in your stupid nerd turf wars.
Bearded Fellow: I just want people to care about the infrastructures we're building and who-
Cueball: No, you just want to feel smugly superior. You have no sense of perspective and are probably autistic.
2010:
Cueball: Oh my God! We handed control of our social world to Facebook and they're DOING EVIL STUFF!
Bearded Fellow: Do you see this?
[Inset, the bearded fellow rubs his index and middle fingers against his thumb.]
Bearded Fellow: It's the world's tiniest open-source violin.There's no real difference between a site on a server and a cache on a server from any kind of philosophical decentralization point of view.
Just put the thing on the server in the first place and forget about the phone entirely.
Go install AOSP and see how useless your device becomes. An OS is more than a kernel and filesystem, it's also a basic set of userspace utilities and functionality. Last time I installed AOSP on a device- wifi wasn't even supported. And Google is removing messaging from AOSP. Phone OS my ass, it's useless without 3rd party cruft that isn't available to end users.
That said, office supplies don't make something an operating system. If all it had was a launcher, it would still be an operating system, because you can install the apps you want onto it.
I don't know why your device didn't have WiFi, ut it's not the norm. Standard AOSP images should use the vendor partition to load additional drivers if the ones built into the Android kernel don't suffice.
Under this view, every device should be a standard-issue military-grade turing-machine. There would be no individuality, every device would be the same GPL licensed Free Operating System.
Almost all differences among the various modern phones, laptops are mere software, the software is where the individuality is. Hardware differences exist in degree rarely in kind (megapixels of cameras, gb of ram etc) and even if some new type of hardware or sensor comes out its just a matter of developing a proper interface for the cpu, os etc.
This still doesn’t remove the issue with running a server via mobile connectivity. Especially when there’s free options, or inexpensive options that won’t run up your mobile data bills.
Do phones not have WiFi? Yeah, it's not ethernet but you intentionally made it sound like mobile data is the only option.
And this is a terrible argument IMO. The idea of “It’s my device, it’s my right to do exactly what I want with it” is beyond dead and buried. There are lots of things people want to do with their devices that Apple doesn’t let them do. That’s literally been Apple’s philosophy for decades and at this point it shouldn’t be surprising.
Buy the Pinephone if you absolutely have some arcane use-case you can’t live without.
Also, "I don't need this so nobody should have it" is a terrible take.
Literally the title of the post (every phone)…
It’s not a terrible take. I want the features Apple decides are best for the iPhone because I prefer their philosophy to the idea of some device with unlimited options and settings.
Okay, then you've got me confused. Apple decided years ago to allow applications to bind to port 80 and run a personal website on their phones.
Does that mean you want Apple to change something or not? Because Apple decided their devices should be able to serve anything on "privileged" ports.
The opposite opinion that you seem to advocate is equally terrible -- "I want it so everyone should accept it" (which is the title of the post). How about you go advocate for a phone that supports it, says a Linux phone, and if it takes off and Apple/Google adopt it, then we can have it without this tiresome debate?
Eg if that terminal app is capable of playing audio, it can play silence to keep the app alive forever in the background.
I don't mean to imply that this is practical. Any solution would still destroy battery life.
My use case: I plug in an old phone into the wall, a 65W Thinkpad charger to be precise. The input for the Thinkpad is USB type C which is the same as my ZTE phone. I connect the USB C cable, attach my spicy pillow of a battery (it is removable), wait until the device powers up, and remove the spicy pillow from the phone. The phone stays on.
What I would like to see instead is some way for phones and laptops to work directly off of the wall, not charging or using the battery at all once it is done charging, without me having to physically remove the battery. I thought this is how laptops used to work but I am not an expert. Phones I am positive do not work like this for some reason. I believe one reason is the camera flash. The camera flash requires more oomph (very technical term) than the wall can deliver. I'm guessing that based on a single anecdote that I once tried to use the flash without a battery and the phone rebooted.
I guess the main gist of this comment is to say I'd like to see better thought go into making battery more durable so you can use a phone, connected to the wall for ten years if you wanted to. I am positive that if we could use the phone off the wall without constantly charging and discharging the battery, we would be able to eliminate most cases of spicy pillow.
Most flagship devices already do this. They automatically enter kiosk mode after being plugged in for a few days which eliminates the spicy pillow problem by keeping battery voltage significantly lower than normal. Eg https://support.apple.com/en-gu/HT208710
> I thought this is how laptops used to work
Transients are a problem for laptops and desktops too. Eg:
- Macbooks go into limp mode by asserting PROCHOT when the battery is <10% (or disconnected or high internal resistance) regardless of whether the laptop is plugged in. If they didn't, a sudden increase in power usage would cause enough voltage sag to reset the machine or cause data corruption. See https://apple.stackexchange.com/questions/380493/cpu-throttl...
- An RTX 3090 draws only 350W, but transients are often double that. A lotta people with weak PSUs and aggressive OCP had random reboots and bluescreens until they upgraded their PSU. The newer RTX 4090 has a better VRM which causes smaller transients so it can work with a smaller PSU despite having a 450W TDP.
“wHy WoULd YoU wAnT tO Do tHaT aNyWaY¿” -typical Apple fanboy response
Repurposing old hardware is cool too, but when you’re not using it as a phone anymore, you could run a different OS.
When people complain about how Windows (and for that matter also Linux and BSD, et al.) don't lock their environments down, they should remember it's because both devs and users alike appreciate and respect the freedom to do whatever the hell we want on our computers.
Great power begets great responsibility. Android and iOS place next to no responsibility on the devs and users, but likewise also none of the power.
---
But why?
The sending client is supposed to retry if the receiving server is down.
But it's still built with the expectation that the recipient host will usually be available, and that unavailability is a transient condition -- a failure to contact the recipient SMTP server is a noisy failure, and, after the first few retries, most servers back off to one attempt every 8 hours. Mail servers which are only sporadically available would require some fairly substantial rearchitecture.
The noisy failure is probably not a part of the standard, more likely a recent trend.
But the article is about a personal website. Websites run over HTTP, which is not designed for anything unreliable.
It's interesting to think about a web that was designed to have lots of intermediary caching peers along the way as part of the protocol, but that's not what we have.
The notion of mobile-device-as-origin-server which can provide either content in a local context (on a LAN, localhost-only), or globally via cache-and-redundancy / cache-and-forward networks has definite and positive use-cases.
That said, when I imagine self hosting from a phone I definitely think the phone + USB drive in a closet approach makes more sense.
In your photo example, my mom, the first time the website wouldn’t work, would demand I just email her the photos from the trip from then on.
even this low bar is (imo sadly) currently impossible for someone who just has a spare phone in their closet and a bit of html knowledge
looking forward to the unicorn that makes wordpress for ios/android
Termux can install nginx, PHP, and various SQL clients, so I'm sure someone can make a copy/paste script that'll set up a WordPress server on your phone.
https://datatracker.ietf.org/doc/draft-ietf-dnsop-svcb-https...
So even if you can run it at port 80 you can't really do that without NAT or tunnel somewhere and if you need that you can just NAT to get it visible on 80 from the outside
It's mostly imaginary problem
It took me about two mins, and most of that was because I typed a minimal html page on my phone using vi.
My phone has an apple logo, and the whole point of the article is that android is the one which blocks you from doing this without jailbreak. But on an iPhone it takes like one minute and zero configuration. (I literally just ran `python3 -m http.server 80` with no issues in ish).
Sorry ma, I was in a meeting.
Really, our proclivity for instant gratification over patience is unhealthy.
I'm sure there's all sorts of neat ideas for what could go onto a phone's website, but I can't say that I see the appeal, personally.
We just need a good algorithm for reciprocity-pinning.
This might allow a smartphone to host a publicly-accessible website with caching and DDoS protection for free. You'd still have to buy a domain, but https://gen.xyz/number is $1/year.
Though the keepalive traffic would eat your battery, unless cloudflared were integrated with Firebase Cloud Messaging somehow... seems easier to just put content on Neocities.
Maybe the value of running on your phone would be so people could see that your phone is up or something like that?
We already have crappy written apps waking up devices on OEM software, last we need is random agents on the internet waking up our phones.
i.e. when you can't take a call or a text or read a social media notification. Why does this need to be always-available if those don't?
Also, I wonder what the actual "downtime" of a smartphone is. I doubt it's that much worse than a lot of websites. The downtime of a smartphone is also usually completely independent of the phone itself, as it's usually service and/or location related.
Commercial websites typically run on dedicated server hardware.