Don't pilots need to keep up their skills by getting in flight hours? So perhaps this expense is somewhat offset by fewer practice flights?
And we're happy to cooperate by signing our own version of that into law since there's an underlying treaty behind this warrantless data sharing: https://citizenlab.ca/2025/06/a-preliminary-analysis-of-bill-c-2/
I hope we can find a way to fulfill our treaty obligations with something that's not as terrible as the current one: https://www.michaelgeist.ca/2025/06/lawful-access-on-steroids/
Sure, and this is a Canadian company roasting Ethiopian beans (as far as I know we don't grow coffee). There are many things we don't make here and even for those we do the supply chain likely intersects with the US.
Another example this had me thinking about is close to your goals: a Canadian baker making bread from Canadian wheat might use a mixer or an oven or whatever as part of that where the only way to get parts is from a US distributor because it's too niche a thing to have a Canadian presence.
neutrality/cooperation with China and Russia,
the reality of Russia’s claims of self defense
...WTF? There are way too many Canadians with ties to Ukraine, myself included, that would be offended at the very idea of anything but utter condemnation of Russia's inhumanly brutal invasion. How can an invasion ever be "self defense", that's absurd.
https://en.wikipedia.org/wiki/War_crimes_in_the_Russian_invasion_of_Ukraine
How can abducting children, laying siege to residential areas, rape, torture, etc. be self defense? It's not. It's abhorrent. Russia is worse than Trump.
Cory Doctorow thought that through: https://pluralistic.net/2025/01/15/beauty-eh/#its-the-only-war-the-yankees-lost-except-for-vietnam-and-also-the-alamo-and-the-bay-of-ham
The new version of Recall is now opt-in rather than opt-out – I got prompted to enable Recall immediately after installing the Insider Build.
This seems to be the important bit, hopefully it stays opt in.
And not just any Americans. They're owned by Chatham Asset Management, a hedge fund associated with the Republican party that also owns a notably Postmedia-like publication: The National Enquirer (via a360) https://en.wikipedia.org/wiki/Chatham_Asset_Management
I got a nice deal on the x280 and am happy with it, was also looking at the various X1 carbon. Two criteria I had were I wanted USB-C charging (since I have those chargers around and they can handle these laptops) and a single battery (eg. the T470s I have from work is nice but it has two small capacity batteries that each cost the same to replace as the full size single ones in the carbon and x280). One thing to keep in mind is some of the earlier X1 carbon don't support NVME SSD (I think it started with 5th gen?)
Edit: another thing to consider is soldered RAM. Part of why my x280 was cheap was it's only 8gb and can't be upgraded. Since you're looking at lighter weight things and using FOSS (and perhaps open to tinkering with things like ZRAM) that might be a useful aspect to focus on because there is probably a glut of such machines given how memory inefficient things are lately with every trivial app running a whole browser engine. OTOH, depending how many tabs you tend to have open and how many electron apps you tend to keep floating around, 8gb might start to feel cramped. Especially if you think you might want some VMs around.
More detail / similar concepts if you're not a video person: https://www.centerforbuilding.org/blog/we-we-cant-build-family-sized-apartments-in-north-america
Thanks, that's encouraging and very relevant. Looks like it was introduced in Android 10 and aside from "Project Mainline" is referred to as "modular system components": https://source.android.com/docs/core/ota/modular-system
Can you shed more light on what someone would be risking by continuing to use an EOL device? You say you don't advise it, but it'd be helpful to elaborate on why.
It seems like the increased vulnerability would be relatively limited: I presume the browser and messaging are by far the most common vectors and those would be as up to date as ever but I can see how exploiting an unpatched vuln there on an unsupported device could have more impact as it would give more options for privilege escalation.
Otherwise it'd be something RF based. Aside from widely publicised things like BlueBorne (that we should be keeping an eye out for anyway), is it a reasonable concern that there are identify theft rings employing people with modified hardware wandering around subway systems trying to exfiltrate credentials from devices with specific vulnerable basebands? Seems like Android also offers some defence in depth there that'd make it unlikely enough to ensure it wouldn't be worth their while?
There are a few technologically disinterested people in my life that I advise (as is no doubt the case for many here) and I don't know how strongly to push for them to get new devices once theirs fall out of support. Most of them are quite content with what they're using and are not in the habit of installing apps (and will reliably ask me first) so they really would be replacing the device solely for the updates. In some cases it's not only the time and effort to decide on a replacement and get things transferred over but the expense can also be a burden. So I don't want to raise the alarm lightly.