• 0 Posts
  • 65 Comments
Joined 2 years ago
cake
Cake day: January 25th, 2024

help-circle


  • Yes, however, the article is titled “F-Droid Security Issues”, not “F-Droid FOSS Issues”. I’m not sure why anyone would read that and say “well what about the four freedoms?”. That’s not what the article is talking about.

    ultimately conclude that its premise is inherently flawed regardless of implementation details

    In terms of security, which is true.

    aside from a bizarre claim that F-Droid supporting multiple repositories is a Bad Thing because it interferes with, and I quote, “UserManager which can be used to prevent a user from installing third-party apps” - what does this have to do with privacy?

    It doesn’t. It’s a security issue.

    Just allow devs to upload their own build with their own keys like Accrescent. It’s not like the whole “audit” system is meaningful anyways.

    It’s true, F-droid’s signature doesn’t provide any meaningful security guarantees.











  • You are likely thinking of google play protect, which does the same verification on their platform’s end (to try to remove bad actor developer accounts as soon as possible), and the local device end as well (to remove said developers apps if they are already installed on your device). But yes, at the base level, what arrives on your phone from the play store are just signed apk files. That’s why mirror sites like apkmirror or apkpure can do what they do, by extracting said apks after they have been released onto the play store.



  • tomalley8342@lemmy.worldtoAndroid@lemdro.idVerified developer
    link
    fedilink
    English
    arrow-up
    19
    ·
    8 months ago

    How is this going to be enforced if you are just downloading apks? It states they will enforce verification across sources outside of the play store. This doesn’t sound possible unless they just make stock android unable to side load

    apks will have to be cryptographically signed through Google’s developer console, and this signature will be checked by the operating system at install time regardless of where you got the apk from. It’s like how windows has signed applications for smartscreen, except in this case all applications must be signed through Google, and in order to sign it, you have to let Google know where you live, and unsigned applications will simply be denied instead of just being presented with a warning.



  • “Every sub on Reddit is like a HS drama fest” is too true. I’m not interested in the drama. What I’m interested in is the fact that Mr Threat Interactive has admitted to not knowing what the fuck he was talking about regarding anything related to graphics and engine design a year ago, put out a video titled “graphics are being murdered” just a few months after, and now thinks the entire industry is out to get him after being put in his place by people who do actually have experience in this niche field because he thinks his facebook boomer tier research is just as good as their experience. This guy is the anti vax of video games.