‹ BackHN Continuity

Thread

F-Droid 2.0

1465 points · 420 comments · daveoc64

  1. jjice · · focus · HN ↗
    What does the future of something like F-Droid look like once Google does their lock down next year?
    1. pritambaral · · focus · HN ↗
      Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
      1. trinsic2 · · focus · HN ↗
        It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
        1. McDyver · · focus · HN ↗
          > sideloading

          That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised

          1. ragequittah · · focus · HN ↗
            Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.

            Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.

            1. krzyk · · focus · HN ↗
              That means education for people: don't perform actions that are in emails.

              Blocking apps is like blocking buying of knifes because one can hurt themselves.

              1. halostatue · · focus · HN ↗
                Because education has worked so well on Windows.

                There's not an easy answer, but the non-answer of "people just need to be educated" is trivially dismissed.

                1. Aachen · · focus · HN ↗
                  I'm not sure the situations are comparable when Windows doesn't have this permission system where the apps are still very limited in what they can access unless you grant specific directory access or access to the contact list or such
                  1. wizzwizz4 · · focus · HN ↗
                    It does, but approximately nobody uses it, because Microsoft also tried to apply loads of constraints on what kinds of program could exist when they rolled it out, as part of their "all Windows software should also work on Windows Phone and Xbox" campaign.
              2. ragequittah · · focus · HN ↗
                Have you ever tried to educate a 70+ year old person on this kind of stuff? Their eyes gloss over and they don't care. I've told my mother not to install random apps on her phone several times yet she still does it. I could probably send her a phishing e-mail right now that 'looks like' it's from me (so long as my name is in the from: field that's enough) and she'd follow the instructions to install a malicious apk too.

                "Everyone should just be smarter/more educated" is what I used to think as well. I now fully understand some people have no desire to be educated in any way and it's a net good for society to not have a large % of devices compromised.

                1. LtWorf · · focus · HN ↗
                  It's full of malicious apps on google play. There are none on f-droid.

                  The logical conclusion is that fdroid should be allowed and google play banned by default.

                2. dogmatism · · focus · HN ↗
                  yes, got my father on linux a decade (or more) ago. He's 84. No problem. Most recently we discussed being vigilant against vishing.

                  Now my in-laws (similar age) one very demented, the other thinks he knows best because he was a chemical engineer...they could use some built in protections

                  so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch

                  1. ragequittah · · focus · HN ↗
                    >so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch

                    Which is really exactly what google is implementing here and why I'm so perplexed so many people are upset. You or I or smart parents (my mother has never used a computer in her life and wouldn't want to) will have absolutely no issue sideloading apps after the proposed changes.

                    1. folkrav · · focus · HN ↗
                      Given Google's track record, I don't think it's just "being upset" to have serious doubts about the probability of this escape hatch staying indefinitely.
                      1. ragequittah · · focus · HN ↗
                        But that's just a completely different discussion that we could've had a long time ago when they introduced it as a on/off security setting ~15-20 years ago too (and I bet people did). IMO nothing has changed except I bet more people will take going into developer options, being sternly warned, then having to wait 24 hours as a sign this is something maybe they shouldn't be doing. And I'd argue if you come to that conclusion and don't look into it further you're probably right,

                        Given that google is now forced to have competing app stores due to Epic v. Google and the ninth circuit courts went into long and arduous detail in that anti-trust case about sideloading restrictions I don't think they have a leg to stand on if they get rid of sideloading completely. Oddly Apple continues to get away with it no problem.

                        1. folkrav · · focus · HN ↗
                          This description is downplaying what's changing by a lot. The way you present it, they're merely adding a 24h wait time to the existing local "unknown sources" toggle.

                          They've been chipping away at AOSP for years, pulling more and more parts of the Android experience into their proprietary Google Play Services. In this case, they're doubling down in the same direction. Sure, it may be more or less transparent from a user-facing perspective, but it's a fundamental change to the model.

                          Previously, it was ultimately a local decision: Android warned you, you enabled the permission, and you installed the APK. It now becomes dependent on a Google-controlled verification/authorization mechanism. That's fundamentally different from making the existing "unknown sources" toggle more annoying.

                    2. tpxl · · focus · HN ↗
                      Google is the one peddling the malware. Any changes to 'security' that don't start with them removing the oodles of malware from their store are not security but profit driven.
                3. bigstrat2003 · · focus · HN ↗
                  The answer to people refusing to care about important things in life is not to put restrictions upon everyone's freedom. Ultimately, being an adult means you have to take responsibility for your actions (or lack thereof). It isn't hard to learn how to use a computer responsibly, and I've known plenty of older people who did so just fine. There's no excuse here.
                  1. ragequittah · · focus · HN ↗
                    You do understand we've broadly come to the conclusion that this isn't how society should work though, correct? It's why there's warning labels on everything, liability for not warning people for even the dumbest of things they might do with your product or in your establishment, extremely strict laws for things like driving a car, flying an airplane, or using any kind of heavy machinery, responsibility of servers to cut people off if they've had too much alcohol, the list goes on. I find intelligent people often have this mindset that all "real adults" are just as responsible as they are. It's just not the case.

                    And I generally wouldn't care "have at it" if their phone/computer being compromised only harmed them. But a bulk amount of compromised devices harms us all.

                    "Think of how stupid the average person is and then realize half of them are stupider than that!" -George Carlin

                4. krzyk · · focus · HN ↗
                  It is like saying that you should not have free speech because someone might influence 70+ to say stupid stuff (well, that is already happening...).

                  Family should be responsible on education or making phone of people that are not educated enough (minors, elderly, etc.) limited - I do that using Family Link. I have there my child and also my in-laws - both of them can't install new apps without my permission.

                  So the tech is already there, one just needs to use it.

                  1. ragequittah · · focus · HN ↗
                    What about an entire family of people who have no interest in learning technology they just want the shady ad-free youtube on their phone? I find it perplexing you've never met people like this. I'd wager it's more common than not in our world.
                    1. krzyk · · focus · HN ↗
                      There is no way to have no "shady ad-free" on Google play. Have you tried installing anything that is free? Games for example? There are ads every few minutes that you either wait or accidentally click on them and you install another approved google play app, that has similar ads.

                      Look at apps on fdroid, no such thing.

                      So the solution is simple - ban google play and allow only fdroid if one wants good apps.

                      You can't protect everyone. Just like there are people oblivious to bad eating habits - it is a tax on ignorance.

                5. m4rtink · · focus · HN ↗
                  That would be like requiring people taking driving lessons before driving cars - what nonsense! Just let them behind the wheel & they will figure it out just fine!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.