‹ BackHN Continuity

Thread

F-Droid 2.0

1465 points · 420 comments · daveoc64

  1. jjice · · focus · HN ↗
    What does the future of something like F-Droid look like once Google does their lock down next year?
    1. pritambaral · · focus · HN ↗
      Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
      1. trinsic2 · · focus · HN ↗
        It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
        1. McDyver · · focus · HN ↗
          > sideloading

          That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised

          1. ragequittah · · focus · HN ↗
            Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.

            Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.

            1. krzyk · · focus · HN ↗
              That means education for people: don't perform actions that are in emails.

              Blocking apps is like blocking buying of knifes because one can hurt themselves.

              1. ragequittah · · focus · HN ↗
                Have you ever tried to educate a 70+ year old person on this kind of stuff? Their eyes gloss over and they don't care. I've told my mother not to install random apps on her phone several times yet she still does it. I could probably send her a phishing e-mail right now that 'looks like' it's from me (so long as my name is in the from: field that's enough) and she'd follow the instructions to install a malicious apk too.

                "Everyone should just be smarter/more educated" is what I used to think as well. I now fully understand some people have no desire to be educated in any way and it's a net good for society to not have a large % of devices compromised.

                1. dogmatism · · focus · HN ↗
                  yes, got my father on linux a decade (or more) ago. He's 84. No problem. Most recently we discussed being vigilant against vishing.

                  Now my in-laws (similar age) one very demented, the other thinks he knows best because he was a chemical engineer...they could use some built in protections

                  so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch

                  1. ragequittah · · focus · HN ↗
                    >so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch

                    Which is really exactly what google is implementing here and why I'm so perplexed so many people are upset. You or I or smart parents (my mother has never used a computer in her life and wouldn't want to) will have absolutely no issue sideloading apps after the proposed changes.

                    1. tpxl · · focus · HN ↗
                      Google is the one peddling the malware. Any changes to 'security' that don't start with them removing the oodles of malware from their store are not security but profit driven.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.