‹ BackHN Continuity

Thread

F-Droid 2.0

1465 points · 420 comments · daveoc64

  1. jjice · · focus · HN ↗
    What does the future of something like F-Droid look like once Google does their lock down next year?
    1. pritambaral · · focus · HN ↗
      Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
      1. trinsic2 · · focus · HN ↗
        It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
        1. McDyver · · focus · HN ↗
          > sideloading

          That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised

          1. ragequittah · · focus · HN ↗
            Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.

            Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.

            1. g-b-r · · focus · HN ↗
              > a device that holds your entire life, bank info, photos, etc

              That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.

              1. JumpCrisscross · · focus · HN ↗
                > That device was called personal computer

                To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking.

                1. g-b-r · · focus · HN ↗
                  Web banking was offered by all banks long before banking apps, and you could of course access it from smartphones

                  The move to apps made things more difficult, if anything

                  1. JumpCrisscross · · focus · HN ↗
                    Offered but less broadly adopted. Having a platform that doesn't tend to get infected when used by normal users helped with that.
                    1. g-b-r · · focus · HN ↗
                      It was adopted by everyone I knew

                      And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............

                      It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.

                      1. m4rtink · · focus · HN ↗
                        Yeah, compared to separate hardware HSMs mobile banking is a massive downgrade in both security as well as user being in control of the hardware they own (by forcing locked down closer source OS & forcing hardware updates).

                        If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.