5 ms·
> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pa
by delibes 7y ago
> However, if you install an application from an untrusted source, attackers can take advantage of that. Attackers can also take advantage of the bug if they pair it with vulnerabilities in the Chrome browser to render content.
So, you have to sideload an app or from some other source. Is it unreasonable to say don't do that? How common is it anyway? I work with IT folks and only a few ever seem to load outside the Play store. Perhaps in other parts of the world it's more common...?
- mehrdadn 7y agoThere are lots of sites out there that host APKs of apps (older versions, etc.)... I'd wager they have more than a few users.
- klingonopera 7y ago...there need to be more developers like these! I'm not sure, but aren't Play Store submittals APKs anyways? Is additionally self-hosting them that much more complicated? I've heard that developers often go Play Store exclusive, for fear that Google might block them. Is that true?
- soulofmischief 7y agoSome of us are just trying to remove ourselves from Google's teat because we don't want to be sucking from Apple's teat instead, but it's getting increasingly harder to do so.
- detaro 7y agoI believe the article is translating that badly from the bug report. An app installed through the Play store is also an "untrusted app code execution" - Play deploys some scanning tools on submitted apps during the review, but do you trust them to catch it always? There's also things like Amazon devices with Amazon app store, ... Similarly, Chrome is only mentioned because it's notable that it can be effective from inside its isolation if combined with a browser exploit. That likely applies to all browsers, but the article recommends to switch browsers.
- m-p-3 7y agoI use some apps on F-Froid.
- jdnenej 7y agoIn places without proper internet access it's common for phone stores to host their own fdroid repos on the local network to set people up with apps.
- Arkanosis 7y agoI don't get why you're being downvoted, because that's an excellent question: I do that all the time: I'm using F-Droid more often than the Play Store. Actually, I haven't ever used the Play Store on my second smartphone (it requires a Google Account and I don't want to link it to a Google identity) — I've tens of apps on it.
- klingonopera 7y agoI've been using LineageOS on my phones for a couple of years now, recently reinstalled and made the decision to not install the Play Store... and am totally happy with it! I get most of my stuff from F-Droid and some software vendors provide APKs straight from their websites and whatever is Play Store exclusive, I simply don't use. It was going really well, at least until recently, when here in Germany they started introducing mandatory apps for online banking, available (of course) only on Play Store or App Store. I wouldn't even mind everyone's app-obsession if they'd at least always provide a store-free APK as well.
- Yetanfou 7y agoUse YALP [1] or Aurora [2] (both are on FDroid) to get the APK's for your banking apps. These apps This is what I do for the Swedish electronic ID app, it has worked for years and hopefully will continue to do so. [1] https://f-droid.org/en/package/com.github.yeriomin.yalpstore/ https://f-droid.org/en/package/com.github.yeriomin.yalpstore... [2] https://f-droid.org/en/packages/com.aurora.store/ https://f-droid.org/en/packages/com.aurora.store/
- klingonopera 7y agoTried 'em both, IIRC Yalp didn't work, Aurora seemed fine. Since it was a banking app, I got the APK of many different sites/programs and compared the hashes, and one of the programs had definitely tampered with the APK, but I can't remember which. Since I left Aurora on my phone, they seemed to have passed on untouched APKs, but don't take my word for it. EDIT: Also, this voids me of any "warranties" my bank would offer me, so I'm really not going down that path. Really, the only correct thing would be for the bank to offer the APK on their site, but I'd probably have to wait until the government forces this to happen (if ever).
- Yetanfou 7y agoYALP and Aurora get the APK directly from the play store, that is the whole point about these programs. Get the source to Aurora (or YALP) and find out how it downloads the APK from the play store. Now either build something which does what you want (e.g. feed it an identifier and it downloads an APK), simplify the existing code until only the required functionality is left or use Aurora as it is. You can feed it a Google account (if you have one) to log in to the play store or it can do so 'anonymously'.
- e12e 7y agoIn addition to "essential" apps, like the early versions of Pokémon Go(?) that bizarrely needed to be sideloaded IIRC, and running your own (unpublished) apps - there are the numerous vendor-provided apps and app stores that avoid the play store gatekeeping. (of course, the vendors should be gatekeepers here..) Then there's f-Droid, the people that run without Google apps (alternate roms). And then there's "Android TV" that has a "different" play store due to the TV profile being different - but allows sideloading of apps like zerotier(VPN) or chrome - that work fine on TVs - but unfortunately isn't flagged as supporting TV in the Manifest.