3 ms·
I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged.
by aq3cn 6y ago
I stick to F-droid android app store. it asks developer to submit their code which gets compiled by the F-Droid team. apps with proprietary codes are flagged.
few QR code apps from F-Droid.
https://f-droid.org/en/packages/com.example.barcodescanner/ https://f-droid.org/en/packages/com.example.barcodescanner/
https://f-droid.org/en/packages/com.secuso.privacyFriendlyCodeScanner/ https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...
- uzakov 6y agoAdditionally you can have two/three separate phones, linked to separate accounts for different purposes. I keep one phone separate for phone gaming.
- haspok 6y agoBoth recommended apps use the ZXing library. So it is a small world, and if someone overtakes ZXing (assuming that it is not malicious right now), then all apps become infected. Otherwise no security and bugfixes, no improvements, no version upgrades... who knows how long this library will work?
- ignoramous 6y agoOpen source apps can absolutely have trackers in them. F-Droid isn't a security solution by any measure. I have inspected code of at least one popular "privacy" app that absolutely tracks its users out in the open (I mean, the code is right there on GitHub), yet I see repeatedly that app (and F-Droid) being touted as some elixir that fixes security and privacy for one and all. It doesn't. Don't place your trust on F-Droid apps blindly, and more importantly, refrain from blanket advocating F-Droid apps as a security / privacy panacea. What I do instead is monitor Android's traffic with a LittleSnitch-esque firewall and block all apps I don't use. Also, I've disabled auto-updates on non-essential apps. Only Photos, Maps, Chrome, and Firefox are allowed to auto update on my Android.
- krageon 6y agoIt would be more compelling if you actually mentioned what app you've found that's so naughty.
- rectang 6y agoWhat open source gives you is an audit trail, which is helpful but not sufficient. You still need to be able to trace malicious code to actual individuals. Then you need the ability to punish those individuals, ideally through criminal prosecution.
- marcodiego 6y agoF-droid flags apps that have known anti-features. Using Open source software is a very significant security solution.
- epicide 6y ago(F)OSS by itself is not a security solution. Largely because you can't "solve" security. There are plenty of insecure open source apps. To deny that would be to deny tons of security-related CVEs. Yes, open source software is easier to audit, but does nothing to a) make those audits actually happen (frequently enough), nor b) improves the quality of those audits. i.e. just because I have access to information does not validate that information. Work still has to be done.
- marcodiego 6y agoFLOSS may have security vulnerabilities, just like any other software. An OSS android app which has no anti-feature flags on f-droid with intrusive advertisements or malware behavior, deliberately implemented by its own developer, is something I have never heard about. The same can't be said about 'free' (or sometimes even paid) proprietary apps from play store.
- higerordermap 6y agoIt's manually curated and generally flags such things as anti-features if found, and I'd believe them more than some tensorflow_script_to_detect_malware.py
- ignoramous 6y agoI wouldn't depend on F-Droid or FOSS as a measure of security. Of course, I get that F-Droid is run by volunteers, but I hope no one is spreading the notion that the F-Droid apps are magically uber secure and private or anything.
- higerordermap 6y agoI wasn't clear. What I told was comparative.
- schmorptron 6y agoWhat app are you talking about specifically?
- ignoramous 6y agohttps://news.ycombinator.com/item?id=25492855 https://news.ycombinator.com/item?id=25492855 and https://news.ycombinator.com/item?id=25263876 https://news.ycombinator.com/item?id=25263876
- schmorptron 6y agoah, thanks!
- You-Are-Right 6y agowhy is nebulo not on fdroid?
- ignoramous 6y agoIt is on the main developer's f-droid repo: https://github.com/Ch4t4r/Nebulo#f-droid https://github.com/Ch4t4r/Nebulo#f-droid
- You-Are-Right 6y agoI do like the fdroid review process - private repos do not have that.
- JeremyNT 6y agoWere the trackers already labeled in F-droid? They maintain a list of these anti features for all apps. If not, when you reported your findings to F-Droid, did they flag the app as having trackers at that time? Nobody said blanket trust anything. F-Droid is a community project with a framework that allows for disclosing user hostile behavior in apps. By using it and paying attention, we can all make it even better - the exact opposite of Google, whose incentives do not align at all with these goals.
- pieter_mj 6y agoSame here. The first one is also installable from Google Play with a different package name however : https://play.google.com/store/apps/details?id=org.barcodescanner https://play.google.com/store/apps/details?id=org.barcodesca... It also uses the ZXing library. It does not contain any tracking or ad SDK's per the exodus report : https://reports.exodus-privacy.eu.org/en/reports/org.barcodescanner/latest/ https://reports.exodus-privacy.eu.org/en/reports/org.barcode...
- abrowne 6y agoThe second one too: https://play.google.com/store/apps/details?id=com.secuso.privacyFriendlyCodeScanner https://play.google.com/store/apps/details?id=com.secuso.pri...
- benibela 6y agoI once tried to get my app in F-Droid, but they refused, because they did not want to install the dependencies because the dependencies were too big. Turns out you cannot compile something without dependencies. I wrote my app in FPC/Lazarus to make a truly cross platform app that runs natively on anything from a Raspberry PI to Windows 2000, and they did not like that tech stack.