6 ms·
Although I'd like to applaud any alternative to Google Play the approach F-Droid pursues does not fit a serious security model. F-Droid builds are custom signed
by nosedief 5y ago
Although I'd like to applaud any alternative to Google Play the approach F-Droid pursues does not fit a serious security model. F-Droid builds are custom signed and can be made by random parties without proper auditing after initial review.
Also, it is stuck on old APIs and won't allow the use of Android's new unattended update feature (UPDATE_PACKAGES_WITHOUT_USER_ACTION) and requires intrusive privileged system access to do that.
A more serious flaw opposing the Android security model is the fact that an app store is supposed to feed from a single repository which F-Droid does not adhere to.
Also, often these repos are poorly maintained, rarely updated and often conflict with Play Store packages because they use identical app ids.
All they care about is to be free from "evil proprietary components" which comes at a great cost of security and inescapably privacy.
It's just not a good choice for these and additional reasons such as building a ton of their apps unattendedly on a potentially malicious server.
- temptemptemp111 5y ago
- _joel 5y ago
- ranger207 5y agoThis sounds like the traditional Linux packaging model: one repo with software built by distro maintainers, additional repos added by the user with software built by whoever. I don't see any problems with it
- nosedief 5y agoThe Android security model strictly forbids it. This should be enough of a problem as it is the very foundation to establish security for the system's user.
- lolinder 5y ago> The Android security model strictly forbids it. Citation, please?
- ranger207 5y agoI don't know enough about the Android security model to evaluate what you're saying. What parts of the Android security model does F-Droid violate? Is there a spec or description of the Android security model anywhere that I can read?
- lolinder 5y agoThere's a paper by several Google employees describing it. I haven't read it, just skimmed and searched keywords, but near as I can tell it doesn't mention anything like what the OP thinks it does: https://arxiv.org/abs/1904.05572 https://arxiv.org/abs/1904.05572 See my other comment for what I did find, which is exactly the opposite of what OP says: https://news.ycombinator.com/item?id=30507713 https://news.ycombinator.com/item?id=30507713
- pserwylo 5y ago> F-Droid builds are custom signed and can be made by random parties without proper auditing after initial review. F-Droid follows a similar model to traditional linux package managers which has shown time anda gain the they are both trustworthy and secure (or at least, they offer the user the freedom to choose the level of trust they have in the package signers). When installing from a Debian repo, I'm typically installing a package that is not build/signed by the upstream developer. I am implicitly (in the case of a default install) trusting the Debian developers signing practices or explicitly (if you add a third party repo). This means you trust both those in charge of the building/packaging/signing as well as the upstream developers. The same is true of F-Droid. Of course, the notable exception is that F-Droid also supports upstream packages signed by the developer if the builds are verifiably reproducible.
- nosedief 5y agoThere is a difference in your Linux desktop workstation and your most private device. Desktop systems are not nearly as secure and should not be seen as such, and Linux surely at the tail end. People using F-Droid might not be aware that they are trusting a third party as they think it is a trusted distribution channel, relying on the information stated on the client app or website.
- lolinder 5y agoIn order to get started with F-Droid you have to jump through several hoops with strong warnings from Android about allowing third party apps to install applications. Here's the exact text of the warning: > Your phone and personal data are more vulnerable to attack by unknown apps. By installing apps from this source, you agree that you are responsible for any damage to your phone or loss of data that may result from their use.
- toastal 5y ago> your most private device What? A smart phone is just a computer—they are the same thing. Everything from private chats to TOTP tokens are on both my phone and my laptop. The only difference is my bank cries if I’m rooted on my phone and says nothing about it on my laptop.
- lolinder 5y agoDo you have a citation for your claims about the Android security model? The only things I can find about app stores in the paper by Google[0] run directly counter to your idea: > Android explicitly supports installation of apps from arbitrary sources, which led to the development of different app stores and the existence of apps outside of Google Play. And this: > Both users and developers are part of an open ecosystem that is not limited to a single application store. Central vetting of developers or registration of users is not required. And as far as signing goes: > In order to ensure that it is the app developer and not another party that is consenting, applications are signed by the developer. This prevents third parties — including the app store — from replacing or removing code or resources in order to change the app’s intended behavior [0] https://arxiv.org/abs/1904.05572 https://arxiv.org/abs/1904.05572
- Wonderfall 5y agoYou misunderstood what they said. Indeed, Android can have multiple app repositories and this is an integral part of its security model design. However, for the security model to be respected, each app repository should represent a single source. The device and user management APIs expect that in Android. F-Droid fundamentally bypasses the trust boundaries in that regard by allowing multiple repositories to coexist within a single client. Not to mention it also results in a terrible UX given that the application IDs are often reused but signed by another party.
- lolinder 5y ago> However, for the security model to be respected, each app repository should represent a single source. The device and user management APIs expect that in Android. This is exactly the point that I was questioning, so it sounds like I understood their point just fine. Do you have a citation for this assertion? The paper from Google doesn't even mention a repository as a concept. Here's what it does say: > Untrusted code is executed on the device. One fundamental difference to other mobile operating systems is that Android intentionally allows (with explicit consent by end users) installation of application (A) code from arbitrary sources, and does not enforce vetting of apps by a central instance. The Android security model is based on the idea that you can install arbitrary APKs from literally anywhere. If I download an APK through Chrome and install it, I might turn around and download another APK from a different website. If anything, Chrome is more arbitrary in its sourcing of APKs. How does F-Droid break the security model but Chrome doesn't? Alternatively, how does Google allow Chrome to break its own security model? And again, what is your source for your claim? I'm reading the actual document from Google, and it appears to say exactly the opposite of what you're saying.
- rpdillon 5y agoI don't understand the definition of 'repository' here: > A more serious flaw opposing the Android security model is the fact that an app store is supposed to feed from a single repository which F-Droid does not adhere to. Also, where is this documented? I read through several security pages (e.g. https://source.android.com/security/overview https://source.android.com/security/overview) and can't find any reference to a 'repository' or the idea that F-Droid is not secure because it aggregates apps from many sources. I think I'm misunderstanding your point entirely...any links to more detail would be very interesting to me.
- eighthave 5y agoThat may be true if you are sideloading F-Droid. Our security model focus is based on integrating F-Droid into the ROM, like with CalyxOS. This method is proven to provide better security than Google Play devices, since by default, all apps are open source and reviewed by humans. For example https://f-droid.org/2020/03/04/f-droid-is-a-key-source-for-academics-and-researchers.html https://f-droid.org/2020/03/04/f-droid-is-a-key-source-for-a...