4 ms·
The KeePassXC team has also been trying to get their app into the store while this has happened. While this is nothing new in general, it's yet another "counter
by ls65536 4y ago
The KeePassXC team has also been trying to get their app into the store while this has happened. While this is nothing new in general, it's yet another "counterfeit" app proliferating in what's supposed to be considered a trusted source to be able to get your applications from.
This is a good example of how "app stores" tend to provide a false sense of security about what you're really downloading. There are clearly failures in terms of vetting what's there and towards ensuring that the user is actually getting what they think they're supposed to be getting.
Perhaps the "app store" model is still generally better than downloading executable code from completely random sources (nobody should be doing that), but I'm not sure there's anything more reliable (and also "secure") here than downloading a piece of software from its official source (such as from a server under the domain of the known publisher), verifying hashes/signatures, and leaving out as many intermediaries as possible who often have motives not fully aligned with the software user. Of course, this would require users to possess and be willing to use some knowledge of basic software and data hygiene, but it seems that along the way we have somewhat given up on that and so now we're stuck trusting these intermediaries usually much more than they ought to be trusted.
- _t4za 4y agoI was trying to mirror my Android smartphone to my Samsung TV to show a webpage to someone. This feature is called "Smart View" in the TV's menu, but I didn't know how to connect, so I searched that name in the Google Play store. There are dozens of results, only one of them is the official app that has any chance of working. There are two apps[1][2] that actually appear to be the same app just with slightly different names presumably so they appear twice in the search results. One app[3] has some very suspicious ratings and I can't help but notice that the publisher's name is "SmartThings.net" which appears to add more credibility until you see the domain has nothing to do with the app. I understand it can be hard for Google to vet these apps but some of these failures (like verifying you actually own the domain you are pretending to be affiliated with) seem like they could be automated. Edit: spelling 1. https://play.google.com/store/apps/details?id=com.screenmirror.forvizio.smarttv.screenshare 2. https://play.google.com/store/apps/details?id=com.smartview.castto.screenmirror.appfor.miracast 3. https://play.google.com/store/apps/details?id=com.smartview.screen.mirroring
- WorldMaker 4y agoThe publisher name one is a silly social engineering hack: Google does validate publisher name, but it validates it as a Legal Name, a Company Name. Those are handled by various political registries (State Tax Organizations, for instance). They don't know or care about domain names and "SmartThings.net, LLC" is silly looking to them but acceptable. They often generally try to avoid name clashes in a region (state), but generally they don't even work that hard at it because true name clashes are the territory of trademark/small mark/service mark laws. It was one of the failure cases in EV certificates back when browsers briefly thought "maybe it would be a good idea to highlight the website's legal name in the URL bar". Find the right jurisdiction and you can get any sort of "legal name" you want, including things that should have been "obviously" counterfeit like a "Facebook.com, LLC" and were perfectly good for phishing.
- ultraforce 4y agoIt is kind of annoying how often when using winget there might be two options the winget version which is the app and a msstore version that is from an unknown publisher just using the same name for the app.
- tpoacher 4y agoIf only there was a way to have quality repositories of packages curated by the OS team itself... alas, such a thing is probably not possible in the operating systems space for another few decades at least ... /s
- winnie_ua 4y agoNice irony :D
- PaulKeeble 4y agoI think we ought to be able to have a model that suits the Windows model better which doesn't require centralisation. A piece of software running on the desktop that provides update capabilities but where each piece of software is picked up from its original site and the location is set to that site. Somewhat like the Ubuntu repository model but without the multiple steps just an installer that installs the common updater tool if needed, registers itself and then this works for all over software too that buys into the model. It should be fairly cheap to run such a tool since the bandwidth is for all the different software tools and completely common features are available to everything. Its just the updater with some standards for implementing software updates without a store.
- easton 4y agowinget does almost exactly this. It detects apps that are already installed on your machine and if it can find a match in its catalog, it can upgrade it. (Of course you can install/uninstall via the tool if you have a fresh box). `winget upgrade —-all` from a command line (assuming your Windows is reasonably up-to-date, otherwise, https://github.com/microsoft/winget-cli https://github.com/microsoft/winget-cli to get the latest release manually)