3 ms·
F-Droid is indeed a nice alternative for Play Store, but still, it's not perfect. https://privsec.dev/posts/android/f-droid-security-issues/ https://privsec.de
by _imnothere 2y ago
F-Droid is indeed a nice alternative for Play Store, but still, it's not perfect.
https://privsec.dev/posts/android/f-droid-security-issues/ https://privsec.dev/posts/android/f-droid-security-issues/
- captainepoch 2y agoI hope they use the money to improve all the issues people have arised over the years. It can be a really good platform, if they're open to change. Otherwise, it might be dead in the future.
- yjftsjthsd-h 2y agoNote that most of that page is a matter of the authors having a completely different security model than F-Droid rather than what I would consider to be true defects.
- udev4096 2y agoIt's not. Stop being in an echo chamber. Refer to this post for more valid criticism: https://news.ycombinator.com/item?id=42653176 https://news.ycombinator.com/item?id=42653176
- glenstein 2y agoSetting aside agreement or disagreement, what about that comment is striking you as symptomatic of coming from an echo chamber?
- udev4096 2y agoOh please. It's a factual argument and you've contributed nothing to it apart from steering away from the goalpost
- glenstein 2y agoLet's say I'm doing all of those things, and am prepared to atone for my sins. And I just want to know what you found echo chamberry about the other comment. Can you enlighten me? Maybe that way I can avoid all of the mistakes that I'm making.
- yjftsjthsd-h 2y agoIn order: It is; the authors appear to be operating in a model where they completely trust app authors and nobody else, though they never actually spell out the threat model (which really should make us view their assessment skeptically anyways), where F-Droid specifically avoids trusting app authors. Nearly all of their objections come down to this single difference. What echo chamber? I'm not aware of anyone else arguing this position. That post contains 3 items: One fixed audit finding that only affects initial install of an app, one claim of problems that are unspecified and therefore impossible to assess, and one allegation of poor behavior (which is worth noting but not a security concern).
- awalGarg 2y agoTo add insult to the injury, they claim that most people should stick to Play Store - a malware repository controlled by an ad distribution company - for better privacy. We're supposed to take this seriously.
- NotPractical 2y agoThey had a much more convincing argument before the Play Store started forcing the same exact thing that they said was one of the main problems with F-Droid, and F-Droid started providing reproducible builds.
- captainbland 2y agoThis reads really weirdly and seems to downplay concrete threats/malicious activity in the play store and emphasise best practice/security model violations on F-Droid. I get F-Droid is the subject, and it's reasonable to make space to highlight issues with it here but it doesn't seem reasonable to conclude your security posture is better if you go with the play store.
- glenstein 2y agoI agree that the article is very bizarre and seemingly written by a non-expert. The criticism of the inclusion policy sticks out like a sore thumb for strangeness. They criticize f-droid for requiring hosted apps that don't include proprietary software or ads. which of all the things you could criticize F-Droid for, is very strange. And instead of making like a systematic point about process or about best practices or standards, it meanders into an anecdote about one instance of an app where the developer packaged an outdated version of WebRTC to comply, and then blames F-Droid for the way that the developer packaged the app. And then bizarrely refers to this as a "case study". There's an informal sense in which you can say case study, which I guess is fair enough, but when speaking a bit more formally case studies are real research projects, not just one-off anecdotes loosely summarized in a paragraph. A lot of the language here is used in this gray area of formal and informal, seemingly characteristic of a high school essay.
- fngjdflmdflg 2y agoAssuming one did have reproducible builds, would you even need signing keys anymore? All you would need is to build the app yourself or have some trusted third party build it and verify that both outputs are the same. You could also use md5s published by the developer and check that against the f-droid build. It seems like the advantage of signing is pretty small at that point. At least in the case I am thinking of, where the developer is using GitHub, it seems unlikely that a malicious actor would be able to add malicious code to the repo and create a new release but somehow be blocked by the signing keys. In that case, I think it would be better to just use "00000000" as the signing key for all apps (8 character minimum jks length) to make build scripts more reproducible, ie. the signing is part of the build script, which also makes apk md5 comparisons easier. Am I missing something?
- wakawaka28 2y agoThe benefit of having a signature over a simple hash is that even if the code was tampered with, you would know it is not the same as what the author used. On the other hand, if it was a reproducible build, it could have still been tampered with somewhere and only the original developer could verify that you got the right code to start with. Also, not everyone is equipped to build software. Signatures enable you to easily know that there was no MITM tampering (or at least, to assume much lower chances of it), with less overall trust required.