4 ms·
I wonder what would happen if F droid signed all software under their keys even though they aren't the developer? Make Google ban them instead of just giving up
by DevelopingElk 1y ago
I wonder what would happen if F droid signed all software under their keys even though they aren't the developer? Make Google ban them instead of just giving up?
- zx8080 1y agoAny centralisation like this is bad: it's too easy for Google to delete all f-droid apps with their play protect one day.
- Aachen 1y agoOkay so the options are: - don't exist - exist until you get deleted You seriously prefer the former?
- zx8080 1y agoAre you serious? There are more options than you think (or try to convince others). I do prefer control over what I can install to my computer be it a box or a mobile one, and control on what runs there.
- Aachen 1y agoOkay so people can choose to buy a second device and do some things there (until chatcontrol 3.1 finally is approved by parliament anyway), but for the device that's basically mandatory for normal life now, what other options than "work with the system" or "don't" does F-Droid have? I'll probably end up doing that btw. For now I'm still fighting the "have control on 1 device" battle, simply not using things that require a locked DRM state (no 2FA government login for example, limited bank choices, soon no age verification, etc.) until that's no longer tenable for me. I'll be among the last 0.02% to give in, judging by how it's going today (not even 99% of tech people seem to care that they're not the admin on their own device). We're on the same side with the same goals here, but I'm simultaneously also looking at what realistic remaining options are for my friends, family, and semi-child
- weikju 1y agoThis is addressed in the article as well, and while there's no technical reason they couldn't do this, it would break the licensing of the apps as well as the dangers of centralizations mentioned by a sibling reply. > The F-Droid project cannot require that developers register their apps through Google, but at the same time, we cannot “take over” the application identifiers for the open-source apps we distribute, as that would effectively seize exclusive distribution rights to those applications.
- 4ndrewl 1y agoThat might be the least-worst option here.
- em-bee 1y agof-droid could distribute their apps with a different identifier.
- fluidcruft 1y agoOh... this makes things much clearer to me actually. The issue is that you don't want apps that impersonate other apps showing up. For example, if someone put an app in another market that could sideload to impersonate Facebook's intents and do evil-maid type things. In the new system it would become very difficult to install a fake Facebook that is able to convince other apps that it is in fact Facebook's own app. Google's announcement can be seen as them operating essentially like DNS for app ids and intents and making things safer for a multi-app-store universe. For example, there is an annoyance that happens sometimes with apps that are distributed in both F-Droid and Play Store related to updates. F-Droid and Play Store will think they both can update the app (they have the same tld.what.ever identifier) but the signing keys only match the store they were installed from. I think F-Droid is now a bit more careful about this and only tries ones it has specifically installed. This is different... but somewhat related. F-Droid in general is a model good actor as far third-party app stores go, but from the perspective that malicious app stores might exist you would want to try and isolate apps from each other (and prevent unauthorized re-distribution of tampered versions etc). I think what Google is doing forces apps in each store to be cleanly namespaced from each other and prevent collisions (accidental or otherwise). This lets each app store tend and be responsible for its own walled garden.
- fluidcruft 1y agoMaybe users could provide their own keys into the F-Droid app and the F-Droid installer swaps keys as part of the download and install. At the end of the day we're just talking about a signature.
- notrealyme123 1y agoNo. You pay Google for the license and Google can kill your app, even on f droid. We don't need a work around. We need Google to stop killing our apps.
- fluidcruft 1y agoThe new registration system is not the paid the full developer registration--that's only needed for Play Store distribution. The new thing everyone is complaining about is a different registration system that will be free (but likely requires identity verification). Google's announcement said that a solution was being developed but is not yet available to support individual and hobbyist use. They said it will be available before the system becomes mandatory (except for a few high-risk countries) Frankly, I don't see why anonymous app distribution is necessary. The "I own my own device goddammit" thing is hobbyist category. Why should it be friction-less to install crap that has no provenance? That specifically seems like a really dumb hill to die on.
- g-b-r 1y agoBesides making compiling apps yourself very difficult (you'd have to register and change the app's name), it's extremely likely that they won't just accept anyone and any app; at least things like NewPipe and Aurora Store are likely to get banned.
- fluidcruft 1y agoCompliling apps yourself would fall under and use the system for hobbyists Google said they are working on. At a basic level, apps you compile yourself would likely sideload over adb/USB and it's easy enough to exception adb as an install vector as distinct from app stores downloading and installing from the the network. adb doesn't help F-Droid, but that's clearly a very different thing (at least as I see it).
- deivid 1y agoFDroid owns the keys for any app submitted without reproducible builds. But I believe they would prefer 100% reproducible builds and to own no keys
- dariosalvi78 1y agomaybe they can distribute the apps with a different identifier? just add a suffix? like fdroid.__original_identifier__ ?