6 ms·
I really like the popular "popular" sections, the one thing that's missing from f-droid. What could be improved: 1. HTTPS, especially for APK downloads 2. Inf
by Dosenpfand 11y ago
I really like the popular "popular" sections, the one thing that's missing from f-droid. What could be improved:
1. HTTPS, especially for APK downloads
2. Information about the APKs: built/signed by whom
- SnaKeZ 11y agoThanks for the suggestions :)
- higherpurpose 11y agoAnd if you're going to add signatures please don't make them MD5/SHA1. I don't understand why so many sites still offer those. Is it some default feature of some software stack where developers just "check" a button for signatures and it only supports MD5/SHA1? Otherwise I can't explain it.
- sarciszewski 11y agoI recommend RSA (GnuPG) or Ed25519 signatures with two key pairs: A weekly/monthly signing key pair, and a long-term one that is only used to validate the short-term public key. https://scott.arciszewski.me/blog/2015/01/package-signing-thread-modelling https://scott.arciszewski.me/blog/2015/01/package-signing-th...
- JohnTHaller 11y agoIn Windows world, you basically have to use SHA1 digests for digital signatures (though you use SHA2 certs to do the signing) as Windows XP doesn't support SHA2 at all, Windows Vista SP1 or SP2 prior to a patch a view years ago won't run the EXE or show an error due to a buffer overrun, and Windows Vista's Internet Explorer full patched will show the download as "reported unsafe" due to an unfixed bug in IE.
- CyberShadow 11y agoWhat do APK signatures have to do with Windows?
- JohnTHaller 11y agoI was giving an example of a context when using something stronger than SHA1 doesn't work even though it is supported. To show that there are sometimes reasons other than laziness and on the off chance that there may be something similar with specific versions of Android or possibly some software that deals with APKs.
- deleted 11y ago[deleted]
- justonepost 11y agoGoogle has made it so you can't enforce APK signatures via PKI on android os. Gee, I wonder why!
- icebraining 11y agoSure you can. Android itself just doesn't do it for you, but the F-Droid installer could very well verify the APK before installing it.
- justonepost 11y agoNo doubt. But it's pretty funny that Google refuses to add a few lines of code to do it via the OS installer.
- icebraining 11y agoWhat would the OS check the signature against, though? The certs that come with the OS are for validating sites, not apps, so passing a check wouldn't tell you much. It seems that Android would have to add a whole new cert store (and mechanism for adding certs), not just a couple of lines.
- justonepost 11y agoThat's not true at all. CA and leaf Certs have extensions and policies and can be used for any particular purposes. All the cert verification has to do is check for the code signing extension / policy.
- eighthave 11y agoVerifying signing keys is one thing, but even better, f-droid.org can verify that the APK builds 100% from source, and that the APK f-droid.org builds matches the developer's official released APK: https://f-droid.org/wiki/page/Deterministic,_Reproducible_Builds https://f-droid.org/wiki/page/Deterministic,_Reproducible_Bu...
- vetinari 11y ago
- pserwylo 11y agoIt is worth keeping in mind that the download stats which determine popularity [0, 1] should consumed with care. They represent HTTP requests which hit the server to download a particular apk file. Thus, things such as web crawlers can trigger downloads, which result in incrementing the download count. Having said this, they definitely seem to be useful as a general rule of thumb about how apps are more popular, _relative to other apps_. [0] - https://gitlab.com/fdroid/fdroiddata/blob/master/stats/total_downloads_app.txt https://gitlab.com/fdroid/fdroiddata/blob/master/stats/total... [1] - https://gitlab.com/fdroid/fdroiddata/blob/master/stats/total_downloads_app_version.txt https://gitlab.com/fdroid/fdroiddata/blob/master/stats/total...
- SnaKeZ 11y agoNow Fossdroid in on HTTPS