I'm trying to run a totally open-source android installation, and have opted-out of Google entirely. It's worked out fairly well so far, but the app choices are fairly limited, of course.
I'm trying to run a totally open-source android installation, and have opted-out of Google entirely. It's worked out fairly well so far, but the app choices are fairly limited, of course.
But it does mean you can install apps on the play store that have a dependency on gsf but are otherwise open-source (e.g. maps.me, signal, tomahawk).
Isn't that a good way to get a modified / malware version of Signal? Anyone can upload to APKMirror, can't they?
This is also useful: http://www.onyxbits.de/raccoon It's a dektop play store client. I tried it out a while back and it worked, don't know about now.
Edit: The series is a little out of date, but should give you the general idea. ROMs that are probably new since that article was published that have no google dependencies are Replicant (entirely libre), OmniROM, Copperhead OS, and CyanagenMod w/ a no-gapps-script.
Edit: [0] https://f-droid.org/wiki/page/Setup_an_FDroid_App_Repo
The whole point of software stores is giving users the ability to trust the motives of the software they install, because the store and / or its users would never condone hostile software being hosted there.
Once you start having everyone run their own F-Droid repos, you are having independent developers give you their own trust keys, but you have no one else who needed to verify those developers were legitimate.
F-Droid itself is not particularly secure, given anyone can upload anything there, but in the same way the Archlinux AUR, OpenSUSE Build Service, Ubuntu Launchpad, etc work those third party software repositories are at least hosted by a trusted maintainer of the store / repo itself. If anyone ever uploaded malware there, once found out, it would be taken down and the responsible users banned.
With distributed app stores under F-Droid, or the equivalent third party repos for Arch / Suse / Ubuntu, the host has absolutely no control over the behavior of third parties, and thus anyone can host all the hostile malware they want, and if users add those repos they give them absolute trust in doing so.
That isn't a valid security model by any estimation.
The alternative is download static apks today and maintain updates yourself(bad) or remove the freedom to install what you want on your device.
But for, say, an app for a restaurant or a document reader, you would not know or have any reason to trust the vendor, so if they are self-hosting their own repos you are taking a tremendous risk trusting them.
The end result would probably remain the same - users might use third party repos for huge popular apps, but small apps would still need to stay centralized because there is no way to introduce a viable trust model against an organization you never interacted with before.
Most people don't change their default browser, adding third party repos would be similar. Removing the ability for the owner of a device to install software they want fixes one symptom, not the main issue of trust. Also it makes your device into a glorified feature phone. No thanks.
In other words, moxie is wrong. Again.
The whole thread is a good read too haha