As a replacement for the Play Store, check out https://f-droid.org/
As a replacement for the Play Store, check out https://f-droid.org/
[1] https://f-droid.org/forums/topic/what-to-do-with-private-api...
You distribute user-specific secrets after a user has logged in over a secure channel.
You don't get to have app-specific secrets - since anybody can get and run the app (and modify it!), nothing in it has a reason to be secret. This means that you don't get to have an API that's available only through that app and with limitations set by that app. If you use a third-party API that requires you to enforce limits on its use (e.g. that end users can't redistribute access to that API), this means that you can't meet the requirements of that API licencing.
Don't include API_KEY in the published source, include rot13(API_KEY).
It's the source code part that is open to interpretation. I could of course just ask for explicit permission for that.
---
I dont get all that API key nonsense, you can search this board for our opinions on API keys. I’ll keep this short:
If your app requires an API key and you withhold it (because you entered an agreement with the service provider), this basically makes it not buildable for 3rd parties in a useful manner. F-droid will not sign an agreement with whatever service provider you use nor will we withhold build information.
There are actually only two solutions:
1) Provide a way for the user (!) to enter API key or account information at runtime.
2) Provide a way for us to get the key at buildtime, e.g. there was one app where I had to download a pre-compile APK file, extract the key from it and re-use that key in our builds.. which sucked. Anyway, I dont see what’s the difference to just providing the API key. If you distribute an APK, you distribute the API key (in one form or another) — since without it the app would not work… sigh.
I think many times you can limit the FOSS version to not include functions such as leader boards to avoid such issues and no one will complain.
Other alternative app stores are the Yandex Store (https://store.yandex.com/) or the Amazon App Store, those include non-free software too.
[1] https://f-droid.org/forums/topic/api-keys-and-free-software-...
F-Droid has several apps where they download a built APK, decompile it automatically, extract the API key, and build the open source app with that key.
You can do exactly that already.
Extended per-app privacy settings, built-in root manager, lots of customization options... And the best of all: enormous community. There are builds for crazy amounts of devices.
GPLv3 would help.
https://www.amazon.com/LG-Tablet-Snapdragon-Android-JellyBea...
https://download.lineageos.org/v500
There are over 150 devices supported, but the vast majority are smartphones
My last 3 mobile phones were MediaTek phones, but that's one of my biggest gripes with them.
I've been carrying Windows but Microsoft just effectively announced end of life for the last two phones on my carrier.
Why do you think that?
Heck, Fuchsia is built with a reasonable security model, most work on Android goes into making excuses for theirs.
At least if I'm carrying something obscure the likelihood of being targeted is low.
I don't have the time or desire to do what's required to securely operate on the Android platform.