The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't.
This alone is enough for me to lose trust in Signal.
The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't.
This alone is enough for me to lose trust in Signal.
[0]https://signal.org/android/apk/ [1]https://whispersystems.discoursehosting.net/t/how-to-get-sig...
If you are so concerned about state-level actors that play store is untenable to you, signal and android on commodity hardware are probably not the solutions you want anyways.
Or are we just going by the author's ignorant or disingenuous (depending on how you interpret his words) statements?
For it to be on F-Droid. I think that much was clear.
Are there any identified, non-state-level actor threats here, or is this just an ideological rant against proprietary software? If state-level actors are your concern, using android means you have already lost.
It was posted elsewhere but here's Moxie's take: https://github.com/signalapp/Signal-Android/issues/127#issue...
Most likely one of those, yes. Though on Android 8+ you can only give that allow-install from unknown soures permission to F-Droid.
Also both Copperhead and Fairphone Open ship with the F-Droid priviledged extension by default allowing you to kee that setting entirely disabled.
wtf. I have been using F-Droid for many years, and this has not been the case. as far as I know, this has never been the case, as Android has always had functions for third party app stores. in fact, even today, F-Droid recommends not using root for installs, since then you don't get the screen showing permissions.
> allow third party code
that's called running apps.
tl;dr nice FUD.
This is what I do on lineageOS. I don't regularly install new apps.
Side rant: This marketer-driven "install an app for everything" is a threat to the open internet and privacy. Usually the only reason is to extract more personal info.
Already, young people barely use a web browser. That appears to be the future. Now get off my lawn or I'll start talking about the war.
Android could undoubtedly be stronger in this regard, and in permission control, firewall, ad blocking etc, but it's not going to happen.
Apps wouldn't be so bad if they were actually sandboxed properly, but yeah, they suck.
I was interested in Copperhead OS as an alternative, but it seems to have fallen into a greed induced mess.
I am arguing Play store is fine, and side loading is bad policy.
I argued that for every person who will take the time to micromanage permissions, thousands wouldn't.
So what are you talking about?
https://twitter.com/APKMirror/status/1027580291374702592?s=1...
And you accuse me of making things up? "Allow third party code" is not called "running apps"
... are using a platform "you" don't trust.
Really? That's not really odd.
At least, it's not odd, if that usage and what it entails is the denominating part of the persona in this question.
Here's a thought. If you are so concerned about the NSA that you think Google's cloud is a problem, why are you running the OS developed by Google?
I'm not, and I find that position naieve. For the overwhelming majority of people who are not a cross between Bruce Schneier and Linus Torvalds, a threat model that tries to protect against the NSA and GRU and MSS pretty much requires avoiding anything with a network connection. If you have a smartphone, you should probably just use its default application store.
I can trust people that I think made incorrect technical decisions, because I can see that they made a decision for technical reasons and have different priorities and reasoned soundly.
There are, I'm sure, apps that are better, and that's never been moxie's goal. He's said it over and over that he'd rather have encryption for the masses than the perfect messaging app. It seems disingenuous to assume that he's acting in bad faith when he's clearly doing exactly what he said he wanted to do.
If you want to make the prefect, self-hosted, chat eco system, fire up that matrix server and invite your non tech friends to join. I'm sure that will work out incredibly well.
In the mean time, Moxie seems to realize that to accomplish his goal and make communication incrementally more secure for average users, he needs to go where the users are.
It's crazy to me that people still think that secure communication is a technical problem. We've had GPG for the competent for a long time. The hard problems in secure communication are about using the eco systems that are available to large groups of average users and still being secure.
Am I missing something?
I donated some money to them a while back. How hard could it be to push the binaries out to a second app store?
I tried to publish my open-source game on F-Droid, but the build process involves building native components with a specific third-party version of the NDK toolchain, as well as shell scripts to move files around, so it never made it to the store.