It's quite amazing when you think about it, that two US companies have absolute power over deciding what 99% of people in the world can do with a device that many would describe as an extension of themselves.
It's quite amazing when you think about it, that two US companies have absolute power over deciding what 99% of people in the world can do with a device that many would describe as an extension of themselves.
> When Fortnite launched on mobile in 2018, Epic Games very notably sidestepped the Google Play Store and pushed users to download the title directly from their website, an effort made to avoid the substantial revenue cuts that Google takes from in-app purchases of Play Store downloads. After 18 months of harsh rhetoric regarding platform gatekeeping, Epic Games says that Fortnite is now available for download on the Google Play Store, though it will still be downloadable from fortnite.com moving forward.
> Google puts software downloadable outside of Google Play at a disadvantage, through technical and business measures such as scary, repetitive security pop-ups for downloaded and updated software, restrictive manufacturer and carrier agreements and dealings, Google public relations characterizing third party software sources as malware, and new efforts such as Google Play Protect to outright block software obtained outside the Google Play store,: an Epic Games spokesperson said in a statement. "Because of this, we've launched Fortnite for Android on the Google Play Store."
https://www.cnet.com/news/fortnites-battle-royale-with-andro...
Isn't that actually proof that something doesn't need to be on google play to be checked and improved?
> Any app with the WRITE_EXTERNAL_STORAGE permission can substitute the APK immediately after the download is completed and the fingerprint is verified. This is easily done using a FileObserver. The Fortnite Installer will proceed to install the substituted (fake) APK.
Notably, all operating systems that allow programs to write to files have this "pathologically bad security". Download a .exe file on Windows and check its hash before installing and you have a TOCTOU bug where malware can sub the file after you've checked the hash.
Another alternative is to not permit any application to be installed unless it is signed by the OS manufacturer or some other finite trusted list of signers - but then we are right back at the app store model that pisses people off.
That's a solved problem. Apps on iOS can request access to the photo library. Why Apple still doesn't allow write access to the music library is frustrating.
It would be nice if you had a universal "folder picker" where multiple apps could be given access to a user created folder on ios, admittedly.
That's not Android fault: you're asking Android to give you access to an unrestricted storage area (e.g. because you want to edit photos shot with your Camera app), and the fact that other apps can read/write to it, is the whole point of that storage. Hence you need to treat it as untrusted, and validate that you're going to install the APK that you thought you were going to install.
Which, yes, is a reason to not use external storage. But for large downloads it's undeniably the norm, since internal storage is frequently limited. Since Android doesn't appear to provide a way to use the SD card and also prevent this, that part of it is an Android flaw IMO.
As evidence, note the external storage options say "can another app access it? yes, if it's in external storage": https://developer.android.com/training/data-storage
https://developer.android.com/guide/topics/data/data-storage...
The fact that the norm is different is a good point, but the norm is also not to implement your own app stores.
In fact, if internal storage is so limited that you don't have space for the APK, you'll get errors due to lack of space even while installing apps from the Play store
Anyway. Yeah, silent installs make this dangerous, no disagreement there at all (tho they're always more dangerous. I'd prefer to never have them). But there's also no reason that Android can't provide a protected external store, except that they've been self-destructively hostile to external storage in any form. It won't work if you remove the SDCard and manipulate it elsewhere, but that's not the attack vector here - it's entirely possible to protect from things on-device, just like they do for internal storage. They even partially achieve it now, with "adopted" internal storage, so it's absolutely possible.
> That's because Fortnite isn't available through Google's Play Store. Epic instead chose an unorthodox -- and more dangerous -- route for the game's fans. Rather than download it through the official Google app store, players need to download the game and "sideload" the app on their Android devices instead. That Epic is allowed to do this underscores why Google's Android often gets knocked for its security chops.
No wonder they ultimately folded and came back into the “protection” [racket] offered by Google Play with PR like this coming to bear.
But really? That's the card you're going to play? That "every app has security issues" so this is okay?
They probably invested quite a few engineering hours to devise a solution, as there’s a lot of code / Google services that need to be replicated. It’s unsurprising to me that there were some bugs in this code, and I think generally companies that respond to bug reports and issue patches should be commended.
Where I would disagree is if you are claiming that we should be treating Google Play akin to a low-level cryptographic library in the vein of a “don’t ever roll your own” approach. Allowing independent software distribution is usually considered a positive differentiator for Android. For this to be a viable distribution channel it’s actually extremely important for large and popular entities to be using side loading in order to build recognition and trust in its use. Ideally it results in open-source sideloading frameworks and best practices that the larger community can build upon.
Personally I’ve relied on Zoom to get meetings running quickly (without wasting precious time fighting with hard to install client software) many times on meetings where I would gladly trade ease of use for security posture.
I think Zoom messed up but has shown they can admit fault and course correct.
They are—as far as I’m aware—an entirely content neutral communications network that lets me pay for a service, doesn’t try to analyze and data mine my content, isn’t operating as a middleman between me and my customers, and isn’t at risk of becoming my competitor if it detects my product is becoming successful. They aren’t leveraging a monopoly position to maximize rent seeking and crushing the little guy through arbitrarily enforced content moderation policies. They aren’t exploiting cheap labor or phish a business to intercept their customers.
So as far as growth-hacks go, playing some API tricks on Mac and Windows to get their client ridiculously easy to install and running in a meeting — which risked you entering a meeting without an extra prompt, or potentially provided a pivot for unsigned code....
Frankly they seem about as un-villainous as they come in terms of publicly listed tech companies or venture-backed unicorns.
They aren’t sorry for doing it. They are sorry for getting caught....
It wasn’t used to track their users, or serve ads, or nag users to come back to Zoom or monitor anything on your machine. It was used so that when you wanted to join a meeting, it would get you into the room completely effortlessly.
Again I just feel like compared to the innumerable ways that big and “well respected” companies are regularly screwing their customers, using a technical hack only to make your product easier to use is in some ways commendable even.
I’ve wasted 15, even 20 minutes on some hour long conference calls just trying to get everyone dialed in and able to hear and talk. I actually chose Zoom because of how hard they worked to make it “Just Work”. I guess I feel like they had their heart in the right place, and didn’t actually abuse their users’ trust like almost every other company I’m forced to put up with.
I think Fortnite is even more ethically clear cut than Zoom though, because Fortnite tried to develop a feature that they have every moral and technical right and justification to do.
I see self-distribution along the lines of self-hosting. It’s feature that we want to be able to exist and be well tested and understood how to “do it right” for strong competitive and anti-censorship reasons.
Fortnite just happened to screw up a specific aspect of the implementation. In some cases you screw up, you patch it, you write a blog post explaining what you got wrong and how you fixed it, and you’re a hero for helping the community learn from your mistake!
I don’t understand why Fortnite got pilloried instead of the community wanting them to succeed so that they could blaze the trail for independent developers in the future?!
Why wasn’t the pressure on Google for not having better documentation and support for what they were trying to do, and for imposing arbitrary technical limitations like not allowing developers to keep the sandbox enabled for side-loaded apps?
Wasn’t it Google that actually found and disclosed the bug in Fortnite’s installer? That’s some serious gray hat level hacking.
If Fortnite had succeeded in mainstreaming the concept of side-loading it might have made it much more popular and pressured Google into not making side-loading technically inferior. That put the fear of God into Google and gave them a massive financial motive to undermine that effort.
It’s not like Google hasn’t badly screwed up many times with Android security in the past.
QubesOS, Snaps, Firejail, Sandboxie, browser tabs to some extent, restrict user-freedom in only the most technical way, with no bundled choice traps. On the contrary, a good sandbox allows users to forego human curation/proprietary malware detection services and execute any code they want.
Do you remember all of the moral panic about violent video games after Mortal Kombat came out?
Wait a sec, does this affect F-Droid as well?
It was done with Windows and Explorer so I don't see why this is any different.
That said, auto-updates are still not possible without root access, I believe.
https://github.com/termux/termux-packages/wiki/Termux-and-An...
Just because the parent is talking about the implementation doesn't mean the user-facing UI will actually expose any of it.
I believe the parent was suggesting, like with Windows/IE decades ago, that Android phones may have to come with a prompt to enable alternative stores to Play.
[1] https://f-droid.org/en/packages/org.fdroid.fdroid.privileged...
[2] https://f-droid.org/en/packages/org.fdroid.fdroid.privileged...
I think we agree this is a crucial technical disadvantage. Do you think it would be fair for users to be able to make this decision for themselves on devices they own?
https://www.xda-developers.com/xda-labs/
It tries to provide an alternative to the 30% "platform charge", and offers PayPal and cryptocurrency payments (with real-time approval etc from what I recall).
It's hard to gain users on an alternative store, especially when most don't know what isn't available to them. And most also don't see the 30% fee being taken from the developer by the platform. Low cost apps are pretty much unaffordable to do at hobbyist scale when you factor in the platform charge, VAT, and taxes, and I fear for the future with app development heading down the route of only large professional outfits doing so (with their large, professional data gathering and monetisation plans).
Aurora Droid supports F-Droid-like repos, you can have multiple selected, and they may include proprietary applications.
All usual issues with Android's security getting in the way still applies though.
Overall Aurora Droid is still miles away from a "proper" store, because there is no payment, there is no user feedback (so apps are still ordered by last updated or name...), and I don't think the author plans on adding such features (Because it also requires backend work). That's still a nice update to F-Droid original app.