https://www.cnet.com/news/fortnites-battle-royale-with-andro...
https://www.cnet.com/news/fortnites-battle-royale-with-andro...
Isn't that actually proof that something doesn't need to be on google play to be checked and improved?
> Any app with the WRITE_EXTERNAL_STORAGE permission can substitute the APK immediately after the download is completed and the fingerprint is verified. This is easily done using a FileObserver. The Fortnite Installer will proceed to install the substituted (fake) APK.
That's not Android fault: you're asking Android to give you access to an unrestricted storage area (e.g. because you want to edit photos shot with your Camera app), and the fact that other apps can read/write to it, is the whole point of that storage. Hence you need to treat it as untrusted, and validate that you're going to install the APK that you thought you were going to install.
Which, yes, is a reason to not use external storage. But for large downloads it's undeniably the norm, since internal storage is frequently limited. Since Android doesn't appear to provide a way to use the SD card and also prevent this, that part of it is an Android flaw IMO.
As evidence, note the external storage options say "can another app access it? yes, if it's in external storage": https://developer.android.com/training/data-storage
https://developer.android.com/guide/topics/data/data-storage...
The fact that the norm is different is a good point, but the norm is also not to implement your own app stores.
In fact, if internal storage is so limited that you don't have space for the APK, you'll get errors due to lack of space even while installing apps from the Play store
Anyway. Yeah, silent installs make this dangerous, no disagreement there at all (tho they're always more dangerous. I'd prefer to never have them). But there's also no reason that Android can't provide a protected external store, except that they've been self-destructively hostile to external storage in any form. It won't work if you remove the SDCard and manipulate it elsewhere, but that's not the attack vector here - it's entirely possible to protect from things on-device, just like they do for internal storage. They even partially achieve it now, with "adopted" internal storage, so it's absolutely possible.
Notably, all operating systems that allow programs to write to files have this "pathologically bad security". Download a .exe file on Windows and check its hash before installing and you have a TOCTOU bug where malware can sub the file after you've checked the hash.
Another alternative is to not permit any application to be installed unless it is signed by the OS manufacturer or some other finite trusted list of signers - but then we are right back at the app store model that pisses people off.
That's a solved problem. Apps on iOS can request access to the photo library. Why Apple still doesn't allow write access to the music library is frustrating.
It would be nice if you had a universal "folder picker" where multiple apps could be given access to a user created folder on ios, admittedly.
> That's because Fortnite isn't available through Google's Play Store. Epic instead chose an unorthodox -- and more dangerous -- route for the game's fans. Rather than download it through the official Google app store, players need to download the game and "sideload" the app on their Android devices instead. That Epic is allowed to do this underscores why Google's Android often gets knocked for its security chops.
No wonder they ultimately folded and came back into the “protection” [racket] offered by Google Play with PR like this coming to bear.
But really? That's the card you're going to play? That "every app has security issues" so this is okay?
QubesOS, Snaps, Firejail, Sandboxie, browser tabs to some extent, restrict user-freedom in only the most technical way, with no bundled choice traps. On the contrary, a good sandbox allows users to forego human curation/proprietary malware detection services and execute any code they want.
Do you remember all of the moral panic about violent video games after Mortal Kombat came out?
They probably invested quite a few engineering hours to devise a solution, as there’s a lot of code / Google services that need to be replicated. It’s unsurprising to me that there were some bugs in this code, and I think generally companies that respond to bug reports and issue patches should be commended.
Where I would disagree is if you are claiming that we should be treating Google Play akin to a low-level cryptographic library in the vein of a “don’t ever roll your own” approach. Allowing independent software distribution is usually considered a positive differentiator for Android. For this to be a viable distribution channel it’s actually extremely important for large and popular entities to be using side loading in order to build recognition and trust in its use. Ideally it results in open-source sideloading frameworks and best practices that the larger community can build upon.
Personally I’ve relied on Zoom to get meetings running quickly (without wasting precious time fighting with hard to install client software) many times on meetings where I would gladly trade ease of use for security posture.
I think Zoom messed up but has shown they can admit fault and course correct.
They are—as far as I’m aware—an entirely content neutral communications network that lets me pay for a service, doesn’t try to analyze and data mine my content, isn’t operating as a middleman between me and my customers, and isn’t at risk of becoming my competitor if it detects my product is becoming successful. They aren’t leveraging a monopoly position to maximize rent seeking and crushing the little guy through arbitrarily enforced content moderation policies. They aren’t exploiting cheap labor or phish a business to intercept their customers.
So as far as growth-hacks go, playing some API tricks on Mac and Windows to get their client ridiculously easy to install and running in a meeting — which risked you entering a meeting without an extra prompt, or potentially provided a pivot for unsigned code....
Frankly they seem about as un-villainous as they come in terms of publicly listed tech companies or venture-backed unicorns.
They aren’t sorry for doing it. They are sorry for getting caught....
It wasn’t used to track their users, or serve ads, or nag users to come back to Zoom or monitor anything on your machine. It was used so that when you wanted to join a meeting, it would get you into the room completely effortlessly.
Again I just feel like compared to the innumerable ways that big and “well respected” companies are regularly screwing their customers, using a technical hack only to make your product easier to use is in some ways commendable even.
I’ve wasted 15, even 20 minutes on some hour long conference calls just trying to get everyone dialed in and able to hear and talk. I actually chose Zoom because of how hard they worked to make it “Just Work”. I guess I feel like they had their heart in the right place, and didn’t actually abuse their users’ trust like almost every other company I’m forced to put up with.
I think Fortnite is even more ethically clear cut than Zoom though, because Fortnite tried to develop a feature that they have every moral and technical right and justification to do.
I see self-distribution along the lines of self-hosting. It’s feature that we want to be able to exist and be well tested and understood how to “do it right” for strong competitive and anti-censorship reasons.
Fortnite just happened to screw up a specific aspect of the implementation. In some cases you screw up, you patch it, you write a blog post explaining what you got wrong and how you fixed it, and you’re a hero for helping the community learn from your mistake!
I don’t understand why Fortnite got pilloried instead of the community wanting them to succeed so that they could blaze the trail for independent developers in the future?!
Why wasn’t the pressure on Google for not having better documentation and support for what they were trying to do, and for imposing arbitrary technical limitations like not allowing developers to keep the sandbox enabled for side-loaded apps?
Wasn’t it Google that actually found and disclosed the bug in Fortnite’s installer? That’s some serious gray hat level hacking.
If Fortnite had succeeded in mainstreaming the concept of side-loading it might have made it much more popular and pressured Google into not making side-loading technically inferior. That put the fear of God into Google and gave them a massive financial motive to undermine that effort.
It’s not like Google hasn’t badly screwed up many times with Android security in the past.