Who would have thought 30 years ago someone would be saying "People can run any code they want on their computer" as a shocking thing.
Who would have thought 30 years ago someone would be saying "People can run any code they want on their computer" as a shocking thing.
Any mastodon app that refused to blacklist Gab got banned from F-Droid or something like that.
It is the perfect example of why I don’t even bother with federated projects. It’s just “wouldn’t it be great if _I_ were in charge?”
If that’s the situation, I’d rather Big Tech be in charge because at least they have some name recognition and hierarchy for decision making. Nobody cares if pizza-witches wrongfully broke terms. With Twitter at least peoples’ ears perk up.
In other words, there’s no rules in the alley. But there are rules in the town square.
There was no requirement to blacklist gab. Mastodon clients on f-droid are allowed let users use Gab.
What f-droid does not allow is apps preconfigured to connect to Gab, or who's primary purpose is to connect to Gab.
There was even a petition to have fdroid remove an app (fedilab) that had a blacklist to disallow Gab then removed it, claiming that removing Gab from the blacklist was specifically endorsing it, and there were some people who tried to claiming that not apps that were not blacklisting Gab when other apps did meant those apps primary purpose was to connect to Gab, but f-droid weren't having it: https://gitlab.com/fdroid/fdroiddata/-/issues/1736.
However, they did consider an app that was a straight fork tracking another with the only change being the removal of a blacklist to be disallowed.
However, some fdroid users asked for its removal. They felt removing the blacklist feature, which had previously only blocked gab, was itself an endorsement of Gab and indicated the app's purpose was to access Gab since the other available mastodon app (Tusky) still had a blacklist.
fdroid did not agree and fedilab is still available.
OpenTusky was not allowed as it was literally Tusky with the server blacklist removed, created in response to Tusky blocking Gab. It also advertised this in the app description, so fdroid judged it to be primarily for accessing gab and removed it.
That's cutting the hair mightily fine.
EDIT: This is mentality I find hilarious. It's either I can something for free or I can't get it at all. I think freedom in this case is about having something with little expended work.
The "build your own if you don't like it" answer is often absurdly impractical, but not here. Someone who feels it's important can put up an alternate repo containing clients preconfigured to connect to Gab and even an alternate build of F-Droid preconfigured to use it in an afternoon.
Maybe the real reason will be pressure from the government to hurt the ones like Huawei a little more, maybe it will be the need to squeeze more money, or maybe the need for censorship because those evil alternative app-platforms allow whatever unwanted stuff.
Google standing in Europe is already really shaky. They keep taking fines after fines for abuse of their dominant position. That won't last forever. If they close the ability for other stores to exist, the best case scenario is the EU giving them a huge fine and forcing them to go back. Worst case is being force to split Android out of the main company. Google knows that which is why they will not do it.
1. You download the apk
2. When you try to install it, it tells you it's from an unknown source and the installation was blocked to protect you
3. You tap "settings" and flip a switch to allow installing apps from your browser
4. You go back and tap "install". That's it. It's done. And you won't need to go to the settings the next time, it'll just work.
> And you won't need to go to the settings the next time, it'll just work.
You will still have to find the apk when there is an update, download it and confirm install. There are still three steps to update the apk compared to Play Store's one tap (or even zero clicks if automatic updates are on). Only "Allow installing from this source" step is removed when updating the app.
But I think you can actually still load arbitrary dex files using a ClassLoader? I thought that the update was only affecting JNI libraries. I remember reading how they wanted for any and all executable code to come from a signed package. Even then, if you're determined enough, you can load arbitrary native code by allocating some rwx memory pages and copying it in there ;)
Sounds like there are ways to do it within the Android ecosystem, but in cases where Google is suspending things wouldn't they just turn off all the self-update stuff?
I guess my overall point is that Google is motivated to have complete control over Android app distribution, and they'll plug as many of the types of holes you're talking about as they can get away with.
That's bearable though unpleasant when you have one or two pieces of software that rarely get updated, that's absolutely impossible when you have 10+ pieces of software - you'll sit there for 5 minutes just approving install prompts every week, which isn't something a normal human is going to do.
It doesn't help that FDroid is pretty broken, and constantly pops up notifications about updates that don't work/aren't actionable (i.e. tapping the notification doesn't result in an install prompt followed by a successful installation, instead I get various errors etc.). Also, apparently the FDroid review process is even slower than the Play store review process.
Yes — because that's something reserved for privileged system apps. You have to root your device to take advantage of that, or make a custom ROM with the alternative store in it. Having that ability as a permission you could grant to any app is an immense security risk. But then there are "device administrator" apps that can literally factory reset the device... I don't know. Maybe package installation should be part of that. Especially now that the legacy permission model was taken care of — if you install an app that doesn't support runtime permissions, you'll get a list of its permissions with toggles next to them when you run it for the first time.
> you'll sit there for 5 minutes just approving install prompts every week
Unpopular opinion: well-made software that serves its user doesn't need to be updated very often. Remember how you bought a program on a CD and used the exact same build for years?
> Unpopular opinion: well-made software that serves its user doesn't need to be updated very often. Remember how you bought a program on a CD and used the exact same build for years?
Sure, I'm even old enough to remember this but on cassettes and floppy disks! But - software now is much more complex than it used to be - most software has dependencies on other libraries/frameworks, and has to deal with communication and encryption (where it is all to easy to make subtle mistakes). IMO, for security reasons alone, it's no longer realistic to expect software without at least occasional updates.
It often means that. :( But it is not that bad for some devices. Geeks from Lineage community regurarly update closed vendor code in the LineageOS. So if you are lucky and Lineage is well-supported on your device, you can still have root nowadays with up-to-date vendor blobs.
For example I rooted my Xperia XZ2 Compact and I am quite happy with it. By using Magisk and Magisk Hide, I am still able to use Google Pay. At the same time, I can use Titanium Backup and f-droid root extension to let f-droid install updates automatically. I hope this device will last me for a long time as I don't see many alternatives - most other phones are too big for me, too old/slow or unsupported.
I'd say software now is much more complex than it needs to be. It's made to ease the life of the developer, usually an inexperienced one, at the expense of the user.
> IMO, for security reasons alone, it's no longer realistic to expect software without at least occasional updates.
If people would stop rewriting things that already work fine, we'll run out of vulnerabilities at some point. Or, if you must rewrite them and have a good reason to do so, at least use a memory-safe language. Even C++ is much better than C and raw pointers. Anything is better than C and raw pointers. Yet all major OS kernels and most userspace components are written in C and use raw pointers and vulnerabilities in those are being found all too often.
A risk to whom? There is no permission that is a "security risk" so long as it's the device owner granting that permission.
The nice thing is that once the DPC is installed you can `adb install -r` (reinstall, ie update) it without needing to factory reset. Just don't uninstall it accidentally :D
Technically 100% possible, but practically never going to happen.
If someone were willing to write and maintain the necessary plumbing and then poked F-Droid, it would be interesting to see if they cooperated, but they may well be reluctant to.
Does this actually matter? On the desktop it's normal for apps to update themselves. Is there some fundamental reason an Android app cannot do this too?
Dropbox wouldn't be a thing if we can "educate" users.
Many people, myself included, love products that "just work" out of the box. That's what everything should be like, ideally. My gripe with modern technology is that it actively inhibits your ability to go in and tinker. DRM, forced app stores, code signing with enforced signing identity, all that kind of stuff.
See, imagine someone releases an amazing messaging app that's lightyears ahead of everything else on the market. But — it's only available through F-Droid or as an apk download on the developer's website. People will flock there and install it. And they will be unstoppable.
A concrete example of this phenomenon: Pokemon Go wasn't officially released in Russia, so you couldn't download it from the app stores. Yet, everyone played it. And I mean everyone, in 2016, especially during summer, you couldn't take a walk in the downtown St Petersburg without hearing the Pokemon Go sounds from people's phones. Android users sideloaded apks, iOS users created separate Apple IDs to bypass the geoblock. Suddenly everyone educated themselves to get the thing they wanted.
But even if 99% of people could figure it out, it'd still be an unnecessary hurdle whose only purpose is to provide Google with an unfair competitive advantage.
Until all of that bs goes away, side-loading and secondary app stores will be nothing more than a hobby for enthusiasts.
Minecraft.
Steam.
Heck, every video game ever.
Skype.
Microsoft Office. Made billions when people had to physically go to a store and get it.
Google Earth. Chrome itself.
IntelliJ, any developer tool.
Zoom. WebEx. Most video conf tools, actually.
Any pro tool whatsoever.
You get the picture. No, ticking a box and tapping is not the end of the world and never has been. The UX for app installation on macOS and Windows is totally atrocious in both cases and people figure it out.
If you live in the Valley bubble world where every single app that exists is VC funded and desperately racing to get to a 100M daily actives first, then it might seem like one extra click is literally the end of the world. But FFS the vast majority of all businesses and products require more effort to get than that, and they work just fine.
Well here's your problem
I don't deny the utility of app stores. My point was about the freedom of platform at a capability level.