Google to remove all VPN ad blockers that don’t comply with their policy
community.blokada.org
community.blokada.org
There are no news here. Ad blockers were never allowed to Play store, here is the relevant policy: https://support.google.com/googleplay/android-developer/answ...
This is exactly why AdGuard ad blocker is not distributed via play store. It was removed in 2014, we learned the lesson and see no reason in trying to abuse Google’s non-existent review process.
Interestingly enough, at first Google used a different rule, some vague stuff about interfering with networks. Later they reworked the rule and added ad blocking to examples of common violations.
Anyways, at least Google allows sideloading so devs can live without Google Play. When Apple pulls something like that we have no choice.
It is a click-bait (upvote-bait)?
TFA: ... we've been closely following the situation of the Google Play Policy changes and the company has now entered into the next phase ...
Yeah, they've got inside information. Sure.
Being able to sideload apps is the single issue that has kept me on android my entire life. Not being able to install the apps that I want to install on my own phone is a no-negotiation deal breaker for me. I really wish Apple would loosen their white knuckle grip on their precious iOS devices so that I could have options, but they obviously don't respect their users enough to give them that choice.
Android used to be clearly better for a lot of what I wanted my phone to do: more customizable, better app integration ecosystem, less vendor lock in for default apps.
Apple has slowly shored up its software weaknesses, and Android has slowly gotten worse at this (e.g. Google appears to have no plans to make RCS APIs available - they whitelist client APKs - so you're stuck with the stock messenger app). The single thing holding me back now is the walled garden for app installation.
> Apple has slowly shored up its software weaknesses
Every time i think about this, i check and see that there is still no way to customise the "desktop", all installed apps are just plastered on it and the best you can do is folders. Having used Nova launcher for like 10 years now i shudder at the thought of that chaos.
Also having to use a work-provided MacBook Pro, I've discovered that Apple's UIs are nice, but UX has a lot of hidden stuff (aka poor UX) and weird rough edges (you're holding it wrong). (If anyone wants examples, having different scroll directions between mouse/touchpad, having DP chaining work over USB-C, customising keys/key combos without installing a keylogger, etc etc etc.). I doubt iOS is different in that regard, so Android it is, imperfect as it is.
- AltStore and AltServer
Apple lets every user "side-load" 3 apps, but the caveat is that they expire in 7 days if not renewed on time. AltStore uses a mail plug-in on Mac to sign those apps in the background so you can keep using them indefinitely
- $99/year Apple Developer Program
You can "side-load" apps and they don't expire for 1 year. This is supposed to be for developers to test their app, but Apple may restrict this to stop side-loading in the future
why should location require sharing data with google? why? why should i not be able to stop google location sharing and continue using location based apps?
I agree.
- phones cannot be used as weapons during a shooting
- guns don't require a monthly subscription to use bullets not approved by the manufacturer
etc
Theoretically, a phone can absolutely be used as a component of the triggering mechanism of a rigged up firearm.
Yes, there are even extant regulations around that.
The ATF will consider anything that meets the definition of a firearm rigged with an electrically actuated trigger a machine gun by default due to being readily convertible to being fully automatic.
That you don't have the creativity or will to go down these rabbit holes does not in any way mitigate their existence.
I would say that we can have different devices for different peoples' needs; I personally want the ability to purchase a device with an absolutely locked-down state where no unauthorized or unaudited code can be ran, and currently iOS gets pretty close to that for me. But that is being taken away by laws like the EU's new sideloading law. Even if, after this is passed, I go out and make my own phone that serves my interests, I am forced to limit how many I sell if I want to keep it operational.
No one is forcing you to run any "unauthorised" code. What you suggest is that, because you don't want to side load stuff, no one should be allowed to? Doesn't make much sense to me, to be honest.
FIFY.
If you want choice of software to run (sideloaded or not), you are correct, Apple does not make the device for you. They've always been transparent about this. You are buying an Apple phone with apple software, and the option to install some apple-approved third party apps.
What made me leave Apple was for a real headphone socket, an SD card slot, and especially USB-C charging. Those were the non-negotiables for me.
Ideally Apple can keep it's walled garden for regular users and also let power users unlock their device to side-load apps if they so choose.
This is not necessary. Apple has sold millions of iPhones. If Apple customers did not feel respected they would not buy the product.
Just because a product doesn't have a feature YOU want doesn't mean the rest of us don't appreciate the added layer of security and simplicity.
For example, if you respect your girlfriend or wife, you give her the freedom to choose her own clothing at the store and don't force her to wear only what you've authorized for her to purchase.
This comment is absolutely unacceptable. I understand this isn't your decision, but its a decision I disagree with in the strongest possible terms. Ad blocking is the number one extension I use above all others. So if someone finds some excuse to bring attention to that fact, I say, let them do it.
What I am saying is that the title is misleading as it tries to represent an old rule as if it is something new.
Maybe because we're majorly affected by this whims of this supranational corporation and the only power we have to respond is to have as-visible-as-possible discussions about it.
The EU seems to exercise some control in limited cases, or that privacy law that somehow got passed in California, but those actions are the exception by far.
If Justice approves Adobe-Figma you can be sure our antitrust teeth are gone.
The only reason one may wish to implement as a VPN instead is to get a lot of data about users to sell. They otherwise provide less control, use more battery, are less reliable, and have privacy issues.
iOS even provides some good APIs for this that apps can hook into so that they don't need to deal with networking at all. Much faster, and the app receives no data about network usage.
Edit: Misunderstood Blokada's comment, they use DNS to do their filtering now.
iOS provides APIs to do content filtering at the system level, I assumed they were referring to something similar.
EDIT: I see you're affiliated with Google Play. You should've lead with that.
I don't believe there is a "content-blocking api". Correct me if I'm wrong.
Using a VPN could technically allow an ad blocker to block based on the full http path instead of blocking based on domain name.
It should also be noted that you can use the VPNService in android to only set a DNS server to use, without actually sending any traffic through a VPN. Using the VPNService in this way is not going to be allowed with the new Developer Policy update. When used this way, the privacy issues aren't there--though there is the potential misunderstanding of end users who might think they are using a full VPN when in reality they aren't.
Oh, good, I had interpreted "Cloud filtering" as some sort of content blocking API. DNS makes sense.
> It should also be noted that you can use the VPNService in android to only set a DNS server to use, without actually sending any traffic through a VPN. Using the VPNService in this way is not going to be allowed with the new Developer Policy update. When used this way, the privacy issues aren't there--though there is the potential misunderstanding of end users who might think they are using a full VPN when in reality they aren't.
That's good if VPN apps aren't always actually implementing a VPN, and it likely eliminates the battery life issue, but the confusion is a problem as users can't tell the difference between an actual VPN and one that is only doing DNS stuff.
In fact an app could say "don't worry we're only doing DNS" but actually be a VPN. That sounds dangerous to me?
I could be mistaken here, but I believe it's only dangerous if you're using an insecure connection (ie, http (no https) which is already dangerous). Or if you install a custom CA certificate--then the VPN could perform man in the middle attacks on your connection.
This assumes apps don't use cert pinning. Many chat apps, social media, some games, and all kinds of external libraries employ certificate pinning so that even when a malicious CA generates a certificate for their domain, their clients will not send secrets to that server. In this scenario that means that Facebook won't work even if you manage to get Symantec's private CA keys loaded onto your VPN because Facebook trusts specific Facebook certificates and nothing else.
For unencrypted connections the MitM risk is there and SNI sniffing can be used to log tons of sensitive information in all other cases. However, I wouldn't portray it as risky as this solution may sound on the desktop where there is a proper firewall API.
That's also the core issue, there is no firewall API on Android. The VPN system is the only API that can filter packets (though Google's and the manufacturer's apps can choose to bypass it) so most ad blocking VPNs are actually just user mode firewalls that need to appear as a VPN to work. Alternative solutions include changing your DNS server (to localhost or their cloud servers, depending on if DoH/DoT needs to be enforced) which works less reliably and has very similar risks.
The risk is definitely there, but in practice the risk is lower.
My solution is a WireGuard VPN to my home network (which is behind PiHole) but a local solution cannot properly block network requests without the VPN API.
Blokada has switched to doing DNS-based blocking through DNS but that's purely to get around Google's arbitrary restrictions on the VPN API.
Users should be able to use whatever network filters they like. If I don't want to send ICMP packets, or DNS packets for certain servers, or any other kind of specific traffic, I should have control over what my device is doing.
Note that the VPN API does not necessitate actually setting up a VPN to a cloud server. The VPN API exposes packets to an Android app so it can decide whether or not to forward the packet, rewrite it, send it through a tunnel, etc. Normally, there is no cloud service when VPN ad blockers are in use. Blokada has switched to a cloud system but only after Google blocked their normal system.
Until Google releases a comprehensive network filter driver API or firewall API there is simply no alternative. The Blokada local DNS server solves one problem (the need for a VPN) but cannot prevent ad libraries from using DoH to work around content blockers.
In-app (browser, css aware)
In-dns (local resolver)
In-network (pihole or IP firewall)
Ex-Network (vpn/proxy)
Since the first option has very sparse universal support (and shrinking) - you need to rely on the less savoury options to achieve proper adblocking.
Using their DNS with Blockada 6? No thank you.
I'm saving the APK and I will sideload it for as long as it will work. The problem is the maintenance of the blacklist. Anyway, a lot of people are interested in blocking ads, a solution will be found.
Is already there an open source app equivalent to Blockada?
"With the launch of Blokada v6 last June, Blokada successfully dodged this bullet as Blokada no longer requires a local VPN. Blokada v6 uses Cloud filtering instead; this method does not break Google policies and also provides certain advantages 850 over local VPN filtering since it won’t impact battery life, device speed, or network speed."
Surely this is only a temporary workaround as Google slowly brings this frog to a boil, right?
As long as you’re going towards the cloud I bet they’ll affirm it.
Right now Google does not allow alternative app stores like F-Droid (FOSS), Steam etc. on Google Play.
The important part is that it will be user-friendly install, instead of preinstalled app or hacky dev-like experience.
Play is a store. It's used on Android, which allows other stores, of which there are many.
It's not complicated to reset your windows password either, but there are entire careers dedicated to helping average people do it because not everyone is technically inclined.
If another app store is allowed, people will definitely download apps from there, though I believe percentage would be quite low.
Also, I think average guy knows how to install APK in Android. It's literally easier than installing Chrome on Windows, and 80% of windows web share usage is from chrome.
I believing OP was suggesting Google will need to allow the latter to be available in the former, not just allow the latter to be installed on Android.
They just need to give them fully equal status than Play Store (I think they promised this for Android 13, not sure what the state is.)
The API seems to have been added in Android 12 actually [1], but I'm not sure if app stores use it already.
[1]: https://developer.android.com/reference/android/content/pm/P...
It's been a long time since I last looked at this, but not even Google Play installed apps silently.
IIRC, what Google Play did was to tell the Google Play servers that you wanted to install the app, and the Google Play servers sent a message through C2DM/GCM to a system service on your phone, which downloaded and installed the app. The same thing happened if you opened the Google Play site on your desktop browser, and told it to install an app on your phone.
Obviously, a third party store cannot tell the Google Play server to send that "install this APK" message to your phone; and even if they could, it would have to be one of the APKs available for download on the Google Play servers.
The whole mechanism you describe is unrelated to the issue of installing user apps without confirmation for alternative stores.
Somehow the infrastructure and content must get paid for, or it will deteriorate and go away. If not via ads, what's a better plan?
Wouldn't it be better to see MORE relevant, more valuable, and overall fewer ads?
As for content monetization, I host my own site without ads, solely to spread my own views. I take enjoyment in that.
I watch YouTube with uBlock Origin on my laptop, and NewPipe on my phone. If I were forced to watch ads, I'd stop watching. And I wouldn't pay for YouTube, because I believe it is much larger than its competition, and don't want to contribute to a monopoly.
I pay for Nebula, and when the creator also posts there, that is where I watch their videos.
I'd rather pay cash money for the app that is being advertised, than pay-per-view for ads promoting a free app I'll never download, which itself is funded by more adverts.
"I'd rather pay cash money for the app that is being advertised" Me too! But I think we're in the minority. When I ask most people about whether they'd pay for content to avoid ads, they say "no, why would I pay when it's free?"
"than pay-per-view for ads..." - Actually I'd LOVE to have literal pay-per-view for content. Can I pay 1 cent or 5 cents or whatever to read that article without any ads or trackers and such? I think that would be a great experience - but again, I think I'm alone on that.
I think the ads are encrypted end-to-end from amazon-ad server to stick, using likely the same channels as the regular video content
I don't think they even need to encrypt them. IIRC pihole is just a DNS blocker essentially. All they have to do is serve them up from the same domain and you can't separate the wheat from the chaff any longer with this method.
Is this is surprise? I understand why people don’t like this but anyone think they made a new rule and weren’t going to enforce it?
Same for DNS66:
>The app establishes a VPN service, with routes for all DNS servers diverted to it. The VPN service then intercepts the packages for the servers and forwards any DNS queries that are not blacklisted.
>Custom upstream DNS can be configured. If the feature is turned off, the current connection's DNS servers are used. The app ships are pre-defined list of well known (mostly German) non-logging servers courtesy of the Chaos Computer Club.
https://github.com/julian-klode/dns66#user-content-how-it-wo...
Adblockers use this API to block connections, redirect DNS traffic, or possibly even rewrite content for DNS lookups. There is no system wide content blocker and even if there was, there is no way to enforce applications to use a content-blockable network API.
Google cracks down on VPN based adblockers - https://news.ycombinator.com/item?id=32636412 - Aug 2022 (596 comments)
Note that the VPN API is just the API of choice to be allowed to mess with network packets. There's no firewall API or network level driver that can do so in any other capacity. In almost all cases, there is no cloud server. Blokada uses some kind of cloud server, probably as a way to bypass Google's restrictions, but other apps work fine without it.
Some blocking apps work with custom, usually locally-generated, CA certificates to intercept HTTPS traffic. They're very spotty at best and very uncommon in my experience. Since Android 7, apps need to manually opt in to using user certificates from the CA store and most of them don't; in fact, most of them seem to be moving towards certificate pinning, meaning that even system-trusted CA certificates (which you will need root access for to inject them yourself) don't pass the validation step. Such a VPN filter would throw TLS errors across all major applications and services, leaving only the browser and the very few apps that opted into user certificates working. Not a great user experience to say the least.
I would change browsers if so. Ads trigger me. The change would suck since I have developed/use my own Chrome Extensions.
I assume no by VPN vs. extension.
Use Aurora Store for those few irreplaceable proprietary apps, or apps you previously purchased that are linked to your Play account.
As others have mentioned, Aurora Droid and Aurora Store are helpful alternatives to the Google app store.
RedReader (for Reddit)
AntennaePod (podcasts)
NewPipe (YouTube)
Wikipedia's official app
Voice (audiobook player)
Book Reader
RSS Reader
Twire (Twitch)
Easy XKCD
Ning (network scanner)
Some of these are available from the Play store as well of course, but not all. For random utilities where I want something lightweight that does a basic task it's the first place I go. Ironically it's some of these fdroid apps that are what keep me on Android. I'd love to be rid of Google, but would really miss AntennaePod and NewPipe.
- OsmAnd - offline version of Google Maps
- FreeOTP+ - FOSS 2FA app
- NewPipe and/or SkyTube - Youtube app alternatives. They break every so often when Google changes something, but when they work, the experience is much better than the stock YouTube app
- Simple Gallery Pro - view/manage photos
- OpenTracks - track running/biking/etc.
- MuPDF viewer - view PDFs
- FairEmail - privacy-first email client
- NetGuard - Application-level firewall (can block outgoing network requests)
- Forkyz - downloads and lets you solve daily crossword puzzles
- Gadgetbridge - app to connect/manage wearables
- Aurora Store - replacement for Google App Store
- Barinsta - Instagram client
- Fennec F-Droid - Firefox for Android
- Silence - Text message app
- VLC
Was Vanced Manager actual malware?
I suppose it makes sense in a way; Vanced replaced an existing system package with a modified APK through root access. Google's intent was obviously not to protect the user, but the behaviour of the app was sketchy as hell. Especially for a closed source app.
ReVanced does this differently, that modifies the Youtube APK and changes the package name so it doesn't conflict.
Regardless, the notification could just be dismissed and the AV is entirely optional. The warning ("this app tries to bypass Android's security protections") is entirely justified because that's exactly what the app was doing. Anyone pirating anything knows to disable their AV at their own peril and this is hardly something new, at least this time the app wasn't flagged as a trojan with a fake name like most cracks and key generators are.
Lastly, there are tons of people reporting weird behaviour after installing a modified version of Vanced blaming it on the app itself, so the warning wasn't always disingenuous.
https://f-droid.org/en/2022/09/30/free-software-and-inspecti...