VideoLAN unable to update VLC on Android
twitter.com
twitter.com
> If you wonder why we can’t update the VLC on Android version, it’s because Google refuses to let us update:
> - either we give them our private signing keys,
> - or we drop support for Android TV before API-30, and all our users on TV API<30 can’t get fixes.
I still don't understand the "or".
But there are nightlies on VLC's site itself: https://nightlies.videolan.org/
It's not a feature that you enable with a button and it's good to go. It's basically giving up control of your own app, even for people getting this app from non-Google app stores.
You need to give your signing key to Google and accept that Google employees (or any government asking Google nicely) can release updates to your own apps without going through you, and the user phones will accept those updates as being from the original developer because the signatures match.
With an update installed with matching signatures, the system doesn't wipe existing data from the storage and the fake update can read all of it. As a user of VLC I would not want them to use app signing keys that Google has access to.
And when you load the shim, it redownload the app to be used again. The only way to achieve that currently is to "upgrade" or replace the app by a shim with the same digital signature, on the system will block it.
For instance, the OS could have a carve out for these shims that allows a Google-signed app to overwrite an app, but without access to its local data. Then that overriding app could delete itself when the original is re-downloaded.
Using a shim application is a giant hack, allowing to implement this feature by updating only the Google Playstore without modifying the base OS and how it handles application installation and managing process. This is only relevant only because most android phone manufacturers are bad at providing Android updates. Some Google engineer probably felt very clever, that he came up a with a trick which in theory allows adding this feature to older phones that probably won't receive any Android system updates.
Google could have also allowed application developer to sign the shim. That way getting the benefits of archiving feature on older phones, without forcing app developer to give up the key.
They don't need to do any of this to keep your local data without keeping the entire app. Android phones have had the ability to uninstall apps without removing their data for some time. Any time you can install the application again and if the keys match, it has access to its data.
But that wouldn't create a good excuse for Google to ask for private keys from developers.