1. You have an app you want to use.
2. That app isn't on the google app store or you don't want to/can't use google services.
3. The app is not open source so it can only be built and packaged by the first party.
4. You don't want to manually update the app by downloading a new APK every time.
5. You don't want to give a black-box closed-source app you downloaded from the internet permissions to install new apps (and therefore grant them certain new permissions as well).
My example of this is WhatsApp. I hate the app. I think it's scummy as shit. However if I want the version of WhatsApp that doesn't package google services, I either have to download a 3rd party app store, update the app from their web page manually, or grant the app permission to update itself. I obviously don't want to install a (often closed source) 3rd party app store just to install this app without granting it keys to the castle. So instead as I already use F-Droid, I can install the FOSS build of Obtanium and pin my trust on F-Droid. Then I use Obtanium to manage my WhatsApp updates.
Technically this also extends to open source apps where you trust the first party enough to use the app but not enough to let it update itself and where you want to be able to just download updates from github releases.
You don't see the difference between allowing a dedicated app installer app written by an author with no other goal and no other source of reputation to install apps, vs allowing a random app to install apps just to hopefully only use that power to keep itself updated and do so in a way that only serves your interests and not those of the apps author? (ie it will never be a Facebook and one day decide that it wants you to use Messenger, and that's the nicest example let alone something hidden)
The thing that you give permission to install apps must be a seperate thing written by a seperate author who has no incentive to install or remove any other apps.
In these cases, the middlemen like Google are the hostile party. Essentially the threat actor. It is natural: big tech is big tech, because they are very good at limiting user choice.
For these applications, Obtainium is brilliant.
It also shows that the store model that everyone is working to enshrine in digital policy is not the necessity that Big Tech would have everyone believe.
The latest victim of this travesty is the removal of syncthing from the play store and the subsequent discontinuation of the app. This was ostensibly due to syncthing's failure to leverage the storage access framework to access files on Android devices. In reality, developers were benchmarking the storage access framework as somewhere around 50 times slower than direct system access, and that made it infeasible for usage in apps like Syncthing. That bug has been open for years, and the Android team has done nothing other than claim it's fixed when benchmarks show otherwise.
So I'm not sold at all on the value of these gatekeeping stores that have black box approval processes with changing rules. It is a system that is set up to be evil because it can reject and accept on a whim with no accountability. We should not so easily give up on installing the software of our choosing on the devices we purchase.
Anyhow, when the apps stop being updated, it's usually due to something that was added that doesn't make them compliant with F-Droid's policies anymore; or, they changed something in the release process without telling F-Droid.
Other times, the apps were set to be updated only at the developer's request, and for some reason they still haven't done that request (some developers deliberately update F-Droid less frequently, to be more confident of not giving bugged releases to the F-Droid usere).
The normal delay, due to their manual (and lazy) signing process, is from few days to about ten
This or some variation of the idea. The result is the same, what should protect the user becomes a vector to help spread malicious apps.
Strangely, almost everything the Play Store pushes at me (Temu, TikTok, millions of communication apps with dubious reputation) is crap.
I would never install an app without checking the permissions it asks for, researching the owner of the app as well as the the tracking it includes - yet the store never makes those things transparent, quite the opposite.
Google even takes money to show you bad apps through PlayStore app ads designed to look like an organic app listing. This is apparently a mechanism to profit directly from deceiving users. (Right now, for example, it shows a gambling app, some "beautifying" shovelware, and "Tango live streaming," which the author probably believes by heart is not made for porn.)
So either Google is trying to protect its users and just isn't very good at it, or it's a fake argument to hide corporate power.
But it's impossible to know for sure, isn't it?
That's what they say for their defense yeah but personally I don't buy it. I've published an app myself and I've also seen the countless app scams which are allowed to advertise on YouTube.
The value we get from the store is dubious.
- Make sure that they get their cut
- Shift the blame of the privacy issues to the app developers since the duopoly is very often targeted in the media on this subject.
Anything else has a lower priority.
I’m an iOS user but one of the reasons I like iOS is because I know that I’ll be able to Sign in with Apple, and pay via the App Store. I recently signed up to a service which charged me for a free trial and I opened a support ticket. They refunded me, and charged me again immediately.
I trust apple and google (rightly or wrongly) to have my back in that situation, but this dev clearly didn’t.
It resolved itself fairly quickly when I got my bank involved, but it took a month from start to finish. I have never, not once, had that issue with App Store managed purchases.
You can argue you're adding F-Droid to the entities you trust (unless it's a reproducible build), but at the same time you're relying a lot less on a random's developer honesty (and security)