OpenAPK – open-source Apps for Android, updated weekly
openapk.net
openapk.net
The only gripe I have is that screenshots on individual apps pages can sometimes be slow to download, but that gripe is so small I'm looking at it through a microscope. :)
I wish the updated/new section would filter "update spam" better, but right now it works for app discovery, without requiring f-droid to collect usage data. The search function sorting by "recently updated" also helped a lot in finding well supported apps.
There's a lot of room for improvement of the search function though.
OpenAPK here seems to be linking directly to official binary downloads, whereas F-Droid insists on building the APKs for the apps.
You could say that OpenAPK blindly redistributes whatever APK upstream is peddling whereas F-Droid builds from source. I see the merits of both systems but prefer reproducible builds so that we can have the best of both worlds
All of that said, not particularly speaking for OpenAPK here, given their motives seems rather unclear to me. If I am to be charitable, I guess they're just trying to provide a different platform than f-droid for discoverability, but for whatever reason they seem to be marketing the distribution-side of things more which is just odd to me, but alas.
There is a lot of extra work done behind the scenes to "thrive in spite of it". Windows Defender (built into Windows after XP) has to periodically download updated virus definitions and always scans programs for potential malware, and still can't catch them all.
F-Droid, however, allow the developer's binary to be reproduced if they have tested that the APK is reproducible when replacing the APK's signature with the original APK.
Reproducible builds would allow distributing Shizuku in F-Droid, that’s correct. (If Shizuku banned third party builds by the means of code license, it would not be FOSS and thus wouldn’t be eligible for inclusion in F-Droid altogether.)
With fdroid i trust 1 party, by downloading random binaries I have to trust hundreds.
https://github.com/signalapp/Signal-Android/blob/main/reprod...
Why? The official one can be backdoored and with a gag order you would never hear about it
Not trusting signal's build and then turning around and trusting some third party build seems strange. The official build probably has more eyes on it, and signal has more reputation to lose.
I'd start here if I were you: https://protonvpn.com/support/wireguard-configurations
This is the best of both worlds because the distributor (F-Droid) verifies that the published source matches the binary but does not possess the private key to sign the APK. This means the distributor cannot push a backdoored binary blob at some later date.
F-Droid guarantees that the binaries it distributes always match the corresponding source, which adds another layer of security.
To ensure transparency, it also provides an archive of the source code used to compile different versions.
I am impressed to see the F-Droid maintainers sticking to their principles.
> "Israel" is blocked
I guess, good on them for at least blocking the country outright and being honest about it, and not sneakily distributing malware like some very good people did to Russians back in 2022.
- The project's web page blocks users from Israel
- The project's developer delegitimizes Israel in response on HN
Surely we need more "context"
(1) I'm not sure to which organisation you were referring, but on its own I don't think a link contitutes endorsement, especially when the context is the open source project and not political in nature. It's worth noting that there are a lot of external links in the readme, none looked at the surface level to be linked because of any reference to BDS therewithin. That said, I don't think we should argue this further, it's already innapropriate to comment on political topics such as Israel and BDS here on HN.
(2) Again, the exact cause for this is not clear. There are possible explanations which suppose good faith, and others, bad faith.
(3) While personally I'd lean towards your interpretation (especially considering the use of quotation marks by the poster), it's still not explicit and could be a communication failure.
edit: removed a "but" from (3)
Literally the first link in the README.
website -> Incubator -> "list of projects we’d love to get started!":
> ### Built with Israel
> Many companies and NGOs unwittingly use tools created by Israel
> ### BDS in your bank account
> Build an app that can apply BDS to your bank account.
or
website -> Blog -> "T4P Incubator Alum Boycat Is Teaming Up With BDS"
If you can't figure out what the first website link is in the README that's on you. I'm not gonna promote that hateful organization's website.
For most app there is an Obtainium download badge of you want to follow the updates automatically.
It's great we are seeing more effort be put into open source android apps, but being forced to use restricted tooling to develop and build them leaves an extremely foul taste in my mouth.
Could be useful for a spare phone for secure but non critical work.
https://www.straitstimes.com/singapore/uob-dbs-introduce-new...
As for getting upset about sharing a phone with unapproved apps, I think this is a failure of sandboxing. The app should see as much of the phone as I want it to and no more.
These days banks have KYC and should know who finally gets the money. Even across borders except perhaps in North Korea etc. for those countries that don't co-operate entire SWIFT system must be blocked.
But for some reason they try other things, blame users but never claw back
From a security perspective it makes sense. If an app actively abuses such information it would be easy enough to hide it in a future build. The only way around that is an attestation scheme such as SafetyNet.
Is this like, to send money, zelle, CashApp sort of things you all keep talking about?
Can't you just use the browser on your phone to interact with the bank? The browser doesn't know its rooted, does it?
You could set a clock by the "but my banking apps" every time Firefox or F-Droid or Sideloading comes up.
I don't carry a wallet, my banking app supports NFC payments.
I'm pretty sure you can only be born once.
I guess it could be "Google Wallet, né Google Wallet, rené Google Pay".
Speak for yourself! Google's products are eternally trying to escape Samsara through a product cycle of death and (sometimes) rebirth.
It sends me notifications when money arrives or is spent. Scanning a QR code to pay for something is much less clunky than doing the same in a browser. And it integrates into my phone authentication system so I only need to scan my fingerprint to open the app instead of remembering a password and waiting for a one-time code.
What do I do on the app? I check the balance on my accounts, I move money between my accounts to get more interest, I pay for my kid's remedial classes, I pay my trainer, I scan QR codes to pay online when the shop provides this payment option so I don't have to type in my card details, I check my virtual card details when I do have to enter them, I buy and sell stocks.
All this is possible in browser nowadays. And scanning QR codes doesn’t have to be clunky – it’s just that developers are sloppy.
To each his own.
it's all so reminiscent of "you must use IE6 to access this site"
So the 3dparty component doing the "security" check for the banking apps is a little overzealous.