If Linux on the desktop were to get popular, I'd hate to imagine what might happen to the open source Fedora and Debian/Ubuntu repositories.
If Linux on the desktop were to get popular, I'd hate to imagine what might happen to the open source Fedora and Debian/Ubuntu repositories.
Nothing. In case you haven't been paying attention, Debian repositories were "app stores" before there were app stores. The software goes through extensive vetting and rigorous testing; no, I'm not saying every line of code is inspected, but to claim that a Debian maintainer would just blithely let crapware in is ignorant.
As for the walled gardens of Google and Apple, people are objecting to precisely that: the locked in, tinker-hostile way that the platform (not the app store) is managed. It's great that Google and Apple have finally seen the light and started curating software and making it easy to install, like it's been in Debian for nearly two decades. What's not great is telling people what they are and are not allowed to do with their property by anti-competitively denying the right the to install third party apps.
...through extensive vetting and rigorous testing...
I wanted to upvote your comment, but then I almost died laughing when I read that. Most Linux distributions are better about it now than they were many years ago, but I still remember being absolutely floored when RedHat had packaged a Perl module with a syntax error some years ago.Same goes for Debian; some of the more "fringe packages" (those of upstream projects that haven't been updated in a while) tended to rot (compilation option changes to dependencies that silently broke parts of the program), and packages from upstream projects that changed rapidly tended to have dependency issues.
I'd also like to point out that while Debian may have had "app stores" before anyone else so to speak. The implementation left much to be desired compared to today.
Today a user simply selects an application and it gets installed. There's no prompts about whether I want the 37 additional dependencies, no text-based prompts about the configuration of some obscure package, and certainly the presentation was sorely lacking.
So yes, Debian may have had the concept early on, but as usual, Apple made something only a geek could love into something usable by everyone.
But in the past, even the packages in the "first tier" were often pretty busted. But even for that tier, Linux distributions are not performing "extensive vetting and rigorous testing". They don't generally test beyond relying that other components that use it work as expected, and for many components, those are only as well tested as the tests that are included with the component.
Yes, some distributions do run security analysis tools or other things on the components they integrate, but that still doesn't count as "extensive vetting and rigorous testing".
Debian has the unstable, testing and stable distros, that move on different speeds and are subject to different amounts of testing.
I had hoped the addition of "not every line of code" would have made clear that I make no claim that every package in Debian is bug free. But I still insist, Debian extensively tests packages, mostly for compatibility and dependencies, not to mention bug squashing parties. They are also very careful about what's allowed in (due to being license sticklers).
Of course, all of this strays from my main point: the Debian maintainers are highly unlikely to let in crapware, as opposed to some stores that have had viruses. And that's just the stuff they (eventually) got rid of; don't start me on all the officially approved software that tracks users.
As for your opinion of the ease of use, well, you're entitled to it but it doesn't make it true. What's so hard about using apt-get or, if you can't use a keyboard, one of the graphical managers? So it asks you if you really want to install dependencies instead of just filling up your hard drive, and that's a bad thing? Does the Apple or Google way of "managing" packages even track dependencies, or are they still forcing every vender to include their own (possibly filled with security holes) copy of a library with their apps? I haven't had to answer a configuration question for years, and I've never had a dependency issue with Debian. I say this as a daily user of, developer on, and administrator of machines running Debian for the past twelve years.
You would get plenty of shady sites encouraging you to add another line to /etc/apt/sources.list for cool free screensavers, but it would be a lot more practical than it is in windows to tell people to ignore them and never install anything that doesn't come with the system.
That way you are not tied to one gatekeeper but it is in your interest to get your app into at least one good repo that has a reputation to uphold.
There are a ton of good people who work to keep those repos clean. Lets not trivialize their contribution by acting like anyone and their mother can make changes to the repo for a popular distro. Sure, a black[/grey] hat can make their own repository, but who in their right mind will use it?
AFAIK, 0 QC or checking is done on the contents of a repo. additionally, there have been enough times in the past where someone has just straight up rooted the servers that the repo lives on ...
Are you talking about debian/fedora repos? Because if so, that is simply false. Both have heavy QC, and the packages are all signed by the developers keys, and the OS checks those keys.
What on earth are you talking about? Linux on the desktop is just above line noise. If hackers don't bother targeting Mac's ~10% desktop share, why would they bother targeting Linux' ~1%?
It's not third-party ads, it's first-party ads, which is slightly better.
Like OP, I have a lot of sympathy for software developers trying to sell in a world full of people who don't think they should pay any dollars for software. They are still gonna pay, just in terms of their privacy and computer security.
Ad Network Detector
Addons Detector
AirPush Detector
However, it's still preferrable to Apple's draconian policies.
If you want, you can install security tools which scan apps prior to being installed, like Lookout, which will alert you to various issues.
Yes there's a lot of spammy apps, but if you're even halfway aware of what you're doing, you'll have to be very unlucky to be caught out by one.
You must've forgotten Path fiasco, with its quiet uploading of user's full address book to company's servers, which turned out to be - SUR-PRI-SE - a "standard industry practice". Wall garden sanctuary my ass. Same rotten ethics, except far less visible.
This is definitely not true. The following scenario seems to be quite possible: Due to the various problems of Windows 8, developers massively revolt and most applications are either written to older API's, or use cross-platform environments like C#, Python or Java. This essentially changes the Windows API from a moving target to a stationary target; as a result, Wine catches up -- it reaches near-100% app compatibility, perhaps with the aid of a donation from a philanthropist, Google, or some other player. OEM's recognize the cost savings possible from avoiding the Microsoft tax, and with good software compatibility now possible, they start selling discount models with Linux instead. Microsoft stops issuing new licenses for Windows less than 8 to try to pressure developers to port their stuff to Windows 8 by forcing customers to upgrade. But the move is too little, too late: The customers revolt, and since the alternative is already out of the bottle, people jump ship en masse due to lower prices and Windows 8's shortcomings.
Is this a particularly likely scenario? No. But it seems plausible, and it's not due to crapware, or consumer awareness about anything other than price tags.
A risk might be drive-by malware that adds stuff to /etc/apt/sources.list though, however to do this you would need drive-by malware that can bust into the root account, or to get the user to enter the admin password.