This is something that has always sketched me out about the Android rooting and moding scene. "Download this suspect binary from rapid share and run it as root" seemed to be a cornerstone of it.
This is something that has always sketched me out about the Android rooting and moding scene. "Download this suspect binary from rapid share and run it as root" seemed to be a cornerstone of it.
I honestly don't understand why more people don't create Github accounts and use that to distribute, or at least use their ISP's free web space. Most of these tools have names, are well-known, and are the top hit on Google, but none of them have an actual website that you can go to to see if they've released new versions, something for other games, etc.
It's all very sketch.
The (pseudo)anonymous aspect of not having a fixed identity which could easily be linked to something else is both convenient and valuable to privacy?
Dwarf fortress stuff is like that, Minecraft is even worse, you get adfly in the middle :D
dffd exists for things that aren't github(etc)-appropriate such as tools. No real reason to use anything else unless you're trying to monetise it with adf.ly etc (which might also count as a reason not to download).
To me it seems very simple: level of effort. Uploading your hack/mod/whatever to rapidshare takes about one minute, or less. On the other hand, if you want to learn about git and github, you have to spend plenty of time on that.
Zero knowledge of git was necessary. Oh and also if you want to edit that README.md? You can do it from inside Github too, still zero need to know git.
(Plus I suspect that if a lot of people started hosting multi-megabyte binaries on github, their policies would change pretty quickly)
But yes, the most simplest site is the best for the most simplest people. However we're talking about people who spent a lot of time into creating their mod/whatever here. They can spend a minute or two more to figure out distribution.
There's a huge amount of "pirated" software/porn shared on many of those platforms for that reason.
The warez/cracks scene was essentially the same thing, and yet if you knew where you were getting things from, it was quite safe. The antipiracy groups have since been spreading plenty of FUD (and some possibly attaching malware to releases, I don't know) and working with the AV/security industry to make you believe otherwise, however.
Just as a warez/cracks group would be called out for it and very publicly shamed if they put malware in their releases, the same would happen in the Android scene. It's true that there are many rather clueless users (known as "leechers" in the vernacular), but there are also many knowledgeable ones and all it takes is one to give sufficient evidence of malice to trigger the "immune reaction".
And there are so many places for things to wrong. Any one of the following could be malicious, incompetent, or compromised:
* The ROM's maintainer. There are many groups here, for example many ROMs are based on ParanoidAndroid, which is based on Cyanogenmod, which is based on AOSP.
* The device maintainer. Typically each brand/model device has its own volunteers to maintain any proprietary blobs or special upgrade process
* The hackers who provide special binaries that root each device, unlock the bootloader, etc.
* The added packages you typically get separately from the ROM, for example Google Apps.
* The build machine, typically just some random box donated semi-anonymously by someone
* The web hosting (without TLS, of course) provided by some other random person.
I love Android. I compile and run my own ROM. But the current scene scares the shit out of me.
How much would it cost to buy off, for example, the entire radio hardware/firmware team at a manufacturer in your own country (meaning pretty much either China or South Korea), and on a governmental scale how reasonable or unreasonable is that number?
Isn't this racketeering?
Furthermore, AV programs which classify keygens, etc. in similar categories as keyloggers/ adware, etc. (such as Microsoft Security Essentials) also have a net effect of increasing malware prevalence by training users to ignore AV warnings.
The fact that antipiracy and AV groups have an interest in getting you scared does not mean that there's no reason to be scared of running random binaries you found on the net.
And most people do not feed directly off the warez/cracks hubs - they feed of whatever they can find. Which means a lot of opportunity for bad actors.
I'm not an Android user myself, but I will nevertheless suggest that optimally these things would be distributed as source on GitHub, with a deterministic build system guaranteed to be able to reproduce binaries in the future, and only secondarily as binaries.
Android has "regular old joe sixpack" users by the millions, but has the Android community actually benefited from that? The existing "desktop linux" community has their act together far more than the Android community, despite (or because of?) not having those legions of unskilled users.
Hardware support in official ROMs from phone manufactures is good of course, but what is freely available to the Android community is much worse. It turns out joe-sixpack doesn't really give any shits about hardware support being open-sourced.
It's nice that Google has given back some stuff, but that's peanuts compared with what the "year of the linux desktop" meme promises.