Remix.run Logo
ivl 8 hours ago

Your complaint about Android .apk install is... similar to unsigned software installs on Windows in some cases (not a great argument, I know, but the same as the vast majority of users would be used to).

As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.

microtonal 8 hours ago | parent | next [-]

For the former there is: https://github.com/privacyguides/verified-apps-android

Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money:

https://www.macrumors.com/2026/07/27/apple-app-store-fake-bi...

skobes 8 hours ago | parent | prev [-]

The main difference is that signing a Windows binary doesn't require any third party review of the app content.

lern_too_spel 8 hours ago | parent [-]

Signing an APK also doesn't require third party review of the app content.

skobes 7 hours ago | parent [-]

But the context of this discussion is the difficulty of installing an APK from outside the Play Store.

lern_too_spel 6 hours ago | parent [-]

This is the first time I've seen a complaint about giving permission to an app to install another app. The SmartTubeNext issue was due to the developer's keys being stolen. If you want to keep an app signed with stolen keys, you can disable Play Protect. If Play Protect uninstalled apps that Google disliked instead of apps with known vulnerabilities, people would mass disable Play Protect, which would defeat its purpose.