| ▲ | jjice 5 hours ago |
| What does the future of something like F-Droid look like once Google does their lock down next year? |
|
| ▲ | pritambaral 4 hours ago | parent | next [-] |
| Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question. |
| |
| ▲ | trinsic2 4 hours ago | parent | next [-] | | It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model? | | |
| ▲ | McDyver 3 hours ago | parent | next [-] | | > sideloading That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised | | |
| ▲ | folkrav 3 hours ago | parent | next [-] | | Fully agree. Installing software is installing software, signed or unsigned, app store or not. | |
| ▲ | ragequittah 3 hours ago | parent | prev [-] | | Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people. Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it. | | |
| ▲ | OroPla 2 hours ago | parent | next [-] | | > a device that holds your entire life, bank info, photos, etc. I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc. | |
| ▲ | krzyk 2 hours ago | parent | prev | next [-] | | That means education for people: don't perform actions that are in emails. Blocking apps is like blocking buying of knifes because one can hurt themselves. | | |
| ▲ | halostatue 2 hours ago | parent [-] | | Because education has worked so well on Windows. There's not an easy answer, but the non-answer of "people just need to be educated" is trivially dismissed. | | |
| ▲ | Aachen 2 hours ago | parent [-] | | I'm not sure the situations are comparable when Windows doesn't have this permission system where the apps are still very limited in what they can access unless you grant specific directory access or access to the contact list or such |
|
| |
| ▲ | g-b-r 3 hours ago | parent | prev | next [-] | | > a device that holds your entire life, bank info, photos, etc That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it. | | |
| ▲ | JumpCrisscross an hour ago | parent | next [-] | | > That device was called personal computer To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking. | | |
| ▲ | g-b-r 37 minutes ago | parent [-] | | Web banking was offered by all banks long before banking apps, and you could of course access it from smartphones The move to apps made things more difficult, if anything |
| |
| ▲ | charcircuit 2 hours ago | parent | prev [-] | | The world may not of ended but to of people have been hurt by malware ruining their computer, cryptolocking all of their company's files for ransom, stealing all of your login credentials, stealing cryptocurrency, taking secret photos with your webcam, screen recording what you are doing on your computer, etc. The "personal computer" has a terrible track record. | | |
| ▲ | krzyk 2 hours ago | parent | next [-] | | Just like people get robbed, it is as common as that. It doesn't mean one can't buy nice things because one is afraid of being robbed. | | |
| ▲ | charcircuit 2 hours ago | parent [-] | | Except a sane society puts rules in place against robbers and then bans such people from society. | | |
| ▲ | Vrondi an hour ago | parent [-] | | There have already been laws against scammers and hackers for a long time. |
|
| |
| ▲ | Vrondi an hour ago | parent | prev | next [-] | | For many decades, people have been mistakenly putting diesel fuel into their gasoline cars, yet we never outlawed diesel vehicles. You can only do so much to protect people without destroying their rights to their property. | |
| ▲ | g-b-r 2 hours ago | parent | prev [-] | | That seems to happen on phones too | | |
| ▲ | charcircuit 2 hours ago | parent [-] | | It is much rarer since it needs 0 day to do these at the same level as possible on a pc. The play store scanning apps for malware is an important safety mechanism against this. Further more imposter apps like YouTube but with no ads that are Trojans that steal people's accounts. | | |
| ▲ | g-b-r 25 minutes ago | parent [-] | | Or the accessibility permission, or to some degree the access all files ones; but it's also enough for the app to pilfer the data you trust it with. The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs. Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google |
|
|
|
| |
| ▲ | catlikesshrimp 3 hours ago | parent | prev [-] | | Block installs outside of playstore ON/OFF (ON by default) isn't any less secure. "Sideloading" is scaremongering. |
|
| |
| ▲ | wongarsu 4 hours ago | parent | prev [-] | | If the issue Google has with sideloading is really just the rampant app piracy (and the malware that comes with cracked apps) that might be something F-Droid can accomodate. | | |
| ▲ | OroPla 2 hours ago | parent | next [-] | | I don't think malware is the problem, as most malware comes directly via Google's ecosystem carried by ads. Just recently I had to uninstall some app from the play store since it tried to distribute malware through scary pop-ups and had it replaced with something from f-droid for someone I know. | | |
| ▲ | autoexec 2 hours ago | parent [-] | | > most malware comes directly via Google's ecosystem carried by ads. Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google. |
| |
| ▲ | inquirerGeneral 3 hours ago | parent | prev [-] | | [dead] |
|
| |
| ▲ | rom1v 3 hours ago | parent | prev [-] | | They have to use one key per app, otherwise independent app could end up sharing some permissions (IIRC). | | |
| ▲ | aquariusDue 3 hours ago | parent [-] | | The Emacs version for Android makes uses of something like this IIRC by signing a version of Termux with the same key and distributing it in the same SourceForge repo such that Emacs on Android can access CLI tooling like git for example. |
|
|
|
| ▲ | creatonez 3 hours ago | parent | prev | next [-] |
| It seems google is going to allow an "advanced flow" that is scam resistant by requiring the user to wait 24 hours before they can start installing their own apps. It sucks, but assuming they don't change the plan again, F-Droid should be able to continue working. |
| |
| ▲ | reddalo an hour ago | parent [-] | | > assuming they don't change the plan again Knowing Google, that's a big assumption |
|
|
| ▲ | rdsubhas 3 hours ago | parent | prev | next [-] |
| Alternative app stores are mandated atleast here in the EU I believe? |
| |
| ▲ | someonebaggy 2 hours ago | parent | next [-] | | Yes but the process to enforce it is intentionally so difficult that nobody can do it. | |
| ▲ | Elfener an hour ago | parent | prev [-] | | Yes, but the ability to install any software isn't. goggle can still decide to allow only "official" apps in """3rd party""" stores. |
|
|
| ▲ | someonebaggy 2 hours ago | parent | prev | next [-] |
| The current lockdown plan is that you'll need to wait 24 hours before installing the first unauthorized app, right? So probably exactly the same as it is now except setting up a phone will take 24 hours longer. |
|
| ▲ | rurban 4 hours ago | parent | prev | next [-] |
| Switch to GrapheneOS or HarmonyOS |
| |
| ▲ | tazjin 3 hours ago | parent [-] | | Currently, switching to GrapheneOS means giving Google money. Next year's Motorola-based alternative is also likely going to be several price classes above the Pixels you can currently put GrapheneOS on. | | |
| ▲ | microtonal 3 hours ago | parent | next [-] | | Then buy a Pixel second-hand or when they hit rock-bottom prices, which usually happens after 6 months or so. At some point Google is probably not making a lot of profit from the devices anymore and they want to sell it to you for tracking and to sell Google One subscriptions, which are mostly irrelevant if you use GrapheneOS. | | |
| ▲ | OroPla 2 hours ago | parent | next [-] | | I don't want to pay more than $150 for a phone, though. And installing an alternate OS is a real hassle. | | |
| ▲ | someonebaggy 2 hours ago | parent | next [-] | | If the current $500 pixels are too expensive you're going to hate the $1000 motorolas. | |
| ▲ | ghetsisharmonia 2 hours ago | parent | prev [-] | | Not really, GrapheneOS has a nice web installer that makes all the job for the user. |
| |
| ▲ | g-b-r 2 hours ago | parent | prev [-] | | I followed Pixel prices for the last year, and rock-bottom for a 256gb version (the current absolute minimum for a device without an sd, to my eyes) meant 450€. There are occasional good deals for (unused) older models on eBay, but they're surprisingly rare. I wonder if Google demands stores to give the old models back, after the release of newer ones; they disappear from every store extremely quickly. |
| |
| ▲ | flexagoon an hour ago | parent | prev [-] | | There's zero reason to buy a last year phone. |
|
|
|
| ▲ | drnick1 2 hours ago | parent | prev | next [-] |
| There is an entire world of Android phones not controlled by Google, including GrapheneOS, LineageOS, and countless variations in China and other places where Google is effectively banned. |
|
| ▲ | burningChrome 3 hours ago | parent | prev | next [-] |
| Updates on this have been slowly trickling out and the best I can discern is you will be able to still install apps from stores like F-Droid, but you have to go through a manual "advanced flow" which will most likely make you wait 24 hours before installing it and make you go through other hoops. In short, google has referred to this as "increased user friction" to try and deter people from doing this. Essentially not making it impossible; just really frustrating for users so they get sick of the process and just install verified apps through them. The only way I know around this is to install a custom rom like GrapheneOS or Lineage OS since this change targets Because the policy targets the Google Mobile Services (GMS) framework rather than the foundational Android Open Source Project (AOSP). |
| |
| ▲ | iamjackg 3 hours ago | parent | next [-] | | Wait, it's not 24 hours per app though, is it? Isn't it 24 hours before the "allow installing apps from .apks" setting turns on once and for all? | |
| ▲ | krzyk 2 hours ago | parent | prev [-] | | If I'm a developer I also need to wait 24hrs to test my app? |
|
|
| ▲ | OutOfHere 4 hours ago | parent | prev [-] |
| Isn't it possible, however complicated, for users to undo the lockdown to install an app? The required 9 steps are noted at https://keepandroidopen.org/ for devices that use Google Play Services. Irrespective, people should probably be migrating to a GrapheneOS or similar OS asap once the OS ships with a device. |
| |
| ▲ | jjice 4 hours ago | parent | next [-] | | Ah this is good to know. Awful it's required, but glad there is a work around. | |
| ▲ | autoexec 2 hours ago | parent | prev | next [-] | | Honestly not as bad as I feared it would be. Still not great and it's moving us farther from the idea that people who paid for the device should be allowed to install what they want on it, but as it stands it's a workable process. We'll see how quickly it takes Google to make it worse | |
| ▲ | Brian_K_White 3 hours ago | parent | prev [-] | | no root on graphene, non starter |
|