Hacker News new | ask | show | jobs
by fsflover 82 days ago
Are Debian repos a viable grift target?
2 comments

They absolutely are and that's why they're tightly curated by maintainers.
Exactly like... you guessed it... F-Droid. Not Google Play.
FDroid has 0.2% of app volume of Play Store.

Don't mistake obscurity for security. FDroid isn't the size to even be noticed by problems that Play Store and AppStore are dealing with.

F-Droid at least does a quick review to make sure there's nothing malicious in the app before adding it. Since we know Google does something similar and there is still malware on the Play Store one might reasonably conclude that Google doesn't actually care about malware.

Now, it might be a problem of vetting at scale or malware being really subtle, but if that's the case Google should focus on improving their process before locking down Android for "security".

This is exactly why I gave the example of Debian repos.
Which again work on a model of a single entity having all the curation power.
My point is that Google does not want to protect users by restricting "side loading". If they actually wanted that, they would remove all the malware in their store. They are just building higher walls in the walled garden to lock you in.
Right, but the Debian Developers don't prevent you from installing (installing, not "sideloading") other programs. If you want to install malware you're free to, but they don't distribute it.
What does that have to do with Android and iOS?
Free software protects from malware, not walled gardens.
If you don't want Play Store, don't use it?
"Google is slowly removing such option "for your safety", and "hackers" on this website really believe them.
You can still install any ROM you want. Not having Play Store has some downsides, but those trades offs should be familiar to a free software enthusiast.
You can only do this on a tiny number of devices supporting free drivers (and mainline kernel), otherwise you are tied to an ancient Linux kernel. I'm using Librem 5 btw and don't believe that Android, whose development completely depends on Google, is a viable long-term solution.