▲ 585 ▼ Nextcloud cries foul over Google Play Store app rejection (www.theregister.com) submitted 1 year ago by GertrudGoethe@feddit.org to c/technology@lemmy.world 80 comments fedilink hide all child comments
[–] sommerset 3 points 1 year ago (4 children) What is the point of obtainium ? Over fdroid? permalink fedilink source parent hideshow 4 child comments replies: [–] Wispy2891@lemmy.world 6 points 1 year ago (3 children) You get apps a couple days earlier But it comes with a huge downside: if dev goes rogue or gets hacked, you could install a malicious version of the app that doesn't match the source permalink fedilink source parent hideshow 3 child comments replies: [–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago (2 children) "If dev goes rougue" Isnt that a risk for all app stores? permalink fedilink source parent hideshow 2 child comments replies: [–] Wispy2891@lemmy.world 1 point 1 year ago (1 child) For fdroid the app is compiled on fdroid servers when dev tags a new release on GitHub. So the app matches the source, it's not possible to put a tainted APK to download Now, if the malicious code is slowly added to the source over the course of an year like it happened with the xz utils, this won't change the result, but it's easier to do so with a compiled binary. Release clean source and infected binary, it will take a longer time to get caught For the closed source app stores, on iOS there's the manual inspection (which is not infallible especially if they timebomb or geofence the bad feature) and for Google there's the automated inspection (which fails often seeing the news) that should find problems permalink fedilink source parent hideshow 1 child comment replies: [–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago What if fdroid goes rogue or gets hacked? I'm an fdroid user, but i often wonder if it is safer than google play store Likelihood of google getting hacked/rogue is much lower than a small, community run volunteer project permalink fedilink source parent
[–] Wispy2891@lemmy.world 6 points 1 year ago (3 children) You get apps a couple days earlier But it comes with a huge downside: if dev goes rogue or gets hacked, you could install a malicious version of the app that doesn't match the source permalink fedilink source parent hideshow 3 child comments replies: [–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago (2 children) "If dev goes rougue" Isnt that a risk for all app stores? permalink fedilink source parent hideshow 2 child comments replies: [–] Wispy2891@lemmy.world 1 point 1 year ago (1 child) For fdroid the app is compiled on fdroid servers when dev tags a new release on GitHub. So the app matches the source, it's not possible to put a tainted APK to download Now, if the malicious code is slowly added to the source over the course of an year like it happened with the xz utils, this won't change the result, but it's easier to do so with a compiled binary. Release clean source and infected binary, it will take a longer time to get caught For the closed source app stores, on iOS there's the manual inspection (which is not infallible especially if they timebomb or geofence the bad feature) and for Google there's the automated inspection (which fails often seeing the news) that should find problems permalink fedilink source parent hideshow 1 child comment replies: [–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago What if fdroid goes rogue or gets hacked? I'm an fdroid user, but i often wonder if it is safer than google play store Likelihood of google getting hacked/rogue is much lower than a small, community run volunteer project permalink fedilink source parent
[–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago (2 children) "If dev goes rougue" Isnt that a risk for all app stores? permalink fedilink source parent hideshow 2 child comments replies: [–] Wispy2891@lemmy.world 1 point 1 year ago (1 child) For fdroid the app is compiled on fdroid servers when dev tags a new release on GitHub. So the app matches the source, it's not possible to put a tainted APK to download Now, if the malicious code is slowly added to the source over the course of an year like it happened with the xz utils, this won't change the result, but it's easier to do so with a compiled binary. Release clean source and infected binary, it will take a longer time to get caught For the closed source app stores, on iOS there's the manual inspection (which is not infallible especially if they timebomb or geofence the bad feature) and for Google there's the automated inspection (which fails often seeing the news) that should find problems permalink fedilink source parent hideshow 1 child comment replies: [–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago What if fdroid goes rogue or gets hacked? I'm an fdroid user, but i often wonder if it is safer than google play store Likelihood of google getting hacked/rogue is much lower than a small, community run volunteer project permalink fedilink source parent
[–] Wispy2891@lemmy.world 1 point 1 year ago (1 child) For fdroid the app is compiled on fdroid servers when dev tags a new release on GitHub. So the app matches the source, it's not possible to put a tainted APK to download Now, if the malicious code is slowly added to the source over the course of an year like it happened with the xz utils, this won't change the result, but it's easier to do so with a compiled binary. Release clean source and infected binary, it will take a longer time to get caught For the closed source app stores, on iOS there's the manual inspection (which is not infallible especially if they timebomb or geofence the bad feature) and for Google there's the automated inspection (which fails often seeing the news) that should find problems permalink fedilink source parent hideshow 1 child comment replies: [–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago What if fdroid goes rogue or gets hacked? I'm an fdroid user, but i often wonder if it is safer than google play store Likelihood of google getting hacked/rogue is much lower than a small, community run volunteer project permalink fedilink source parent
[–] 9488fcea02a9@sh.itjust.works 1 point 1 year ago What if fdroid goes rogue or gets hacked? I'm an fdroid user, but i often wonder if it is safer than google play store Likelihood of google getting hacked/rogue is much lower than a small, community run volunteer project permalink fedilink source parent