VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users... For now, iOS App Store still allows us to ship for iOS9, but until when?

you are viewing a single comment's thread
view the rest of the comments
[–] 45 points 2 years ago* (43 children)

What exactly is the issue preventing them from updating the Android version?

Also, if that's the case, it sounds like "App stores were a mistake" is a bit misleading, since the particular app store isnt the problem.

  • source
  • parent
  • hideshow 43 child comments
  • [–] 60 points 2 years ago (38 children)

    Basically, modern app stores have changed how they work and now require the signing keys, VLC feel this is a bad thing and refuse to update. Banks are okay with it, but VLC feel more strongly than banks.

  • source
  • parent
  • hideshow 38 child comments
  • [–] 93 points 2 years ago (32 children)

    Banks are okay with it, but VLC feel more strongly than banks.

    I mean banks are known for horrible security practices all around so that makes perfect sense.

  • source
  • parent
  • hideshow 32 child comments
  • [–] 3 points 2 years ago (31 children)
  • [–] 14 points 2 years ago (2 children)

    Darren Kitchen from Hak5 has an amusing story about a bank teller who assured him email was entirely fine to send sPII through. "No sir, you just need to send it to us, and once we have your information then it'll be secure." No encryption. So, yes.

    Also look into the Equifax security breach. Un-patched software for months.

    It makes almost no sense to have a password length limit. 1_000_000, that's One Million, characters is equal to 1MiB. That's twice the length of the Lord of the Rings Trilogy and much less than most modern webpages. After hashing, which is how passwords should be stored, text length is irrelevant. All hashed inputs come out the exact same length. 65 characters for SHA256.

    Very much known for their horrible security practices, yes. Absolutely.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 10 points 2 years ago* (1 child)

    Setting a max password length is sometimes done to prevent ddos attacks. Without it, attackers could just spam 1MB passwords constantly and force the login server to just spend all its cpu time hashing garbage.

    That being said, a password limit of under 20 characters probably just means they are just storing passwords in plaintext.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 2 years ago

    In Brazil, the govt owned lottery site, created around 2015, only accepts passwords with 6 numeric digits. Your password has to be a number between 000000 and 999999. Only somewhat recently (6 months ago or so) they've added a 2FA through an email link.

    Oh, said lottery is run by the biggest govt owned bank. Chances of people reusing their bank password there are very fucking high.

  • source
  • parent
  • [–] 13 points 2 years ago (22 children)

    Absolutely. They are entrenched in their regulations so much that it takes forever to change things.

    Years ago, I had an account at an american big4 bank with an 8 character password and was going through and making all my passwords unique. I was changing everything to random strings of 20-30 characters (this isnt the best practice, btw, but still better than 8chars), so when I get to this bank account it capped me at 15chars. I couldnt believe the forced low entropy they gave me for something as vital as a bank account.

    I asked them why, and basically they said their system would break with anything over 15chars.

  • source
  • parent
  • hideshow 22 child comments
  • [–] 1 point 2 years ago

    The equivalent of a 20-30 character random password with numbers and characters is a 7-11 word passphrase. Seeing how passphrase generators default to 4-5 words (equivalent to 11-14 characters) what you did isn't so bad

  • source
  • parent
  • [+] -24 points 2 years ago (18 children)
  • [–] 10 points 2 years ago (9 children)

    Show me a legitimate vendor that accepts Monero as payment.

  • source
  • parent
  • hideshow 9 child comments
  • [–] -4 points 2 years ago (8 children)
  • [–] 6 points 2 years ago (3 children)

    Alright, so monero is good for coffee, maple syrup, and meat bars (?!). I don't currently eat a lot of any of those things, so I'm not sure how this will help me with my groceries.

  • source
  • parent
  • hideshow 3 child comments
  • [–] -5 points 2 years ago (2 children)

    That was only one vendor, which is what you asked for. There's a whole directory of different vendors offering different services at monerica.com.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (1 child)

    Looking at the Food & Drink section, it doesn't look like you can get much more than coffee and meat with monero, so I'm really not sure how you're supposed to "be your own bank" by using it and still have access to food.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 5 points 2 years ago (3 children)

    What about something like groceries, oil changes, metro cards, hospital bills, mortgage payments, rent, gym memberships, cash only business, payroll, or anything else that is actually needed by people.

  • source
  • parent
  • hideshow 3 child comments
  • [–] -3 points 2 years ago (2 children)

    Inatacart gift card, visa or mastercard giftcards, mortgage and hospital bills i dont have a way for, visa giftcards, cash only businesses would benifit greatly due to lower theft risk.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (6 children)

    Yes thank you I will have my employer update my direct deposit information now

  • source
  • parent
  • hideshow 6 child comments
  • [–] -3 points 2 years ago (5 children)
  • [–] 2 points 2 years ago (4 children)
  • [–] -2 points 2 years ago (3 children)

    In your wallet. Its called an address and starts with "4" or "8"

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 2 years ago (2 children)

    My employer says they don't pay to non FDIC institutions

  • source
  • parent
  • hideshow 2 child comments
  • [–] -3 points 2 years ago (1 child)

    There are ways around that but it starts to get complicated. There are companies that will take your paycheck in your name and then automatically convert it and send you crypto, But I have never used them, so I don't know anything more than that.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 8 points 2 years ago (2 children)

    Who do you think makes the decisions for a bank?

    The person writing the Android app?

    Or the person who just wants customers to be able to access the app and use the services?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago* (1 child)

    Banks have laws and regulations that they must abide by to secure the access to and information of customer accounts. A security team will surely have to sign off on whatever the app developer or customer experience manager wants to implement.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 18 points 2 years ago* (last edited 2 years ago) (1 child)

    Isn't that how fdroid worked for a long time?

    Edit: although it doesn't make sense to me for play store to do the same without the source code available

    Edit 2:

    The reason is that they forced new apps AND apps for Android TV to use App Bundles https://developer.android.com/guide/app-bundle This type of release cannot be installed as it but can be used to generate the apk files. In order to do so, the Play Store has to sign on the fly.

    Not buying it. They could let the dev sign evey combination before uploading. They'll be caching them anyways

  • source
  • parent
  • hideshow 1 child comment
  • [–] 21 points 2 years ago* (last edited 2 years ago) (2 children)

    In addition to the private key thing, the Play Store is requiring them to drop support for APIs older than API 30 unless they provide the key.

    Which in effect means VLC can no longer be updated on AndroidTVs running Android 11 or earlier.

    Which is millions of customers, according to VLC

  • source
  • parent
  • hideshow 2 child comments