VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users... For now, iOS App Store still allows us to ship for iOS9, but until when?

top 50 comments

sorted by: hot top controversial new old
[–] 142 points 2 years ago (64 children)

Reminder that VLC is on F-Droid

  • source
  • hideshow 64 child comments
  • [–] 51 points 2 years ago (63 children)

    They've not updated it there either though. It seems to be less of a case of can't update Android and more of a case of won't update Android

  • source
  • parent
  • hideshow 63 child comments
  • [–] 63 points 2 years ago* (last edited 2 years ago) (5 children)

    From their Twitter:

    If you wonder why we can't update the VLC on Android version, it's because Google refuses to let us update:

    • either we give them our private signing keys,
    • or we drop support for Android TV before API-30, and all our users on TV API<30 can't get fixes.

    It's not much, just dozens of millions of people use Android TV before Android-11...

    Maybe we should tell users to buy new TVs? #electronicWaste

    I can't speak to why they're not updating on FDroid but seeing as how it's much more difficult to get people to use FDroid on Android TV, I don't think it will help them with that issue anyway.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 89 points 2 years ago (3 children)

    Google requiring their private signing key is insane, and goes completely against the concept of private/public keys.

    Why is Google asking for this?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 26 points 2 years ago* (last edited 2 years ago)

    C-I-A Confidentiality, Integrity, Accessibility. They don't need the keys for C or A. Only one option remains. To modify the code and pass it off as code VLC wrote or signed off on.

    Likely to install malware and re-sign. Brazen identity theft.

    Maybe I'm wrong, they could use VLC's private keys to gobble encrypted communications too.

  • source
  • parent
  • load more comments (1 reply)
  • [–] 45 points 2 years ago* (43 children)

    What exactly is the issue preventing them from updating the Android version?

    Also, if that's the case, it sounds like "App stores were a mistake" is a bit misleading, since the particular app store isnt the problem.

  • source
  • parent
  • hideshow 43 child comments
  • [–] 60 points 2 years ago (38 children)

    Basically, modern app stores have changed how they work and now require the signing keys, VLC feel this is a bad thing and refuse to update. Banks are okay with it, but VLC feel more strongly than banks.

  • source
  • parent
  • hideshow 38 child comments
  • [–] 18 points 2 years ago* (last edited 2 years ago) (1 child)

    Isn't that how fdroid worked for a long time?

    Edit: although it doesn't make sense to me for play store to do the same without the source code available

    Edit 2:

    The reason is that they forced new apps AND apps for Android TV to use App Bundles https://developer.android.com/guide/app-bundle This type of release cannot be installed as it but can be used to generate the apk files. In order to do so, the Play Store has to sign on the fly.

    Not buying it. They could let the dev sign evey combination before uploading. They'll be caching them anyways

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (3 replies)
  • load more comments (1 reply)
  • [–] 9 points 2 years ago* (3 children)

    VLC don't update on Fdroid, Fdroid compile all the apps on their repo (the one that comes with the app). Fdroid do some checks on the updated app before they compile it, so it's always a little behind the main release.

    Edit: it could also be that VLC haven't yet released the updated app (and in particular its source), so Fdroid have nothing to work with.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (3 replies)
  • load more comments (9 replies)
  • [–] 83 points 2 years ago* (last edited 2 years ago) (39 children)

    Fdroid is the obvious answer me thinks. Anyway love you guys/gals at videolan still haven't come across a piece of software that destroys every other in its field in every aspect.

  • source
  • hideshow 39 child comments
  • load more comments (39 replies)
    [–] 63 points 2 years ago* (25 children)

    Dear VLC, in your download section there is the F-Droid app store option which I consider a good thing. p.s. Why are you still posting on Twitter ??? On your website I see two buttons Facebook and Twitter. Time for a change ?

    By the way, archive.is and archive.ph are Tor unfriendly. Another link : https://news.ycombinator.com/item?id=39798565

  • source
  • hideshow 25 child comments
  • load more comments (23 replies)
    [–] 52 points 2 years ago (2 children)

    VLC is still on Twitter? I thought they would be quick to migrate to Mastodon, slightly disappointed.

    And thanks OP for linking outside of Twitter.

  • source
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 42 points 2 years ago (3 children)

    and yet the fdroid version was updated last month!

  • source
  • hideshow 3 child comments
  • [–] 38 points 2 years ago

    TIL that my country has bended over the copyright trolls and blocked Archive.is, need a VPN to view...

  • source
  • [–] 34 points 2 years ago (1 child)
  • [–] 26 points 2 years ago* (14 children)

    So, uh, why not? The link doesn't answer that.

  • source
  • hideshow 14 child comments
  • [–] 47 points 2 years ago* (last edited 2 years ago) (2 children)

    Google is forcing apps to have Google services handle private keys. VLC doesn't think that's a good policy for security (it's not), so they're refusing to adopt it. Whenever you sign in on an app with your fingerprint, the encryption/authentication is being handled by a different program and stored alongside all your other keys. This creates a single point of failure for all sign-ons on your phone.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
  • load more comments (4 replies)
    [–] 21 points 2 years ago (13 children)

    I don't think app stores are the problem. I think big company app stores are the problem, such as the Google Play Store and the Apple App Store. I think something like F-Droid where you can add your own app sources or Droid-ify that has a ton of sources by default you just need to enable is the way to go.

  • source
  • hideshow 13 child comments
  • load more comments (13 replies)
    [–] 15 points 2 years ago (2 children)

    Can someone break down the thinking behind this?

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 9 points 2 years ago (9 children)

    With Play App Signing, Google manages and protects your app's signing key for you and uses it to sign optimized, distribution APKs that are generated from your app bundles

    You can use google's play app signing. It's not mandatory.

  • source
  • hideshow 9 child comments
  • load more comments
    view more: next ›