Android
The new home of /r/Android on Lemmy and the Fediverse!
Android news, reviews, tips, and discussions about rooting, tutorials, and apps.
🔗Universal Link: [email protected]
💡Content Philosophy:
Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.
Support, technical, or app related questions belong in: [email protected]
For fresh communities, lemmy apps, and instance updates: [email protected]
📰Our communities below
Rules
-
Stay on topic: All posts should be related to the Android OS or ecosystem.
-
No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to [email protected].
-
Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to [email protected].
-
No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.
-
No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.
-
No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.
-
No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.
-
No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.
-
No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!
-
No affiliate links: Posting affiliate links is not allowed.
Quick Links
Our Communities
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
Lemmy App List
Chat and More
view the rest of the comments
F-Droid has a lot of security issues(if you care about security), use Neo Store if you want access to F-Droid apps with a more secure app.
EDIT: Even better to use Obtainium and add the links of the APP's own Github/GitLab repo to it.
Any chance u can explain how Neo Store is more secure?
iirc fdroid utilizes very old api which is problematic as newer api gets newer security features droidify and neostore both are more modern
Neo Store can enable automatic updates for apps downloaded from F-Droid.
And how does that make it more secure?
I don't think it would make F-Droid itself more secure, but it's best to get possible security updates for apps sooner with auto-updates.
I read through that article, and though I don't have the time or knowledge to properly critique it, I found quite a lot of it unconvincing.
It's one thing to agree there are potential issues, but the article seemed to jump a bit too easily, via rhetoric more than logic, to "therefore it's unsuitable" and similarly to "the other ones are better".
(Disclaimer: I only know mildly what I'm talking about!! If whoever reads this is interested, I hope you can follow the details to their source and get involved in the proper discussion for improving f-droid and/or encouraging another respiratory client.)
This is, quite frankly, borderline misinformation. Malicious packages in Linux distributions are unheard of. Malicious apps in the allegedly-more-secure Google Play, on the other hand, are a dime a dozen.
The downplaying of the importance of reproducible builds further diminishes my opinion of this piece.
I'm going to go ahead and continue using F-Droid, thanks.
Here are a couple of videos that try to explain it a little easier.
Video 1
Video 2
Here is an alternative Piped link(s): https://piped.video/watch?v=IzpVI4zaso0
https://piped.video/watch?v=lAbgeJau3eE
Piped is a privacy-respecting open-source alternative frontend to YouTube.
I'm open-source, check me out at GitHub.
This is, quite frankly, borderline misinformation. Malicious packages in Linux distributions are unheard of. Malicious apps in the allegedly-more-secure Google Play, on the other hand, are a dime a dozen.
The downplaying of the importance of reproducible builds further diminishes my opinion of this piece.
I'm going to go ahead and continue using F-Droid, thanks.
What exactly are you trying to point out ?
From your quote: "It really shouldn’t be compared to the Android platform in any way."
And where exactly does it downplay reproducible builds ? "reproducible builds are not as common as we would have wanted."
"I'm going to go ahead and continue using F-Droid, thanks." Good friend, do whatever it is you want to do.
I'm just trying to spread security awareness.
EDIT: "Saying Play Store is filled with malicious apps is beyond the point: the false sense of security is a real issue. Users should not think of the F-Droid main repository as free of malicious apps, yet unfortunately many are inclined to believe this."
I quoted that because it's part of the borderline misinformation. Security is security. Malware is malware. Android isn't magical and neither is desktop Linux. They absolutely can be meaningfully compared.
Ah, you're right. I misread that part, sorry.
So am I. I'm an ornery old Linux nerd and security snob. I'd excise all proprietary software from my home and office if I could, precisely because it has such an appalling track record and the blatantly unnecessary attack surfaces of DRM and telemetry.
Can F-Droid be more secure than it is? Sure. Do the issues described in this paper mean F-Droid is so rampantly insecure that even Play is safer? Absolutely not.
By the way, I'm not sure I understand how Neo Store is supposed to be more secure, as it's supposedly just an alternative UI for F-Droid. As for Obtainium, it'll protect you from malfeasance or compromise on the part of the F-Droid repository, but it won't protect you from malicious app developers, and unless I'm mistaken, the latter is a much more common threat.