this post was submitted on 24 Mar 2024
385 points (96.2% liked)

Privacy

32383 readers
146 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users... For now, iOS App Store still allows us to ship for iOS9, but until when?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 61 points 8 months ago* (last edited 8 months ago) (2 children)

From their Twitter:

If you wonder why we can't update the VLC on Android version, it's because Google refuses to let us update:

  • either we give them our private signing keys,
  • or we drop support for Android TV before API-30, and all our users on TV API<30 can't get fixes.

It's not much, just dozens of millions of people use Android TV before Android-11...

Maybe we should tell users to buy new TVs? #electronicWaste

I can't speak to why they're not updating on FDroid but seeing as how it's much more difficult to get people to use FDroid on Android TV, I don't think it will help them with that issue anyway.

[–] [email protected] 87 points 8 months ago (2 children)

Google requiring their private signing key is insane, and goes completely against the concept of private/public keys.

Why is Google asking for this?

[–] [email protected] 34 points 8 months ago* (last edited 8 months ago) (1 children)

See also: NSA PRISM

Member when all the companies listed released a PR statement within 24 hours of each other, all very basic and denied allowing the NSA direct access to their users?

I member.

[–] [email protected] 11 points 8 months ago

Oh yeah, I remember that...

[–] [email protected] 25 points 8 months ago* (last edited 8 months ago)

C-I-A Confidentiality, Integrity, Accessibility. They don't need the keys for C or A. Only one option remains. To modify the code and pass it off as code VLC wrote or signed off on.

Likely to install malware and re-sign. Brazen identity theft.

Maybe I'm wrong, they could use VLC's private keys to gobble encrypted communications too.

[–] [email protected] 8 points 8 months ago

I didn't know F-droid was on Android TV, but it will be on mine pretty soon.