this post was submitted on 24 Mar 2024
385 points (96.2% liked)

Privacy

30753 readers
929 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS
 

VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users... For now, iOS App Store still allows us to ship for iOS9, but until when?

top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 137 points 5 months ago (1 children)

Reminder that VLC is on F-Droid

[–] [email protected] 51 points 5 months ago (12 children)

They've not updated it there either though. It seems to be less of a case of can't update Android and more of a case of won't update Android

[–] [email protected] 60 points 5 months ago* (last edited 5 months ago) (2 children)

From their Twitter:

If you wonder why we can't update the VLC on Android version, it's because Google refuses to let us update:

  • either we give them our private signing keys,
  • or we drop support for Android TV before API-30, and all our users on TV API<30 can't get fixes.

It's not much, just dozens of millions of people use Android TV before Android-11...

Maybe we should tell users to buy new TVs? #electronicWaste

I can't speak to why they're not updating on FDroid but seeing as how it's much more difficult to get people to use FDroid on Android TV, I don't think it will help them with that issue anyway.

[–] [email protected] 86 points 5 months ago (2 children)

Google requiring their private signing key is insane, and goes completely against the concept of private/public keys.

Why is Google asking for this?

[–] [email protected] 33 points 5 months ago* (last edited 5 months ago) (1 children)

See also: NSA PRISM

Member when all the companies listed released a PR statement within 24 hours of each other, all very basic and denied allowing the NSA direct access to their users?

I member.

[–] [email protected] 11 points 5 months ago

Oh yeah, I remember that...

[–] [email protected] 25 points 5 months ago* (last edited 5 months ago)

C-I-A Confidentiality, Integrity, Accessibility. They don't need the keys for C or A. Only one option remains. To modify the code and pass it off as code VLC wrote or signed off on.

Likely to install malware and re-sign. Brazen identity theft.

Maybe I'm wrong, they could use VLC's private keys to gobble encrypted communications too.

load more comments (1 replies)
[–] [email protected] 43 points 5 months ago* (last edited 5 months ago) (3 children)

What exactly is the issue preventing them from updating the Android version?

Also, if that's the case, it sounds like "App stores were a mistake" is a bit misleading, since the particular app store isnt the problem.

[–] [email protected] 59 points 5 months ago (5 children)

Basically, modern app stores have changed how they work and now require the signing keys, VLC feel this is a bad thing and refuse to update. Banks are okay with it, but VLC feel more strongly than banks.

[–] taladar 93 points 5 months ago (32 children)

Banks are okay with it, but VLC feel more strongly than banks.

I mean banks are known for horrible security practices all around so that makes perfect sense.

load more comments (32 replies)
[–] [email protected] 18 points 5 months ago* (last edited 5 months ago) (1 children)

Isn't that how fdroid worked for a long time?

Edit: although it doesn't make sense to me for play store to do the same without the source code available

Edit 2:

The reason is that they forced new apps AND apps for Android TV to use App Bundles https://developer.android.com/guide/app-bundle This type of release cannot be installed as it but can be used to generate the apk files. In order to do so, the Play Store has to sign on the fly.

Not buying it. They could let the dev sign evey combination before uploading. They'll be caching them anyways

[–] [email protected] 24 points 5 months ago

Traditionally Fdroid signs every app. Not with the developers key. The future are reproducible builds. https://f-droid.org/2023/01/15/towards-a-reproducible-fdroid.html this is a futuristic app store, not what google has.

load more comments (3 replies)
[–] [email protected] 20 points 5 months ago* (last edited 5 months ago) (2 children)

In addition to the private key thing, the Play Store is requiring them to drop support for APIs older than API 30 unless they provide the key.

Which in effect means VLC can no longer be updated on AndroidTVs running Android 11 or earlier.

Which is millions of customers, according to VLC

load more comments (2 replies)
load more comments (1 replies)
[–] [email protected] 9 points 5 months ago* (last edited 5 months ago) (3 children)

VLC don't update on Fdroid, Fdroid compile all the apps on their repo (the one that comes with the app). Fdroid do some checks on the updated app before they compile it, so it's always a little behind the main release.

Edit: it could also be that VLC haven't yet released the updated app (and in particular its source), so Fdroid have nothing to work with.

load more comments (3 replies)
load more comments (9 replies)
[–] the_rogue 78 points 5 months ago* (last edited 5 months ago) (39 children)

Fdroid is the obvious answer me thinks. Anyway love you guys/gals at videolan still haven't come across a piece of software that destroys every other in its field in every aspect.

load more comments (39 replies)
[–] [email protected] 62 points 5 months ago* (last edited 5 months ago) (24 children)

Dear VLC, in your download section there is the F-Droid app store option which I consider a good thing. p.s. Why are you still posting on Twitter ??? On your website I see two buttons Facebook and Twitter. Time for a change ?

By the way, archive.is and archive.ph are Tor unfriendly. Another link : https://news.ycombinator.com/item?id=39798565

[–] [email protected] 11 points 5 months ago (1 children)

By the way, archive.is and archive.ph are Tor unfriendly.

Not just Tor, they poison DNS queries from Cloudfare and Quad9, basically any DNS that doesn't give them sufficient location information about the end user.

load more comments (1 replies)
load more comments (23 replies)
[–] idefix 52 points 5 months ago (2 children)

VLC is still on Twitter? I thought they would be quick to migrate to Mastodon, slightly disappointed.

And thanks OP for linking outside of Twitter.

[–] [email protected] 18 points 5 months ago

Probably on both?

load more comments (1 replies)
[–] [email protected] 41 points 5 months ago (2 children)

and yet the fdroid version was updated last month!

[–] [email protected] 33 points 5 months ago (1 children)

I just checked it's 23 February 2023. Last year.....

load more comments (1 replies)
[–] [email protected] 10 points 5 months ago

Or just using their official release APK over obtainium

[–] [email protected] 37 points 5 months ago

TIL that my country has bended over the copyright trolls and blocked Archive.is, need a VPN to view...

[–] [email protected] 32 points 5 months ago (1 children)
[–] sugar_in_your_tea 17 points 5 months ago

I wish I was lost in dessert, but it's better for my wasteline that I'm not.

And good on VLC for standing up against this. This type of thing should absolutely be opt-in by the developer.

[–] [email protected] 26 points 5 months ago* (last edited 5 months ago) (6 children)

So, uh, why not? The link doesn't answer that.

[–] [email protected] 47 points 5 months ago* (last edited 5 months ago) (2 children)

Google is forcing apps to have Google services handle private keys. VLC doesn't think that's a good policy for security (it's not), so they're refusing to adopt it. Whenever you sign in on an app with your fingerprint, the encryption/authentication is being handled by a different program and stored alongside all your other keys. This creates a single point of failure for all sign-ons on your phone.

[–] [email protected] 13 points 5 months ago

This creates a single backdoor for all sign-ons on your phone.

load more comments (1 replies)
[–] [email protected] 13 points 5 months ago (1 children)

My guess is that their update won’t be approved unless they drop support for old OS versions

[–] [email protected] 15 points 5 months ago (5 children)

Which is a problem given it's a media player, and AndroidTVs still on Android 11 or earlier would be denied updates.

load more comments (5 replies)
load more comments (4 replies)
[–] [email protected] 21 points 5 months ago (13 children)

I don't think app stores are the problem. I think big company app stores are the problem, such as the Google Play Store and the Apple App Store. I think something like F-Droid where you can add your own app sources or Droid-ify that has a ton of sources by default you just need to enable is the way to go.

load more comments (13 replies)
[–] [email protected] 14 points 5 months ago (2 children)

Can someone break down the thinking behind this?

load more comments (2 replies)
[–] [email protected] 9 points 5 months ago (1 children)

With Play App Signing, Google manages and protects your app's signing key for you and uses it to sign optimized, distribution APKs that are generated from your app bundles

You can use google's play app signing. It's not mandatory.

[–] [email protected] 11 points 5 months ago (8 children)

That is not better, it still means that the app is signed with a non private key, which goes against the very concept of the private/public key concept

load more comments (8 replies)
load more comments
view more: next ›