this post was submitted on 18 Feb 2026
275 points (97.6% liked)

Android

21465 readers
457 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: !android@lemdro.id


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] tomalley8342@lemmy.world 0 points 17 hours ago (1 children)

Yes, well, everything they say about F-Droid and Firefox is more or less true.

[–] beyond@linkage.ds8.zone 1 points 2 hours ago* (last edited 2 hours ago) (1 children)

I would say there is a difference between constructive criticism and an "attack" and although the privsec article does bring up valid points* I would still regard it as the latter (despite their claims of objectivity), because they ultimately conclude that its premise is inherently flawed regardless of implementation details. They claim

This article aims to be purely technical. It is not an attack on F-Droid or their mission.

Yet while the authors claim to be "objective and technical" its not hard to notice all the "attacks on F-Droid's mission" in this article, from the reference to F-Droid's "ridiculous inclusion policy" to all the dismissive references to "ideology." The message is clear, that F-Droid's "mission" is Stupid and Ideological and the problems F-Droid aims to solve are not real. Thus, their suggested "alternatives" are just regular app stores that don't enforce any of the guarantees that F-Droid does (namely, that the app corresponds to its source code and does not include proprietary components), because those guarantees aren't worth anything** to the "Objective and Technical" people of privsec - you are Stupid and Ideological if you care about software freedom. In fact, Accrescent even says they allow proprietary software because free software "is not inherently more secure or private" - which is technically true, but very misleading, because free software never has claimed to be "more secure" - it has only ever offered the four freedoms, which as a user I feel entitled to on my own devices, so I only install apps that give me these four freedoms. Far from being "objective and non-ideological" the position of Privsec, Accrescent, and their advocates is that users neither deserve, need, or should want software freedom, as such I would characterize these organizations as hostile to the free software movement even if some of their points are factual.

I will add I am not entirely uncritical of F-Droid either, but my criticisms are more that they aren't strict enough and should be building as much from source as possible instead of relying on prebuilt Maven dependencies as much as they do. I would also say although as a user I think F-Droid's inclusion policy is a good thing and not "ridiculous" I agree it does put some amount of burden on developers who I imagine develop for the Google world first and the FOSS world second. It might be a good idea for F-Droid maintainers to take a more active role in, well, maintaining these apps instead of pushing the extra work onto the developers (this is typical in the GNU/Linux world, in which distro maintainers take up all the work to package upstreams, but F-Droid sometimes tries to cosplay as an "app store" despite it being a fundamentally different model).

* aside from a bizarre claim that F-Droid supporting multiple repositories is a Bad Thing because it interferes with, and I quote, "UserManager which can be used to prevent a user from installing third-party apps" - what does this have to do with privacy? I think this also speaks to a deeper conflict between security people and free software people, that being uncritical worship of "security models" even when they harm the user. Accrescent offers more or less the same justification for why it locks the user into their own store/repository, and I think it is subtly dangerous to suggest this is an "alternative" to F-Droid because it has very different values.

** According to one of the writers of that article,

Any better ideas for it are welcome.

Just allow devs to upload their own build with their own keys like Accrescent. It's not like the whole "audit" system is meaningful anyways.

Of course, characterizing it as an "audit system" is missing the point entirely, but I imagine he knows that. Reducing the four freedoms down to "you can look at the source code and audit it" to then follow it up with "you can't/aren't going to audit every app you download so why bother with FOSS anyway" is a favorite rhetorical tactic.

[–] tomalley8342@lemmy.world 1 points 1 hour ago* (last edited 1 hour ago)

Yes, however, the article is titled "F-Droid Security Issues", not "F-Droid FOSS Issues". I'm not sure why anyone would read that and say "well what about the four freedoms?". That's not what the article is talking about.

ultimately conclude that its premise is inherently flawed regardless of implementation details

In terms of security, which is true.

aside from a bizarre claim that F-Droid supporting multiple repositories is a Bad Thing because it interferes with, and I quote, “UserManager which can be used to prevent a user from installing third-party apps” - what does this have to do with privacy?

It doesn't. It's a security issue.

Just allow devs to upload their own build with their own keys like Accrescent. It’s not like the whole “audit” system is meaningful anyways.

It's true, F-droid's signature doesn't provide any meaningful security guarantees.