160
submitted 6 days ago by zdhzm2pgp@lemmy.ml to c/fdroid@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] Ferk@lemmy.ml 4 points 5 days ago* (last edited 5 days ago)

But the thing is that they are not really making Android more secure with this policy.

They are still allowing APKs signed with debug keys to work.. so the only alternative now for any developer that doesn't want to register with Google is gonna be using those debug credentials to sign their app releases.

This is not gonna stop rogue APKs from outside Google’s store, it’s just gonna make them less secure (since they'll have to rely on debug keys, which is essentially equivalent to being unsigned, from a security point of view).

This is not gonna stop alternative stores either, in fact, it will make it more important to use stores, since they might still be able to to implement alternative ways to check package authenticity before installing, even when using debug keys.

The issue with using debug keys is that you are now not gonna be able to shield apps signed this way from getting replaced by illegitimate malware you might download from outside the store. So overall, this move is making Android LESS secure, not more.

[-] cRazi_man@europe.pub 3 points 5 days ago

None of that logic matters man. Regulators don't understand this shit. Do you think the UK's online age restrictions make anyone safer? It's all bullshit for their own purposes.

this post was submitted on 30 Sep 2025
160 points (99.4% liked)

F-Droid

9687 readers
46 users here now

F-Droid is an installable catalogue of FOSS (Free and Open Source Software) applications for the Android platform. The client makes it easy to browse, install, and keep track of updates on your device.

Website | GitLab | Mastodon

Matrix space | forum | IRC

founded 4 years ago
MODERATORS