Live data from Hacker News

Termux no longer updated on Google Play

wiki.termux.com

211–220 of 349 posts

Re: Termux no longer updated on Google Play

#211

Earlier quoted context omitted.

Note that there are 297 hidden items in that issue so you have to click "Load more..." ceil(297/60) times to read all of the comments about how APK packaging is soon necessary for latest Android devices so the termux package manager can't just dump executable binaries wherever. FWIU: - Android Q+ disallows exec() on anything in $HOME, which is where termux installed binaries that may have been writeable by the execut…

What about development on-the-device? - It seems C compiled with clang on the device wouldn't be executable? (If it was, that would be a way around the restriction: distribute packages as source, like the good old days) > offer users the option of generating an apk wrapping their native code in a usable way. https://github.com/termux/termux-app/issues/1072#issuecommen... This seems a promising solution: compile from…

You can run binaries you compiled either. On device dev is essentially pointless.

You can run interpreters, but possibly in a restricted context in the future.

Re: Termux no longer updated on Google Play

#212

Earlier quoted context omitted.

Is that unreasonable? Running another OS on a device with physical hardware switches is a privilege right now, so it costs more. There are essentially two companies doing this, and neither of them are even at the point where they can completely honestly say their products are out of beta. The Librem is expensive in no small part because its feature list is fringe, and even ignoring the inherent hardware challenges th…

These days, a braille display can be had for around $400-$600. We also have multiple manufacturers, with multiple models and prices you can choose from. I don’t see that happening with open source hardware.

From where?

Genuine question, I was interested in trying to play around with one a while ago, and I spent a fair amount of time searching and could not find a single monitor for under $1000, and most of them were in the $3000 to even $7000(!!!) range for a device that can literally only display a single line of text at a time.

If there are manufacturers making cheaper devices, or even just doing anything interesting with the hardware like building multiple-row 2D displays instead of 1D single-line outputs, I would love to know about them. It's a market I'm somewhat interested in.

The cheapest option I ever found was https://www.boundlessat.com/Blindness/Braille-Displays/Brail..., which is $1000 for a device that can display a whopping 14 characters at a time.

Re: Termux no longer updated on Google Play

#213
post #172

Earlier quoted context omitted.

A bunch of things that add up...: * Lack of things like w^x enforced across the OS. (the root of this post). * The quality of SoC and OEM provided drivers being very very poor - there are lots of kernel exploits to be found. * Very slow/no updates. Time from an exploit being reported to Google to it being patched by a typical user is usually 6 months or more. That means for any random device you find on the street, t…

Some good points, although... > Lack of things like w^x enforced across the OS. (the root of this post). Are you sure iOS does this for the filesystem at all? I can't find any documentation besides some comments that they don't allow apps which exec other binaries in the app store. > The quality of SoC and OEM provided drivers being very very poor - there are lots of kernel exploits to be found. And how do we know ab…

> Where did you get this 6 month figure? Was that before or after the introduction of Project Treble, Project Mainline, the new security update system, etc?

Note: definitely not about Pixel outside of US (or even in the US if the phone was direct from Google).

You underestimate the time that it takes to approve updates, even taking into account what Google have done to speed up the update process.

The SoC and the Kernel

From the start, you need to have good driver/HAL for the specific SoC of the device. Qualcomm is very spotty on these: historically, the 8-series revives updates for up to two years (which is an improvement already considering that some older chipsets only has around 1.5 years of updates). This would be a minimal problem if it is Windows-style (where drivers are separate to the system) but Android is currently based on Linux, which integrates the drivers to the build. This means that major kernel upgrades are PITA or even impossible. Worse, Mediatek and other SoCs (aside Samsung, but they control it anyway) tends to only have a binary build of the kernel and as a device manufacturer you have to deal with it (that's why HMD cannot disable the DuraSpeed optimisation that Mediatek has put on it because Mediatek controls to a degree the whole device).

OEM-specific Customisations

It is no secret that OEMs modify Android hard, to the point that the modifications they have done is beyond the UI of the device. This means that patching of the devices takes time even when the OEM and the SoC manufacturer are responsive (as alluded to earlier, not already good). Worse of all, some fixes are in the mercy of SoC manufacturers as they affect the kernel.

OEM Priorities

If you have a flagship phone, congratulations! You receive patches monthly. However what if you are using a regular device (or even a budget device) from an OEM? Unless it is a device from an Android One OEM or a Pixel, you usually only receive updates quarterly, if at all (see SoC and the Kernel above). Plus, good luck contacting your manufacturer about this problem. This rather obviously slows down patching.

Carrier's Shenanigans

If you are not using a carrier-specific device, congratulations! The update should come to you as smoothly as the OEM wants to. But wheat if you bought your device under a carrier? Depending on your country, no significant difference to the non-carrier version or your devices' updates is being hold to by your carrier because they wnat to check it (apparently). Sometimes, your carrier is benevolent and really has a team that checks if the update will break something and authorise the OEM to release the update within a day or two. However, it is more likely that the carrier will slow down the process to the point that the non-carrier version is three versions ahead.

User Efforts

Well, that's the users' fault then. Not really relevant considering that Windows users tends to turn off updates.

What Google has done to mitigate this

Project Treble and Play Services Updates (aka Mainline) have reduced the time of patching of devices significantly and prevent a whole class of attacks (including the Stagefright component, which decodes media files and often has bugs in it due to it being mainly a third-party component). However, you have noticed that the SoC, and hence the kernel, still has teetering problems when it comes to updating. The good news is that Google has requested SoC manufacturers to "mainline" their drivers (aka including the SoC driver source code in the kernel, not to be confused with Project Mainline). However, that is just last month and it is still somewhat rejected by SoC manufacturers. Qualcomm have even promised to improve the updates, but we haven't heard anything from Mediatek et al. And that even excludes the pesky carriers who holds updates for no apparent reason at all.

Re: Termux no longer updated on Google Play

#214
post #204

Earlier quoted context omitted.

This point is moot and off-topic. termux is not perfect because it is already a compromise! When google scammed us and sold android devices to all the hackers here and then surreptitiously removed our access to the terminal, we said "that's fine, we can still package this as an app like so and so" and termux was born. now they are removing access from running any code not signed by their store, even if you install te…

Ironically, the software we create, Android in this case, isn't oriented at us. Castration in Android is considered a feature, because it makes the average user's phone more reliable.

[deleted]

Re: Termux no longer updated on Google Play

#215

Quick note: Google's Advanced Protection program disallows sideloading apps, so you can't install F-droid. Edit: Note that the Advanced Protection program is opt-in for users that require the highest degree of security Google can offer. Regular users won't be impacted by this. Edit: proof https://imgur.com/a/yktPNIc Edit 2: see @haunter's comment for a link to the change announcement

I wonder what the actual numbers are on malware installed via side-loading and malware installed from the play store. There is no shortage of sketchy apps on the play store. Through my personal bias I would imagine that most people side-loading apps tend to be people using F-Droid who know more or less what they're doing. Although I'm sure there are some people who blindly follow sketch website telling them to instal…

There is "people intentionally side-loading", and "people getting social engineered into installing something they shouldn't".

Re: Termux no longer updated on Google Play

#216

TL;DR: Android is trying to enforce all data being either writable, or executable, never both. iOS already does this. There are big security benefits (it becomes much harder to exploit an app). A disadvantage is it becomes much harder to make things like terminal emulators and things that want to download random code and run it. But those are by far the minority of apps, and it seems crazy to make a pretty massive se…

>But those are by far the minority of apps, and it seems crazy to make a pretty massive security tradeoff for something that 99% of apps don't need to do. It also completely eliminates general purpose computing. >One solution might be a special permission to be allowed to do that, but it seems unlikely a user could really make an informed decision. I think the way "Developer Mode" on Android is implemented is pretty…

General purpose computing is not secure, and can most likely never be made secure.

Re: Termux no longer updated on Google Play

#217
BTW: I just now have read an announcement that Retroarch is affected by the same policy, and they solve that by offering a limited number of Libretro ‘cores’ that are downloaded from Google's servers on request from the app: https://www.libretro.com/index.php/retroarch-android-new-ver...

I now invoked the ‘convert cores to the Play Store versions’ functionality, and not seeing any new separate apps installed, nor was I asked to install anything (and Retroarch doesn't have permissions for that). It seems like Termux could use the same approach.

Re: Termux no longer updated on Google Play

#218
post #209

Earlier quoted context omitted.

iOS apps on the App Store effectively cannot create W^X mappings.

Sure, but the other poster seemed to be talking about software policy-based security measures with that point (like what Android is adding) and not just app store review restrictions.

iOS enforces this in the memory manager.

Re: Termux no longer updated on Google Play

#220

Earlier quoted context omitted.

€297 pre order pricing for a very simple phone.

To be fair, I would pay for a libre phone. And regarding that it is very simple and or basic, OK. Life has become too complicated.

https://www.crowdsupply.com/sutajio-kosagi/precursor
Post reply on HN