Live data from Hacker News

Termux no longer updated on Google Play

wiki.termux.com

261–270 of 349 posts

Re: Termux no longer updated on Google Play

#261

Earlier quoted context omitted.

My personal security metric is "how many bitcoins would I leave in a wallet app on this phone". Currently that number is about 1 ($30k) on an up to date android. I believe that if I had more bitcoins on a phone, and told people about it, there's a good chance a targeted exploit would steal those keys. Even if I had them encrypted, at some point I have to type a password in to decrypt, and that would be the point they…

Well yes, I would consider any Android device family other than the Pixel / Nokia line a security hazard, with or without any bitcoins on it. Comparing a rushed Q4 market Samsung phone to an iPhone is simply comparing a brick and an orange. There are many problems with Android, but that the price for a zero day exploit on Android has become more valuable than one for iOS as far as 2019 [0] should tell you something a…

> Android device family other than the Pixel / Nokia line a security hazard

As someone who uses a HMD (Nokia) phone, please do not buy the models with Mediatek SoC in it when you are absolutely concerned with security. Apparently Mediatek is the one building the kernel of the device and not even HMD has knowledge on what modifications have been made (for example is DuraSpeed, which was an aggressive battery saver that ruined some apps, was enabled without permission and even HMD cannot disable it permanently). Qualcomm SoC devices are okay, but expect a slight delay (around a week or two especially if it was a device from a carrier) for updates.

Re: Termux no longer updated on Google Play

#262
post #162

Earlier quoted context omitted.

The problem will start with such offerings only if third parties (like employers or banks) demand turning this on. The patronizing of users that started with saftynet is horrifying. I think it will become crucial that some commercialy relevant group uses non play store content. Otherwise the affordance to use non main stream stuff will become higher and higher.

I mean it makes sense. The employer requires you to only trust Google-approved apps since something like an evil maid (or mugging, or blackmail, etc) attack on an unlocked phone is part of their threat model.

And it seems reasonable for an employer. What about banks? The argument I'm coming up with just isn't as compelling for no other reason than I'm 'only' risking my money, not corporate access.

Re: Termux no longer updated on Google Play

#263

Earlier quoted context omitted.

No. Beside Android 5.x/6.x devices, I has Symbian 9.x (Nokia N82) smartphone which works perfectly. And there are a lot of new apps for it: - https://old.reddit.com/r/symbian/new P.S. My 10+ year-old laptop perfectly works with latest MX Linux distribution (based on Debian 10 buster ) and all modern FLOSS desktop apps (GIMP, FreeCAD, Inkscape, etc.) works like a charm on it. So, software devs should NOT declare users…

Phone manufacturers certainly ought to offer 5+ years of OS updates. Apple does, after all. So I agree with you to that extent. But if users want third parties volunteers to support devices whose vendors have already dropped support? If there are no volunteers wanting to do the work, the work doesn't get done. The bad guys here are the phone vendors, not the Termux developers IMHO.

> The bad guys here are the phone vendors, not the Termux developers IMHO.

Here is Termux devs reply to Termux user:

> ... Time to upgrade your devices...[0]

Who is bad guy here according this quote?

P.S. It would not be so bad if devs just says "we don't support such devices", but instead devs declared to upgrade device in reply to user...

[0] https://github.com/termux/termux-app/issues/1407#issuecommen...

Re: Termux no longer updated on Google Play

#264

Earlier quoted context omitted.

Lay off implications about bad faith, please. The argument is not that general purpose computing was a mistake, but that general purpose computing is not necessary and is to some extent counterproductive for the majority of consumers. Consumers moved away from flip phones because they wanted more capable phones, that doesn't mean they largely want capability to the extent of general purpose computing. Consumers will…

> Lay off implications about bad faith You're right, I crossed a line there. From a market perspective, the problem is that in the short term it might be feasible to build a closed, tightly controlled market that rivals open alternatives, but in the long term general purpose computing acts as a safeguard against market capture and anti-consumer behavior -- and to a certain extent, consumers and markets in general are…

General purpose computing is one possible safeguard, it also has pretty big and clear downsides for many consumers and isn't obviously the right choice for most.

And again, the proof is in the pudding. If closed-down markets degrade and become awful over time, the market will eventually reflect and account for that in the future. Long-term consequences eventually materialize into immediate consequences after all. In fact, the market exists to validate lofty claims like yours because history is filled with failed attempts to dictate what people should produce, by minorities like you who believe they know better than the people who buy them.

> I do think it's slightly problematic to assume that users are conscious enough of security to make an educated decision to opt into a locked-down platform, but are not educated enough to avoid flipping a switch in the settings that turns that environment off and on.

This seems pretty obviously true to me. It's quite easy to realize you suck at security, all you need to do is suffer a security breach or know of one. For example, the Windows era taught many users just how insecure they could be, the lessons were pretty simple. Knowing when to disable security guardrails, however, requires actual security knowledge that most users don't have. We know users usually don't have them because Windows tested this with UAC, which users happily and quickly disabled to allow malicious programs that they didn't really evaluate at all; A long and painful case study in "how to let your users choose to fuck themselves".

Of course users don't think about a tradeoff between open access and security, the choice is obvious to them. Security matters and open access doesn't. On the one hand you have the tangible risk of getting your stuff or info stolen, and on the other you have danShumway's nebulous & unproven prophecies of a day that will soon(tm) come where the lack of open access causes stuff to degrade and become awful.

I don't personally make the same tradeoff because open access matters more to me personally, but I think the majority of consumers have made legitimate choices for themselves. They know what they want and have made choices to support their desires, same as you or I, and frankly no one should be able to violate their choices.

Re: Termux no longer updated on Google Play

#265

Earlier quoted context omitted.

Phone manufacturers certainly ought to offer 5+ years of OS updates. Apple does, after all. So I agree with you to that extent. But if users want third parties volunteers to support devices whose vendors have already dropped support? If there are no volunteers wanting to do the work, the work doesn't get done. The bad guys here are the phone vendors, not the Termux developers IMHO.

> The bad guys here are the phone vendors, not the Termux developers IMHO. Here is Termux devs reply to Termux user: > ... Time to upgrade your devices... [0] Who is bad guy here according this quote? P.S. It would not be so bad if devs just says "we don't support such devices", but instead devs declared to upgrade device in reply to user... [0] https://github.com/termux/termux-app/issues/1407#issuecommen...

I'm not seeing a problem there?

I mean, I'll admit its tone is quite direct - I guess they could have copy-pasted some corporate-speak about what a difficult decision it was and how very sorry they were about having to make it, instead of being so direct and unambiguous. But that's pretty trivial IMHO.

Re: Termux no longer updated on Google Play

#266

Earlier quoted context omitted.

No. Beside Android 5.x/6.x devices, I has Symbian 9.x (Nokia N82) smartphone which works perfectly. And there are a lot of new apps for it: - https://old.reddit.com/r/symbian/new P.S. My 10+ year-old laptop perfectly works with latest MX Linux distribution (based on Debian 10 buster ) and all modern FLOSS desktop apps (GIMP, FreeCAD, Inkscape, etc.) works like a charm on it. So, software devs should NOT declare users…

It's an open source project. Feel free to pitch in, sponsor, or shut the fuck up .

> Feel free

And I feel free to tell my personal POV on this situation, as you and everyone else.

Re: Termux no longer updated on Google Play

#267

Earlier quoted context omitted.

Sadly, since January 1st, 2020 Termux team dropped[0] support for Android 5.x/6.x , so actually in F-Droid repo it now requires minimum Android 7.x : > Support for Android 5.x.x - 6.x.x is dropped forever. Time to upgrade your devices or learn how to backport git changes. [1] And this part from Termux devs reply is especially cynical: > ... Time to upgrade your devices... [1] It looks like they has a contract with de…

It is not Termux devs fault that many phone manufacturers fail to handle OS upgrades. They are not obligated to support them, feel free to support all Android versions at once in your project.

> It is not Termux devs fault

This reply to Termux user is Termux devs fault:

> ... Time to upgrade your devices...[0]

[0] https://github.com/termux/termux-app/issues/1407#issuecommen...

Re: Termux no longer updated on Google Play

#268
post #162

Earlier quoted context omitted.

The problem will start with such offerings only if third parties (like employers or banks) demand turning this on. The patronizing of users that started with saftynet is horrifying. I think it will become crucial that some commercialy relevant group uses non play store content. Otherwise the affordance to use non main stream stuff will become higher and higher.

I have a strict "if you want me to use a phone for work, then issue me a work phone" policy. No, I will not install your MDM app on my personal phone, because that is tantamount to surrendering my phone to the company.

My Android's work profile has reasonable isolation. AFAIK my employer can't see or erase anything personal.

Re: Termux no longer updated on Google Play

#269

Quick note: Google's Advanced Protection program disallows sideloading apps, so you can't install F-droid. Edit: Note that the Advanced Protection program is opt-in for users that require the highest degree of security Google can offer. Regular users won't be impacted by this. Edit: proof https://imgur.com/a/yktPNIc Edit 2: see @haunter's comment for a link to the change announcement

> Quick note: Google's Advanced Protection program disallows sideloading apps...

According this rule, all web browsers should be removed from Google Play too, as JavaScript apps (embedded in webpages) are "sideloading apps" by design.

Re: Termux no longer updated on Google Play

#270

Earlier quoted context omitted.

>But those are by far the minority of apps, and it seems crazy to make a pretty massive security tradeoff for something that 99% of apps don't need to do. It also completely eliminates general purpose computing. >One solution might be a special permission to be allowed to do that, but it seems unlikely a user could really make an informed decision. I think the way "Developer Mode" on Android is implemented is pretty…

> It also completely eliminates general purpose computing. The number of people who want general purpose computing on phones is vanishingly small. And since malware is often indistinguishable from general purpose computing, it can be a reasonable product choice.

Not if you want developers to use your product.
Post reply on HN