Live data from Hacker News

Termux no longer updated on Google Play

wiki.termux.com

271–280 of 349 posts

Re: Termux no longer updated on Google Play

#271

Quick note: Google's Advanced Protection program disallows sideloading apps, so you can't install F-droid. Edit: Note that the Advanced Protection program is opt-in for users that require the highest degree of security Google can offer. Regular users won't be impacted by this. Edit: proof https://imgur.com/a/yktPNIc Edit 2: see @haunter's comment for a link to the change announcement

I wonder what the actual numbers are on malware installed via side-loading and malware installed from the play store. There is no shortage of sketchy apps on the play store. Through my personal bias I would imagine that most people side-loading apps tend to be people using F-Droid who know more or less what they're doing. Although I'm sure there are some people who blindly follow sketch website telling them to instal…

[deleted]

Re: Termux no longer updated on Google Play

#272

Earlier quoted context omitted.

> Lay off implications about bad faith You're right, I crossed a line there. From a market perspective, the problem is that in the short term it might be feasible to build a closed, tightly controlled market that rivals open alternatives, but in the long term general purpose computing acts as a safeguard against market capture and anti-consumer behavior -- and to a certain extent, consumers and markets in general are…

General purpose computing is one possible safeguard, it also has pretty big and clear downsides for many consumers and isn't obviously the right choice for most. And again, the proof is in the pudding. If closed-down markets degrade and become awful over time, the market will eventually reflect and account for that in the future. Long-term consequences eventually materialize into immediate consequences after all. In…

> the market will eventually reflect and account for that in the future.

Which won't help unless we're willing to break apart duopolies and enforce government antitrust. The point I'm making is that when you get rid of consumers' ability to solve their own problems, they lose the ability to solve their own problems.

They don't magically get that ability back when the market starts being terrible. Take a look at Amazon's DRM -- it doesn't matter if you as a consumer wake up one day and realize that there are negative consequences to being unable to port your library to any other devices. You still can't do it.

Market capture is not a problem that can be solved by the market on its own, which we've seen repeatedly throughout the history of US markets, including in the computing market.

This is why we have regulations around some of the most egregious anti-free-market activities companies can take. For example, it's illegal to use warranties to block unrelated consumer repairs. Car makers are legally required to use some universal interfaces that allow non-manufacturers to repair and alter the vehicle. And we're currently campaigning to get rid of DMCA restrictions on breaking DRM for legal purposes like porting Kindle books to other platforms. None of that is stuff that consumers on their own would prioritize, but they're market conditions that benefit everyone tremendously. These are instances where the free market can't solve the problem on its own, there have to be legislative changes that allow the market to compete.

And unless you're currently buying stock in Purism or Windows Phone, I think we both know that the current smartphone market is not set up to allow competition.

> which users happily and quickly disabled to allow malicious programs that they didn't really evaluate at all

So what makes you think they didn't? You're assuming that consumers are making a rational choice when they purchase a phone, but not when they use the phone. I don't think people's brains stop working when they turn their devices on, I think that we should apply a consistent framework to understand both people's computing usage and their purchasing decisions.

> Knowing when to disable security guardrails, however, requires actual security knowledge

No, it really doesn't. You can have a big warning that says "this makes your phone insecure" and people don't need to know the details to trust you.

Of course, in practice, people ignore those warnings. But there's two ways to interpret that -- either people don't understand security/access at all and we shouldn't treat any of their purchasing decisions on this with reverence, or people are making a security decision not to trust phone manufactures when they uncheck that box, and we shouldn't shame them for having a different risk model than us.

I object to any attempt to try and characterize them as somehow being both conscious/unconscious of the risks at the same time, there has to be some consistency in how we talk about those people. How do you know that normal users don't just have a separate threat model than you and that they're willing to uncheck that box because they're consciously deciding to tolerate a greater rate of infection/malware than you find acceptable?

Re: Termux no longer updated on Google Play

#273

Earlier quoted context omitted.

> Lay off implications about bad faith You're right, I crossed a line there. From a market perspective, the problem is that in the short term it might be feasible to build a closed, tightly controlled market that rivals open alternatives, but in the long term general purpose computing acts as a safeguard against market capture and anti-consumer behavior -- and to a certain extent, consumers and markets in general are…

General purpose computing is one possible safeguard, it also has pretty big and clear downsides for many consumers and isn't obviously the right choice for most. And again, the proof is in the pudding. If closed-down markets degrade and become awful over time, the market will eventually reflect and account for that in the future. Long-term consequences eventually materialize into immediate consequences after all. In…

> General purpose computing is one possible safeguard, it also has pretty big and clear downsides for many consumers and isn't obviously the right choice for most.

Yes, but isn't it sad if (say) mom and dad have better hardware at their disposal than people who need general purpose computing for their jobs (e.g. scientists, hackers, ...).

Optimizing for the majority is not always a good thing as it can result in bad outcomes for minorities.

Re: Termux no longer updated on Google Play

#274

Earlier quoted context omitted.

I think even when you sum those two quantities it'll still be less than the number of people getting hit by apps from the regular play store.

Likely but not because no filtering at is is better than mediocre filtering rather precisely because it's not easy for a user to "accidentally" side load.

Tons of apps are referencing 100% turing complete web content and not taking flak. NORPS don't "accidentally" side load by means of typing stuff in a terminal that makes them both feel hackerman and scared shitless at the same time. Only boomers and ties believe it's not about anti competitive behavior.

Re: Termux no longer updated on Google Play

#275

Earlier quoted context omitted.

I wonder what the actual numbers are on malware installed via side-loading and malware installed from the play store. There is no shortage of sketchy apps on the play store. Through my personal bias I would imagine that most people side-loading apps tend to be people using F-Droid who know more or less what they're doing. Although I'm sure there are some people who blindly follow sketch website telling them to instal…

There is "people intentionally side-loading", and "people getting social engineered into installing something they shouldn't".

The problem is, it's much easier to be socially engineered into installing something from the Play Store, or far worse, the Chrome Web Store, and both have extremely unchecked amounts of malware.

The real difference is between "apps that have to give Google 30%, and apps that don't".

Re: Termux no longer updated on Google Play

#276

Earlier quoted context omitted.

It is not Termux devs fault that many phone manufacturers fail to handle OS upgrades. They are not obligated to support them, feel free to support all Android versions at once in your project.

Precisely. If you want long-term support, don't use Android in the first place.

Or at least buy phones where at least some support is promised.

Re: Termux no longer updated on Google Play

#277

Earlier quoted context omitted.

It is not Termux devs fault that many phone manufacturers fail to handle OS upgrades. They are not obligated to support them, feel free to support all Android versions at once in your project.

> It is not Termux devs fault This reply to Termux user is Termux devs fault: > ... Time to upgrade your devices... [0] [0] https://github.com/termux/termux-app/issues/1407#issuecommen...

If someone is stuck on Android 6 due to failure to deliver OS updates then it is still fault of whoever manufactured such device.

And a bit of failure to buy something where there are updates.

Re: Termux no longer updated on Google Play

#278

Earlier quoted context omitted.

HN has this fetish for root access. But it's more important to protect dumb users, and script kiddos watching youtube videos for everything, than letting someone do some text operation his smug greybeard (tm) 1970s way. And Google technically allows it, buy a phone with unlockable bootloader.

Why would "dumb" users create a root account on their phone?

By watching a youtube video or worse, strange link on how to make youtube ad free. They aren't hard to mislead.

Re: Termux no longer updated on Google Play

#279
post #65

Earlier quoted context omitted.

Not exactly, it doesn't use "java frameworks". I don't exactly remember Implementation details (has been few years since I fiddled with it). It executes binaries same way as any app can do, there may be some JNI involved in the way you get to shell, but that's it. And what's wrong with it? It may be implementation detail but termux increases utility of the phone. It seems you always have an axe against UNIX / FOSS ec…

I surely have, because it killed desktop inovation, as everyone keeps trying to replicate PDP-11 CLI experience, as termux is a living proof of it. UNIX compatibility is also what keeps C alive, actually. Want a CLI? The Java APIs on Android provide all the required features.

I mean, yes I know Unix and Linux are broken, 50yo and all that but that's still better than nothing.

Re: Termux no longer updated on Google Play

#280

Earlier quoted context omitted.

Note that there are 297 hidden items in that issue so you have to click "Load more..." ceil(297/60) times to read all of the comments about how APK packaging is soon necessary for latest Android devices so the termux package manager can't just dump executable binaries wherever. FWIU: - Android Q+ disallows exec() on anything in $HOME, which is where termux installed binaries that may have been writeable by the execut…

What about development on-the-device? - It seems C compiled with clang on the device wouldn't be executable? (If it was, that would be a way around the restriction: distribute packages as source, like the good old days) > offer users the option of generating an apk wrapping their native code in a usable way. https://github.com/termux/termux-app/issues/1072#issuecommen... This seems a promising solution: compile from…

Unfortunately not. The underlying mechanism they're using to enforce this is essentially: if your app can write to a directory, it can't execute from that directory.

Apparently this is plugs a vulnerability known as W^X. See their explanation in the issue here[0]. Personally I would love to know how many real-world exploits they can blame on this specific vulnerability, stacked up against the number of truly useful apps like Termux that have now been hamstrung.

Also, this leaves the state of running native executables on Android as something of a joke. Any executable you want to run has to be named `lib.so`, and included in your jniLib directory at build time.

It's clear what side GOOG has picked in the war on general-purpose computing[1].

[0]: https://issuetracker.google.com/issues/128554619

[1]: https://www.youtube.com/watch?v=HUEvRyemKSg

Post reply on HN