Live data from Hacker News

Obtainium: Get Android App Updates Directly from the Source

obtainium.imranr.dev

81–90 of 97 posts

Re: Obtainium: Get Android App Updates Directly from the Source

#81
post #70

Earlier quoted context omitted.

What is broken in F-Droid? I just got Android 15 and are using F-Droid but have not noticed anything broken yet.

Crashes on startup. Offers to send a stack trace, which I've done. I've been updating apps manually, which is tedious.

Well I have installed latest APK from their site. Browsed for and installed apps without a problem. On my Pixel 9 Pro. So at least its not a bug affecting everyone.

Re: Obtainium: Get Android App Updates Directly from the Source

#82

Earlier quoted context omitted.

> just as with any app not found in Play Store I would recommend caution with apps from the store too. Not only are many predatory practices not disallowed, outright malware can and does slip through review. The advice is the same as ever when it comes to computers: don't run programs you don't trust, and set your bar of trust high.

Agree, the play store isn't secure one bit. We hear enough story how Google removes legit app without reason, using automated process, to know that there is at least as much malicious app that goes through being undetected.

while your app gets rejected when there is a button that does nothing :D

Re: Obtainium: Get Android App Updates Directly from the Source

#83

I use this and it's great. Only problem is when: 1) you want something outside of github (from my experience, already gitlab and codeberg can be buggy here, although very rarely), and 2) when you need a specific release channel (example: Firefox Beta, which requires a bit of work). But overall it works great. Now, one has to consider the security aspects: stores like Google Play (and, to a lesser extent, F-Droid) do…

For those that have never heard of Accrescent: https://accrescent.app/

Re: Obtainium: Get Android App Updates Directly from the Source

#84
post #35

Finally, a no nonsense Auto-App-Updater App! if only sites would include a version number somewhere on the download page so obtainium could find it. Looking at you https://grayjay.app (it doesn't seem to work for partial file hash either so I had to turn auto updates off for this one) We sorely need 1:1 replacement of app store trust and discovery mechanisms too without any kafka-esque approval hoops. Obtainium app c…

I work for FUTO, does it just need to be somewhere in the Download section? I'll see if I can get this added if so.

No need. Obtainium already supports downloading from third-party F-Droid, so users can add Grayjay this way: 1. Enter the URL "https://app.futo.org/fdroid/repo/" 2. In "Override Source", select "F-Droid Third-Party Repo" 3. For "App ID or Name", enter "grayjay" 4. Press "Add" 5. Done

Reference images: - Add app: https://ibb.co/dL1Hqw6 - Result: https://ibb.co/whmL3PY

Re: Obtainium: Get Android App Updates Directly from the Source

#85
post #29

Earlier quoted context omitted.

Why do you trust it to run code and to install updates from their website but not to execute that update? What’s the threat model there?

You don't see the difference between allowing whatsapp to run, vs allowing whatsapp to install apps? You don't see the difference between allowing a dedicated app installer app written by an author with no other goal and no other source of reputation to install apps, vs allowing a random app to install apps just to hopefully only use that power to keep itself updated and do so in a way that only serves your interests…

I do see a theoretical difference, but in reality there’s no guarantee that they don’t ship AB testing in the ipa/apk and do it at runtime. In fact, everything points to them doing exactly that already. By running a closed source medsenger client with a closed backend service, they have the power to say “WhatsApp off, use messenger now” if they want to- and they don’t need to push a client update to do so. I’m not concerned about meta having root access to my device - they already have access to my contacts for messaging, all ny message data (I’m in Europe, WhatsApp is my default communication method),Bluetooth and WiFi settings because you need it for location stuff. They have the data, and the permissions already. The only thing they can’t do is install another app (which I would have to grant the permissions WhatsApp already has) to do the nasty, but they can just do the nasty in the app I’m already running.

Re: Obtainium: Get Android App Updates Directly from the Source

#86
post #61

Love this app, makes it really easy to keep non-store apps up to date by linking directly to the apps GitHub repo for example. Obviously you have to be careful what you install, just as with any app not found in Play Store, but if you're getting your apps elsewhere anyway this is really convenient.

> Obviously you have to be careful what you install How?

Use F-Droid.

Re: Obtainium: Get Android App Updates Directly from the Source

#87

Earlier quoted context omitted.

Alright, well I don't think I personally know anyone who has ended up with malware on their phone. I'm sure it could be better but it seems alright. I'm not gonna advise everyone I know to stress out about it by trying to have a high bar of trust and evaluate every app they wanna try only to have the exact same result they've had for years. The advice is absolutely not the same as it's always been - it would be weird…

It's not just the outright malware. It's the McDonalds app that sends them a few notifications per day reminding them that they have One Free McFlurry Waiting!, or 5 ad-ridden games they downloaded to play once and now litter their 5th and 6th homescreen, one of which got them to agree to background location tracking. It's the SuperCoolEmojiKeyboard they installed one time 2 years ago because they couldn't figure out…

> McDonalds app that sends them a few notifications per day reminding them that they have One Free McFlurry Waiting!

the mcdonald's app has never sent me a notification

Re: Obtainium: Get Android App Updates Directly from the Source

#90
post #73

Love this app, makes it really easy to keep non-store apps up to date by linking directly to the apps GitHub repo for example. Obviously you have to be careful what you install, just as with any app not found in Play Store, but if you're getting your apps elsewhere anyway this is really convenient.

> Obviously you have to be careful what you install, just as with any app not found in Play Store, but if you're getting your apps elsewhere anyway this is really convenient. Its still a lot more dangerous than the Play store, and I assume a good threat actor can go undetected, but the Play Protect even scans apps that are installed from outside the store.

Disney proved that terms of service and conditions for their media content can be more dangerous than the content they serve.
Post reply on HN