• 0 Posts
  • 46 Comments
Joined 4 months ago
cake
Cake day: February 13th, 2025

help-circle













  • To answer your top level question:

    If it’s not Linux from Scratch, then we don’t know exactly what is running, and we need to consider that.

    We made rocks think. There’s some trust decisions involved.

    Should I blindly trust every app I find on F-Droid? No. The article correctly lays out reasons why.

    Most of them also apply to Google Play and to Aurora.

    Your decision which to trust depends which threat protections you need the most:

    • Google Play provides stronger protections against people who are trying to run up your credit card through Google Play purchases. Many of the protections cited in the article were developed for this reason. Google Play store apps can fraudulently charge your credit card. But Google works hard to prevent this, with mixed results.

    • Aurora serves the same apps as Google Play and effectively benefits from the same protections.

    • In addition, Aurora adds additional context about malicious corporate behavior. Google has slowly added some, but not all, of these to Google Play. But at the end of the day, Google is being payed to look the other way by some corporations.

    • Like Aurora, F-Droid includes details meant to protect you from abuses by corporations. I would argue that F-Droid’s protections are stronger than even Auroras.

    • F-Droid does not include a method to charge your credit card. This makes a number of security differences in the article much less important, to most people. Of course, there’s more harm that an app can do than credit card charges.

    Because I am aware of many harms caused by individual bad actors and corporations, my preference order goes:

    • F-Droid - Preferred. I find the arguments in the article weak, and a bit out of date. I also feel that F-Droid had dramatically less need for the protections discussed, because there’s no mechanism available to F-Droid apps to run up my debi lt card.
    • Aurora Store - Acceptable. Some useful apps aren’t of F-Droid.
    • Google Play Store - Unacceptable to me. Aurora provides the same apps, but gives me better insights into the privacy impact of each app. Google Play is getting better over time, but the Google team has financial incentives to present trading my privacy for convenience as a good idea.