• digger ( digger@lemmy.ca ) 
    link
    fedilink
    arrow-up
    89
    ·
    3 years ago

    Something worth noting is that F-Droid is both an app to download other apps but they also maintains a repository of apps. You can use alternative store apps (like Droid-ify) with the F-Droid repository OR you could use the F-Droid app with a different repository (like IzzyOnDroid). You can mix and match to meet your needs.

    I use the Droid-ify app with the F-Droid, IzzyOnDroid, microG, NewPipe, and Collabora repositories.

    Once you start down this rabbit hole, give Obtanium a look.

      • digger ( digger@lemmy.ca ) 
        link
        fedilink
        arrow-up
        6
        ·
        3 years ago

        On Android, we’re used the “Play Store” being both the app that facilitates downloads as well as the collection of apps available. With F-Droid, you can add additional collections of apps to make available for download.

        You might add an additional repository to gain access to apps not in the main F-Droid repository. You might add a developer’s repository to gain access to updates to their apps before those updates hit the main F-Droid repository.

        Divest is the developer repository for app maintained by Divest OS, a fork of Lineage OS.

      • fulano ( fulano@lemmy.eco.br ) 
        link
        fedilink
        arrow-up
        6
        ·
        3 years ago

        Some software developers prefer to host their own repos and have more control over the release process and/or don’t want to fill all the criteria for being included on f-droid, so they create their own repos. Some of these apps can still be found on vanilla fdroid, but often aren’t updated so frequently.

        Izzyondroid, on the other hand, is a different project, aimed at hosting different apps that are usually from smaller devs and can’t be included on fdroid yet, for different reasons.

        The greatest thing about fdroid is that it allows anyone to create their own repos and you aren’t forced to depend on anyone.

      • digger ( digger@lemmy.ca ) 
        link
        fedilink
        arrow-up
        4
        ·
        3 years ago

        There is safety there, but you’re just as safe using the the developer’s own repository for their apps, like NewPipe, Collabora, or the Guardian Project.

    • Many years ago I tried to go completely de-googled, and that involved using only F-droid. One of the many problems I faced was the tedious update process. I needed to tap each and every app individually every time there were updates. I wonder if droid-ify could have fixed that. Unfortunately I didn’t come across that app at the time, so I didn’t try it out.

      • digger ( digger@lemmy.ca ) 
        link
        fedilink
        arrow-up
        4
        ·
        3 years ago

        Oh for sure! Droid-ify offers a few different installation methods. The Legacy and Session install options are what you are used to. With those methods, you are prompted to download and install with each update.

        With the Root install method, updates can be downloaded and installed in the background using root privileges. Lastly, and I think most intriguing, is using Shizuku. Shizuku is a utility that will give you close to root access using ADB. See link for details. So, with the Shizuku install methods, Droid-ify can keep all your F-Droid apps up to date with little intervention from the user.

        Footnote: Because Shizuku leverages ADB, it needs to be started manually after each reboot.

    • skybox ( skybox@lemm.ee ) 
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 years ago

      Oh THAT’S what repos are for? I assumed they were all independently structured and incompatible with each other for different reasons lmao.

  • qyron ( qyron@sopuli.xyz ) 
    link
    fedilink
    arrow-up
    36
    ·
    3 years ago

    Been using Fdroid to the point where my first boot into a new phone is:

    Open chrome > download fdroid > open settings > uninstall/disable every single application I can > open fdroid > install all the relevant apps I require for making my phone useful

    I’m just waiting for a small life upgrade in order to be able to support some app developers; it will be money better spent than using the standard google apps.

      • It’s insane that I can’t make any steps towards ungoogling myself w/o paying 2.5 times the price of a phone. I can’t buy an allready degoogled pixel here, I can’t buy fairphone here, I can only use a package forwarding service from the US, declare it to customs - and watch them add a monstrous fee to it.

        I wish I could have the courage to buy a pixel and try to replace the OS myself - but I fear I will just brick it…

        • Keith ( kzhe@lemm.ee ) 
          link
          fedilink
          arrow-up
          4
          ·
          3 years ago

          You 99% won’t brick it, I guarantee you. Graphene’s install is really easy. You press a few buttons on a website and never touch a terminal, aside from if you’re on GNOME. As for price, I got a used Pixel 4a 5g for 100 and newer ones won’t be as expensive as the things you might’ve gone for. Try a used Pixel 6a? (Graphene doesn’t extend software support)

        • arc ( arc@lemm.ee ) 
          link
          fedilink
          arrow-up
          2
          ·
          3 years ago

          Bricking is a possibility but for phones that can be unlocked, it should be a matter of following the instructions on Lineageos - unlock the bootloader, flash the recovery partition, flash lineageos + Google apps.

          The biggest pain in the ass for me was trying to get the adb & fastboot tools to talk to the device in the first place. For example OnePlus requires drivers for its devices but Windows doesn’t install them automatically so you have to go find them. Except the adb driver works but the fastboot one didn’t. Then after a bunch of searching it turns out OnePlus forgot to sign the fastboot driver so Windows refused to install it and I had to boot Windows in a convoluted way to disable signature verification to get the driver installed.

          After all that, the rest was relatively straightforward but it still took several hours of effort. IMO Lineageos is a pretty ugly dist but if you install Google Apps it’s not missing anything and it extends the phone’s life beyond what the manufacturer could be bothered to support.

      • qyron ( qyron@sopuli.xyz ) 
        link
        fedilink
        arrow-up
        3
        ·
        3 years ago

        I’ve used so called entry level phones my entire life; I can’t motivate myself to spend the amount a Fair Phone costs, although the concept is appealing and regardless the geek in me going nuts with the idea of tinkering with my phone as I do with my computer. I also prefer rugged phones, which is something most brands don’t cater to.

        My current phone is an Oukitel and has already passed the three year mark, still more than enough for my needs, in great part thanks to my option to run FOSS whenever possible.

        • Possibly linux ( possiblylinux127@lemmy.zip ) OP
          link
          fedilink
          English
          arrow-up
          17
          ·
          3 years ago

          The author of this article completely misses the point of F-droid. They clearly are used to a world of proprietary software that takes “security” over freedom

          So yes I did read the article and no it doesn’t change anything. If your going to make an argument you shouldn’t just link to someone else’s work. Part of the problem with the internet is no one thinks for tuemselves

          • Sure, I’ll spell it out for you since apparently the point went right over your head. Fdroid devs are a single point of failure by signing every application themselves. This introduces a potential for supply chain attack, not to mention Fdroid running on EOL servers.

            When you use an individual dev repo, you can avoid any trojanized apps from Fdroid because the developers maintain their own infrastructure and sign their own apks.

            That’s called… D I S T R I B U T E D T R U S T

            • Captain Beyond ( beyond@linkage.ds8.zone ) 
              link
              fedilink
              arrow-up
              18
              ·
              edit-2
              3 years ago

              The reason F-Droid builds from source is to ensure that they can enforce their inclusion criteria. If you go outside F-Droid you lose that guarantee. For example, self-published apks in github or google play may contain anti-features or proprietary code that are forbidden by the F-Droid standards.

              From another point of view, what you call a single point of failure is a third party that represents the interests of the user community, independent from individual developers. This is the same model used in GNU/Linux distributions, and Drew DeVault explains here the role that software distributions play in the free software community.

              Of course, this represents a trade-off, in that you are placing trust in the software distribution instead of or in addition to the upstream developer. The question is, how can you solve the problem without foregoing F-Droid’s inclusion standards? The answer is reproducible builds, where F-Droid builds from source and compares to the developer’s apk, and publishes the developer’s apk with their signature if the build reproduces successfully.

              Until Reproducible builds are the norm in the Android free software world, I accept the trade-off because I value having software freedom in my computing, and I know I can’t trust upstream developers to care about that as much as F-Droid or I do.

              • Sure, atleast you admit there’s a trade off (security) for (FOSS) and maybe some additional privacy.

                People should be made aware of the risks and choose according to their threat models, which is why I’ve highlighted some of these issues to begin with.

            • Possibly linux ( possiblylinux127@lemmy.zip ) OP
              link
              fedilink
              English
              arrow-up
              3
              ·
              3 years ago

              Everything the F-droid team does is out in the open. Your welcome to audit it once in a while and suggest changes to make it better. I’m sure they wouldn’t mind the help.

              F-droid is the best tool we got. Its not a silver bullet but it is better than anything else I’ve seen

  • lejsh ( lejsh@lemmy.ml ) 
    link
    fedilink
    arrow-up
    17
    ·
    edit-2
    3 years ago

    Are they planning on modernizing the app for Material You? It feels out of place in my phone in 2023.

    edit: all the people who suggested Droid-ify know what’s up. Thanks, guys!

  • limeaide ( limeaide@lemmy.ml ) 
    link
    fedilink
    arrow-up
    13
    ·
    3 years ago

    I know this thread is already a little old, but here is the list of my favorite apps from F-Droid/Izzy. I use a lot of these almost daily and just thought I would share these in case someone might find a new app they find useful

    • Eternity (Infinity for Lemmy)
    • Buckwheat (Budgeting)
    • Aegis (Authentication)
    • Lawnchair (Pixel-like launcher)
    • Quillnotes (Markdown notes app)
    • Forkyz (Crosswords)
    • Geometric Weather
    • Imagepipe (Removes exif data and reduces pics)
    • AntennaPod (Podcast app)
    • Olauncher (Beautiful and minimal text based launcher)
    • qyron ( qyron@sopuli.xyz ) 
      link
      fedilink
      arrow-up
      14
      ·
      3 years ago

      Not really.

      Fdroid is a secure repositorie and the applications are reviewed before being made available for end users.

      The repository is also highly focused on privacy and security and will warn if applications have security flaws or depend on non free services.

      As an example, I use NewPipe instead of the standard YT app and it has a warning it depends on non-free services.

      One other example I can give is Librera. It’s a very feature rich ebook/pdf/etc reader. At some point, a security flaw was discovered and the app was instantly flagged has having such problems and users were advised to not install it.

    • dmrzl ( dmrzl@programming.dev ) 
      link
      fedilink
      arrow-up
      3
      ·
      3 years ago

      What I can tell you is that Google was extremely detailed in their monitoring of my apps - even looking up e.g. rate limits of the steam api to check if I properly deal with those. And I pick that example since I don’t want to talk about the ways I mishandled user data out of negligence or ignorance.

      Back then I perceived it as harassment. Today I will certainly not install any apps that didn’t pass their testing.

      And we’re not even talking about deliberate malware but simple incompetence. I would consider the average hobby app project to be borderline malware and a proper QA needs qualified personnel. I don’t see how F-Droid can ever reach those standards.

      • Play’s reputation for being full of malware stands directly at odds with your assessment.

        Hobbyists are rarely incompetent. They actually take pride in their work, and aren’t just trying to quickly slap something together for a quick buck.

        Not sure what gave you the impression that most phone apps have gone through professional QA, but I very seriously doubt that they have.

        As for mishandling user data, it’s a lot easier to avoid doing that when user data never leaves the user’s device in the first place. Proprietary apps collect user data for profit; free and open source apps often don’t.

    • Even small companies have to deal with, “supply chain”, attacks, criminals putting code into open source repositories to steal data and get access to servers. App stores are major targets too.

      There have been weather apps that need your location to show you weather and oops we also send your location history to our data center in China and sell that data.

      There have been, “document scanner”, apps that help you take pictures of things like credit card statements and did we not mention we send those images to Russian servers?

      Do use a major brand phone like Samsung, keep your OS up to date, and don’t expose private info to these apps or give them special privileges, especially, “accessibility”, or, “screen reader”, and you should be okay.

  • It’s also a buggy piece of crap…
    Update notification? Sweet! Gotta click it, right? Oh, some obscure error message that doesn’t let me update the apps. I guess I start the app itself then, right? Oh, it immediately crashed with an even more obscure error message. And what’s this? It shows me updates for apps that I have already removed. I wonder why? Maybe I should clean the cache and update the repositories. Huh? Oh, the update is stuck somewhere and doesn’t move forward anymore and now I can’t even search for anything.

  • eric ( eric@lemux.minnix.dev ) 
    link
    fedilink
    English
    arrow-up
    6
    ·
    3 years ago

    I can’t use F-Droid without the Play Store but I tend to check there first to see if there is something available there before installing something from the Play Store.

    • chrizbie ( chrizbie@lemmy.nz ) 
      link
      fedilink
      arrow-up
      3
      ·
      3 years ago

      You should check out aurora store on f-droid if you haven’t already, its basically an alternative front end for the play store, which means you can remove your google account from your phone (if you want to)