Repo timestamp expected blah blah... toast coming out of nowhere is such a bad design. Really, the architecture in which you absolutely have to download the multi-MB index is as well.
Yes. F-droid allows that, you can have multiple repositories and ... a few of those even exist :)
I'm using that with 2.0 (or rather with F-droid Basic, but I noticed Basic was updated to the same that is described in article, but a while ago). It works just fine.
Very cool, the visual redesign was very much needed and I had been using Droid-ify for a while because of this. I'll switch back to the official app, congrats to the contributors!
All new code in this effort uses modern Android code standards and designs. This gives us a codebase that is easier to maintain, test, and easier to extend with new features in the future.
No, this increases the overall complexity of the system. Android will hopefully eventually collapse under its own weight.
For people who are die-hard F Droid users, do you get all your apps from it? I have tried in the past but it seemed like even when I restricted my use to basics it was missing things I needed to make my phone feel useful. Wonder if it has gotten better.
Yes, essentially. I do have the Guardian Project repository and I get a handful of applications from the Play Store (via Aurora Store), but everything else comes from F-Droid. If you want even more, you can add the IzzyOnDroid repository[0], but bear in mind that unlike F-Droid, applications are built by developers themselves, and the rules on FOSS-only licensing are less strict.
It did yesterday, for me.
Sometimes it doesn't work for a while and the dev needs some time catching up to what Google deliberately or inadvertently or indifferently put in the way of access to the place where apps are published (and they are published there, not because app creators deliberately chose Google out of many app distributors in some healthy competitive market; there is no choice).
The Aurora project accepts donations, if you want to hurry things along some time! And they have a donation button right there in the app listing, try doing that for yourapp in the PlayStore and see who comes knocking in 3...2..1 to make you a non-person.
What do you find is missing? The main apps I need Google Play for are apps that are tied to a specific company or government service (eg, banking apps, or HMRC). For pretty much all basic functions I think F-Droid does the job.
No... I use a combination of Aurora, Obtainium and F-Droid.
Unfortunately there are APP providers actively preventing their apps to work on graphene OS, so i own an extra use@home cheap broken glass iphone for these mandatory but non-graphene apps.
It is a pain and it is getting worse... I'm really tempted to get back to the Apple ecosystem for less shens but currently i cannot do this yet... It just feels wrong but the pain is real. I'm Lösung the fight of investing too mich of my time in things that just should work.
I wouldn't use F-Droid exclusively. Many apps can simply be downloaded from their respective webpages. GrapheneOS also has also its own very basic app store.
FDroid offers the guarantee that the apk was built from source, and at least some marginal safety in terms of having passed their security and analytics/ads checkers.
Obtainium makes it easy to download apps directly from their webpages. Many of them have ready configurations you can simply add: https://apps.obtainium.imranr.dev/
It is not my main device, nor even my secondary device. It’s basically just a device I bought for cheap hoping that maybe I was lucky and it was actually pretty snappy. It’s not snappy :(
I occasionally watch a couple of YouTube videos on it and read a couple of HN posts on it, when my phone is out of battery or when I’m doing a backup of my phone and have left the phone on the table for that.
Anyway, aside from YouTube the other apps I have installed on it myself are all from F-Droid, including the DuckDuckGo browser that I use on it. I also have Signal on it, which I don’t remember if I installed from F-Droid or from Google Play.
My main device that I actually use a lot is an iPhone. And like I said I basically only use the tablet like a couple of hours a week and only to watch a couple of YouTube videos and read a couple HN threads, when I am not able to use my phone for those things.
Most of them, yeah. My main non-F-Droid apps are YT-Music, Google Maps, Duo auth, Bible, and my bank app. Firefox, podcasts, local music player, ebook reader, RSS reader, email client, Matrix client, XMPP client, audiobook player, calendar sync, KeePassDX, SyncThing, Nix terminal, etc are all F-Droid.
I use droid-ify as frontend; and it's been fine to use f-droid repos for most of my needs. I try to install my apps from there in general. Biggest issue for me is android auto capability usually requires the app to be installed from play store (CoMaps) and my music player app (GoneMAD) has a companion unlocker that is from paid app store.
I need banking and bunch of vendor related apps. I need play store for them; so not full on f-droid repos. But close-ish when it comes to phone functionality.
When I need some category of app - say a note app or an audiobook player - I generally check F-Droid first.
If there's a good enough app on there, I generally stick with that as opposed to trying what Google Play has to offer.
I like having that prefiltering, knowing that the app will be open source, not trying to pull anything shady and not have ads or sell my data. On the Play Store, more often than not, at least one of those is not true.
Similar experience for me. I find f-droid a great supplement store but cutting out the default store entirely has felt like more of a commitment than I'm interested in so far.
No I have Obtainium side by side with F-Droid. There are some closed source apps or apps that are not published on F-Droid (like Wireguard) that unfortunately I need. Obtainium is great for that.
Fossify Clock has the best accidental feature: when your alarm is going off, there's no way to stop it except for unlocking your phone, opening the app, finding the current alarm in the list of alarms, and disabling it.
Also, F-Droid Privileged Extension (FPE) is not currently supported by 2.0. That means even if FPE is installed, F-Droid 2.0 won’t use it. This overhaul focused on full featured support for the Android “session” installer. That lets F-Droid run background updates on any recent Android version without requiring FPE. Like with any of the changes here, we welcome feedback.
This is a shame. Is the privileged extension a large maintenance burden?
I have been using droid-ify on GrapheneOS for a few years now; because F-Droid ui is terrible, and the privilege extention has been such a pain to configure and get working without issues on my previous lineageOS phone. Happy to see this major overhaul; and i'm glad the FPE is being phased out.
I tried Neostore. All the info it shows is pretty cool, but ultimately I felt the expierence suffered from all the extra information shown compared to the simpler UI in Droid-ify.
The other way is to use fdroid as source within obtainium.
The benefit is to maintain app list at one place, so you can export/import to another device, when needed.
I tried it with 3 random apps for a while, but instantly got into issues. Two stopped updating due to Obtanium falling behind how app releases - for instance, developer changed version numbering scheme but Obtanium didn't expect that, so an outdated version was always presented. It wasn't fixed for quite a while.
I have 23 currently. It's surprising how fast it happened... I don't have any problems, but I don't pay much attention to it and apps seem to update automatically sometimes and after a manual refresh other times.
I've found Droid-ify more reliable at doing background updates, though it still only manages it sometimes (possibly due in some way to how I installed the apps). Hopefully Fdroid's app will be better at this.
I tried Obtainium a while back and didn't like it too much, finding apps seemed difficult.
Then I discovered https://apps.obtainium.imranr.dev/ which makes it very easy. I feel like Obtainium should make this more obvious. It would help adoption a lot.
Fwiw, that link is documented in the readme at https://github.com/ImranR98/Obtainium so it's not hard for someone to find again. It's also prominent in the Obtainium app UI itself.
I use F-Droid precisely because I don't want that. When https://news.ycombinator.com/item?id=38505229 happened - and when the same thing happens again in the future, because it will - I explicitly want F-Droid doing some basic due diligence on updates before shipping them to me. Cutting out the middleman is the opposite of what I want.
Counterpoint: I use NewPipe pretty much daily for watching YouTube. One day, YT introduced an API change that broke NewPipe, and so I patiently waited for an update.
A few days passed, and I eventually get a notification from NewPipe prompting for an update. But I can't install it just yet, because of mismatching signatures between the F-Droid and GitHub versions (yes, that's the point, I know...). The F-Droid build took so long to release, that in the meantime, another version of NewPipe came out...
True. And especially for that use, I can imagine that the slow return around is actually a breaking problem. I think there are relatively few apps that need that kind of quick update, and I'm more concerned with malicious authors than that, but it would depend on precisely what you need out of your apps.
Notably, this is still cutting out the middleman and bypassing the extra review that that entails. It's fine as long as you trust everybody involved in publishing the repo, which is probably fine here, but a thing to keep in mind.
This issue happens to some extent within liunux distros too. I think specifically for youtube maybe it would be beneficial for a single core library that deals with the API and is shared by every single project that cares to interface with youtube. Rather than dozens of projects trying to chase youtube changes and overburdening repository maintainers, there would only be a single library whose updates would be fast tracked. This also requires there to be no embedding it in anything too, I don't know how feasible this would be on android/f-droid, but it kinda already happens with yt-dlp in linux distros, but yt-dlp isn't a proper library nor does it deals with all youtube endpoints that a proper youtube frontend would require.
It would perhaps be nice if yt-dlp could eject it's youtube api handling into it's own project that is then augmented to handle anything youtube related and turns into THE library for dealing with youtube.. maybe even call it libyt :)
I've never actually had this issue, for whatever reason. In-app updates to NewPipe (and the various forks) install just fine even if I originally downloaded from F-Droid. Not sure how that works exactly.
Dear F-Droud, please stop redirecting me to the Mandarin version automatically without an option to read the original message. Just because I have a Chinese keyboard layout available.
Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
If the issue Google has with sideloading is really just the rampant app piracy (and the malware that comes with cracked apps) that might be something F-Droid can accomodate.
I don't think malware is the problem, as most malware comes directly via Google's ecosystem carried by ads. Just recently I had to uninstall some app from the play store since it tried to distribute malware through scary pop-ups and had it replaced with something from f-droid for someone I know.
most malware comes directly via Google's ecosystem carried by ads.
Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google.
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
The world may not of ended but to of people have been hurt by malware ruining their computer, cryptolocking all of their company's files for ransom, stealing all of your login credentials, stealing cryptocurrency, taking secret photos with your webcam, screen recording what you are doing on your computer, etc.
The "personal computer" has a terrible track record.
a device that holds your entire life, bank info, photos, etc.
I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc.
I'm not sure the situations are comparable when Windows doesn't have this permission system where the apps are still very limited in what they can access unless you grant specific directory access or access to the contact list or such
The Emacs version for Android makes uses of something like this IIRC by signing a version of Termux with the same key and distributing it in the same SourceForge repo such that Emacs on Android can access CLI tooling like git for example.
Isn't it possible, however complicated, for users to undo the lockdown to install an app? The required 9 steps are noted at https://keepandroidopen.org/ for devices that use Google Play Services.
Irrespective, people should probably be migrating to a GrapheneOS or similar OS asap once the OS ships with a device.
Currently, switching to GrapheneOS means giving Google money. Next year's Motorola-based alternative is also likely going to be several price classes above the Pixels you can currently put GrapheneOS on.
Then buy a Pixel second-hand or when they hit rock-bottom prices, which usually happens after 6 months or so. At some point Google is probably not making a lot of profit from the devices anymore and they want to sell it to you for tracking and to sell Google One subscriptions, which are mostly irrelevant if you use GrapheneOS.
I followed Pixel prices for the last year, and rock-bottom for a 256gb version (the current absolute minimum for a device without an sd, to my eyes) meant 450€.
There are occasional good deals for (unused) older models on eBay, but they're surprisingly rare.
I wonder if Google demands stores to give the old models back, after the release of newer ones; they disappear from every store extremely quickly.
Updates on this have been slowly trickling out and the best I can discern is you will be able to still install apps from stores like F-Droid, but you have to go through a manual "advanced flow" which will most likely make you wait 24 hours before installing it and make you go through other hoops.
In short, google has referred to this as "increased user friction" to try and deter people from doing this. Essentially not making it impossible; just really frustrating for users so they get sick of the process and just install verified apps through them.
The only way I know around this is to install a custom rom like GrapheneOS or Lineage OS since this change targets Because the policy targets the Google Mobile Services (GMS) framework rather than the foundational Android Open Source Project (AOSP).
It seems google is going to allow an "advanced flow" that is scam resistant by requiring the user to wait 24 hours before they can start installing their own apps. It sucks, but assuming they don't change the plan again, F-Droid should be able to continue working.
The current lockdown plan is that you'll need to wait 24 hours before installing the first unauthorized app, right? So probably exactly the same as it is now except setting up a phone will take 24 hours longer.
Because nobody uses it except a handful of uber-nerds who can put up with wasting hours of time for "altruism".
The answer to freedom isn't another marketplace. It's legislation that requires Google and Apple to allow web installs without scare walls or deeply hidden permission toggles.
You should be able to just download an app. And Grandma should be able to do it.
There's nothing insecure about it in a world of sandboxing, permissions, scanning, blacklisting, etc. When the tech giants are more than happy to sell ads to malware, you know their "safety" stance is just economic moat protectionism.
---
Edit because of rate limits:
This is not derogatory. This is making the point that the wrong battle is being fought. F-droid fans are cheering a small victory, yet losing the entire war.
F-droid does not matter in the grand scheme of things. It's not the point. The point is the app store monopoly. That there are only two platforms and that both are almost completely locked down.
F-droid users don't even see that Google is purposefully allowing this as an antitrust sponge in their calculus. Google doesn't mind because 0.0001% of their users will install this. If they had a sense that the regulators wouldn't bother them, they'd just as well close this loophole. And they probably will eventually.
This isn't beachhead, and even if it was, it isn't sound footing or a stable foundation. It can easily go away.
Because nobody uses it except a handful of uber-nerds who can put up with wasting hours of time for "altruism".
What? I'm not sure how you would manage to waste hours installing a single app and then using it to install other apps, and I'm not using it because of "altruism" (what does that even mean?), I'm using it because it's the best way to get apps.
You should be able to just download an app. And Grandma should be able to do it.
There's nothing insecure about it in a world of sandboxing, permissions, scanning, blacklisting, etc. When the tech giants are more than happy to sell ads to malware, you know their "safety" stance is just economic moat protectionism.
Even if you 100% trust Android's sandboxing and permissions, which is... not a choice I would personally make, I like it when my apps don't have scams or ads internally, either. I'm not worried about Grandma downloading any app off F-Droid; I am a little concerned about what happens if she can download any app being pushed by any random website.
Can't you at least see and file issues and discussions on the respective app's code repo site? This is often although not always sufficient, as the repo owner can censor issues and discussions.
Google has for years censored app reviews anyway on its Play Store, and also allowed too many low-value reviews which drown out useful reviews.
In addition to F-Droid on the device, I'd love an F-Droid "package manager client" on a computer, that allows installing apps on an Android device via adb:
# update repo lists
fdr update
# upgrade all apps on the connected device
fdr upgrade
# search packages
fdr search vlc # lists org.videolan.vlc
# install on the device
fdr install org.mozilla.firefox
# download the apk
fdr download org.mozilla.firefox
# uninstall
fdr uninstall org.mozilla.firefox
Of course, all operations would verify the signatures first.
Amazing news! I mainly use the F-droid Basic version which does automatic updating of apps. The regular one needs user confirmation for updates if I remember correctly.
Can someone recommend a good F/OSS ebook reader on F-Droid? The existing ones I have tested have too many knobs and options and are not really user-friendly.... My wife started to get into reading, but I could not get her to get out of the Kindle/Play Books ecosystem because of the user-friendliness and easy synchronisation across devices that Kindle gives.
Koreader interface with syncthing is not that user friendly to non techs, very powerful can do anything but i don't think i would advise that to non techie
To add to this, since the original comment mentioned kindle, you can jailbreak many of the models and install KOReader in them if you want to keep using the hardware.
GrapheneOS security complaints about F-Droid are a load of nonsense except for one: the APK on the website is signed by a different key from the one that F-Droid updates itself with.
I hope the new redesign makes the store easier to navigate on TVs. It's a nightmare trying to install/update apps on F-Droid on either my Nvidia Shield Pro or my Onn 4K TV using the tv remote. The cursor gets lost all the time and it's often impossible to see what option is currently in focus when you click Ok on the remote.
Not any super user but about three/four months, I'm using my device without any google account. Also not using any G service apps such as mail/yt/maps and of course play store. Instead of play store I found aurora store very helpful. "Very" because of the anonymous login future. But sometimes the store disturbs. Newly added apps on Play store doesn't appears on aurora. Also many applications fails to be installed without showing any reason. Some shitty apps redirect to the play store app (which I'm unable to disable but uninstalled her! Updates) and just doesn't works anything more then redirecting me. So I'm still not a fan of Aurora. But it's going not bad. But sometimes I should browse other sites to get old/delated from Play store apps. Also for mod/adless version of some apps.
I heard of fdriod but what I think it may only serves feature less, low UI/UX optimized apps. So didn't installed it yet. But something should be available where people can find all Play store apps (as aurora supplies) + premium/adsense deleted modified apps (random website) + Open source apps (fdroid)…… this will make android insane
This is very good to see. Classic F-Droid always seemed to fail at updating repos at least every week or so.
Repo timestamp expected blah blah... toast coming out of nowhere is such a bad design. Really, the architecture in which you absolutely have to download the multi-MB index is as well.
The official page still downloads 1.23.2. I wonder when this will go live, and if the old app will auto-update.
Try F-Droid basic, it has this for a few weeks.
That page uses the term ''repository''' singular. Can additional repos be added in the way Neo Store allows?
Yes. F-droid allows that, you can have multiple repositories and ... a few of those even exist :)
I'm using that with 2.0 (or rather with F-droid Basic, but I noticed Basic was updated to the same that is described in article, but a while ago). It works just fine.
It's always been possible on F-Droid, I doubt they would change something like that.
Very cool, the visual redesign was very much needed and I had been using Droid-ify for a while because of this. I'll switch back to the official app, congrats to the contributors!
No, this increases the overall complexity of the system. Android will hopefully eventually collapse under its own weight.
Once GrapheneOS ships on devices, it and Samsung can in time pick up where Android stops.
If only they improve the AndroidTV experience a bit
For people who are die-hard F Droid users, do you get all your apps from it? I have tried in the past but it seemed like even when I restricted my use to basics it was missing things I needed to make my phone feel useful. Wonder if it has gotten better.
I do, but then there is aurora store on f-droid for the gplay only apps.
Note it doesn't work very well, and Graphene recommends using Graphene's sandboxed Play Store instead.
Yes, essentially. I do have the Guardian Project repository and I get a handful of applications from the Play Store (via Aurora Store), but everything else comes from F-Droid. If you want even more, you can add the IzzyOnDroid repository[0], but bear in mind that unlike F-Droid, applications are built by developers themselves, and the rules on FOSS-only licensing are less strict.
[0]: https://apt.izzysoft.de/fdroid/
does Aurora still work? Last few times I tried, I couldn't install anything.
Last used yesterday found no problem to install random application.
It did yesterday, for me. Sometimes it doesn't work for a while and the dev needs some time catching up to what Google deliberately or inadvertently or indifferently put in the way of access to the place where apps are published (and they are published there, not because app creators deliberately chose Google out of many app distributors in some healthy competitive market; there is no choice).
The Aurora project accepts donations, if you want to hurry things along some time! And they have a donation button right there in the app listing, try doing that for yourapp in the PlayStore and see who comes knocking in 3...2..1 to make you a non-person.
What do you find is missing? The main apps I need Google Play for are apps that are tied to a specific company or government service (eg, banking apps, or HMRC). For pretty much all basic functions I think F-Droid does the job.
No... I use a combination of Aurora, Obtainium and F-Droid.
Unfortunately there are APP providers actively preventing their apps to work on graphene OS, so i own an extra use@home cheap broken glass iphone for these mandatory but non-graphene apps.
It is a pain and it is getting worse... I'm really tempted to get back to the Apple ecosystem for less shens but currently i cannot do this yet... It just feels wrong but the pain is real. I'm Lösung the fight of investing too mich of my time in things that just should work.
I wouldn't use F-Droid exclusively. Many apps can simply be downloaded from their respective webpages. GrapheneOS also has also its own very basic app store.
FDroid offers the guarantee that the apk was built from source, and at least some marginal safety in terms of having passed their security and analytics/ads checkers.
You lose all that if you go directly to source.
Obtainium makes it easy to download apps directly from their webpages. Many of them have ready configurations you can simply add: https://apps.obtainium.imranr.dev/
I have a slow, crappy tablet I bought on Temu.
It is not my main device, nor even my secondary device. It’s basically just a device I bought for cheap hoping that maybe I was lucky and it was actually pretty snappy. It’s not snappy :(
I occasionally watch a couple of YouTube videos on it and read a couple of HN posts on it, when my phone is out of battery or when I’m doing a backup of my phone and have left the phone on the table for that.
Anyway, aside from YouTube the other apps I have installed on it myself are all from F-Droid, including the DuckDuckGo browser that I use on it. I also have Signal on it, which I don’t remember if I installed from F-Droid or from Google Play.
My main device that I actually use a lot is an iPhone. And like I said I basically only use the tablet like a couple of hours a week and only to watch a couple of YouTube videos and read a couple HN threads, when I am not able to use my phone for those things.
Most of them, yeah. My main non-F-Droid apps are YT-Music, Google Maps, Duo auth, Bible, and my bank app. Firefox, podcasts, local music player, ebook reader, RSS reader, email client, Matrix client, XMPP client, audiobook player, calendar sync, KeePassDX, SyncThing, Nix terminal, etc are all F-Droid.
I use droid-ify as frontend; and it's been fine to use f-droid repos for most of my needs. I try to install my apps from there in general. Biggest issue for me is android auto capability usually requires the app to be installed from play store (CoMaps) and my music player app (GoneMAD) has a companion unlocker that is from paid app store.
I need banking and bunch of vendor related apps. I need play store for them; so not full on f-droid repos. But close-ish when it comes to phone functionality.
When I need some category of app - say a note app or an audiobook player - I generally check F-Droid first.
If there's a good enough app on there, I generally stick with that as opposed to trying what Google Play has to offer.
I like having that prefiltering, knowing that the app will be open source, not trying to pull anything shady and not have ads or sell my data. On the Play Store, more often than not, at least one of those is not true.
Similar experience for me. I find f-droid a great supplement store but cutting out the default store entirely has felt like more of a commitment than I'm interested in so far.
No I have Obtainium side by side with F-Droid. There are some closed source apps or apps that are not published on F-Droid (like Wireguard) that unfortunately I need. Obtainium is great for that.
What features does the wireguard app have that alternatives like WG Tunnel or KabelWacht lack?
I didn't know those apps existed.
Fossify Clock has the best accidental feature: when your alarm is going off, there's no way to stop it except for unlocking your phone, opening the app, finding the current alarm in the list of alarms, and disabling it.
This means you're definitely awake.
I'm being sarcastic.
This is a shame. Is the privileged extension a large maintenance burden?
Are you stuck on an older android version?
not the person you replied to, but i'm staying on Android 8 and 11 as long as i can.
I wonder how they got access to the ordinarily Google-locked "session" installer. Did Google open it up because of EU rules? I doubt it.
I have been using droid-ify on GrapheneOS for a few years now; because F-Droid ui is terrible, and the privilege extention has been such a pain to configure and get working without issues on my previous lineageOS phone. Happy to see this major overhaul; and i'm glad the FPE is being phased out.
After 10 years of F-droid, I'm bummed I only found droid-ify a couple of months ago. Sooo much better than F-droid.
Check out Neostore too. You'll love it.
There's also Aurora Droid, last time I checked.
I tried Neostore. All the info it shows is pretty cool, but ultimately I felt the expierence suffered from all the extra information shown compared to the simpler UI in Droid-ify.
There's also F-Droid Classic. For me Droid-ify never felt quite right + it never worked properly with unattended updates, for me at least.
Cool! Unfortunately I switched to Obtanium a year or so ago. I get all my apps from GitHub releases straight from the developers now.
What do you do for apps that don't have GitHub releases?
You can use it with non-github releases too, but it's super rare when one isn't available. In the case when Obtanium doesn't work, I just use F-Droid.
The other way is to use fdroid as source within obtainium. The benefit is to maintain app list at one place, so you can export/import to another device, when needed.
https://apps.obtainium.imranr.dev/ has plenty of apps that don't have F-Droid releases. Many of them come from the developers own website.
And if you see anything is missing, you can always add it!
Do you use a lot of apps with that?
I tried it with 3 random apps for a while, but instantly got into issues. Two stopped updating due to Obtanium falling behind how app releases - for instance, developer changed version numbering scheme but Obtanium didn't expect that, so an outdated version was always presented. It wasn't fixed for quite a while.
I have 23 currently. It's surprising how fast it happened... I don't have any problems, but I don't pay much attention to it and apps seem to update automatically sometimes and after a manual refresh other times.
I've found Droid-ify more reliable at doing background updates, though it still only manages it sometimes (possibly due in some way to how I installed the apps). Hopefully Fdroid's app will be better at this.
Didnt know this! Thanks for sharing !!
The update turnover is so fast for certain apps that I switched back to Fdroid.
Same for me. I typically search on F-Droid to find the apps and then add the github to Obtanium.
I tried Obtainium a while back and didn't like it too much, finding apps seemed difficult.
Then I discovered https://apps.obtainium.imranr.dev/ which makes it very easy. I feel like Obtainium should make this more obvious. It would help adoption a lot.
Fwiw, that link is documented in the readme at https://github.com/ImranR98/Obtainium so it's not hard for someone to find again. It's also prominent in the Obtainium app UI itself.
I know it is there in Obtainium, but I don't think it's prominent enough and it is easy to miss. I missed it my first time.
I use F-Droid precisely because I don't want that. When https://news.ycombinator.com/item?id=38505229 happened - and when the same thing happens again in the future, because it will - I explicitly want F-Droid doing some basic due diligence on updates before shipping them to me. Cutting out the middleman is the opposite of what I want.
Counterpoint: I use NewPipe pretty much daily for watching YouTube. One day, YT introduced an API change that broke NewPipe, and so I patiently waited for an update.
A few days passed, and I eventually get a notification from NewPipe prompting for an update. But I can't install it just yet, because of mismatching signatures between the F-Droid and GitHub versions (yes, that's the point, I know...). The F-Droid build took so long to release, that in the meantime, another version of NewPipe came out...
True. And especially for that use, I can imagine that the slow return around is actually a breaking problem. I think there are relatively few apps that need that kind of quick update, and I'm more concerned with malicious authors than that, but it would depend on precisely what you need out of your apps.
Have you added the NewPipe repo in F-Droid? I get updates this way pretty quickly.
https://newpipe.net/FAQ/tutorials/install-add-fdroid-repo/
Notably, this is still cutting out the middleman and bypassing the extra review that that entails. It's fine as long as you trust everybody involved in publishing the repo, which is probably fine here, but a thing to keep in mind.
This issue happens to some extent within liunux distros too. I think specifically for youtube maybe it would be beneficial for a single core library that deals with the API and is shared by every single project that cares to interface with youtube. Rather than dozens of projects trying to chase youtube changes and overburdening repository maintainers, there would only be a single library whose updates would be fast tracked. This also requires there to be no embedding it in anything too, I don't know how feasible this would be on android/f-droid, but it kinda already happens with yt-dlp in linux distros, but yt-dlp isn't a proper library nor does it deals with all youtube endpoints that a proper youtube frontend would require.
It would perhaps be nice if yt-dlp could eject it's youtube api handling into it's own project that is then augmented to handle anything youtube related and turns into THE library for dealing with youtube.. maybe even call it libyt :)
I've never actually had this issue, for whatever reason. In-app updates to NewPipe (and the various forks) install just fine even if I originally downloaded from F-Droid. Not sure how that works exactly.
Same, Obtanium is great.
Dear F-Droud, please stop redirecting me to the Mandarin version automatically without an option to read the original message. Just because I have a Chinese keyboard layout available.
What Accept-Language header are you sending?
Not sure, it happened on mobile Firefox. My point is that there should be a way to disable it and switch to a different language manually.
What does the future of something like F-Droid look like once Google does their lock down next year?
Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
If the issue Google has with sideloading is really just the rampant app piracy (and the malware that comes with cracked apps) that might be something F-Droid can accomodate.
I don't think malware is the problem, as most malware comes directly via Google's ecosystem carried by ads. Just recently I had to uninstall some app from the play store since it tried to distribute malware through scary pop-ups and had it replaced with something from f-droid for someone I know.
Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google.
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
Block installs outside of playstore ON/OFF (ON by default) isn't any less secure. "Sideloading" is scaremongering.
That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.
The world may not of ended but to of people have been hurt by malware ruining their computer, cryptolocking all of their company's files for ransom, stealing all of your login credentials, stealing cryptocurrency, taking secret photos with your webcam, screen recording what you are doing on your computer, etc.
The "personal computer" has a terrible track record.
That seems to happen on phones too
Just like people get robbed, it is as common as that.
It doesn't mean one can't buy nice things because one is afraid of being robbed.
I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc.
That means education for people: don't perform actions that are in emails.
Blocking apps is like blocking buying of knifes because one can hurt themselves.
Because education has worked so well on Windows.
There's not an easy answer, but the non-answer of "people just need to be educated" is trivially dismissed.
I'm not sure the situations are comparable when Windows doesn't have this permission system where the apps are still very limited in what they can access unless you grant specific directory access or access to the contact list or such
Fully agree. Installing software is installing software, signed or unsigned, app store or not.
They have to use one key per app, otherwise independent app could end up sharing some permissions (IIRC).
The Emacs version for Android makes uses of something like this IIRC by signing a version of Termux with the same key and distributing it in the same SourceForge repo such that Emacs on Android can access CLI tooling like git for example.
Isn't it possible, however complicated, for users to undo the lockdown to install an app? The required 9 steps are noted at https://keepandroidopen.org/ for devices that use Google Play Services.
Irrespective, people should probably be migrating to a GrapheneOS or similar OS asap once the OS ships with a device.
Ah this is good to know. Awful it's required, but glad there is a work around.
no root on graphene, non starter
Switch to GrapheneOS or HarmonyOS
Currently, switching to GrapheneOS means giving Google money. Next year's Motorola-based alternative is also likely going to be several price classes above the Pixels you can currently put GrapheneOS on.
Then buy a Pixel second-hand or when they hit rock-bottom prices, which usually happens after 6 months or so. At some point Google is probably not making a lot of profit from the devices anymore and they want to sell it to you for tracking and to sell Google One subscriptions, which are mostly irrelevant if you use GrapheneOS.
I followed Pixel prices for the last year, and rock-bottom for a 256gb version (the current absolute minimum for a device without an sd, to my eyes) meant 450€.
There are occasional good deals for (unused) older models on eBay, but they're surprisingly rare.
I wonder if Google demands stores to give the old models back, after the release of newer ones; they disappear from every store extremely quickly.
I don't want to pay more than $150 for a phone, though. And installing an alternate OS is a real hassle.
If the current $500 pixels are too expensive you're going to hate the $1000 motorolas.
Not really, GrapheneOS has a nice web installer that makes all the job for the user.
Alternative app stores are mandated atleast here in the EU I believe?
Yes but the process to enforce it is intentionally so difficult that nobody can do it.
Updates on this have been slowly trickling out and the best I can discern is you will be able to still install apps from stores like F-Droid, but you have to go through a manual "advanced flow" which will most likely make you wait 24 hours before installing it and make you go through other hoops.
In short, google has referred to this as "increased user friction" to try and deter people from doing this. Essentially not making it impossible; just really frustrating for users so they get sick of the process and just install verified apps through them.
The only way I know around this is to install a custom rom like GrapheneOS or Lineage OS since this change targets Because the policy targets the Google Mobile Services (GMS) framework rather than the foundational Android Open Source Project (AOSP).
Wait, it's not 24 hours per app though, is it? Isn't it 24 hours before the "allow installing apps from .apks" setting turns on once and for all?
If I'm a developer I also need to wait 24hrs to test my app?
It seems google is going to allow an "advanced flow" that is scam resistant by requiring the user to wait 24 hours before they can start installing their own apps. It sucks, but assuming they don't change the plan again, F-Droid should be able to continue working.
The current lockdown plan is that you'll need to wait 24 hours before installing the first unauthorized app, right? So probably exactly the same as it is now except setting up a phone will take 24 hours longer.
And still no popularity rating, download count or any user review system whatsoever.
Because nobody uses it except a handful of uber-nerds who can put up with wasting hours of time for "altruism".
The answer to freedom isn't another marketplace. It's legislation that requires Google and Apple to allow web installs without scare walls or deeply hidden permission toggles.
You should be able to just download an app. And Grandma should be able to do it.
There's nothing insecure about it in a world of sandboxing, permissions, scanning, blacklisting, etc. When the tech giants are more than happy to sell ads to malware, you know their "safety" stance is just economic moat protectionism.
---
Edit because of rate limits:
This is not derogatory. This is making the point that the wrong battle is being fought. F-droid fans are cheering a small victory, yet losing the entire war.
F-droid does not matter in the grand scheme of things. It's not the point. The point is the app store monopoly. That there are only two platforms and that both are almost completely locked down.
F-droid users don't even see that Google is purposefully allowing this as an antitrust sponge in their calculus. Google doesn't mind because 0.0001% of their users will install this. If they had a sense that the regulators wouldn't bother them, they'd just as well close this loophole. And they probably will eventually.
This isn't beachhead, and even if it was, it isn't sound footing or a stable foundation. It can easily go away.
This seems weirdly derogatory towards people that use F-Droid.
As an F-Droid user for idk how many years now, I'd say it's spot on!
Really? I don't understand
at all. I feel like I install apps from the store, and use them. So I'm confused by both "hours of time" and "altruism".
What? I'm not sure how you would manage to waste hours installing a single app and then using it to install other apps, and I'm not using it because of "altruism" (what does that even mean?), I'm using it because it's the best way to get apps.
Even if you 100% trust Android's sandboxing and permissions, which is... not a choice I would personally make, I like it when my apps don't have scams or ads internally, either. I'm not worried about Grandma downloading any app off F-Droid; I am a little concerned about what happens if she can download any app being pushed by any random website.
Can't you at least see and file issues and discussions on the respective app's code repo site? This is often although not always sufficient, as the repo owner can censor issues and discussions.
Google has for years censored app reviews anyway on its Play Store, and also allowed too many low-value reviews which drown out useful reviews.
Except the 2.0 does have a most popular apps section.
In addition to F-Droid on the device, I'd love an F-Droid "package manager client" on a computer, that allows installing apps on an Android device via adb:
Of course, all operations would verify the signatures first.
Like https://github.com/Hoverth/fdroidcl ? :)
Amazing news! I mainly use the F-droid Basic version which does automatic updating of apps. The regular one needs user confirmation for updates if I remember correctly.
I wish they would add ratings or even just comments
It's nice to see F-Droid going places.
Great visual and usability update.
Even greater HN conversation about all the to-me-unknown alternatives. I used neostore as a replacement, but maybe time to try f-Droid again
502 Bad Gateway
https://web.archive.org/web/20260924152713/https://f-droid.o...
Urgh such a shame to be written by LLM
Can someone recommend a good F/OSS ebook reader on F-Droid? The existing ones I have tested have too many knobs and options and are not really user-friendly.... My wife started to get into reading, but I could not get her to get out of the Kindle/Play Books ecosystem because of the user-friendliness and easy synchronisation across devices that Kindle gives.
KOReader [1] is my favorite reader. Pairs well with my syncthing library of ebooks (I just keep the phone's copy in read-only mode).
[1] https://f-droid.org/en/packages/org.koreader.launcher.fdroid...
Koreader interface with syncthing is not that user friendly to non techs, very powerful can do anything but i don't think i would advise that to non techie
KOReader can update over WiFi as well, right?
To add to this, since the original comment mentioned kindle, you can jailbreak many of the models and install KOReader in them if you want to keep using the hardware.
Just to add, KOReader might not look super use friendly at first, but I highly recommend giving it a try. It’s an amazing reader.
Once your used to it, the controls are a lot better than stock kindle as well imo.
Episteme is pretty good
https://github.com/Aryan-Raj3112/episteme
Using readera with network connection disabled. Super app.
I actually use MuPDF for epubs, as well as pdfs.
It depends.For me it’s not on app For a dedicated device(phablet/tablet) - KoReader. For Smartphone (no longtime reading) - Librera Reader
Honestly I use Lithium with no network permissions. It's not Foss but it's good enough for me.
I run Calibre Content Server on a VM. So my ebook reading is just accessing that in the browser. Works great.
I wonder if FDroid has a policy against LLM? i was reading one of the MR here https://gitlab.com/fdroid/fdroidclient/-/merge_requests/1729 and they seem to gate on LLM contributions (and vibe coded android app)?
In summary of this MR: no, they do not ban AI
so nice. FDroid always looked a bit dated to me
Love it new design fdroid basic really smooth in my ancient phone.
Did they implement any GrapheneOS security complaints for it to be deemed actually secure?
GrapheneOS security complaints about F-Droid are a load of nonsense except for one: the APK on the website is signed by a different key from the one that F-Droid updates itself with.
Fitting, as there really are only 2.0 trustworthy app stores for Android.
I hope the new redesign makes the store easier to navigate on TVs. It's a nightmare trying to install/update apps on F-Droid on either my Nvidia Shield Pro or my Onn 4K TV using the tv remote. The cursor gets lost all the time and it's often impossible to see what option is currently in focus when you click Ok on the remote.
Have you filed a bug? That's niche enough that i wouldn't necessarily expect the devs to have tested such scenarios.
Not any super user but about three/four months, I'm using my device without any google account. Also not using any G service apps such as mail/yt/maps and of course play store. Instead of play store I found aurora store very helpful. "Very" because of the anonymous login future. But sometimes the store disturbs. Newly added apps on Play store doesn't appears on aurora. Also many applications fails to be installed without showing any reason. Some shitty apps redirect to the play store app (which I'm unable to disable but uninstalled her! Updates) and just doesn't works anything more then redirecting me. So I'm still not a fan of Aurora. But it's going not bad. But sometimes I should browse other sites to get old/delated from Play store apps. Also for mod/adless version of some apps.
I heard of fdriod but what I think it may only serves feature less, low UI/UX optimized apps. So didn't installed it yet. But something should be available where people can find all Play store apps (as aurora supplies) + premium/adsense deleted modified apps (random website) + Open source apps (fdroid)…… this will make android insane