this post was submitted on 29 Sep 2025
1105 points (99.6% liked)

Technology

75606 readers
2505 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] ezterry@lemmy.zip 40 points 15 hours ago

I am perfectly ok with android apps being required to be signed by not just a certificate (they always were just it could be self signed and just needed to match to upgrade without removing data) but a list of trusted entities.

As long as:

  • I can install my own key on my phone (I'd I am trusted)
  • major distributors like fdroid and have a key installed without friction (like web CAs)
  • Google let's me mark their key as untrusted (I probably won't but I should be able to refuse things they trust (at install time, not disabling preloaded apps like settings)

Without this it feels too much extending the monopoly despite being forced to allow 3rd party stores.