Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've said this in another comment, but I'll duplicate here:

The microG creator goes into more detail about signature spoofing at https://github.com/microg/GmsCore/issues/1467#issuecomment-8... The concerns usually raised against that are due to the "default" patch included in their repository, which has a specific purpose.

We don't use that, https://calyxos.org/about/tech/microg/ are the precautions we take to try and prevent "weakening overall package security"

In addition, microG is optional and can be disabled on first install, see https://calyxos.org/features/microg/#1-microg-disabled



> see http://127.0.0.1:4000/features/microg/#1-microg-disabled

As someone who also accidentally pastes my local dev URLs from time to time, I feel your pain ;)

For everyone else: that's https://calyxos.org/features/microg/#1-microg-disabled


I edited the comment to fix it, thank you!


Making it system-only still isn't ideal. It then requires a full OS update to push updates to microg/playservices, cannot just update the app components if vulnerabilities are found in the wild.

I would like if there was stronger privacy laws or antitrust orders that force Google to open their service provider API's so people can choose alternative location/push providers, but this doesn't seem like it will exist soon.

For many users, it's going to be the best usability compromise to use minimal play services and use apps that don't send content over the push networks (signal is like this, element can be configured this way).


> Making it system-only still isn't ideal. It then requires a full OS update to push updates to microg/playservices

It does not, you can update system-apps out of band just fine.

Google does it with Play Services (and many other apps), and we have our microG builds in our F-Droid repos for out of band updates.

In fact, that is one of the big selling point of Play Services - the fact that it gets updated outside of OS updates, which means that you have a recent / the latest version on all devices regardless of their update record.

And therefore anything implemented in Play Services can be used even on older Android versions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: