VLC - App stores were a mistake

https://lemmy.world/post/13486264

VLC - App stores were a mistake - Lemmy.World

VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users… For now, iOS App Store still allows us to ship for iOS9, but until when?

Reminder that VLC is on F-Droid
They’ve not updated it there either though. It seems to be less of a case of can’t update Android and more of a case of won’t update Android

What exactly is the issue preventing them from updating the Android version?

Also, if that’s the case, it sounds like OP’s title is a bit misleading, since the particular app store isnt the problem.

Poorly written post …

In addition to the private key thing, the Play Store is requiring them to drop support for APIs older than API 30.

Which in effect means VLC can no longer be updated on AndroidTVs running Android 11 or earlier.

Which is millions of customers, according to VLC

Shit, my own TV is not even on android 10
I know at leadt one person who’s phone isn’t dven on version 10.
Last update 2/23/23 what am I missing?

From their Twitter:

If you wonder why we can’t update the VLC on Android version, it’s because Google refuses to let us update:

  • either we give them our private signing keys,
  • or we drop support for Android TV before API-30, and all our users on TV API<30 can’t get fixes.

It’s not much, just dozens of millions of people use Android TV before Android-11…

Maybe we should tell users to buy new TVs? #electronicWaste

Google requiring their private signing key is insane, and goes completely against the concept of private/public keys.

Why is Google asking for this?

See also: NSA PRISM

Member when all the companies listed released a PR statement within 24 hours of each other, all very basic and denied allowing the NSA direct access to their users?

I member.

How Google and Facebook Cooperated with the NSA and PRISM

Ever since Thursday's blockbuster reports from the Washington Post and the Guardian revealing the existence of the National Security Agency's PRISM — the...

Yahoo News
Oh yeah, I remember that…

C-I-A Confidentiality, Integrity, Accessibility. They don’t need the keys for C or A. Only one option remains. To modify the code and pass it off as code VLC’s wrote or signed off on.

Likely to install malware and re-sign. Brazen identity theft.

Maybe I’m wrong, they could use VLC’s private keys to gobble encrypted communications too.

I didn’t know F-droid was on Android TV, but it will be on mine pretty soon.
VLC don’t update on Fdroid, Fdroid compile all the apps on their repo (the one that comes with the app). Fdroid do some checks on the updated app before they compile it, so it’s always a little behind the main release.