Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems like such a common occurrence, not only with android apps but anything with auto updates. It seems like the only solution right now is to purely limit yourself to apps from f-droid. Not necessarily because open source is resistant to this, but because no spammer would bother attacking such a small group.



Sounds much like the Chrome Extension Store, where people would hijack/buy popular extensions and add malicious scripts to them.


a non-perfect solution of mine - update only android apps that actually make sense, or author is Google. There is no reason my simple calculator app should get an update every few weeks (since nothing visibly changed in it for last X years), or linkedin having almost weekly updates.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: