VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users… For now, iOS App Store still allows us to ship for iOS9, but until when?

  • stoy
    link
    fedilink
    arrow-up
    89
    ·
    9 months ago

    Google requiring their private signing key is insane, and goes completely against the concept of private/public keys.

    Why is Google asking for this?

    • Synnr@sopuli.xyz
      link
      fedilink
      arrow-up
      36
      ·
      edit-2
      9 months ago

      See also: NSA PRISM

      Member when all the companies listed released a PR statement within 24 hours of each other, all very basic and denied allowing the NSA direct access to their users?

      I member.

      • stoy
        link
        fedilink
        arrow-up
        11
        ·
        9 months ago

        Oh yeah, I remember that…

    • Kindness@lemmy.ml
      link
      fedilink
      arrow-up
      27
      arrow-down
      1
      ·
      edit-2
      9 months ago

      C-I-A Confidentiality, Integrity, Accessibility. They don’t need the keys for C or A. Only one option remains. To modify the code and pass it off as code VLC wrote or signed off on.

      Likely to install malware and re-sign. Brazen identity theft.

      Maybe I’m wrong, they could use VLC’s private keys to gobble encrypted communications too.