VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users… For now, iOS App Store still allows us to ship for iOS9, but until when?
Reminder that VLC is on F-Droid
They’ve not updated it there either though. It seems to be less of a case of can’t update Android and more of a case of won’t update Android
From their Twitter:
If you wonder why we can’t update the VLC on Android version, it’s because Google refuses to let us update:
- either we give them our private signing keys,
- or we drop support for Android TV before API-30, and all our users on TV API<30 can’t get fixes.
It’s not much, just dozens of millions of people use Android TV before Android-11…
Maybe we should tell users to buy new TVs? #electronicWaste
I can’t speak to why they’re not updating on FDroid but seeing as how it’s much more difficult to get people to use FDroid on Android TV, I don’t think it will help them with that issue anyway.
Google requiring their private signing key is insane, and goes completely against the concept of private/public keys.
Why is Google asking for this?
See also: NSA PRISM
Member when all the companies listed released a PR statement within 24 hours of each other, all very basic and denied allowing the NSA direct access to their users?
I member.
Oh yeah, I remember that…
C-I-A Confidentiality, Integrity, Accessibility. They don’t need the keys for C or A. Only one option remains. To modify the code and pass it off as code VLC wrote or signed off on.
Likely to install malware and re-sign. Brazen identity theft.
Maybe I’m wrong, they could use VLC’s private keys to gobble encrypted communications too.
I didn’t know F-droid was on Android TV, but it will be on mine pretty soon.
What exactly is the issue preventing them from updating the Android version?
Also, if that’s the case, it sounds like “App stores were a mistake” is a bit misleading, since the particular app store isnt the problem.
Basically, modern app stores have changed how they work and now require the signing keys, VLC feel this is a bad thing and refuse to update. Banks are okay with it, but VLC feel more strongly than banks.
Banks are okay with it, but VLC feel more strongly than banks.
I mean banks are known for horrible security practices all around so that makes perfect sense.
Are they?
My bank restricts the length of my password to…16 characters, I think.
Mine only uses a 4-to-6 digit pin as a password, and sms for 2fa
Darren Kitchen from Hak5 has an amusing story about a bank teller who assured him email was entirely fine to send sPII through. “No sir, you just need to send it to us, and once we have your information then it’ll be secure.” No encryption. So, yes.
Also look into the Equifax security breach. Un-patched software for months.
It makes almost no sense to have a password length limit. 1_000_000, that’s One Million, characters is equal to 1MiB. That’s twice the length of the Lord of the Rings Trilogy and much less than most modern webpages. After hashing, which is how passwords should be stored, text length is irrelevant. All hashed inputs come out the exact same length. 65 characters for SHA256.
Very much known for their horrible security practices, yes. Absolutely.
Setting a max password length is sometimes done to prevent ddos attacks. Without it, attackers could just spam 1MB passwords constantly and force the login server to just spend all its cpu time hashing garbage.
That being said, a password limit of under 20 characters probably just means they are just storing passwords in plaintext.
Absolutely. They are entrenched in their regulations so much that it takes forever to change things.
Years ago, I had an account at an american big4 bank with an 8 character password and was going through and making all my passwords unique. I was changing everything to random strings of 20-30 characters (this isnt the best practice, btw, but still better than 8chars), so when I get to this bank account it capped me at 15chars. I couldnt believe the forced low entropy they gave me for something as vital as a bank account.
I asked them why, and basically they said their system would break with anything over 15chars.
How many wrong guesses were you allowed before the system would lock your account?
The equivalent of a 20-30 character random password with numbers and characters is a 7-11 word passphrase. Seeing how passphrase generators default to 4-5 words (equivalent to 11-14 characters) what you did isn’t so bad
Who do you think makes the decisions for a bank?
The person writing the Android app?
Or the person who just wants customers to be able to access the app and use the services?
Banks have laws and regulations that they must abide by to secure the access to and information of customer accounts. A security team will surely have to sign off on whatever the app developer or customer experience manager wants to implement.
Isn’t that how fdroid worked for a long time?
Edit: although it doesn’t make sense to me for play store to do the same without the source code available
Edit 2:
The reason is that they forced new apps AND apps for Android TV to use App Bundles https://developer.android.com/guide/app-bundle This type of release cannot be installed as it but can be used to generate the apk files. In order to do so, the Play Store has to sign on the fly.
Not buying it. They could let the dev sign evey combination before uploading. They’ll be caching them anyways
Traditionally Fdroid signs every app. Not with the developers key. The future are reproducible builds. https://f-droid.org/2023/01/15/towards-a-reproducible-fdroid.html this is a futuristic app store, not what google has.
Banks probably don’t use it google’s signing process.
Uploading your signing keys sounds like Windows uploading your bitlocker keys
Banks aren’t run by the people that develop the apps. They have no idea what a signing key is, they just want the app available and updated.
In addition to the private key thing, the Play Store is requiring them to drop support for APIs older than API 30 unless they provide the key.
Which in effect means VLC can no longer be updated on AndroidTVs running Android 11 or earlier.
Which is millions of customers, according to VLC
Shit, my own TV is not even on android 10
I know at least one person who’s phone isn’t even on version 10.
Poorly written post …
Last update 2/23/23 what am I missing?
It’s the same version that’s on the Play Store.
Which is current according to their site, 3.5.4
I can’t read archive.is links
I don’t dispute that
I am not trying to argue but what is the issue? The site shows the same release as F-Droid.
Ugh, I’m biased and so I don’t really want to answer but will try. According the VLC, the reason for them becoming so terrible as a media player is because they can’t update their app. Now as you and me can both clearly see, the latest version available is the version that is in the app store and on F-Droid. If they were crying about not being able to update and had a version or two that they were unable to upload, it would make sense. But nope, they have nothing beyond what they have. Add to that, if you look at their forums, lots of people have been raising issues. One very handsome man even posted this in October
VLC was once the best in class. Not only was it a great piece of legacy software, the Android team were so passionate that they took that reputation and all the expectations that go along with it and exceeded it.
But as time has gone on, it’s just started to languish. If you attempt to rewind a few too many times, the video freezes and you get audio. You can’t play a folder on a NAS without creating a playlist. You play a folder locally without VLC losing its place. Every time the screen goes off, it needs to scan the device anew. And despite being at the forefront of Holo Design and Material Design 1, it’s yet to implement Material You.
It feels like VLC for Android has been forgotten…
To which their response was to ask for logs, despite the fact that the issues can be reproduced on every device I’ve ever tried.
Nice reach
deleted by creator
Fdroid is the obvious answer me thinks. Anyway love you guys/gals at videolan still haven’t come across a piece of software that destroys every other in its field in every aspect.
Have people actually checked the versions there before making the suggestion?
F-Droid: Version 3.5.4 (13050408) suggested Added on Feb 23, 2023
Google Play: Updated on Aug 27, 2023https://f-droid.org/en/packages/org.videolan.vlc/
https://play.google.com/store/apps/details?id=org.videolan.vlcThe problem seems to be squarely with VLC themselves.
I dont think that works for windows?
How about winget or the other commandline package managers? winget does have VLC according to winget-pkgs. This is the kind of “stores” we need, ones that emulate Linux repositories instead of locked down smartphone garbage.
Is singer secure tho? Iirc chocolaty isnt
Asking if something is secure on an insecure OS. Seriously, both the program and the repositories are on github:
https://github.com/microsoft/winget-cli
https://github.com/microsoft/winget-pkgs
So you be the judge.
Unfortunately even FlatPak is insecure, so OS doesn’t really matter
Maybe don’t check all the permission boxes in flatseal and you might find it’s more secure than you think.
It’s all about default permissions
Winrar?
7zip.
PeaZip is something you should check out too
What does 7zip do better?
Not show annoying popups about licenses?
7z is better than rar and its algorithm is fully open source
Removed by mod
Check out PeaZip
Oh shit I did not know that. Switching now, thanks
Encryption?
I tried it and went back so winrar.
Dear VLC, in your download section there is the F-Droid app store option which I consider a good thing. p.s. Why are you still posting on Twitter ??? On your website I see two buttons Facebook and Twitter. Time for a change ?
By the way, archive.is and archive.ph are Tor unfriendly. Another link : https://news.ycombinator.com/item?id=39798565
The guy upset about his 14 year old iPad not still receiving support is hilarious!
Ok yeah it’s kind of funny but if you think about it for a second that ipad is perfectly functional. If apple doesn’t want to support it because it doesn’t make them money, then why can’t the community? Why does apple get to decide what is e-trash and what isn’t?
The laptop I bought second hand in 2014 is still very much functionnal, and in fact it still runs. I’ll concede that it doesn’t run well, as it was already unpowered back then, but it runs some flavors of Linux oriented towards low-power devices, because people made them to do specifically this. If I had bought a second had ipad instead, it would be in a landfill by now. It didn’t even take any special actions on toshiba’s part to make it behave like this, they just made a laptop that was up to the standards of every other laptop at the time. What I’m getting at is that this isn’t a new idea, we know how to take care of our devices for longer already, were it not for the apples and googles telling us what we can’t and can do on the device we own.
I thought MissTake’s response was really good and covers pretty much everything
“Thanks to Apple”?
The original iPad was a 32 bit A8 single core CPU that topped out as 1Ghz and with 256MB Ram and used the ARMv7 instruction set.
How do you expect a modern day OS with requirements to deal with real world sensors, and user requirements that didn’t exist back then, to run against that?
The latest iPads have 2GB Ram, are 64 bit, run multiple cores and have embedded motion coprocessors and neural capabilities running a much later instruction set.
Let’s be reasonable here - that device is now about to be 14 years old.
And, if “the hardware works beautifully” how is it “pretty much a brick”?
iPads are not the same as laptops or desktops. Sure, you can still run some Linux distros on older 32 bit hardware, but everyone who does knows of the limitations of doing so and realize that they lack the horsepower of modern day computers and use them accordingly.
Disagree. They should be forced to open it up for the community to maintain it when they end support.
My thoughts exactly. It would be unreasonable to expect full support 14 years after it came out, and it would be unreasonable to expect modern apps to work flawlessly. But it’s not unreasonable to say that all the specs mentionned by the commenter can just be considered to all be 0 if the device cant run anything - not because it is physically incapable of it, but because we can’t even try.
From my understanding of the quoted text, that’s what the person is suggesting. That at a certain point, things shouldn’t any longer just work and users should be made to take responsibility.
Its hilarious that apple is creating a bunch of ewaste for no good reaaon?
My mom’s macbook is 14 years old and perfectly functional. So why doesnt it work (well) anymore?
Apple doesnt provide updated root certificates anymore, so all https sitesare borked.
Name a company that gives security updates to 15 year old tablets.
I wish they did, but this is hardly just an Apple problem. The only reason I bring this up is because people very quickly dunk on Apple without thinking about the fact that we need more access to all of our hardware in order to increase the longevity for those who want to.
Frankly I find iPads work longer on average than most other tablets. Purely anecdotal though.
The other elephant in the room is that most people don’t want to use 15 yr old tablets. I know I don’t want to edit video on 15 yr old desktops, even though they were perfectly capable of editing 15 years ago. But not current videos. Just like 15 year old tablets will not be able to readily stream or display a lot of modern content correctly.
Why does it have to be a company?
Tons of old hardware continues to be useful to its owners just by virtue of being on open and maintainable platforms.
But Apple continues to push harder and harder for planned obsolescence while claiming they support their devices better than the competition.
Apple earns unique hate in this category because of how strenuously they fight against things like right to repair. Failing to support old products isn’t the end of the world but intentionally making it so that old products aren’t supportable is very bad and the Apple App Store is a major instrument for making sure old Apple devices stop being useful.
apple does ‘support’ their hw better, it’s just that it’s a pretty low bar to start with these days. they and their competitors could do better–much better, but zomg! someone has to think of the shareholders. they’re far more important than users or the planet.
Apple innovates in new and exciting ways to not support devices. They invent new antirepair technologies and have pioneered locked-in walled-garden app stores that prohibit users from doing what they want or need to keep their devices working.
They don’t get to wear the white hat just because they do some shit well. They are the bad guy. And they could change posture pretty much immediately if they were at ALL serious about their devices having long-term support. They control basically their whole tech stack and could make it so their devices can continue to be maintained indefinitely even if they aren’t doing it. But control matters more to them than support.
I really don’t think anyone should be giving them credit here, not even as a backhanded compliment.
They only support their hw better on phones and tablets. On a computer you’ll longer support from Windows or Linux LTS distros. I have a 13 year old laptop still running the latest version of Ubuntu
deleted by creator
So the ending to the story which i didnt feel like typing out earlier was that i loaded debian on to the macbook and it runs 2x faster now with regular security updates…
The vast majority of people will never edit a video. The vast majority would be perfectly happy doing 90% of their work in a browser on older hardware instead of chucking it in the bin
i do edit photos and video on a 15 year old desktop. yea, it’s not as fast. it even still only has mechanical hdd. it works. i really don’t give a shit how long it takes to encode. it can sw encode hd h264 in ‘real time’ (sw giving better quality output and at a smaller file size than the faster gpu encoding), that’s good enough for me. it does everything the much newer system i’ve been able to use recently at the office can do–it’s just slower at some things.
deleted by creator
My 2007-era desktop was perfectly capable as an HD video editor and streaming server. Anything worth a shit in the Desktop space since round-about 2010 has been decent at on-the-fly transcoding as well.
Your incredulity is astounding to me. The Xbox 360 and PS3 were both perfectly capable as streaming players, way back in 2006. The PC’s of that era were more powerful, not less, and avoiding emulation or discrete gpus are some of the main reasons those consoles used PowerPC. They wanted a more compact solution
deleted by creator
deleted by creator
My iPad2 can’t do internet anymore, or for instance used as a panel for home assistant webpage or client, but it’s perfectly fine as a homestudio controller and music / midi generator and that is what I still use it for. Battery is still great too. I got it about 13 years ago and I will be using it until it stops working. Looks as good as new too.
I do have a recent iPad too, it’s for all the stuff I cannot do on the old one.
Almost any iPad works great as a second monitor as well, with minimal setup. I wish they could be easilly made to work like a Bamboo tablet for drawing purposes though.
VLC is still on Twitter? I thought they would be quick to migrate to Mastodon, slightly disappointed.
And thanks OP for linking outside of Twitter.
Probably on both?
Mastodon and other federated platforms are still confusing to normies and less ideologically-minded users. Aside from that, unless VLC starts hosting their own instance, it is hard to say if the particular one they decide to use will stick around. They can relocate by taking some extra steps of course. But they would likely care to put that effort into making VLC Player better instead of into social media. For now at least. X has been more or less the same for a long time (even with the past couple of years) for what they use it for. I am sure they would like to be on an open platform over propriety if that were the only difference. And nothing is stopping them from using both at the same time in order to reach as many people as possible.
and yet the fdroid version was updated last month!
I just checked it’s 23 February 2023. Last year…
Oh Jesus
Or just using their official release APK over obtainium
TIL that my country has bended over the copyright trolls and blocked Archive.is, need a VPN to view…
I wish I was lost in dessert, but it’s better for my wasteline that I’m not.
And good on VLC for standing up against this. This type of thing should absolutely be opt-in by the developer.
Can someone break down the thinking behind this?
It’s explained here: https://social.treehouse.systems/@Aissen/112139649840297169
“Ios still allows us to deliver to ios 9”
It’s a poorly written post. On whatever site this is. Looks like crap.
deleted by creator
I wonder why they aren’t allowed to just rant a bit
With Play App Signing, Google manages and protects your app’s signing key for you and uses it to sign optimized, distribution APKs that are generated from your app bundles
You can use google’s play app signing. It’s not mandatory.
That is not better, it still means that the app is signed with a non private key, which goes against the very concept of the private/public key concept
Thats what they complain about. They can use it. They dont have to. Yes its bad but they mix up a lot in one post.
An unacceptable option is not an option. This is like saying somebody has access to multiple Internet providers when one ISP is so slow as to be nearly unusable, but it technically exists and you can technically pay for it. That’s not really what we mean by “choice.”
Your response is so typical and frustrating to be honest. It’s flippant nonsense where you know what we are talking about but you don’t want to agree so you hide behind lazy responses like the one you wrote.
Why do Google need the private key? I can only see it being used to modify apps without notice.
Iirc, they build the app and publish it for you. “For convenience and security”
Wow, that is terrible.
Yyes.
With Play App Signing, Google manages and protects your app’s signing key for you and uses it to sign optimized, distribution APKs that are generated from your app bundles. Play App Signing stores your app signing key on Google’s secure infrastructure and offers upgrade options to increase security.
https://support.google.com/googleplay/android-developer/answer/9842756?hl=en
I’ve scrolled through the F-Droid repositories in Droidify app and see that VLC does not have their own F-Droid repository ? They could create one, and set up mirrors for it, think of a way to cover the hosting costs, why not ? Making yourself depend on Apple and Google and saying that app stores were a mistake feels wrong.
Better to use the official fdroid repo
Unlike certain services, the main fdroid repo is pretty reliable
It doesn’t because you should get the app from F-droid main.
Several projects have their own F-Droid repository. A few years ago VLC was not updated for some time for some reason. A project like NewPipe has their own F-Droid repository making it possible to let users download the latest version, which can be useful when there is issues with the main F-Droid repository.
deleted by creator
MPV can also be configured to look way better than VLC. Especially if you use HDR.
Last time I tried it, the prebuilts packages didn’t work, and the version I built from source couldn’t recognize any graphics or video outputs to use 😞
Off topic
deleted by creator
Windows only. Useless
MPC is decidedly not better than VLC.
deleted by creator
Don’t care, vlc is the best .
Reading this I remembered that stupid apple is now forced to let us sideload on iphones. I just kicked off the ios update to enable it.
same thing for linux. their repo’s latest version is 1.16 while their github version is 2.4.
Edit: my version numbers are wrong but you get the idea. The repo’s version is like 20 releases behind
Gentoo has version 3.0.x available