Everyone seems kind of mad about this. Doesn't Debian do the same thing? The original developer doesn't build and sign Debian packages, the Debian project does that. Now Google does the exact same thing, and the conspiracy theories abound about how the NSA is making them do it or something. Is the NSA also making linux distributions sign packages?
Debian builds and signs which is rather different from just signing what someone else builds. This makes sense for Debian since they often make changes to the upstream code a bit, primarily for consistency with the rest of the distro, which you can see in the source packages. It's good for the signing party to be the one who built it asserting 'this is what we intended to ship'. It's also very clear that they are Debian packages, rather than anything originating from the upstream author(s). That's a very different thing than Google's new policy.
It sounds exactly the same to me - the repository owner is the one signing packages and has to be trusted not to modify it before delivering data. Where's the difference?
I think to me it boils down to need and trust. Debian needs to do things this way and has earned trust over decades not to abuse its power. Google doesn't have the need and is burning trust in enough other areas where it doesn't instill a lot of confidence that they will not abuse the increased control.
That I agree with and is actually my point - you NEED to trust your platform. There's just no other way. There's no sensible way for you to keep using Googles platform if you use Googles OS.
There are cases in which upstream (the original developer) and the Debian packager (Debian Developer) are one and the same. Not many but some. Debian is also the developer and packager of a large set of the core packages.
Upstream can sign or otherwise indicate integrity (e.g., Git revision checksums) of all individual source files. This ... becomes tedious to check, but can be checked against Debian sources to identify where any changes might reside. Note that this still applies only to sources rather than builds, though it's an option. It's likely not an option in wide use.
Debian also ships sources rather than builds, which can be built directly on your own systems (or within your own build-and-distribution network). Debian's had a "reproducible builds" initiative for some years (https://wiki.debian.org/ReproducibleBuilds), and this covers a fair number of packages (I don't have a count offhand), though there are notable exceptions of packages which are simply too complex to build reproducibly. I think the September 2020 summit notes are the best current overview of status, tools, and issues: https://reproducible-builds.org/reports/2020-09/
And, unlike Google Play, it's possible to download from any arbitrary Debian mirror without authentication. Authentication-prior-to-download could lead to branching logic for user-specific modified packages being delivered. Another option of course being for a generically-modified package that targets a single user or specified set of narrow criteria.
Debian does everything in the open. You can download the source of a package and build it yourself, compare checksums, run diffs. Most packages have reproducible builds so you can confirm what you're getting! Debian also doesn't require or use an "account" for downloads, and if they release a version of something, it's on the public mirrors that many people will be able to access.
With Google the entire process is completely opaque, they do everything behind closed doors, and can hand different users different blobs on demand.
Ultimately with Google, you only have Google's word for what they're doing, and you know they have the capability to provide different versions to different users on demand of an NSL. With Debian, they have no way to attack a specific user, and you fully have the ability to "check their work."
In Debian you can still get the sources, including the Debian specific patches, and build it yourself. There is no hard requirement to blindly trust the Debian maintainers.
There's nothing guaranteeing that Deb contains the same thing as source Deb. At the end of the day you still need to trust the organization building your OS so they don't push a backdoor in your root installed package.
No it's not - reproducibility doesn't defend you against malicious repository at all. You still need to trust every single maintainer of your packages and the repository owner to not serve you backdoored package.
Yes and no. Just having reproducibility does not automatically prevent bad things from happening. But it's certainly easier to defend against them.
Multiple people can grab the sources from the developer, review and apply the patches, build the package and publish the resulting hash. With reproducible builds, all people end up with the same hash, which should also be the same for the pre-built package in the repository.
In other words, instead of trusting one single person (the maintainer) you split the trust across multiple people. This is definitely an improvement thanks to reproducible builds.
You can do the same thing here. There is no hard requirement that you use Google Play. If the app developers publish their source you can build an apk yourself.
No, it's the developer's _choice_. The problem is that there are instances where you trust the developer but not the way it is distributed (commonly through Google's app store). I signature from the developer is enough to verify that the app has not been tempered with.
With the upcoming change, we loose this verification when using Google's app store.
This has nothing to do with the developer publishing the source and allowing you to build from source or publishing through other channels (the topic of this subthread).
Developers can still create key pairs themselves and upload them to Google. So they can still publish their public key if they want and you can be certain that APKs distributed from somewhere other than Play were definitely signed by the developer.
Yep, Debian, Apple, F-Droid all sign binaries themselves. The posters here mostly mistakenly believe that they can fight against the owner of their operating system without replacing the whole thing.
In the case of Debian and F-Droid, they do so transparently, often with reproducible builds. The fact that packages are signed by those groups is one of the reasons why they are trusted. I would not consider "signed automatically by Google" to be an improvement in trustworthiness.
In the case of Apple, I agree. It doesn't make sense to use their ecosystem without trusting them fully.
However, in the case of Android / Google Play, right now the developers have the option to choose between APKs and App Bundles. Why take away that choice? If App Bundles are superior, then developers will choose that option freely. (Google Play is already really pushy when recommending to use App Bundles.)
I trust Debian hell of a lot more to only make the changes that are in my interest and to pass the code through unmodified otherwise. Google doesn't get any trust in my book. The only reason I'm on Android is because alternatives aren't viable yet and I loathe iOS more than Android.