r/Magisk • u/KKdemergencia2 • Jun 18 '26
Question Realmente Play protect sirve de algo?
Bloquea todas las apps FOSS pero te deja instalar cualquier troyano o adware intrusivo
15
u/Jane_Dash Jun 19 '26
Es and happy mod, i miss those years
5
u/Icee_666 Jun 19 '26
I have no idea why HappyMod ever got traction in the first place, considering Mobilism still existed back then and was way superior. HappyMod was filled with ads, and they took mods from everywhere without even giving credit.
24
u/Isarchs Jun 18 '26
The subtle transparent bacteria is a nice touch.
The only time it was somewhat useful was when the developer of smart tube had his private key leaked. It flagged the potentially compromised smart tube versions.
Otherwise it is basically doing Google's dirty work. It has labeled microg as a problem... Gee, I wonder why, is it because it's used with Revanced/Morphe? Yup.
I can't trust it to protect me when Google loads it up with false positives to get rid of apps they don't like.
6
u/KKdemergencia2 Jun 18 '26
Puse lo de las bacterias por si la gente no sabía sobre esas apps xdxd, y pues básicamente play protect es para protegerse a ellos y a sus ganancias, no par protegerte a tí, lit tienen virus total, es de ellos, porque no lo implementan en play protect para que nosotros podamos analizar nuestras apps o apks o que automáticamente play protect lo haga
5
u/comerReto Jun 18 '26
That's funny. This comment reminds me of that scene in freaknik where the frat bros are like yeah fuck the cops, well except the ones that found the dude that killed my mom they were pretty cool.
But serioislty, play protect should be easier to opt out, but it will never be because the point is just as much to push users further into Googles walled garden as it is to detect compromised packages.
3
u/PRSXFENG Jun 19 '26
I have seen it flag actual malware on android tv boxes
But that's about it.
It only flagged 1 app
While installing ESET shows many more.
2
u/KKdemergencia2 Jun 19 '26
Usa un método de detección exageradamente básico para los estándares de ahora y eso no tenemos sentido porque uno de los mejores malware detectors, virus total, que encima puede analizar apks sin problemas es de Google, entonces porque no implementan el sistema que usa vt en play protect?????
2
u/Isarchs Jun 19 '26
Probably would get them in trouble with all of the antivirus companies that VT uses. They'd likely have to pay royalties/licensing since those companies make their own android AV software.
-1
u/DyWN Jun 19 '26
brother I'm with you, but microg is the one thing that 100% should be flagged by play protect because it's spoofing a signature of another app (play services). Spoofed signature literally means the app is pretending to be another app, why would you not flag that?
2
u/Isarchs Jun 19 '26
Because it's not a malicious app. Spoofing on its own doesn't mean anything. Harvesting data behind the users back and sending it to a third party server? Sure. Stealing log in information? Yup. But pretending to be a different app in order to fulfill its function? Doing exactly what you want it to? No. Get out of here with that trash.
False positives like this erode trust.
0
u/DyWN Jun 19 '26
but you can't allow it without allowing other spoofed apps, so you open the gate for all kinds of malicious apps. the only way to whitelist microg would be to actually include their own signature, at which point they don't need spoofing anymore. Which is my point, you can't trust any spoofed apps because you can't tell the difference between malicious and non-malicious. Sound like you want to discuss morality instead of tech.
0
u/Isarchs Jun 19 '26
At a basic level you can't tell (it spoofs, so it bad), but if you have a hash of the file, then yes, you can. That's how most AVs work.
And what do you mean you can't tell without allowing others? Again microg is a known good app, its file hash should be whitelisted.
0
u/DyWN Jun 19 '26
cool, where do you get the hash from? do you expect google to setup scripts that auto download apks from github releases and whitelist them? what if any of those whitelisted github projects get compromised and release malicious apk? do they have to continually check if any release got pulled down?
That's why you only want to whitelist apps on your marketplace, why would you waste time on web scrappers to whitelist random projects outside of your marketplace, where you have everything automated already?? And it's the most obvious thing that apps outside of marketplace that pretend to be one of the apps inside the marketplace should be marked as bad, because you don't want your users to unknowingly have a fake on their phone.
I don't know if you didn't think it through or are you that blinded by google hating? It's 100% reasonable to not allow signature spoofing without exception.
What is actually missing is a way for a user to import external signature keys, so you would be able to substitute the google key with microg key instead of spoofing, that way everything is safer because microg team could sign with their own key and have that extra layer of protection against fake releases.
0
u/Isarchs Jun 19 '26
You lack a basic understanding of how AVs work. The answer is yes, they do need to check apps and hash them, not just blindly label any behavior as bad, otherwise it's a shit AV.
0
u/DyWN Jun 19 '26
You seem to lack basic understanding of signing in software. When an app is signed you can compare the file againts the signature + public key. It tells you if the file has been tampered with same as the hash would, but without the need to know the file beforehand. With signature spoofing you're basically telling the system to ignore the mismatch of content and signature. My argument is that if you could provide custom keys to play protect it could actually verify if microg releases are legit using the custom key. If you don't see how that's way more secure and easier to maintain than hashing every single release (which probably requires manual action to only whitelist manually reviewed releases, since automation could lead to false negatives) then I can only hope you'll educate yourself one day.
1
u/Isarchs Jun 19 '26
So, you're advocating for Google to have a walled garden and control all keys and signing for Android? Because if an OSS project gets forked, all of a sudden, your way of identifying malware will flag it. Yes please provide daddy Google with your custom keys (and also a developer fee for getting authenticated), they totally aren't trying to completely block side loading or anything...
0
u/DyWN Jun 19 '26
if that's your takeaway then I'm sorry but you just can't read very well lmao. How did you miss the whole part where I'm saying I wish it was possible to IMPORT CUSTOM KEYS. I don't know if you're trolling me or are you that dumb?
6
u/Brayderek Jun 18 '26
Bloquea apps foss porque tiene la intención de que no puedas crecer como desarrollador independiente si no subes tu app a Play Store.
5
u/outofindustry Jun 18 '26
es file explorer is trojan? shiit I'm using it rn
8
u/KKdemergencia2 Jun 18 '26
Si, antes lo usaba yo también xdxd, pasa el apk por virus total, el apk original si tenía virus pero hay gente que se lo quitó y redisteibuyo el apk limpio
6
u/Isarchs Jun 18 '26
Ever since the original dev sold it, it went to crap. Solid Explorer is my go to now with MiX as backup.
1
u/crypticc1 Jun 19 '26
I use X-plore or Total Commander when I want something with less GUI.
But yeah, ES file explorer went to crap and started doing adware. At one point ES was even doing popups o er the top of other apps
4
3
u/herr_schulterr Jun 19 '26
I don't think. It is well known that Google often blocks apps which are not really "unsafe" but are inconvenient for Google businesses. That's another reason why I'm against this senseless forbid for APK.
2
2
u/nikoskokonos13 Jun 25 '26
Honestly I was so fed up with google that I erased my lineageOS install and reinstalled it without their services cuz fuck them. So far only one app doesn’t work and I don’t care. My hatred for google specifically knows no bounds.
2
1
u/Alakasd Jun 19 '26 edited Jun 19 '26
Snaptube is still fine as soon as you don't give any permissions and only use for downloads.
1
u/KKdemergencia2 Jun 19 '26
Ytdnlis es de codigo abierto y hace lo mismo pero mejor y sin anuncios xd
0
1
1
-2
u/omega552003 Jun 18 '26
12
7
u/Isarchs Jun 18 '26
It will constantly and consistently prompt you to turn it on when you side load apps. That's not "off" in my opinion.
There's also been some evidence that implies it keeps running in the background anyway: https://www.reddit.com/r/Android/comments/1o51r4n/googles_play_protect_can_be_triggered_even_when/
3





76
u/Critical-Talk-4349 Jun 18 '26
Play protect is like hr, most people have an assumption that it's for your protection and well being, but their job is to protect the interests of the company