Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

281–290 of 665 posts

Re: Google have declared Droidscript is malware

#282
post #261
post #196

Earlier quoted context omitted.

I keep hearing this and it's totally wrong. Desktop Linux has a huge app ecosystem and arguably has more high quality software than Android does. All of this works on the pinephone and other similar devices.

Okay, so how can I chat to my friends or companies with WhatsApp on Linux? How can I order food similar to Grab or Gojek on Linux? How can I get a date on Linux like Tinder? You can't. Sure, there are technological solutions to all of those, but in the real world that alone is pretty much useless.

Tinder does have a web interface, so does doordash (I've never head of Gojek but I'd imagine it does too.)

I thought WhatsApp also had a web interface but I wouldn't use it anyway and there are similar chat apps that do so why would you?

Re: Google have declared Droidscript is malware

#283

Earlier quoted context omitted.

A walled garden doesn't necessarily exist solely of proprietary protocols and code. In the case of fdroid, apps that violate open source licenses are not allowed. So, technically, from the perspective of a company like Facebook, fdroid is a walled garden they cannot enter without open sourcing their code. (I'm not saying fdroid's policies are bad. I'm just trying to make an argument for the counterside and am playing…

"In the case of fdroid, apps that violate open source licenses are not allowed" ...on the main repository. AFAIK, there's nothing stopping Google or anyone else from setting up their own F-Droid repository to distribute apps with proprietary code. The normal F-Droid app should be able to use a repository like that just fine. EDIT: Addressing the "PS" that was added... > Google advocates always make the argument that…

I totally agree with your points there.

But I think that the main issues of Android (or AOSP) are even a level deeper than just the Play Services.

There are lots of initiatives that try to create a free ecosystem for themselves (Lineage, /e/, Carbon, et al), with their own stores and sources for Apps. Most of them have varying degrees of success, due to gapps counterparts like microG [1] not being able to keep up with what Google's Play Services provide API-wise.

It's an absurd amount of features, and a lot of API workflows to consider. Bugs and crashes everywhere down the user experience...but hopefully they're getting slowly to a stable state.

Coming back to the real problem: I think it's actually the Vendor deals that Google did. Most of the manufactured devices are almost impossible to flash without reverse engineering skills, and this is intentional. Having to wait more than 3 months to unlock a smartphone's bootloader because the manufacturer doesn't give a damn about you is just one of many examples; setting aside that most of the unlock procedures are meant to be understandable by developers-only.

I think that in order to "really free Android" the creation, flashing, updating of ROMs has to be standardized in a more homogenic way (partition fatigue, anyone?), because it would allow a graphical and easy-to-use software to be built. That would allow to flash a ROM without e.g. losing all /data and more importantly - be usable by end-users without technical knowledge.

In my social circles I'm the guy that flashes LineageOS to their devices, because most of the terminology is so far away from the reality of most users that they have no single clue where to start. The amount of knowledge that is required to flash your device (and be Google-free, even in Apps with e.g. with Appwarden [2]) is absurd and as long as this is the case it will be a niche that's being ignored by politics (and potential regulation laws that would force Google's policies to change).

[1] https://lineage.microg.org/

[2] https://gitlab.com/AuroraOSS/AppWarden

Re: Google have declared Droidscript is malware

#284
post #87

Earlier quoted context omitted.

The battle really parallels the larger right to repair debate. (Especially if we realize the latter is probably is better called the right to exercise control over purchased goods.)

Apple is guilty of this too. No general computing company should be the single ingress point to running on their platform. For platforms with significant penetration, this is a market monopoly. [1] For Apple, it's iOS and, increasingly, MacOS. For Google, it's Android, and as has become glaringly obvious, Chrome. They shouldn't be allowed to run a browser. The DOJ needs to stamp out this anti-competitive, anti-consum…

> You can "protect" consumers with a permissions model and malware signature warnlist regardless of whether you enforce a store.

I’ll believe it when I see an alternative to iOS devices that my dad can’t get malware on and only need a few seconds to fix by uninstalling an app or power cycling the device.

Re: Google have declared Droidscript is malware

#285

Earlier quoted context omitted.

It's sort of interesting how long this has worked, and as well as automated customer service the same or similar case can be made for automated moderation. You can often hear people on here excusing this by saying "if they didn't do this, their business model wouldn't scale". Well yes. If you can do the automation and it works then you have a business at scale. If not, perhaps your business shouldn't be a scale busin…

So community lawyers and other interested parties should make sure that their business model doesn't scale this way.

Especially those parties.

Re: Google have declared Droidscript is malware

#286
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

I bought one last week

Re: Google have declared Droidscript is malware

#287
post #87

Earlier quoted context omitted.

The battle really parallels the larger right to repair debate. (Especially if we realize the latter is probably is better called the right to exercise control over purchased goods.)

Apple is guilty of this too. No general computing company should be the single ingress point to running on their platform. For platforms with significant penetration, this is a market monopoly. [1] For Apple, it's iOS and, increasingly, MacOS. For Google, it's Android, and as has become glaringly obvious, Chrome. They shouldn't be allowed to run a browser. The DOJ needs to stamp out this anti-competitive, anti-consum…

> You don't do business, banking, dating, note taking, drawing, stock trading, etc. on them.)

Because it's artificially made impossible. No computer should be artificially restricted – let's not keep any loopholes open for no reason.

Re: Google have declared Droidscript is malware

#288
post #87

Earlier quoted context omitted.

The battle really parallels the larger right to repair debate. (Especially if we realize the latter is probably is better called the right to exercise control over purchased goods.)

The right to purchase. It's become an issue of defining "purchasing". But companies don't want us to purchase appliances, they would be much happier if we could rent them.

Gotta get that steady income. We're quickly becoming a society split between rentier capitalists and renters

Re: Google have declared Droidscript is malware

#289

Earlier quoted context omitted.

Does it? Everyone is quick to judge but coming up with an alternative is hard enough that nobody has done it so far. With scale comes scaling issues; general purpose computing and repairability need a different commercial model that doesn't match with the currently used models. This leaves two avenues: - Make it worse for everyone but keep it going - Make it worse for everyone in a different way and keep it going I d…

If the network can be adversely affected by a "muh righz" device then the network's threat model is shoddy. Taking away freedom to prop up a badly engineered product isn't fixing the bad engineering. The Internet is a good example. The threat model has been far too trusting, historically. We're paying for that in a variety of different ways. Burning it all down and starting over is impossible, so we're stuck in a mes…

Indeed. I would perhaps formulate it slightly differently but it is what it is.

This is also something that feeds the 'it used to be better back in the day' feeling, because some aspects might actually have been better because too many possible threat actors back then wouldn't take internet seriously and as such weren't an actual threat. So it wasn't safer, it was just less-attacked. As a result where was less pressure to make hardened clients and servers, and as a result of that, it meant that things like digital signatures were extremely optional (and computationally too expensive to include for the sake of it).

On the other hand, it's also the openness that brought its success, and may very well cause its downfall. (that said, nobody has been able to come up with a worthy replace ment so far) Having no single owner makes it better in that regard, but also worse.

Re: Google have declared Droidscript is malware

#290

Earlier quoted context omitted.

You can still do things, its just that now the user has to approve it. Maybe a 'let every app have every permission by default' checkbox would make you happy but I'm not going to advocate for it. And you can still sideload an APK without even having to jailbreak the device.

Re read the parent post. They write hobby apps that they clearly sideload themselves. They are also right, each iteration of the SDK takes away another feature of the device the app can access, regardless of whether you ask the user, in this instance the author of the app, for permission. The end state is for apps on Android to be either pointless fluff that basically do nothing useful, or mega apps written by big co…

Exactly. To give an example, I have a dictionary app that I wrote to facilitate my French learning that runs in the background and automatically looks up word copied to the clipboard (e.g. from Play Books or Chrome) and brings up the definition. Starting with Android 10 or so they disabled clipboard listener for apps in the background so the whole functionality is toasted. There is no permission to enable this "clipboard listener in background"
Post reply on HN