Earlier quoted context omitted.
> IIRC this is how it works by default for new apps. Personally, I'd like to see Apple, Google, and possibly Microsoft take this to what I think is the obvious conclusion: developers and independent software vendors submit source code, artwork and other such "assets", sufficient meta data, and build instructions to the store, the store builds and publishes the applications and makes them available to users. F-Droid b…
BTW, with F-Droid does is basically the same what major Linux distros do - build everything from source on trusted infrastructure.
Google I/O 2021 and Uncomfortable Questions
71–80 of 152 posts
Re: Google I/O 2021 and Uncomfortable Questions
#72Earlier quoted context omitted.
> If google wants to claim that a binary they're shipping to users is same the one they received, they don't need my private key to do that. They can make their own signature, with their own key. IIRC this is how it works by default for new apps. Uploading your existing signing key is only necessary for backwards compatibility to allow you to update existing apps that have already been published using that key.
> IIRC this is how it works by default for new apps. Personally, I'd like to see Apple, Google, and possibly Microsoft take this to what I think is the obvious conclusion: developers and independent software vendors submit source code, artwork and other such "assets", sufficient meta data, and build instructions to the store, the store builds and publishes the applications and makes them available to users. F-Droid b…
Not sure how that would work with a proprietary app store like Play store.
Re: Google I/O 2021 and Uncomfortable Questions
#73Earlier quoted context omitted.
BTW, with F-Droid does is basically the same what major Linux distros do - build everything from source on trusted infrastructure.
The model also shields to a certain extent against conflict of interests (the product is the user, i.e. ads/tracking/hostile maintainership takeover)
What I find difficult to wrap my head around is that the Debian model (I know other distributions do this as well but just have to give it some name) is very difficult to scale. We basically need maintainers at every single Linux distributions who will (I imagine) go through all the changesets/diffs and painstakingly build the deployable artifacts for their distributions. I can't imagine a single maintainer being able to maintain more than a dozen or so packages and there is a lot of duplicated effort. The Play Store has about three million apps. I know we want to be able to escalate to a human when necessary but I imagine some automation is necessary.
As I write this, I can see the contradiction in what I am asking for... if the store builds, signs, and distributes binaries using the store's credentials but cannot vouch for the quality of the application. ...
I was just thinking that if the app stores had access to the source code and the build instructions maybe that would help somehow but I didn't think it through.
Re: Google I/O 2021 and Uncomfortable Questions
#74Earlier quoted context omitted.
It is one of those situations where the excuse is really out there and much more complicated than the simple, "we 'need' the ability to modify your app before it ships." Since the article gives a plausible scenario where that would occur (could be totalitarian regime, could be an NSL letter from the FBI[1]) Here is a time where having a history of doing the "good and correct" thing would help reassure people that you…
Yes, I think this will be the way that Google satisfy e.g. the Australian government's mandate to aid intelligence and law enforcement agencies to surveil in a targeted way. Not "everyone gets a subverted copy of Signal", but "these three people get a subverted copy of Signal."
Lawfull intercept was done on IronChat, PGP-SAFE and Ennetcom that gave direct access to the communication of criminals which are now successfully used in court. In the most recent case, the tacktic of subverting all copies was successfully used by the police to decrypt Sky ECC and get access to .5 billion messages used primarily by criminals.
In this comment [1] regarding Sky ECC the question was raised
> How could I get a court order to get blanket access to Signal?
To which we now know the answer: On Android you don’t, you ask a court order for a list of specific phones you want to listen onto.
I’m baffled that Human Rights & Cilvil Liberty organisations are not standing up more fiercely against the new Play Store policy.
[0] https://news.ycombinator.com/item?id=25940566 https://news.ycombinator.com/item?id=25940670
Re: Google I/O 2021 and Uncomfortable Questions
#75really really hoping we are not entering some new capitalist platform control hell, like this article seems to be indicating.
Re: Google I/O 2021 and Uncomfortable Questions
#76Earlier quoted context omitted.
Yes, I think this will be the way that Google satisfy e.g. the Australian government's mandate to aid intelligence and law enforcement agencies to surveil in a targeted way. Not "everyone gets a subverted copy of Signal", but "these three people get a subverted copy of Signal."
And also the European anti-encryption proposals [0] Lawfull intercept was done on IronChat, PGP-SAFE and Ennetcom that gave direct access to the communication of criminals which are now successfully used in court. In the most recent case, the tacktic of subverting all copies was successfully used by the police to decrypt Sky ECC and get access to .5 billion messages used primarily by criminals. In this comment [1] re…
They might not be aware. Can't hurt to send some of those organizations emails about this.
Re: Google I/O 2021 and Uncomfortable Questions
#77Why do I care? Google can already modify the behavior of an app without the developer's permission; they can just push an update to Android that changes the behavior of that app. It's "reflections on trusting trust" all over again.
Re: Google I/O 2021 and Uncomfortable Questions
#78Given that Google has a history of accidentally breaking things in YouTube that only impacts Firefox, I'm 100% certain they can be trusted to muck around in apps written by others. Think of the opportunities. Next time Google releases a new social media system they can automatically add it into every existing Android app as a login option! Google dropping their payment system again? Not a problem, they can just chang…
> Given that Google has a history of accidentally breaking things in YouTube that only impacts Firefox For those not in the loop about this: https://archive.is/ODWrQ
I think they must have recently changed playback sync to be cloud-first, as jumping back 10s in a video has recently been badly glitching for me both in Chrome and on the iPad app. Often jumps back 20 mins to the start of a video, or where a prior session’s playback had been saved, thereby losing progress you’d made. Not the end of the world but frustrating when you’re watching a lecture and want to catch a detail you just missed. Really breaks continuity.
I’m sure maybe it consolidates implementation making each client simpler and probably satisfies a couple buzzword checkboxes from the business side but why would I possibly trust picking up playback across devices when I can’t trust it on one?
Re: Google I/O 2021 and Uncomfortable Questions
#79Google Playstore is a walled garden, like Apple's. The walls are only growing higher and higher. Once Apple adds a layer of bricks, Google follows and vice versa.
They are very different. Google provides open source alternatives. On Linux I can use Chromium. On my Android I can install F-Droid, or just install APKs manually.
Re: Google I/O 2021 and Uncomfortable Questions
#80Why do I care? Google can already modify the behavior of an app without the developer's permission; they can just push an update to Android that changes the behavior of that app. It's "reflections on trusting trust" all over again.
Whilst not preventative, even one attack would likely get enough media coverage it'd destroy Android by Google trust irreversibly.