Live data from Hacker News

Debloat non-rooted Android devices

github.com

181–190 of 231 posts

Re: Debloat non-rooted Android devices

#181
post #40

Where one can find an up to date list of obscure packages on an Android device with short description what it actually does and the impact if it was disabled/uninstalled? I'm especially interested in possible dependencies between such packages, when uninstalling one seemingly unrelated package might break something else.

This [1] is the list that UAD uses. [1] - https://github.com/Universal-Debloater-Alliance/universal-an...

Thank you, that's quite a big list.

Re: Debloat non-rooted Android devices

#182

Earlier quoted context omitted.

Oh dear. I had disabled the Samsung keyboard for some other, but it seems it got reenabled again. Maybe Google broke some API endpoint and the old keyboard didn't do the update grind. No warning what so ever for their spyware taking over the keyboard functionally. The need for some FOSS mobile is really over due by now. Edit: > I immediately found an open source keyboard to replace samsung's with Which keyboard did y…

AnySoftKeyboard I've been using it ever since. It's got a lot of customization options and all the keys I need.

Hmm, seems to not be available for my Pixel 6. The github looks very active but there hasnt been a release there (or Google Play or Fdroid) in over 2 years.

Re: Debloat non-rooted Android devices

#183

Earlier quoted context omitted.

The first time I had a samsung phone I noticed after about two weeks that every single word I typed into any application was being collected and sent to a third party whose privacy policy said it was used to collect data about my interests, my social life, to make guesses about my intelligence level and education, and that the data would be sold for "market research" among other things. No user would ever suspect tha…

I find it mind blowing that: 1. Samsung is able to sell phones like that legally. 2. People are not in jail. 3. Governments somehow think it's ok that random companies can see everything their citizens do online. National security risks maybe? Trade secret issues? It's almost suspicious to the point where I would start thinking those third party spy companies are possibly (US/5 eyes) government run?

well websites ad-tech have been very able to track mouse movement/location, characters pressed (but not submitted) for 15 years at least; people are fine with this fact too (even if its 1 or 2 monopolies that phone home - and then share data lol)

android's have done similar for a very long time; customers have known about it, and turn a blind eye cuz its a new-shiney

Re: Debloat non-rooted Android devices

#184
post #63

Earlier quoted context omitted.

That's a bold understatement, you're pretty much fucked without BankID on your phone.

In Denmark, MitID supports non-phone authenticators. You have to request it, but a few days later they send a TOTP generator keyfob. They also have a version for blind people. I would find it annoying if I had to carry the keyfob. I have it as a backup. https://www.mitid.dk/en-gb/get-started-with-mitid/mitid-auth...

Why don't they just use RFC 6238 TOTP?

Re: Debloat non-rooted Android devices

#185
post #184

Earlier quoted context omitted.

In Denmark, MitID supports non-phone authenticators. You have to request it, but a few days later they send a TOTP generator keyfob. They also have a version for blind people. I would find it annoying if I had to carry the keyfob. I have it as a backup. https://www.mitid.dk/en-gb/get-started-with-mitid/mitid-auth...

Why don't they just use RFC 6238 TOTP?

The system is used for authentication for banking, accessing healthcare records, tax records, filing for divorce (yes, online) and so on. And for doing similar things for ones children, depending on their age.

By using an app or various hardware keys — with a maximum of three active methods — they can reduce the chance that additional people have access, and prevent duplication of the private keys. This isn't possible with a QR code to scan for TOTP (you can scan it on multiple devices, or print it out, or have a computer with malware doing this).

Initial authentication is done using a passport, or in-person at a local government office for people without one (or without access to a phone capable of reading the passport's chip).

(This is just my general understanding of the system.)

Re: Debloat non-rooted Android devices

#186

Kind of related, a few weeks ago I've been thinking to myself what happened to the open source free software operating system developments for mobile devices? Specifically, how are operating system environments such as GrapheneOS and CalyxOS, etctera, only able to be used on a single company's (Alphabet Inc) manufactured phone devices and not any other devices and where are the operating systems that work on as many…

> how are operating system environments such as GrapheneOS and CalyxOS, etctera There are ZERO open source OS for mobile. ZERO. NONE. even the ones you list doesn't have access to essential drivers. What do they do? they get the driver as binary blobs from the original image, and just ship them. So all those projects are 1) full of closed source kernel drivers. 2) stuck on a specific kernel version to be able to use…

There is Replicant [0] which is completely proprietary blob/firmware free but it has extremely limited hardware support with only support for Samsung devices from 2011-2012.

[0] https://www.replicant.us

Re: Debloat non-rooted Android devices

#187
post #82

Earlier quoted context omitted.

Some banking apps detect this, or might detect it in the future, and refuse to work. In some countries (Scandinavia...) not having the banking app is inconvenient, as it's used for authentication with many other services.

Magisk (the main rooting method) allows you to hide root from such apps. Most apps I use (ie. banking) are bypassed simply by adding them to a hide-list. The only apps that require a bit more work / expertise are apps that require integrity checks (ie. google wallet).

> The only apps that require a bit more work / expertise are apps that require integrity checks (ie. google wallet).

"A bit more work" but only for now... There is a loophole (spoofing the device fingerprint with the one of an old model where non-hardware attestation is still accepted) but Google is starting to ban those models and it's only a matter of time until they're all banned.

Re: Debloat non-rooted Android devices

#188
post #18

I bought -- full price, retail -- a midrange Samsung phone for a relative recently. The amount of bloatware was incredible. Various social networks and shopping apps were preinstalled. In addition to all the Samsung apps that more or less duplicate the Google stack, poorly. The entire setup process was full of dark patterns designed to extract as much data from you as possible. No way a regular person gets through th…

What are the reasons someone would want to buy any Android device beside a new or used Google Pixel?

Re: Debloat non-rooted Android devices

#189

Kind of related, a few weeks ago I've been thinking to myself what happened to the open source free software operating system developments for mobile devices? Specifically, how are operating system environments such as GrapheneOS and CalyxOS, etctera, only able to be used on a single company's (Alphabet Inc) manufactured phone devices and not any other devices and where are the operating systems that work on as many…

> how are operating system environments such as GrapheneOS and CalyxOS, etctera There are ZERO open source OS for mobile. ZERO. NONE. even the ones you list doesn't have access to essential drivers. What do they do? they get the driver as binary blobs from the original image, and just ship them. So all those projects are 1) full of closed source kernel drivers. 2) stuck on a specific kernel version to be able to use…

> There are ZERO open source OS for mobile. ZERO. NONE.

This is false. Sent from my Librem 5, which runs FSF-endorsed PureOS.

Re: Debloat non-rooted Android devices

#190
post #188
post #18

I bought -- full price, retail -- a midrange Samsung phone for a relative recently. The amount of bloatware was incredible. Various social networks and shopping apps were preinstalled. In addition to all the Samsung apps that more or less duplicate the Google stack, poorly. The entire setup process was full of dark patterns designed to extract as much data from you as possible. No way a regular person gets through th…

What are the reasons someone would want to buy any Android device beside a new or used Google Pixel?

Combination of price and length of software support.
Post reply on HN