Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

131–140 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#131
post #94
post #61

Earlier quoted context omitted.

Not the parent poster but my bank uses its own mobile app for 2FA. No app, no website.

Perhaps there's another bank you can switch to? Here we have a few mobile-only banks, but traditional banks with websites and physical MFA devices as an option too.

Sadly, traditional banks are very eager to get rid of dedicated multi-factor devices in favour of their own mobile applications. I have seen strong encouragement via nagging and some going so far as to start charging for physical multi-factor authentication devices.

Likely this gives them another way to milk information out of you, push their marketing onto to you, and saves them from having to manage physical devices. The obvious downside is of course a degradation in security and further cementing the duopoly and more or less forced participation in it that we as citizens have to endure.

Re: Uncomfortable Questions About Android Developer Verification

#132
post #115

Earlier quoted context omitted.

All of those are fine things to expect from Google Play but the point is moot because this verification would also apply to apps installed from external sources where they shouldn't have any jurisdiction. Google, just like Apple, should be free to enforce any kind of verification they deems necessary on Google Play, as long as they allow third party stores to be on equal footing, which they don't.

I agree. we should be able to install apps we want to install. But if you're installing them from the Google Play store (which is what is discussed) then you should be allowed to know who you're doing business with.

> But if you're installing them from the Google Play store (which is what is discussed)

Maybe there's been a miscommunication somewhere but Android Developer Verification (what this thread is about) applies to all apps, even those installed outside of Google Play store.

Re: Uncomfortable Questions About Android Developer Verification

#133
post #19

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

> Why is it so complex to have a foss mobile OS.

This is not too hard. What is hard is to trust it enough. A FOSS OS, by definition, allows to install whatever software, and allows for modification of itself. It is built to overcome limitations, not impose them. In this regard, it's a perfect tool for a criminal who wants to circumvent security measures, because these are limitations. It's the same problem as with cheaters in online games, only with more than games on stake. Banks and payment systems want guarantees of integrity and protection, including protection from user's actions.

A FOSS OS also assumes that the user values the freedom, and is competent in its technical aspects. This is emphatically not true about many users. They choose iOS because it's locked down and thus they cannot inadvertently do something they don't understand, and can't be bothered to learn. More importantly, their grandmother cannot do something she doesn't understand but scammers persuade her to do.

It's a bit like driving on public roads. If you want to drive yourself, you have to reveal your identity and obtain a license. If you want the hassle, take a bus, but buses only go along their routes. Letting unlicensed people drive cars where they see fit was found unacceptably dangerous for everyone eround. Maybe mainstream mobile software development will follow this model, too :(

Re: Uncomfortable Questions About Android Developer Verification

#134
post #74

Earlier quoted context omitted.

I think that they are pointing at that using Android in daily life in a meaningful way requires installing Google Play Services because many apps require it.

You can use microG which provides a lot of Google Play Service functionality.

at the mercy of Google, yes.

Re: Uncomfortable Questions About Android Developer Verification

#135
post #73
post #19

Earlier quoted context omitted.

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

My bank blocks my mobile with Lineage OS, and it's not even possible to login to the web site without the mobile app. Absolutely pathetic.

Now I have to keep my 4 year old phone with 2 year outdated Android to access the bank application. Which deemed more safe then my mobile with latest security updates. Haha

Re: Uncomfortable Questions About Android Developer Verification

#136
post #76

Earlier quoted context omitted.

This is 'easily' solved by following the Apple road - focus on one or two devices. I think many FOSS enthusiasts would be happy to buy such devices. (I am holding out hope for the phone that the GrapheneOS project is planning to make.)

This has been attempted multiple times, and always fails because followoing FOSS to the letter doesn't play with how hardware industry works, and when people aren't willing to make concensions they cannot ever deliver a product the general public would replace their Android/iOS phones with.

GrapheneOS and SailfishOS focus on a narrow set of devices and they can keep up with hardware support. I agree that you have to make concessions in terms of allowing proprietary firmware blobs and opaque baseband hardware. You also have to choose your hardware wisely (e.g. GrapheneOS can/could piggyback on Google's driver work).

I was just saying that you can make the problem more narrow by not trying to support every device out there. Start small and pick your battles (which probably means using AOSP and using sandboxed AOSP).

I think the main issue of many previous attempts was what typically happens in the FLOSS community: there are N attempts rather than one coordinated attempt (Ubuntu Touch, Plasma Mobile, PostmarketOS, PureOS, etc.) and everybody is targeting different hardware. It's similar to how the Linux desktop got fragmented, though it's even more problematic for mobile, since the usage is probably 1/1000th of Linux desktop usage.

Re: Uncomfortable Questions About Android Developer Verification

#137
post #45
post #19

Earlier quoted context omitted.

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

It's pretty obvious, it's costly to make one that is up to the level of quality of commercial ones. It's not a mistake that the 2 mobile oses are owned and created by some of the largest and most profitable companies in the world.

It’s costly, but those two companies also operate in a hierarchical manner (like the military or a feudal kingdom) which makes decision-making and accountability much easier. The FOSS world has been rife with petty agree-or-fork squabbles, often over relatively abstract philosophical concerns about license language.

Re: Uncomfortable Questions About Android Developer Verification

#138
post #99

Earlier quoted context omitted.

This is 'easily' solved by following the Apple road - focus on one or two devices. I think many FOSS enthusiasts would be happy to buy such devices. (I am holding out hope for the phone that the GrapheneOS project is planning to make.)

Are you aware of the PinePhone and Librem 5? As others have said, it's already been tried. I bought a PinePhone, and after a few too many show-stopping issues (not being able to receive a call for a scheduled job interview was the last straw), I went back to using LineageOS without gapps. I'm not a developer either, just a fairly technical user, so when the device wasn't working, all I could do was report bugs, and t…

Don’t worry, the PinePhone Pro is now EOL while the original one will go on for 2 more years!!!

Re: Uncomfortable Questions About Android Developer Verification

#139

Earlier quoted context omitted.

From your link 0: > The question here is, is it ever a good thing to use a nonfree program? Our conclusion is that it is usually a bad thing, harmful to yourself and in some cases to others. If you run a nonfree program on your computer, it denies your freedom; the immediate wrong is directed at you. That is most certainly not making concessions for practicality in my book. So if anything, the citation you provided i…

To continue with the text of the rest of the section (with the footnotes present in the original removed): If you run a nonfree program on your computer, it denies your freedom; the immediate wrong is directed at you. That does not mean you're an “evildoer” or “sinner” for running a nonfree program. When the harm you're doing is mainly to yourself, we hope you will stop, for your own sake. Sometimes you may face grea…

Thanks, I wasn't trying to cherry pick or anything. But I don't think that the full text changes the substance of what is laid out in the first couple of paragraphs. The FSF (and by extension Stallman) refrains from calling the user names if he chooses to use nonfree software, presumably because they recognize that freedom must include the freedom to run any software at all, even if they consider it harmful. But they are quite clear that they do consider it harmful both to oneself and others to run nonfree software, even if it is useful. That, to me, is very much refusing to make concessions to practicality within their ideology. The only concession they do make is an explicitly ideological one, not a practical one! So again, this piece seems to me to support my claim, not to disprove it.

Re: Uncomfortable Questions About Android Developer Verification

#140
post #19

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

As Microsoft how is it so difficult to have a mobile os
Post reply on HN