Live data from Hacker News

Keep Android Open

keepandroidopen.org

701–710 of 907 posts

Re: Keep Android Open

#701

I don't understand the Google's move. Google uses Android as a platform to collect virtually everyone's personal info and build the profile to benefit its ad business. If there is an extremely tiny chance that people (or a sizble population) may walk away from the platform, it's not worth the risk.

It's Google's response to the remedies required by the Antitrust act decision last August. The timing is explained by the US Supreme Court decision of Oct 6 to deny Google its request to pause implementation of said remedies.

Re: Keep Android Open

#702

Earlier quoted context omitted.

> Security is important The argument that this is actually a security benefit is a farce. It doesn't do anything. If the device is compromised then it's going to capture your password and send it to the attacker without attempting any attestation. So the only time the attestation is attempted is when the device isn't compromised.

Yes, if it was a measure of device security they would revoke attestation of devices that are behind on security updates. But no, a 5 year old device that never got security updates is A-OK according to Google but a completely up to date custom ROM is not. It's clearly not about real security. It is about control. You follow the rules and get Google's blessing or no SafetyNet for you. These rules include things like…

I think you are right that it is about control.

Let me offer another perspective. The OS vendor actually has significant control over your device. They could plant backdoors in different layers of the OS.

Therefore, in their defense, if the OS doesn't come from a trusted source (in the bank's or Google's point of view), your bank's credentials are essentially compromised.

You could argue that there are backdoors either way. They are just controlling which party gets to plant the backdoors, after all.

Re: Keep Android Open

#703
post #219

Earlier quoted context omitted.

The Year of the Linux Desktop is kind of happening. Not at the scale that the meme implies, but I've never seen anywhere near as much adoption of the Linux desktop as this year. The combination of Valve's efforts, more usage of Linux gaming handhelds, distributions like Bazzite that have strong selling points for Windows gamers, and Microsoft pissing everyone off with everything that is Windows 11, the Linux desktop…

Not really, because Proton is Win32, kind of.

Half of the applications people use on Windows are just browsers in a native frame, at this point Win32 is just one of the many "stacks" that you can run on Linux.

Re: Keep Android Open

#704

Earlier quoted context omitted.

We're already there. Attestation is not in your phone, but in your ID card. European passports and ID cards carry biometric data of your face, so you can be computationally verified. I'm aware of this slippery slope for a very long time, esp. with AI (check my comments if you prefer). On the other hand, I believe that we need to choose our battles wisely. We believe that technology is the cause of these things, it's…

I feel better having a physical token like an ID than it being on my phone, however.

Sure, but the bank feels better about forcing you to interact with their app on a daily basis, because this gives them a direct upsell channel for their financial services. They don't actually want you to us a physical token. Security is only an excuse.

Re: Keep Android Open

#705

Earlier quoted context omitted.

I feel better having a physical token like an ID than it being on my phone, however.

Sure, but the bank feels better about forcing you to interact with their app on a daily basis, because this gives them a direct upsell channel for their financial services. They don't actually want you to us a physical token. Security is only an excuse.

Yup, right on target.

Re: Keep Android Open

#706

Earlier quoted context omitted.

Answer: bank/financial apps, enterprise apps, government apps and copyrighted media (music, video, games, books, ...). Those are the players that demand excessive control over end-user devices, and thus the ultimate driver behind the problem we're discussing. It's not that a new mobile platform couldn't possibly succeed. It's an open platform that cannot, because aforementioned players don't want it, and without them…

> Answer: bank/financial apps, enterprise apps, government apps and copyrighted media (music, video, games, books, ...). The only real issue here is banks that don't offer an equivalent website or require the "app" as authentication factor. I couldn't care less about copyrighted media. It's only fair that I source my media from the high seas when the only options that respect their "rights" infringe my own right to r…

The key thing isn't that the banks (and governments, and enterprise software vendors, and ...) don't provide an alternative to the app as authentication factor. It's why they don't do this.

It's not about security. It's about them wanting people to use the apps. Forcing everyone to use an app streamlines the vendors' operations, reduces the state space of possible user interactions down to small number of flows they control directly, and also provides them a direct channel (communications or upsell, where applicable) to the user.

This is not a fluke or a conspiracy of small number of influential players. It's an emergent alignment of incentives across pretty much the whole supply side of digital aspect of human civilization (not "just" the market, because it's also happening in political and social spheres).

Re: Keep Android Open

#707
post #86
post #46

Earlier quoted context omitted.

Most vendors (at some level) allow flashing custom distributions, as long as you didn't buy that device from carrier: https://github.com/zenfyrdev/bootloader-unlock-wall-of-shame... You will lose DRM-based apps (e.g. Netflix), Payment apps, and bank apps though.

Most DRM / banking apps work fine for me through the browser and you can add them to your home screen. Android / Samsung Pay will stop working, but if you have a Garmin watch, you can still pay with that.

Only for now. Google did push the Web Environment Integrity API, which is basically "Play Integrity API for Chrome," that helps websites check if the OS, browser, or installed extensions are "safe".

Fortunately, they backed off and decided to abandon the proposal after massive backlash. But we don't know when we will see a 2.0 version of that.

Re: Keep Android Open

#708

Earlier quoted context omitted.

Because SMS is not considered a secure 2FA mechanism anymore, and hasn't been for a while. If that's the default for that bank, and not GP going out of their way to pick a legacy access path, then they're about a decade behind what's considered industry standard -- which today is querying a second factor not just per login, but also per important operations (money transfers, dispositions, changes in settings), with t…

Uh, banks still provide separate tokens and one time pad cards last I've heard. If yours doesn't, pick one that does.

The larger point here isn't whether they do, but that they'd rather not. They want you to rely on their app, and have been pushing people to it for years now (some more intensely than others).

Re: Keep Android Open

#709
post #677

Stallman was right.

> Stallman was right. Stallman did not find an economic model that works within our business/legal environment.

Non sequitor. He was right about what companies would do if allowed, and that's the most important thing to keep in mind.

Re: Keep Android Open

#710
post #702

Earlier quoted context omitted.

Yes, if it was a measure of device security they would revoke attestation of devices that are behind on security updates. But no, a 5 year old device that never got security updates is A-OK according to Google but a completely up to date custom ROM is not. It's clearly not about real security. It is about control. You follow the rules and get Google's blessing or no SafetyNet for you. These rules include things like…

I think you are right that it is about control. Let me offer another perspective. The OS vendor actually has significant control over your device. They could plant backdoors in different layers of the OS. Therefore, in their defense, if the OS doesn't come from a trusted source (in the bank's or Google's point of view), your bank's credentials are essentially compromised. You could argue that there are backdoors eith…

> Therefore, in their defense, if the OS doesn't come from a trusted source (in the bank's or Google's point of view), your bank's credentials are essentially compromised.

"Compromised" means that someone has them who will use them for unauthorized activity. When your device is infected with malware because it's running the same version of Android it came with that hasn't received a security update in several years, entering your credentials into that device will cause them to be compromised. When your device has a custom ROM that isn't sending your credentials to anyone it isn't supposed to, they are not compromised.

But the first device passes attestation and the second one doesn't. Moreover, that is the common case -- the version of Android that came with the device is likely to be older and have more vulnerabilities than a custom version installed later. Which means that passing attestation isn't just uncorrelated with uncompromised devices, it's actually anti-correlated with them. Requiring it is forcing users to keep and use the older OS with known vulnerabilities on that device.

Post reply on HN