Live data from Hacker News

Keep Android Open

keepandroidopen.org

731–740 of 907 posts

Re: Keep Android Open

#731

Earlier quoted context omitted.

Answer: bank/financial apps, enterprise apps, government apps and copyrighted media (music, video, games, books, ...). Those are the players that demand excessive control over end-user devices, and thus the ultimate driver behind the problem we're discussing. It's not that a new mobile platform couldn't possibly succeed. It's an open platform that cannot, because aforementioned players don't want it, and without them…

> Those are the players that demand excessive control over end-user devices, and thus the ultimate driver behind the problem we're discussing. But they don't demand the same control over laptops and desktops. Only phones. Why is that? Granted I can't deposit a check with my laptop but I can do any other banking I wish to do. So to me it's more that they see the chance to gain this control where they didn't see it bef…

Apple is already in the process of closing down the Mac. As for PCs... why do you think these hardware requirements were imposed on Windows 11?

Hint: When Windows 12 comes out, everyone, or at least everyone with a newish PC, will have a TPM module that's capable of enforcing and attesting a signed-code boot path from power on all the way down to application-level code. Windows 12 will turn these machines into Xboxes that run Excel. Many computers will also have Pluton technology, which is an on-chip TPM implementation that cannot be tampered with or removed from the CPU, and which literally came from Microsoft's Xbox division.

General purpose computing isn't quite dead yet, but there's really nothing we can do for the patient. We're just waiting for it to flatline.

Re: Keep Android Open

#732

Earlier quoted context omitted.

>This is why I switched to Android, just for Google now to pull the rug from under my feet again 1) You can continue to install unsigned APKs via adb with the upcoming update. 2) Signing APKs for sideloading requires a Google development account which is a one time fee of $25, no yearly fees. So still a free sideloading option available, and if you want to avoid adb it is a one time cost that is 1/4 the annual rate o…

1) Oh yes of course, here friend you just need a PC and the command line tools (unless soon you'll need to be a registered and VERIFIED developer) to install revanced or any open source app 2) Unless they decide to ban you (they can if you don't show any activity in the developer account for X months) and of course because you were verified you can't simply apply again and pay again, because you were banned!!!!

1) OP indicated his scenario was a self developed app he uses on his own personal device, not a hypothetical "friend". In terms of some unknown future scenario, speculative fear doesn't really provide anything in the ways of a constructive dialog.

2) In regards to inactive accounts, from Google's policy page:

>If you have never submitted an app for review and the account is more than one year old, it’s considered inactive.

>If you have apps, the account is considered inactive if it is more than one year old, all published apps have fewer than 1,000 combined lifetime installs, the required contact details are not verified, and you have not used Play Console in the last 180 days.

>Google sends warning emails at 60, 30, and 7 days before actual closure, allowing time to take corrective actions.

While you are correct that this would lose you access to the developer account, inactivity for a year and ignoring multiple warning messages over a 2 month period gives you an opportunity to weigh your options. It doesn't even require app updates, just activity in the Play console.

Re: Keep Android Open

#733

Earlier quoted context omitted.

The web is an open platform, and most, if not all, aforementioned applications are happily working on the web.

Web being an open platform doesn't matter in any way, when the code runs on proprietary servers.

What prevents banks, etc, from doing the same with apps for open mobile OS?

Re: Keep Android Open

#734
post #199

Android has not been really open for a long time now. - Many APIs have been moved to Google Play Services (which is not open source), and many apps have come to rely on them. You can emulate it partially but not fully, see second point below. - Some features like device attestation / SafetyNet fail on non-"official" devices, for example many banking or government ID apps refuse to work on open source os like Graphene…

Android dev at a large company - I've been talking with the folks at Graphene about options for attestation without using Google's API and it looks like there's actually a lot I can do for attestation without them, as long as I add their cert chain to a backend service.

It's a bit of a pain because Google just does that for me normally, but we _can_ support it. It's probably only a sprint of effort give or take. But we're deeply undermanned so it's hard to get done.

Re: Keep Android Open

#735

Earlier quoted context omitted.

They are pretty bad when it comes to security: https://eylenburg.github.io/android_comparison.htm

I'm going to echo the sibling comment that this comparison conveniently centers on GrapheneOS while conveniently ignoring anything they don't do; for example, a firewall using root is useful, but since they've decided user's can't be trusted with control of their devices that's right out.

[deleted]

Re: Keep Android Open

#736
post #523

Earlier quoted context omitted.

But, it doesn't. The browser is unsupported for many of the above-mentioned applications.

Can I get an example of a single one that can't be found on the web?

I seem to remember Venmo and Cash App had near useless web portals. TikTok's web app is very poor. Reddit's mobile app has functions not available on web. I bet the McDonald's web site doesn't let you order for pickup and get the deals (does Starbucks?). CapCut's web site sucks, and their desktop app is missing a bunch of features the mobile app has. I'd guess an absolute ton of betting apps don't work on the web because they are trying to do good location checking. Does Shazam even have a web version? What about mobility apps like Uber/Lyft and the bike/scooter ones?

On the flip side of the coin, some places are locked to web apps because Google & Apple won't allow them to exist. e.g. OnlyFans and Playboy can't get in the app stores, but OnlyFans still manages to make several billion dollars a year, most of which is almost certainly mobile.

Re: Keep Android Open

#737

Earlier quoted context omitted.

Google is a step ahead of that, with their device attestation technology. Now apps can make sure they are only running in an approved environment.

This is the inverse of what he's saying. Attestation takes control away from users. Permissions give control to users. The ultimate user control is not using the software at all.

That's what the GP meant, wasn't it? "Good luck with your sandboxing, Google is already a step ahead in this cat-and-mouse game".

Re: Keep Android Open

#738
post #505

Earlier quoted context omitted.

They are pretty bad when it comes to security: https://eylenburg.github.io/android_comparison.htm

Hmm... that looks like a pretty skewed comparison. It's as if somebody took the security features that make Graphene stand apart and compared everything else to them. No contention that Graphene is safe, but categorizing other OSes as "pretty bad when it comes to security" because they don't copy Graphene is a bit of a stretch.

Eylenburg's site is focused on privacy and security for the comparisons. GrapheneOS is the only privacy and security hardened OS included in the Android-based OS comparison. None of the other operating systems listed in that comparison keep up with Android privacy/security patches or provide significant OS level privacy or security improvements. Many GrapheneOS features aren't listed by the table or are grouped in huge generic categories such as "Hardened system components". An example of a major privacy feature not listed by the table is closing the leaks in Android's standard VPN lockdown mode. GrapheneOS fixes all 5 of the known outbound leaks in VPN lockdown mode, CalyxOS partially fixes 1 of them and the others don't touch this since that's not their focus. It's a privacy and security focused site comparing an OS focused on improving those in the OS layer to ones which mostly aren't.

Operating systems lagging far behind on privacy and security patches are definitely quite bad when it comes to security. For example, the official releases of /e/ for the Pixel 7 are still based on Android 13 and do not include any of the Pixel kernel, driver of firmware patches released from October 2023 and later. Eylenburg's table doesn't put much emphasis on this since it's contained within a couple rows which do not adequately communicate how delayed the updates are and how much that matters.

In addition to the official Android and OEM privacy/security patches, there are also major privacy and security improvements in each major Android release. Android also doesn't backport most Moderate and Low severity patches which are no longer given CVE assignments. Most privacy patches are considered Moderate or Low severity if at all. Many privacy improvements also aren't considered to be bug fixes since they're improvements to the intended design of the system. Only bug fixes considered to have a High or Critical severity security impact are backported. The comparison table could cover a bunch of standard Android privacy/security improvements to emphasize the importance of keeping up with the only actual LTS branch.

Re: Keep Android Open

#739

Earlier quoted context omitted.

They are pretty bad when it comes to security: https://eylenburg.github.io/android_comparison.htm

I'm going to echo the sibling comment that this comparison conveniently centers on GrapheneOS while conveniently ignoring anything they don't do; for example, a firewall using root is useful, but since they've decided user's can't be trusted with control of their devices that's right out.

Eylenburg's site has comparisons between a bunch of different types of software and services with a significant focus on privacy and security rather than aesthetic customization features, etc.

For the Android comparison, GrapheneOS is the only privacy and security hardened OS included in the comparison. DivestOS used to be included before it was discontinued. An OS not including Google Mobile Services and branding itself as private based on that is a much different thing than a privacy and security hardened OS. Which other Android-based hardened OS could be included in the comparison?

None of the operating systems listed in the comparison include app accessible root access. Giving unconstrained root access to a huge portion of the OS including the application layer including a GUI application for managing firewall rules is not a well secured to implementing it. Managing firewall rules is entirely possible to implement while following the principle of least privilege and not substantially reducing OS security. In fact, Android has standard support for it and all of the operating systems included in his comparison rely on it if you want to do fine-grained traffic filtering.

RethinkDNS is a good example of an app providing support for local filtering via the VPN service app feature without losing the ability to use a VPN. RethinkDNS supports using a WireGuard VPN or even multiple chained WireGuard VPNs while doing local filtering of both DNS and arbitrary connections. It can filter connections based on the results of filtered DNS resolution. That's the approach that's used by Android so that's inherited by every OS in the comparison.

GrapheneOS is the only OS that's listed fixing all of the leaks for standard VPN lockdown feature which is needed to prevent leaks for firewall apps including RethinkDNS based on the VPN service app feature. That's not listed by the table, although it could be and it would make sense for someone to file an issue proposing listing it. Many GrapheneOS privacy and features are not listed by Eylenburg's comparison and a lot of what's listed are under huge categories such as "Hardened system components".

Re: Keep Android Open

#740
post #199

Android has not been really open for a long time now. - Many APIs have been moved to Google Play Services (which is not open source), and many apps have come to rely on them. You can emulate it partially but not fully, see second point below. - Some features like device attestation / SafetyNet fail on non-"official" devices, for example many banking or government ID apps refuse to work on open source os like Graphene…

Android dev at a large company - I've been talking with the folks at Graphene about options for attestation without using Google's API and it looks like there's actually a lot I can do for attestation without them, as long as I add their cert chain to a backend service. It's a bit of a pain because Google just does that for me normally, but we _can_ support it. It's probably only a sprint of effort give or take. But…

Why do you need attestation? It seems to always either serve no real purpose (e.g. Bank apps) or be anti-user (DRM) (except for perhaps enterprise managed devices for companies with serious infosec requirements)
Post reply on HN