Live data from Hacker News

Keep Android Open

keepandroidopen.org

811–820 of 907 posts

Re: Keep Android Open

#811

Earlier quoted context omitted.

> Feel free to complain, but don't forget you can make choices. Of course. I can make a choice. When the choice is between being able to login to secure services with my SIM embedded e-signature, use mobile banking and conduct official business and not being able to do any of these things, making choices are easy. Running Linux on desktop is easy mode when compared to phones, and yes, I started using Linux on desktop…

Exactly - if I don't have the Monzo banking app on my phone, I can't do _any_ banking. Thinking about that now... That's not great.

I refuse to use a bank that does not have a website.

I do have one credit card that requires an app if you want to do thing online - otherwise its paper statements only. I use it a lot less as a result.

Re: Keep Android Open

#812
post #681

Earlier quoted context omitted.

Even without counting Ubuntu, was there a significant number of people against systemd in Debian, with convincing arguments?

Summary of some of them can be read at https://lwn.net/Articles/452865/ Debian’s debate page can be read at https://wiki.debian.org/Debate/initsystem/systemd

Nothing there supports there were a significant number / more than a minority of people against systemd in Debian outside Ubuntu, which was the extraordinary claim I was (implicitly) complaining against.

I see the convincing arguments against systemd, mostly wrt to the support of the FreeBSD kernel in Debian. I wasn't familiar with them, it's interesting, thanks.

Re: Keep Android Open

#813

Earlier quoted context omitted.

Kingsoft recently announced that WPS Office has 620M MAU users, the bulk of which is in China. Microsoft has even more Office users in China https://finance.yahoo.com/news/chinas-microsoft-office-rival... So if China has heard of LibreOffice, they clearly didn't like what they've heard...

It's the product of a government owned company... in China. What do you expect? Moreover, what you write is monitored, and you may loose documents based on what you write [1]. [1] https://www.wsj.com/articles/a-frozen-document-in-china-unle...

> Moreover, what you write is monitored

So just like MS Word then

Re: Keep Android Open

#814
post #442

Earlier quoted context omitted.

> Why do we have to beg Google to keep Android open? We don't! Instead, we go to regulators. Though I suspect your question really is "Why bother with salvaging Android at all?" Mobile platforms are hard - famously, Microsoft failed to make Windows phone a viable platform, and John Carmack successfully argued that Meta didn't need a custom OS. Mozilla's Mobile OS that had OEM partners making real phones spluttered ou…

> Mozilla's Mobile OS that had OEM partners making real phones spluttered out, and nor for the lack of trying. Firefox OS had serious issues. * Web standards 2013-2017 weren't ready enough. * 2013-2017 phones still weren't powerful enough for complex JS apps to feel fast. * asm.js was de-facto proprietary (a new FFOS with wasm would be be another story) * The UI wasn't so great. * Their launch devices were slow, chea…

Web standards have progressed but your other points would still apply.

Does there exist a company or project that has the resources to develop a smartphone with better performance, UI, and cost than Android or iOS devices? Microsoft couldn't pull it off, and I am skeptical that Meta would have been able to.

I can imagine an alternative smartphone carving out a niche audience like older users, FLOSS enthusiasts, digital minimalists, kids, gamers, privacy-focused users, etc. Perhaps over the span of decades such a project could iteratively improve while the incumbents enshittify and eventually surpass them in popularity.

But it seems more likely to me that Android and iOS will dominate consumer smartphones for as long as that form factor exists. When they are displaced, it'll probably be by some innovative non-smartphone computing device.

Re: Keep Android Open

#815

Earlier quoted context omitted.

The current cyber security zeitgeist is to only allow "trusted" devices in your SSO flow and to also shove your VPN authentication on that SSO flow which includes even third party browsers not working. Only Chrome with a managed profile is even allowed to login. That pretty much means if you're not using a most recent version of iOS or Android you're SOL for using it for work. And good luck spoofing it these days cau…

I don't argue that the problem isn't serious. I just want to tell that giving up is not the solution. I use a GNU/Linux phone and refuse any banks or services that don't work there. Yes, it's challenging and I have to make compromises because of it. Such is life.

Having a rooted android 11 phone for years was never a problem. My bank apps worked just fine. Even for work stuff (usually). It's on the personal side where I actually started to value having a virtual credit card on my phone with Google pay or apple pay. The stack to enable that securely is only on android and iOS and there's nothing else out there that has that. Open source community needs a full stack for attesting biometric sensors, storing secrets, and pushing them out through NFC and doing it properly is a lot.

Re: Keep Android Open

#816
post #419

Earlier quoted context omitted.

Bingo, this right here. Linux desktop wasn’t a daily driver until one day it was. Although the only problem with this strategy is that Linux got that way because of a lot of private companies that actually wanted that. Valve didn’t want to be locked in with Microsoft. Many of Microsoft’s direct competitors also don’t want to be locked in. IBM famously switched to Mac, Google has been using Mac and Linux workstations…

It's a transient state. Food for thought: how much of Linux being a daily driver depends on you having a modern Android or iOS smartphone ? If you need a locked down phone that passes remote attestation to authenticate yourself to a remote service, then whatever you use to access the service UI doesn't really matter: the only device that's necessary to have to use the service is the one you don't fully control, and w…

My daily driver has been debian and ubuntu since Potato 25 years ago. My bank has been online only since 2006 and has worked with Konqueror and later Firefox all that time.

2FA is either a standard TOTP generator or an SMS.

Now I do have a smart phone, because I'm not a complete luddite, but I can't think of anything other than perhaps some forms of entertainment (apple tv, paramount, disney perhaps) which might not work on my laptop. I shun things like notifications of my bank balance, is that an essential thing? How did people in the 90s cope without a per-minute balance?

Re: Keep Android Open

#817
post #199

Android has not been really open for a long time now. - Many APIs have been moved to Google Play Services (which is not open source), and many apps have come to rely on them. You can emulate it partially but not fully, see second point below. - Some features like device attestation / SafetyNet fail on non-"official" devices, for example many banking or government ID apps refuse to work on open source os like Graphene…

Android dev at a large company - I've been talking with the folks at Graphene about options for attestation without using Google's API and it looks like there's actually a lot I can do for attestation without them, as long as I add their cert chain to a backend service. It's a bit of a pain because Google just does that for me normally, but we _can_ support it. It's probably only a sprint of effort give or take. But…

Why do you need attesation? Why do you think Google should own that device and not the user?

Re: Keep Android Open

#818

Earlier quoted context omitted.

Yeah, I don't understand why people put up with Apple for this. I would love to write small personal apps for my iPhone. But, I don't want to use a mac, I don't want to pay a fee every year and I don't want to use the apple store (yes there are convoluted work-rounds for the last one).

It’s precisely because it’s a filter, they _want_ to filter for people who take it seriously and/or are seeking app sales. This is a company that chooses to pay people to review every app submitted to the app store, they don’t want millions of apps by tinkerers being submitted, and it reduces total crapware in the store. I’m not necessarily advocating for this approach, just explaining why they do it. Doesn’t the pla…

Then why don't they make it stupid easy to just make a build for the iPhone and transfer it directly?

Also, I am highly suspicious that they check every app submitted to the app store with a human.

Re: Keep Android Open

#819

Earlier quoted context omitted.

Samsung can cut ties with Google if they want to, they have market share to go on their own.

I'm sure they would love to. They've been trying to make their own app store (Galaxy Store) a thing for over a decade. But cutting ties with Google would mean no Google Apps and no Google Play Store, and that would probably be catastrophic for them.

Some would argue it would be more catastrophic for Google. Most people equate Samsung to Android.

Re: Keep Android Open

#820

Earlier quoted context omitted.

I haven't heard a compelling reason why remote attestation is more secure. The whole point of 2FA was to have two devices that you own. Now the bank is forcing your login and 2FA to be on the same device. Which is the easiest device to steal. What about SMS is somehow worse than that?

It's fairly easy to get control of anyone's phone number without interacting with them in any form. Just some social engineering at the kiosk in the mall. It is extremely common for people's phone numbers to be stolen (even if temporarily), and then their bank accounts drained.

> Just some social engineering at the kiosk in the mall

What scenario does a kiosk at the mall get control of my phone number but not control of my phone? I don't see how remote attestation solves anything here. Does the bank suddenly know a stranger is holding my phone?

We go from me needing to open a web browser on my computer and getting verified on my phone, to now my most important operations have to be from my phone. That's worse.

Post reply on HN