Live data from Hacker News

Keep Android Open

keepandroidopen.org

831–840 of 907 posts

Re: Keep Android Open

#831

Earlier quoted context omitted.

There are privilege escalation CVEs in bootloader code too. I remember unlocking some very early locked bootloaders this way in the early days of android.

So much rarer now. Its getting more and more locked down unfortunately.

A lack of security vulnerabilities isn't really a matter of being "locked down" but rather "not broken"

Re: Keep Android Open

#832

Earlier quoted context omitted.

This is only until the only 2FA solutions that the bank requires you to use to log in and authorize transactions only come as smartphone apps.

to your point, not exactly a one-to-one, but several discount airlines (e.g., RyanAir, PLAY, Allegiant, Frontier, Spirit, Wizz, Flair, AirAsia) already require an app to check in for a flight, or pay a fee. No app (or the horrors, no mobile), it cannot be done on a regular computer, must go to a ticket counter and pay a fee.

Maybe some, but certainly not all in the list. Neither Ryanair nor Wizzair need app, you can do everything in the browser.

Re: Keep Android Open

#833

Earlier quoted context omitted.

> Answer: bank/financial apps, enterprise apps, government apps and copyrighted media (music, video, games, books, ...). Those are the players that demand excessive control over end-user devices, and thus the ultimate driver behind the problem we're discussing. Those work perfectly via a browser, on any platform where the browser can run. As long as a hypothetical open OS has a browser capable with bog standard moder…

You're getting downvoted because that's not the point. You are technically right, we still have access to these services via a web browser today. It doesn't mean we'll have it forever. With the advent of AI browsers and AI agents, it's not hard to think of a future where LLM chat interfaces and mobile apps are the future, and web apps start getting disregarded as legacy and eventually, discontinued. Try ordering some…

My reply is a counterpoint to the statement that banks, government services and streaming services require excessive control over my device. They aren't, as they all can run in a browser, which sandboxes them from the OS. That's it.

And I guess people who downvoted my counterpoint thought that it means that all services on the planet have very well functioning browser version, judging by their comments. Some don't, some do. But no one of them "requires" excessive access a native app can provide.

Some may want to have it, for some browser version is simply not a priority. But nobody needs to have additional info for those services to function.

Re: Keep Android Open

#834

Earlier quoted context omitted.

Answer: bank/financial apps, enterprise apps, government apps and copyrighted media (music, video, games, books, ...). Those are the players that demand excessive control over end-user devices, and thus the ultimate driver behind the problem we're discussing. It's not that a new mobile platform couldn't possibly succeed. It's an open platform that cannot, because aforementioned players don't want it, and without them…

Back in '99 Linux didn't run Excel/Word/Powerpoint or most games, but I ran it anyway. What others call showstoppers are for me inconveniences. I have a motorolla edge 2024 that I'll load whatever open source phone OS will work well enough to place calls and browse the web. I'll keep another phone for the rare times some corporate/government overlord requires it. Many folks who refuse to use smartphones, similarly ow…

The problem is as aforementioned players pressure users and government, they can make certain aspects of the economy entirely inaccessible to unapproved platforms. Netflix and co can simply refuse to support streaming on devices which aren't hardware locked. Banks can refuse to do business. Sure banks have in person locations, but they've become fewer and more backed up.

One certain thresholds are reached, little can be done even for the committed outcast.

Re: Keep Android Open

#835
post #442

Earlier quoted context omitted.

> Mozilla's Mobile OS that had OEM partners making real phones spluttered out, and nor for the lack of trying. Firefox OS had serious issues. * Web standards 2013-2017 weren't ready enough. * 2013-2017 phones still weren't powerful enough for complex JS apps to feel fast. * asm.js was de-facto proprietary (a new FFOS with wasm would be be another story) * The UI wasn't so great. * Their launch devices were slow, chea…

Web standards have progressed but your other points would still apply. Does there exist a company or project that has the resources to develop a smartphone with better performance, UI, and cost than Android or iOS devices? Microsoft couldn't pull it off, and I am skeptical that Meta would have been able to. I can imagine an alternative smartphone carving out a niche audience like older users, FLOSS enthusiasts, digit…

Nobody was wanting to pay for and deal with the Microsoft lock in.

A new web-centric OS could fix those issues by doing a few things to reduce friction.

First, use an Android-compatible kernel version so drivers are easy to port. This gets manufacturers on board.

Second, make your App Store a non-profit that charges enough for ongoing store development and distribution. This gets devs on board.

Third, make sure you have decent third party framework support. Flutter, react native, and maybe even an Android runtime that legacy apps can integrate into their wasm binary. This helps kickstart your ecosystem.

Fourth, add better integration of webgpu and 2d canvas (which probably needs some extending). In addition, they need to add a low-level API to access DOM nodes from wasm. For security and ease of implementation (without stepping on the toes of the normal standardization stuff), this would probably be a virtual DOM with only a provably secure subset of the actual nodes being sent back and forth.

UI is an easier problem. The best design to date is still webOS. Copy their general design (maybe rip off some of their never-shipped mochi stuff).

The biggest issue as you said is financing. All these things turn into lots of developers and time. The best bet here would be replacing something like Tizen where a corporation is already investing.

Re: Keep Android Open

#836

Earlier quoted context omitted.

> Why do we have to beg Google to keep Android open? Seriously. Because the market has failed, and we have a duopoly. There are many reasons for that, but, this is the exact sort of time a govt must step in - when something becomes a utility, it needs to be regulated as such. I agree, I don't really want to enshrine Google/Apple into law, however if they are makers of an operating system that is used like a common ut…

Unfortunately western governments are moving to impose more and more control over our digital life, and I think they see a locked down commercial platform as a convenient means to that end because they can regulate it. If the EU commission ever succeeds in passing Chat Control, which requires client side scanning on all devices, then it is very convenient for them if people do not use open source operating systems wh…

EU govs siding with google in this move would be catastrophically stupid, it's equivalent to ceding their digital sovereignty to the US. All it would take to knee-cap Europe is for the US to command google to suspend all european developers' accounts, and suddenly Europe is fucked. No banking apps, no government services, no nothing.

The only rational step for the EU is to support open everything: Open Software, Open Hardware, Open platforms, etc...

Beggars can't be choosers. Until they pony up the cache to fork android, they're beholden to the US.

Re: Keep Android Open

#837
post #249

Earlier quoted context omitted.

I can see why they add the fee, but they would both garner so much goodwill by giving free accounts if the app you publish is open source. I don't think it would be that hard to automate by requiring a GitHub link.

Those days are over. Being evil means there is no goodwill to begin with unless you can exploit it financially wise. Google stopped being not evil, they specifically deleted it from the code of conduct. Ofc, being evil is subjective. But also this is the first excuse of evil players!

[dead]

Re: Keep Android Open

#838

Earlier quoted context omitted.

It's a transient state. Food for thought: how much of Linux being a daily driver depends on you having a modern Android or iOS smartphone ? If you need a locked down phone that passes remote attestation to authenticate yourself to a remote service, then whatever you use to access the service UI doesn't really matter: the only device that's necessary to have to use the service is the one you don't fully control, and w…

My daily driver has been debian and ubuntu since Potato 25 years ago. My bank has been online only since 2006 and has worked with Konqueror and later Firefox all that time. 2FA is either a standard TOTP generator or an SMS. Now I do have a smart phone, because I'm not a complete luddite, but I can't think of anything other than perhaps some forms of entertainment (apple tv, paramount, disney perhaps) which might not…

Account balance is a litmus test. If you can't liberate even that information, you've lost control over the banking and your own device.

> 2FA is either a standard TOTP generator or an SMS.

For now. Be grateful while you have it. Most banks everywhere are moving to 2FA through push notifications to their proprietary app, and are deprecating other channels. TOTP is becoming unusual in a bank; where I live, I haven't seen it in use in banking in over a decade (though I'm not counting SMS here; they're technically kind of like TOTP, but they're generated by the service, not on your end).

Between that and a web-wide push for passkeys, having a locked down smartphone is already becoming a soft requirement for doing anything on the web.

Re: Keep Android Open

#839
post #58

Back in the 2007 or when it came out in Sweden I bought the iPhone and started developing for it. This was cool, new and exciting and it was fine as long as my company was paying the $100 fee every year. But then I switched jobs and worked at a company which produced mostly open source code. Suddenly I would have to pay $100 every year just to be able to put my own software on the phone ... This is why I switched to…

Yeah, I don't understand why people put up with Apple for this. I would love to write small personal apps for my iPhone. But, I don't want to use a mac, I don't want to pay a fee every year and I don't want to use the apple store (yes there are convoluted work-rounds for the last one).

Have you tried Expo Go?

Re: Keep Android Open

#840

Earlier quoted context omitted.

It's fairly easy to get control of anyone's phone number without interacting with them in any form. Just some social engineering at the kiosk in the mall. It is extremely common for people's phone numbers to be stolen (even if temporarily), and then their bank accounts drained.

> Just some social engineering at the kiosk in the mall What scenario does a kiosk at the mall get control of my phone number but not control of my phone? I don't see how remote attestation solves anything here. Does the bank suddenly know a stranger is holding my phone? We go from me needing to open a web browser on my computer and getting verified on my phone, to now my most important operations have to be from my…

I am not arguing for some alternate solution. But sim swap attacks are common and relatively easy to do [1].

> The scam begins with a fraudster gathering personal details about the victim .... the fraudster contacts the victim's mobile telephone provider. The fraudster uses social engineering techniques to convince the telephone company to port the victim's phone number to the fraudster's SIM. This is done, for example, by impersonating the victim using personal details to appear authentic and claiming that they have lost their phone.

SMS 2FA should simply not be used if one cares about security.

[1] https://en.wikipedia.org/wiki/SIM_swap_scam

Post reply on HN