Live data from Hacker News

A theoretical way to circumvent Android developer verification

enaix.github.io

11–20 of 185 posts

Re: A theoretical way to circumvent Android developer verification

#11
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

> I hope we can get the EU to fund a truly open Android Fork.

How are things in the EU on whether it's legal to buy a SIM card without showing ID?

Re: A theoretical way to circumvent Android developer verification

#12
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?

I'm confused, how are those two things related?

Re: A theoretical way to circumvent Android developer verification

#14
post #12

Earlier quoted context omitted.

> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?

I'm confused, how are those two things related?

Nanny state

Re: A theoretical way to circumvent Android developer verification

#15
post #5
post #2

Sounds like the UEFI shim loader that's signed by Microsoft but can load an arbitrary EFI executable (with some signing checks). The difference is that the UEFI shim loader is endorsed/condoned by Microsoft. What about Google? This seems easily patchable, ostensibly for "security purposes" (eg. disabling loading dynamic code).

Microsoft also forces manufacturers to provide an option to reset Platform Key aka SecureBoot "root of trust" key - which is supposed to be not possible in spec-compliant UEFI system. They don't do it out of goodness of their hearts, which is why it's more solid than relying on goodwill - Microsoft simply has an offering that depends on that for certain high profile clients.

I suspect it's also a defense against antitrust law suits - lock in was how they got sued for things circa Internet Explorer.

Frankly they should still be getting sued for the way Edge and Cortana are bundled.

Re: A theoretical way to circumvent Android developer verification

#16
post #12

Earlier quoted context omitted.

> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?

I'm confused, how are those two things related?

The commenter you replied to was implying that the EU does not respect the privacy/freedom of mobile device users.

Re: A theoretical way to circumvent Android developer verification

#17
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?

It is neither illegal nor hard to obtain such a prepaid SIM card.

Re: A theoretical way to circumvent Android developer verification

#18
post #9

I suggested this a couple months ago: https://news.ycombinator.com/item?id=45084296 Android may ultimately win the arms race, but if they want to be evil, we should make their task as tedious as possible.

Google doesn't need to make an argument to ban apps or developers.

Re: A theoretical way to circumvent Android developer verification

#19

Earlier quoted context omitted.

> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?

It is neither illegal nor hard to obtain such a prepaid SIM card.

That very much depends on the country, many require ID.
Post reply on HN