Live data from Hacker News

A theoretical way to circumvent Android developer verification

enaix.github.io

21–30 of 185 posts

Re: A theoretical way to circumvent Android developer verification

#21
post #8

Well, I'd rather verify myself with the government identity than accept a stock OS that literally woke me up with a fake message promoting Gemini despite me spending almost 2 hours turning every possible privacy-invasive setting off. To me, the attention to these verification changes seems misplaced. We need to defend the ability to unlock the bootloader, pressure Google to revive AOSP and then encourage people to sw…

In my opinion, the only solution while keeping Google and Apple as the developing entities is regulation.

Despite that, there are some things that should not be for profit in my opinion. A good OS platform is one such thing.

Re: A theoretical way to circumvent Android developer verification

#22

Earlier quoted context omitted.

It is neither illegal nor hard to obtain such a prepaid SIM card.

That very much depends on the country, many require ID.

The ID presented at time of purchase does not have to be the ID of the actual user of the card. Your local drunkard will be happy to get $10 to buy a SIM card for you. Or you could visit eBay (or local equivalent) and get a valid SIM card without leaving your house.

Re: A theoretical way to circumvent Android developer verification

#23

Earlier quoted context omitted.

That very much depends on the country, many require ID.

The ID presented at time of purchase does not have to be the ID of the actual user of the card. Your local drunkard will be happy to get $10 to buy a SIM card for you. Or you could visit eBay (or local equivalent) and get a valid SIM card without leaving your house.

The suggestion above wasn’t a statement of practicality but rather of EU motivations. Maybe you can also find a drunkard to fork Android for you.

Re: A theoretical way to circumvent Android developer verification

#24

Earlier quoted context omitted.

It is neither illegal nor hard to obtain such a prepaid SIM card.

That very much depends on the country, many require ID.

Germany requires ID for all SIMs (for "normal" people). You can buy activated SIMs in every bigger city if you know what to look for though.

Re: A theoretical way to circumvent Android developer verification

#25
This "attack" is not even theoretical. Android apps can just download arbitrary binary code, mprotect(PROT_MAYEXEC) some area in RAM, link the code there, and run it.

Google will simply revoke the keys for the "loader" APK. But that's fine for malware, its authors will just use the next stolen credit card to register a new account.

That's also why this has nothing to do with security.

Re: A theoretical way to circumvent Android developer verification

#26
post #15
post #5

Earlier quoted context omitted.

Microsoft also forces manufacturers to provide an option to reset Platform Key aka SecureBoot "root of trust" key - which is supposed to be not possible in spec-compliant UEFI system. They don't do it out of goodness of their hearts, which is why it's more solid than relying on goodwill - Microsoft simply has an offering that depends on that for certain high profile clients.

I suspect it's also a defense against antitrust law suits - lock in was how they got sued for things circa Internet Explorer. Frankly they should still be getting sued for the way Edge and Cortana are bundled.

Then Apple should get sued for bundling Safari, and also for forcing all browser engines on iOS to use Safari - which is way worse than anything Microsoft ever did with IE.

Re: A theoretical way to circumvent Android developer verification

#27

Earlier quoted context omitted.

That very much depends on the country, many require ID.

The ID presented at time of purchase does not have to be the ID of the actual user of the card. Your local drunkard will be happy to get $10 to buy a SIM card for you. Or you could visit eBay (or local equivalent) and get a valid SIM card without leaving your house.

>While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem.

Re: A theoretical way to circumvent Android developer verification

#29

Earlier quoted context omitted.

It is neither illegal nor hard to obtain such a prepaid SIM card.

That very much depends on the country, many require ID.

You can use any country's SIM card in any other country, regardless of its registration status.

Re: A theoretical way to circumvent Android developer verification

#30
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?

A secure OS is a prerequisite for secure digital services. We can agree on that, right?

The task, therefore, is to convince enough politicians to establish an independent unit that can address this issue without direct political influence.

Fund the unit with enough money so that it can take care of the cybersecurity and sovereignty of all citizens.

A side effect of this would hopefully be that these politicians would then be digitally literate enough to recognize nonsense such as chat control as such and reject it outright. I hope that most politicians would not really want such omnipotent surveillance tools if they could truly grasp their scope.

Post reply on HN