Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

201–210 of 694 posts

Re: Android developer verification: Early access starts

#201
post #67

Earlier quoted context omitted.

Yeah then you have the choice to not buy the locked down hardware, you don't have a right to get open hardware FROM Google. Of course there are no good options for open hardware, but that is a related but separate problem.

It's not a separate problem, Google are actively suppressing any possibility of open mobile hardware. They force HW manufacturers to keep their specs secret and make them choose between their ecosystem and any other, not both. There's a humongous conflict of interests and they're abusing their dominating position.

> They force HW manufacturers to keep their specs secret

Spoken like someone who has never ever worked with any hardware manufacturers. They do not need reasons for that. They all believe their mundane shit is the most secret-worthy shit ever. They have always done this. This predates google, and will outlive it.

Re: Android developer verification: Early access starts

#202
post #193

Earlier quoted context omitted.

> Yeah, let's ask the Debian team about installing packages from third party repos. Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows. Hence you don't realize how good of an argument it is, because you even bamboozled yourself without realizing it. It gets a worse argument if we want to discuss Qubes and other di…

"Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows." This is only true if you use Secure boot. It is already not needed and insecure so should be turned off. Then any OS can be installed.

I agree with you and run with it disabled myself, but some anti-cheat software will block you if you do this. Battlefield 6 and Valorant both require it.

Re: Android developer verification: Early access starts

#203
post #193

Earlier quoted context omitted.

> Yeah, let's ask the Debian team about installing packages from third party repos. Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows. Hence you don't realize how good of an argument it is, because you even bamboozled yourself without realizing it. It gets a worse argument if we want to discuss Qubes and other di…

"Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows." This is only true if you use Secure boot. It is already not needed and insecure so should be turned off. Then any OS can be installed.

While it's possible to install and use Windows 11 without Secure Boot enabled, it is not a supported configuration by Microsoft and doesn't meet the minimum system requirements. Thus it could negatively affect the ability to get updates and support.

> It is already not needed and insecure so should be turned off.

You know what's even less secure? Having it off.

Re: Android developer verification: Early access starts

#204

Earlier quoted context omitted.

I don't buy this argument at all that this specific implementation is under pressure from the government - if the problem is indeed malware getting access to personal data, then the very obvious solution is to ensure that such personal data is not accessible by apps in the first place! Why should apps have access to a user's SMS / RCS? (Yeah, I know it makes onboarding / verification easy and all, if an app can acces…

> if the problem is indeed malware getting access to personal data, then the very obvious solution is to ensure that such personal data is not accessible by apps Then you'd have the other "screaming minority" on HN show up, the "antitrust all the things" folks.

The "let's actually enforce antitrust laws" people are in the majority:

https://today.yougov.com/economy/articles/47798-most-america...

https://www.antitrustinstitute.org/wp-content/uploads/2024/1...

Re: Android developer verification: Early access starts

#205

This is the worst of both worlds, you can spread your malware as a sideloaded apk just fine, but when it's so big that you're probably burned anyways, then you need to verify your account. I think a better compromise would have been for google to require developer verification, but also allow third party appstores like f-droid that don't require verification but still are required to "sign" the apks, instead of users…

It's not super clear from the post, but if I read it correctly there are two modifications suggested.

   - 1: Separate verification type for "student and hobbyist"
   - 2: "advanced flow" for "power users" that allows sideloading of unverified apps - I imagine this is some kind of scare-screen, but we'll see.
What you describe as "worst of both worlds" is about point 1. I'm not sure point 2 is powerful enough to suppor things like f-droid, but again, we'll see.

Re: Android developer verification: Early access starts

#206
post #36

Earlier quoted context omitted.

I bought the hardware, therefore I have the right to modify and repair. Natural right, full stop. That right ends are your nose, as the saying goes.

Oh, so you're good with everyone having the "natural right" to turn handguns into automatic weapons simply because they find themselves in possession of the correct atoms? How about adding a 3rd story on the top of your house without needing a permit or structural evaluation? Note that adding "full stop" pointlessly to the end of sentences does not strengthen your argument.

The difference is that you can’t kill other people by installing an app.

Re: Android developer verification: Early access starts

#207

Earlier quoted context omitted.

Its my device. Not google's. Imagine telling you which NPM/PIP packages you can install from your terminal. Also, its not SIDE loading. Its installing an app.

Well... it would be good if this was true, but read the ToS and it looks more like a licence to use than "ownership" sadly :(

"Android" is really a lot of different code but most of it is the Apache license or the GPL. Google Play has its own ToS, but why should that have to do with anything when you're not using it?

Re: Android developer verification: Early access starts

#208
post #108

Earlier quoted context omitted.

> Why should apps have access to a user's SMS / RCS? It could be an alternative SMS app like TextSecure. One of the best features of Android is that even built-in default applications like the keyboard, browser, launcher, etc can be replaced by alternative implementations. It could also be a SMS backup application (which can also be used to transfer the whole SMS history to a new phone). Or it could be something like…

That's all indeed valid. > One of the best features of Android is that even built-in default applications like the keyboard, browser, launcher, etc can be replaced by alternative implementations. When sideloading is barred all that can easily change. If you are forced to install everything from the Google Play Store, Google can easily bar such things, again in the name of "security" - alternate keyboards can steal yo…

It'd just devolve into security whack a mole about what permissions need those special account or not, ending with basically all of them making it the same as just needing dev verification anyway for anything remotely useful.

And despite that, you assuming that dev verification means no malware. The Play Store requires developers to register with the same verification measures we're talkingand malware is hardly unheard of there.

Re: Android developer verification: Early access starts

#209
post #75
post #34

This brings back memories of "sure you can root your phone, but if you do secure apps like payment won't run anymore"

I can only imagine that allowing "unverified" apps to run would also disable payment/banking apps. Just in case, you know. For your own good.

That should be up to the bank to decide, and it already is. https://developer.android.com/privacy-and-security/safetynet...

None of my banks have complained to me because I'm running a patched YouTube app.

Re: Android developer verification: Early access starts

#210
post #193

Earlier quoted context omitted.

"Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows." This is only true if you use Secure boot. It is already not needed and insecure so should be turned off. Then any OS can be installed.

While it's possible to install and use Windows 11 without Secure Boot enabled, it is not a supported configuration by Microsoft and doesn't meet the minimum system requirements. Thus it could negatively affect the ability to get updates and support. > It is already not needed and insecure so should be turned off. You know what's even less secure? Having it off.

The name “Secure Boot” is such an effective way for them to guide well-meaning but naïve people's thought process to their desired outcome. Microsoft's idea of Security is security from me, not security for me. They use this overloaded language because it's so hard to argue against. It's a thought-terminating cliché.

Oh, you don't use ?? You must not care about being secure, huh???

Dear Microsoft: fuck off; I refuse to seek your permission-via-signing-key to run my own software on my own computer.

Post reply on HN