Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

231–240 of 694 posts

Re: Android developer verification: Early access starts

#231

Google is about to find out the next step of this chain - give access to everyone, don't gatekeep / do checks, and yet take responsibility for anything that goes wrong. "You should open up the tool, put no restrictions, and yet ensure that it is safe and secure" is an impossible task for anyone.

How it was working till now for so many years, now suddenly can't?

Re: Android developer verification: Early access starts

#232
post #229

They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…

They won’t remove it if its been installed from their app stores.

They removed the "ICE" app and if the US government has an issue with other Apps they bend over and do it.

Switzerland is currently dealing with a 39% and Brazil with a 50% tariff because Trump has a personal problem with them. It would not be far fetched for an administration to have another states app removed.

Re: Android developer verification: Early access starts

#233
Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings.

One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

Re: Android developer verification: Early access starts

#234

Earlier quoted context omitted.

yt-dlp's days are fairly numbered as Google has a trump card they can eventually deploy: all content is gated behind DRM. IIRC the only reason YouTube content is not yet served exclusively through DRM is to maintain compatibility with older hardware like smart TVs.

All levels of Widevine are cracked, but only the software-exclusive vulnerabilities are publicly available. It's only used for valuable content though (netflix/disney+/primevideo), so it might still work out for YouTube as no one will want to waste a vulnerability on a Mr. Beast slop video.

The reason they have different levels is that the DRM pitchmen got tired of everyone making fun of their ineffective snake oil, so they tried to make a version that was harder to break at the cost of not supporting most devices.

Naturally that got broken too, and even worse, broken when it's only supported by a minority of devices and content, because the more devices and content it's used for the easier it is to break and the larger the incentive to do it.

If you tried to require that for all content then it would have to be supported by all devices, including the bargain bin e-waste with derelict security, and what do you expect to happen then?

Re: Android developer verification: Early access starts

#235

Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

- warning - SMS read access

So you do know - inform users, increase privacy,...?

Re: Android developer verification: Early access starts

#236
I can access any website or webapp without verification. I can install any app on my PC without verification.

I assume the results of my actions and I accept that if something bad is going to happen, it's my fault. I am fine with that.

I want the same kind of freedom on my phone, a device I own and I payed for with my own money. I am not smarter when using the PC and dumber when using the phone. I want to be able to opt out of verification and install whatever I want.

Re: Android developer verification: Early access starts

#237
post #167

Are there any entities on earth with resources to compete with a complicit global duopoly? If Android is open source, why can't/won't a community fork it? Graphene OS exists but many folks claim Netflix and banking apps do not work with it (despite allowing logins from any common desktop browser)? If all widely-accepted phone operating systems are de-facto proprietary, what does this say about the current phase of so…

LineageOS is based on AOSP and works well. I don't understand the banking app thing either. I suspect it's a regional issue. I can log in to my credit union account via any browser, and if something needs MFA it should be able to use TOTP which works on anything. Android in practice is full of proprietary blobs, stuck on old kernel versions, and the hardware is barely supported. Lots of downstream crap from the vendo…

Yes we have banking websites but they are increasingly moving to an auth model where you have to enter an otp generated in the app but the app refuses to work on non-verified devices.

Re: Android developer verification: Early access starts

#238

Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

The built in Android SMS app seems to be horrible in every incarnation I've seen. The one that comes with the Pixel, the one Samsung has. Some may like it, but I can't stand them. I tend to install my own SMS app in each case, and I don't use computers to be locked into something I don't prefer.

It's my tool. Mine. I'll do with it as I please.

I agree there are issues. But preventing installs aren't the answer, just like removing all windows and doors from a house isn't the answer to neighbourhood crime.

I'd be more inclined to say the problem is allowing apps to be funded by advertising. If all apps were paid apps, and using personal data in any way was immensely, "thrown in jail" illegal, then you'd find yourself approving access to contacts, SMS, Pii quite rarely.

It would really stand out in such a case.

"What?! I've been using my phone for 10 years, and some app wants to see my contacts. Why?? No one reputable asks for that, ever!"

So much of the problem with the internet is that Pii is paying the way.

On GrapheneOS, when I install anything, it flat out asks me if I want to give it internet access at all. SMS could be the same way. Off by default, try to grant it, big warnings.

At a certain point, if you have big warnings saying "Are you serious?!" and people turn it on, it entirely ends up being the end user's fault.

Re: Android developer verification: Early access starts

#239
post #159

Earlier quoted context omitted.

There's a second path, whereby F-Droid registers as an "alternative app store", which is a new category of app created in the fallout of Epic Games v. Google [0]. This is interesting because it applies to all regions and will necessarily need more elevated permissions than the typical REQUEST_INSTALL_PACKAGES permission used today. No idea what requirements Google will impose on such apps. [0]: https://en.wikipedia.o…

What would they have to offer Google in return for being granted this status? Would they have to ban NewPipe, for example?

Up to what a committee of 3 people (or in the alternate district court judge James Donato) believes this means, assuming the judge approves the proposed modification to the injunction in the first place

> Google may create reasonable requirements for certification as a Registered App Store, including but not limited to review of the app store by Google’s Android team and the payment of reasonable fees to cover the operational costs associated with the review and certification process. Such fees may not be revenue proportionate.

One appointed by Google, one by Epic, one appointed by the other two. All three will be barred from private communications about any of this with any parties.

Considering this is an anti-trust suit I suspect the judge would be extremely unamused if the committee members found that "must ban NewPipe" was a reasonable requirement.

Re: Android developer verification: Early access starts

#240

Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

There seems to be a whole market of Google Play developer accounts and apps for sale, developers like myself regularly get emailed by scammy companies offering to buy the account or to publish an app, and malware is regularly found on Google Play[0]. There's no reason to believe that bad actors would be stopped by install restrictions if their scam is effective enough to overcome the financial hurdles

[0] https://www.bleepingcomputer.com/news/security/malicious-and...

Post reply on HN