Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

271–280 of 694 posts

Re: Android developer verification: Early access starts

#271

This is the worst of both worlds, you can spread your malware as a sideloaded apk just fine, but when it's so big that you're probably burned anyways, then you need to verify your account. I think a better compromise would have been for google to require developer verification, but also allow third party appstores like f-droid that don't require verification but still are required to "sign" the apks, instead of users…

It's not super clear from the post, but if I read it correctly there are two modifications suggested. - 1: Separate verification type for "student and hobbyist" - 2: "advanced flow" for "power users" that allows sideloading of unverified apps - I imagine this is some kind of scare-screen, but we'll see. What you describe as "worst of both worlds" is about point 1. I'm not sure point 2 is powerful enough to suppor thi…

malware are good at getting users to click past scare screens unfortunately. this isn't a solved problem, even with desktop browsers.

Re: Android developer verification: Early access starts

#272
post #75

Earlier quoted context omitted.

I can only imagine that allowing "unverified" apps to run would also disable payment/banking apps. Just in case, you know. For your own good.

That should be up to the bank to decide, and it already is. https://developer.android.com/privacy-and-security/safetynet... None of my banks have complained to me because I'm running a patched YouTube app.

That doesn't seem to have anything to do with what apps you have installed, just whether you have Play Protect enabled. I have Play Protect enabled, and I can still install apps without having to scan them first.

Re: Android developer verification: Early access starts

#273
post #244

They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…

Why do you think that will happen?

Paranoia.

Re: Android developer verification: Early access starts

#274
post #229

Earlier quoted context omitted.

They won’t remove it if its been installed from their app stores.

They removed the "ICE" app and if the US government has an issue with other Apps they bend over and do it. Switzerland is currently dealing with a 39% and Brazil with a 50% tariff because Trump has a personal problem with them. It would not be far fetched for an administration to have another states app removed.

I just want to preface that I am not in support of Apple or Google in their closed ecosystem.

I was specifically referring to you saying "Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. However Google and Apple can just remove it, what then?"

It seemed like you were saying that because it is open source, it will be removed. I simply disagreed with that. Plenty of opensource software exists in the app store.

I'm not disagreeing that they have the ability to remove software from their app stores. They have done that before as you mention. That is a fact.

Re: Android developer verification: Early access starts

#275

They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…

Seriously though, can anyone tell me why the fuck banking apps try so hard to find any possible excuse to not run on customised devices? I just can't see any good reason for it but my banking app has invested more work into detecting any possible hint of rooting than into its UX. It's absurd.

> Seriously though, can anyone tell me why the fuck banking apps try so hard to find any possible excuse to not run on customised devices?

As an early cyanogen mod adopter I really don’t want to lose ability to side load etc. but to answer your question this is probably for the lowest common denominators safety. Anecdotal example - a scammer tricked my parents into sideloading an apk which automatically forwarded all sms messages to the said scammer. This lead to 2FA code from bank go through and allowed them to perform some transactions. There were many red flags during this ‘call from a bank’ and I’d say some blame lies on my parents here, I guess this is the only way to lock down bad actors? I am not entirely sure it is.

Re: Android developer verification: Early access starts

#276
post #193

Earlier quoted context omitted.

"Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows." This is only true if you use Secure boot. It is already not needed and insecure so should be turned off. Then any OS can be installed.

Now tell me how Turning off UEFI secure boot on a PC to install another "unsecure distribution" vs. Unlocking fastboot bootloader on Android to install another "unsecure ROM" ... is not the exact same language, which isn"t really about security but about absolute control of the device. The parallels are astounding, given that Microsoft's signing process of binaries also meanwhile depends on WHQL and the Microsoft Sto…

"... is not the exact same language, which isn"t really about security but about absolute control of the device.

The parallels are astounding, given that Microsoft's signing process of binaries also meanwhile depends on WHQL and the Microsoft Store. Unsigned binaries can't be installed unless you "disable security features".

My point is that it has absolutely nothing to do with actual security improvements."

I agree. It is the same type of language.

Re: Android developer verification: Early access starts

#277

Earlier quoted context omitted.

Seriously though, can anyone tell me why the fuck banking apps try so hard to find any possible excuse to not run on customised devices? I just can't see any good reason for it but my banking app has invested more work into detecting any possible hint of rooting than into its UX. It's absurd.

Banks have stupid rules probably made by people who don't understand the matter. A relative recently got victim to phishing and gave away some of his banking details (fake e-banking login screen on a website). After locking the account, the bank said it would only unlock it after the phone got wiped, which obviously doesn't add anything in this situation. Another pet peeve is that they prevent screenshots simply beca…

>After locking the account, the bank said it would only unlock it after the phone got wiped, which obviously doesn't add anything in this situation.

How is that supposed to be a stupid rule? Do you have any idea how much fraud this stops?

Re: Android developer verification: Early access starts

#278

They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…

Is the digital ID just to identify yourself online? Because I've never had to do that. Kind of seems like a solution in search of a problem.

Re: Android developer verification: Early access starts

#279
post #128

> When the user logs into their real banking app, the malware captures their two-factor authentication codes That seems like a severe security bug in Android APIs or sandboxing or something else. > bad actors can spin up new harmful apps instantly Why are harmful apps possible at all?

It's a permission the app can have. Android asks the user whether to allow it when you launch the app. It's a very useful permission for some apps that I use. But a scammer can just tell the user to accept the permission.

Re: Android developer verification: Early access starts

#280

Earlier quoted context omitted.

Banks have stupid rules probably made by people who don't understand the matter. A relative recently got victim to phishing and gave away some of his banking details (fake e-banking login screen on a website). After locking the account, the bank said it would only unlock it after the phone got wiped, which obviously doesn't add anything in this situation. Another pet peeve is that they prevent screenshots simply beca…

> Banks have stupid rules probably made by people who don't understand the matter. Their insurance policies, if I had to guess.

Unlikely, banks do not reimburse this kind of fraud in most of the world.

This is most likely the bank just being genuinely nice and taking care of customers who range between very stupid and momentarily distracted.

Post reply on HN