This is the worst of both worlds, you can spread your malware as a sideloaded apk just fine, but when it's so big that you're probably burned anyways, then you need to verify your account. I think a better compromise would have been for google to require developer verification, but also allow third party appstores like f-droid that don't require verification but still are required to "sign" the apks, instead of users…
It's not super clear from the post, but if I read it correctly there are two modifications suggested. - 1: Separate verification type for "student and hobbyist" - 2: "advanced flow" for "power users" that allows sideloading of unverified apps - I imagine this is some kind of scare-screen, but we'll see. What you describe as "worst of both worlds" is about point 1. I'm not sure point 2 is powerful enough to suppor thi…
Android developer verification: Early access starts
271–280 of 694 posts
Re: Android developer verification: Early access starts
#272Earlier quoted context omitted.
I can only imagine that allowing "unverified" apps to run would also disable payment/banking apps. Just in case, you know. For your own good.
That should be up to the bank to decide, and it already is. https://developer.android.com/privacy-and-security/safetynet... None of my banks have complained to me because I'm running a patched YouTube app.
Re: Android developer verification: Early access starts
#273They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…
Why do you think that will happen?
Re: Android developer verification: Early access starts
#274Earlier quoted context omitted.
They won’t remove it if its been installed from their app stores.
They removed the "ICE" app and if the US government has an issue with other Apps they bend over and do it. Switzerland is currently dealing with a 39% and Brazil with a 50% tariff because Trump has a personal problem with them. It would not be far fetched for an administration to have another states app removed.
I was specifically referring to you saying "Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. However Google and Apple can just remove it, what then?"
It seemed like you were saying that because it is open source, it will be removed. I simply disagreed with that. Plenty of opensource software exists in the app store.
I'm not disagreeing that they have the ability to remove software from their app stores. They have done that before as you mention. That is a fact.
Re: Android developer verification: Early access starts
#275They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…
Seriously though, can anyone tell me why the fuck banking apps try so hard to find any possible excuse to not run on customised devices? I just can't see any good reason for it but my banking app has invested more work into detecting any possible hint of rooting than into its UX. It's absurd.
As an early cyanogen mod adopter I really don’t want to lose ability to side load etc. but to answer your question this is probably for the lowest common denominators safety. Anecdotal example - a scammer tricked my parents into sideloading an apk which automatically forwarded all sms messages to the said scammer. This lead to 2FA code from bank go through and allowed them to perform some transactions. There were many red flags during this ‘call from a bank’ and I’d say some blame lies on my parents here, I guess this is the only way to lock down bad actors? I am not entirely sure it is.
Re: Android developer verification: Early access starts
#276Earlier quoted context omitted.
"Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows." This is only true if you use Secure boot. It is already not needed and insecure so should be turned off. Then any OS can be installed.
Now tell me how Turning off UEFI secure boot on a PC to install another "unsecure distribution" vs. Unlocking fastboot bootloader on Android to install another "unsecure ROM" ... is not the exact same language, which isn"t really about security but about absolute control of the device. The parallels are astounding, given that Microsoft's signing process of binaries also meanwhile depends on WHQL and the Microsoft Sto…
The parallels are astounding, given that Microsoft's signing process of binaries also meanwhile depends on WHQL and the Microsoft Store. Unsigned binaries can't be installed unless you "disable security features".
My point is that it has absolutely nothing to do with actual security improvements."
I agree. It is the same type of language.
Re: Android developer verification: Early access starts
#277Earlier quoted context omitted.
Seriously though, can anyone tell me why the fuck banking apps try so hard to find any possible excuse to not run on customised devices? I just can't see any good reason for it but my banking app has invested more work into detecting any possible hint of rooting than into its UX. It's absurd.
Banks have stupid rules probably made by people who don't understand the matter. A relative recently got victim to phishing and gave away some of his banking details (fake e-banking login screen on a website). After locking the account, the bank said it would only unlock it after the phone got wiped, which obviously doesn't add anything in this situation. Another pet peeve is that they prevent screenshots simply beca…
How is that supposed to be a stupid rule? Do you have any idea how much fraud this stops?
Re: Android developer verification: Early access starts
#278They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…
Re: Android developer verification: Early access starts
#279> When the user logs into their real banking app, the malware captures their two-factor authentication codes That seems like a severe security bug in Android APIs or sandboxing or something else. > bad actors can spin up new harmful apps instantly Why are harmful apps possible at all?
Re: Android developer verification: Early access starts
#280Earlier quoted context omitted.
Banks have stupid rules probably made by people who don't understand the matter. A relative recently got victim to phishing and gave away some of his banking details (fake e-banking login screen on a website). After locking the account, the bank said it would only unlock it after the phone got wiped, which obviously doesn't add anything in this situation. Another pet peeve is that they prevent screenshots simply beca…
> Banks have stupid rules probably made by people who don't understand the matter. Their insurance policies, if I had to guess.
This is most likely the bank just being genuinely nice and taking care of customers who range between very stupid and momentarily distracted.