> we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choi…
Android developer verification: Early access starts
361–370 of 694 posts
Re: Android developer verification: Early access starts
#362> Keeping users safe on Android is our top priority. I highly doubt this is your "top" priority. Or if it is then you're gotten there by completely ignoring Google account security. > intercepts the victim's notifications And who controls these notifications and forces application developers to use a specific service? > bad actors can spin up new harmful apps instantly. Like banking applications that use push or SMS…
Re: Android developer verification: Early access starts
#363Earlier quoted context omitted.
>instead require the user to manually go into settings to turn them on, but if they do then it's still possible They clearly addressed this option in the post, under sufficient social engineering pressure these settings will easily be circumvented. You'd need at least a 24h timeout or similar to mitigate the social pressure.
> They clearly addressed this option in the post, under sufficient social engineering pressure these settings will easily be circumvented. You'd need at least a 24h timeout or similar to mitigate the social pressure. "Under sufficient social engineering pressure" is the thing that proves too much. A 24h timeout can't withstand that either. Nor can the ability for the user to use their phone to send money, or access t…
Absolutely this! It's just nanny state all over again.
Re: Android developer verification: Early access starts
#364I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…
How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.
Re: Android developer verification: Early access starts
#365Earlier quoted context omitted.
This is not a win. This is having independent distribution shut down and controlled. We no longer own our devices. We're in a worse state than we were in before. Google is becoming a dictator like Apple.
It's not being shut down though. The article says that there will be a way to install unverified apps.
Re: Android developer verification: Early access starts
#366Earlier quoted context omitted.
> because the governments of countries where such scams are widespread will hold Google responsible. This is the unsurprising consequence of trying to hold big companies accountable for the things people do with their devices: The only reasonable response is to reduce freedoms with those devices, or pull out of those countries entirely. This happened a lot in the early days of the GDPR regulations when the exact laws…
These two things are not the same. The GDPR afforded rights to common people. Those companies that would pull out are the ones that were abusing data that was never theirs and could no longer do so.
Re: Android developer verification: Early access starts
#367Earlier quoted context omitted.
I don't buy this argument at all that this specific implementation is under pressure from the government - if the problem is indeed malware getting access to personal data, then the very obvious solution is to ensure that such personal data is not accessible by apps in the first place! Why should apps have access to a user's SMS / RCS? (Yeah, I know it makes onboarding / verification easy and all, if an app can acces…
> Why should apps have access to a user's SMS / RCS? It could be an alternative SMS app like TextSecure. One of the best features of Android is that even built-in default applications like the keyboard, browser, launcher, etc can be replaced by alternative implementations. It could also be a SMS backup application (which can also be used to transfer the whole SMS history to a new phone). Or it could be something like…
Re: Android developer verification: Early access starts
#368Edit: be sure to read geoffschmidt's reply below /edit The buried lede: > a dedicated account type for students and hobbyists. This will allow you to distribute your creations to a limited number of devices without going through the full verification So a natural limit on how big a hobby project can get. The example they give, where verification would require scammers to burn an identity to build another app instead…
Re: Android developer verification: Early access starts
#369Earlier quoted context omitted.
> They clearly addressed this option in the post, under sufficient social engineering pressure these settings will easily be circumvented. You'd need at least a 24h timeout or similar to mitigate the social pressure. "Under sufficient social engineering pressure" is the thing that proves too much. A 24h timeout can't withstand that either. Nor can the ability for the user to use their phone to send money, or access t…
>By the time you're done the phone is a brick that can't do anything useful. At some point you have to admit that adults are responsible for the choices they make. Absolutely this! It's just nanny state all over again.
Markets are supposed to be better because you can switch to a competitor but that only applies when there is actually competition. Two companies both doing the same thing is not a competitive market.
Re: Android developer verification: Early access starts
#370> we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choi…