Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

671–680 of 927 posts

Re: Your phone is about to stop being yours

#671

I've resigned to the fact that I'll need to use two phones, one with locked down Android/iOS for banking applications and government services (those require strong bank ID around these parts), another with some kind of a Linux or unlocked Android for literally everything else. Oh well, such is life, most people don't care enough about this to pressure Google/Apple/banks/governments into yielding. A big reason why a n…

Is Linux for phones a thing? Or are you referring to GrapheneOS or LineageOS?

Re: Your phone is about to stop being yours

#672
Will someone clarify my doubt ? The lineancy of allowing sideloading by means of developer options in settings that requires one time wait of 48hr. Will that be available to all android os or only newer. I was using android 10 on samsung model that already hit end of support by brand years ago. So it update is in developer options and its os level would'nt that require ota update but with end of support for system updates from samsung itself how it will be pushed

Re: Your phone is about to stop being yours

#673

Earlier quoted context omitted.

I haven't seen new data from celbrite in awhile, but I believe that grapheneos was the only truly secure phone from it for both bfu and afu as of a couple years ago. Apple lost my confidence after they removed Advanced Device Encryption for British users (plus implemented age verification for them). https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...

I think it's been said that nobody has yet cracked Apple's Lockdown Mode, but that's likely not truly comparable?

iPhones with Lockdown Mode enabled have definitely been exploited which is confirmed by leaked documents and statements from commercial exploit vendors. Lockdown Mode primarily reduces attack surface in Safari and from Apple services. It does very little to protect against other attack vectors such as messaging apps or physical data extraction.

https://support.apple.com/en-ca/105120

You're thinking of Apple saying they haven't detected a case of a device with Lockdown Mode exploited in the wild themselves. Extremely few devices use Lockdown Mode and Apple has very little insight into successful exploits so there isn't much opportunity for them to detect it in the first place. Lockdown Mode bundles everything together and has very inconvenient changes many people won't accept. That greatly reduces usage even by people fully aware of it who want a lot of what it provides. For example, there's

Apple has said they haven't seen a case of a device with Lockdown Mode being exploited which is extremely misleading. Apple doesn't have that much visibility into devices being exploited and would mostly seen failed attempts. All of the Lockdown Mode functionality being bundled together contributes to it barely being used. There's no opt-out system for most of it beyond disabling it as a whole. Only a subset of the Safari restrictions can be partially disabled per-app and per-site which doesn't fully restore web compatibility. It's more that hardly anyone is using it and that Apple doesn't have much insight into apps and the OS being exploited successfully in the first place. Lockdown Mode is definitely useful but people should read about what it actually does and compare that to how devices get exploited. Apple's memory corruption exploit protections aren't tied to Lockdown Mode.

Re: Your phone is about to stop being yours

#674
post #604

Earlier quoted context omitted.

I think it's been said that nobody has yet cracked Apple's Lockdown Mode, but that's likely not truly comparable?

How is then law enforcement getting what they need from people's iphones? Because I understand they do, in some way. And I'm not asking about forcing people to hand over pin or fingerprints, but just by themselves.

Lockdown Mode is focused on reducing the attack surface from Safari including the WebView and Apple services including iMessage/FaceTime. It does nearly nothing to protect against non-browser/non-messaging attack vectors in the OS or other apps. It's up to app developers to implement similar restricted modes and also baseline exploit protections. App developers need to explicitly opt-in to using the standard exploit protections used in many parts of the OS and Apple discourages doing it:

https://developer.apple.com/documentation/Xcode/enabling-enh...

Re: Your phone is about to stop being yours

#675

Someone here on HN used the term "cloud terminal" for modern electronic devices, and I think that is a very fitting name for phones and tablets. They are definitely not computers because they do not actually give the user access to general purpose computing in the sense that the users can control exactly what computations the device is going to execute. They are just terminals whose production costs we cover but whic…

IDK, not really a fan of redefining computer to make a rhetorical point. It seems counter-productive to tell people the computing device they think as a computer isn’t really a computer. It’s like saying my car isn’t really a car because I can’t adjust spark timing. Someone could make that semantic argument but it’s hard to imagine anyone would care.

>It’s like saying my car isn’t really a car because I can’t adjust spark timing.

What if it only drives along select predetermined monetised routes?

Re: Your phone is about to stop being yours

#676
post #16

Let me play out a scenario, imagine to use a Desktop Hardware like a complete built rig, you would need a specific OS like Windows 11 and you could not run Linux on it, just because it's a vendor lock-in. Why is this acceptable for phones but would not for the case above? I know a lot of people don't care, and that's ok, but we should root for an open choice for the users.

So you mean, Macs and macOS? All modern devices are appliances, not computers. They perform the specific functions that they were programmed to perform, and do not allow arbitrary execution of calculations on the underlying hardware. Many people, mostly folks who adopt the Apple ecosystem, see this as a positive thing that allows them to delegate undifferentiated decisions on security and ways of working to the vendo…

>which will result in fragmentation.

Why? And how does that bother you?

Re: Your phone is about to stop being yours

#677

Earlier quoted context omitted.

So if they don't give you an apple dev account, or close yours, you can't. Case in point.

Did you just move the goalposts from “you can’t run arbitrary code today” to “hypothetically, in the future, Apple could prevent running arbitrary code”?

As with Google accounts, it's not hypothetical, it's a risk. People do occasionally get locked out of being an Apple developer for reasons they cannot foresee.

> Apple has locked my Apple ID, and I have no recourse. A plea for help* https://news.ycombinator.com/item?id=46252114

> Apple bans entire dev account, no reason given https://news.ycombinator.com/item?id=44601548

Re: Your phone is about to stop being yours

#678

> "dismiss more scare screens" This whole website is a scare screen. There's a lot that is not being said on this page, such as the advantages of the new system, and the motivations of the authors of this site. There's a reasonable discussion to be had about trade-offs here, but this is entirely one sided, in somewhat bad faith in my personal opinion.

I don't really understand your argument here, isn't Google's announcement also entirely one sided? I also don't see any "discussion" of disadvantages of their solution in their announcements. For example, the "over 50 times more malware" stat is stated without any source at all, same with "Most of your users’ download experience will not change at all" (inb4 I don't care about power users at all). Not to mention stats about scam-by-sideloaded app, anything that would suggest that the proposed solution is going to work.

The point of "keepandroidopen.org", in my understanding, is to be a quick PSA on why the author of the website thinks this is a problem with some call-to-action. It's not supposed to be a place for discussion, it's at best a discussion starter, one of the sides of the discussion to consider. Obviously they present their side, as Google has presented their side.

And anyway, how are users supposed to hold this "reasonable discussion" with a corporation? I know that Google had some sort a feedback form about this, and that they made some changes, but that is not a discussion. I didn't really actually see any "reasonable discussion" being held on this topic ever, anywhere, ever, nor do I really see how it would happen. I don't even really see a good reason for Google to hold such a discussion. It's a decision made by a corporation, about their product, after all.

Could you present your how you see this "reasonable discussion" being had? Where? How?

Re: Your phone is about to stop being yours

#680

> Starting September 2026, a silent update, nonconsensually pushed by Google, will block every Android app whose developer hasn't registered with Google, signed their contract, paid up, and handed over government ID. This is false. Google will provide two other flows for app distribution that are different than this. > Every app and every device, worldwide, with no opt-out. Again, false. There is an opt-out called th…

People like you are the problem. Nitpicking and hand waving the bigger picture.
Post reply on HN