Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

81–90 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#81
post #49

I just launched an app in the Google Play Store. I did find it a bit weird that I had to provide my physical home address to get my app listed. Not sure what I would do if someone turned up to complain. Make them a cup of tea?

This is so that you can be sued or prosecuted if the app is malicious.

There's no such requirement for publishing a website

Re: Android Developer Verification: Threat masquerading as protection

#82

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

Re: Android Developer Verification: Threat masquerading as protection

#83

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

We experienced this with Anthropic, not the same blast radius obviously, but out of nowhere account was terminated. No support available. It was via someone’s 30+ year old classmate via LinkedIn the account got reinstated.

As a counterpoint to the right to the repair there should be a right to recover.

Re: Android Developer Verification: Threat masquerading as protection

#84

I understand the frustration (I'm an avid fdroid user across many many devices). But this article comes off as childish with the virus/trojan/"malware vendor". With such an article, many (including perhaps google) get the ammo to disregard what fdroid says, by branding them as childish/not to be taken seriously. for eg: no reputable news org is going to post this. PS: https://keepandroidopen.org/ is better done.

I have the opposite opinion, Google is doing a lot of garbage in the name of "Security", time to play their game and report their control on Android as security vulnerability

Re: Android Developer Verification: Threat masquerading as protection

#85
post #14

I don't understand how this is legal in the EU under the DMA, does anyone know?

https://www.eu-digital-markets-act.com/Digital_Markets_Act_A... Art 6 (4). Read it to the end. That's how.

I don't get what part of that your think enables them to deny access to third parties distributing their apps on alternate stores. If you're referring to the last paragraph, that very explicitly says that any such security must be an optional setting that is not default. So unless users opt into verified only apps, Google can't force that, according to the DMA.

Re: Android Developer Verification: Threat masquerading as protection

#86
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

> Android users need to switch to Graphene.

Doesn't GrapheneOS supports only Google Pixel smartphones now? For most of the users, that would mean changing their phones beforehand. And if we're talking about common people (especially not in US), it's not even everyone who can afford that. Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

Re: Android Developer Verification: Threat masquerading as protection

#87
post #78

Earlier quoted context omitted.

I wonder if it makes sense to create an independent hard-fork of AOSP in the future. But probably the only option to keep this somehow maintainable is to replace many android-specific components with other userspace linux components that are already well maintained (systemd, networkmanager, wayland)

Would this not require some control over the hardware? Which would be difficult for the FOSS community?

maybe not, heck people reverse engineered apple hardware and implemented it in various FOSS driver stacks

But yeah, vendors maintaining their drivers upstream in FOSS projects would obviously make it easer

Re: Android Developer Verification: Threat masquerading as protection

#88
post #61

This is not malware. It's an official part of Google Play Services.

The point is that it is said to tamper with your installations. If it does, it is malware.

It doesn't tamper with your installations.

Re: Android Developer Verification: Threat masquerading as protection

#89

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

Shame isn’t an applicable concept for a corporation.

Re: Android Developer Verification: Threat masquerading as protection

#90

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

We experienced this with Anthropic, not the same blast radius obviously, but out of nowhere account was terminated. No support available. It was via someone’s 30+ year old classmate via LinkedIn the account got reinstated. As a counterpoint to the right to the repair there should be a right to recover.

There was a more direct case where someone’s child had been interacting with Gemini inappropriately resulting in Google nuking the entire families Google accounts.
Post reply on HN