Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

101–110 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#102
post #62
post #49

I just launched an app in the Google Play Store. I did find it a bit weird that I had to provide my physical home address to get my app listed. Not sure what I would do if someone turned up to complain. Make them a cup of tea?

well they can swat you, order pizza, send you packages (who knows with what inside), spread false info about you if you've given out more info etc... all it takes is one guy who gets too mad for some reason and it's gonna be a lot more costly for you to do anything about it vs. that guy who gets to be completely anonymous about it

How? I don't see the address published.

They can sue you and Google will give your address to the court, clearly. But swat? Send packages? How?

Re: Android Developer Verification: Threat masquerading as protection

#103

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

This is worse than Apple. With Apple you knew where you stood day 1.

Ah so the Do No Evil wasn't serious after all?! /s

Re: Android Developer Verification: Threat masquerading as protection

#104
post #82

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

Let's call them anti-competition services since there's nothing in these increasing security.

Re: Android Developer Verification: Threat masquerading as protection

#105
post #103

Earlier quoted context omitted.

This is worse than Apple. With Apple you knew where you stood day 1.

Ah so the Do No Evil wasn't serious after all?! /s

It was indeed! And Google removed it in 2018.

- https://en.wikipedia.org/wiki/Don%27t_be_evil

Re: Android Developer Verification: Threat masquerading as protection

#106
post #34

Earlier quoted context omitted.

Does Huawei not use android or Google play services?

It's Android but without Google's services, there's an alternative app store. The irony of Chinese vendors providing a breath of fresh low-DRM air.

Partially true, HarmonyOS NEXT is its own thing, with a Typescript based language ArkTS.

https://developer.huawei.com/consumer/en/arkts/

And now they are adding yet another one, AOT compiled, Cangjie

https://cangjie-lang.cn/en

Using Android fork has been a transition step.

Re: Android Developer Verification: Threat masquerading as protection

#107
post #102
post #62

Earlier quoted context omitted.

well they can swat you, order pizza, send you packages (who knows with what inside), spread false info about you if you've given out more info etc... all it takes is one guy who gets too mad for some reason and it's gonna be a lot more costly for you to do anything about it vs. that guy who gets to be completely anonymous about it

How? I don't see the address published. They can sue you and Google will give your address to the court, clearly. But swat? Send packages? How?

Don’t know about US, but in EU you legally have to publish your address and it will be shown on the store page if your app has ads or in-app purchases.

Re: Android Developer Verification: Threat masquerading as protection

#108

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

The blast radius is far worse than any "malware" Google could protect you from.

TFA is playing it up, but it is arguable that this is a real virus, except the shady hackers are Google.

Re: Android Developer Verification: Threat masquerading as protection

#109
post #41
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

I know Graphene has innovative security measures, do you happen to know whether that includes anything wrt. phishing or social engineering? (For those who haven't been following along: this whole affair started with phishing. People were social-engineered into installing an app and a little later their bank accounts were empty. A big issue in various poor countries.)

That's one of its primary arguments: besides the hardening against exploits, they're considered such a safe OS because you cannot access your data either and give the wrong app root access. Everything lives in a sandbox. Whether not being able to grant full access to e.g. adb shell, Termux, or Restic is what you want is a personal choice, but it adds a layer of security against any malware that tries to get you to grant them root access

This is also the argument they use to try to convince app vendors to add their keys to the allowlist, because the app makers can trust that their DRM will be active (if Netflix sets a "no screen recording" flag, you the user cannot circumvent it by e.g. reading /dev/fb0). It should have broader compatibility than other FOSS Android builds (when running the officially signed version of course, you can't compile it yourself and expect such apps to run there)

Re: Android Developer Verification: Threat masquerading as protection

#110
post #21

Earlier quoted context omitted.

Apple's policies were established when you purchased the phone. Apps come through registered developers and their vetting. Google has changed the game on something you already own. I'm sure their lawyers have done their homework, but in some jurisdictions this is certainly actionable.

They already lost a lawsuit and were fined a hundred billion dollars in the EU for locking down Android. Maybe they think since they already lost once, they can't lose again.

Hundred billion would be a quarter's revenue, that can't be right. The lasest I've read is a threat of a fine of around 500mil wrt app store issues back in December, but nothing has been decided yet.
Post reply on HN