Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

111–120 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#111

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

> We need to resist this!

I agree. What do you suggest? How can we contribute to the resistance?

Re: Android Developer Verification: Threat masquerading as protection

#112
This is more than enshittification, it feels like purposeful brand destruction.

Are governments going to institute more lockdowns? Is this some topdown control thing?

I will root this POS android phone I have and forego any Google Play services and just use it as web browser and a phone. Fuck these guys!

Re: Android Developer Verification: Threat masquerading as protection

#113
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

> Android users need to switch to Graphene. Doesn't GrapheneOS supports only Google Pixel smartphones now? For most of the users, that would mean changing their phones beforehand. And if we're talking about common people (especially not in US), it's not even everyone who can afford that. Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

> Doesn't GrapheneOS supports only Google Pixel smartphones now?

For good reasons. Most other devices arent secure enough to guarantee privacy. Especially not if loaded with a custom operating system (most devices don't allow to verify the boot chain with a custom OS)

> And if we're talking about common people (especially not in US), it's not even everyone who can afford that.

You can get a new Pixel 9a here in europe for around 350€ and it will be supported at least until April 2032

> Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

Google phones are surprisingly open and work well. Google takes a pro-user stance here that is extremely rare in the ecosystem, so why not support this product?

Re: Android Developer Verification: Threat masquerading as protection

#114
post #41
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

I know Graphene has innovative security measures, do you happen to know whether that includes anything wrt. phishing or social engineering? (For those who haven't been following along: this whole affair started with phishing. People were social-engineered into installing an app and a little later their bank accounts were empty. A big issue in various poor countries.)

It is not an OS with bubblewrap, you can still mess up your privacy / security if you want to, that includes phishing and social engineering.

Re: Android Developer Verification: Threat masquerading as protection

#115
post #31

Earlier quoted context omitted.

I tried. But then I didnt get access to essential services like banking and national resources.

FWIW, I submitted an EU DMA complaint (Art 27 report) against Alphabet for unfair gatekeeping against third-party distributions like GrapheneOS via Play Integrity. More info: https://github.com/AlexAltea/blog/blob/master/posts/2026-06-... Convincing developers, especially bank and gov apps, is near impossible and won't scale well. Going after Alphabet for not meeting DMA obligations seems the easier path. Might not g…

> Convincing developers, especially bank and gov apps, is near impossible and won't scale well

Not impossible though, my bank and govt eID app did do safetynet, but after enough users complained in both apps you can now skip a warning and use it without issues

Re: Android Developer Verification: Threat masquerading as protection

#116

Earlier quoted context omitted.

We experienced this with Anthropic, not the same blast radius obviously, but out of nowhere account was terminated. No support available. It was via someone’s 30+ year old classmate via LinkedIn the account got reinstated. As a counterpoint to the right to the repair there should be a right to recover.

There was a more direct case where someone’s child had been interacting with Gemini inappropriately resulting in Google nuking the entire families Google accounts.

That’s quite insane, especially considering how Google is pushing Gemini into every single product.

Re: Android Developer Verification: Threat masquerading as protection

#117
post #56

Earlier quoted context omitted.

It all depends on how you define malware. If malware is software doing something that is contrary to the user's interests, then for many users it is indeed malware.

>this malevolent process has exactly one goal: to block you from running software by developers who haven’t been approved centrally by Google. This claim is made by FDroid with no evidence. They make this scary claim which goes against everything Google has claimed so far. They are a biased party, and I can't trust their opinion. I would appreciate if they shared a more in depth investigation or a way to verify there…

Trust is not binary; we can process data with a level of confidence. We do not need either Google or F-Droid to be sanctified before we evaluate their claims.

The claim is that a repeat monopolist is doing monopolist things. Feel free to make the case for the trustworthiness of Google's opposing claim, as I don't see anyone else doing that.

Re: Android Developer Verification: Threat masquerading as protection

#118
We finally live in an age when I can tell a clanker that I want an app that does something that I need, connect the phone with adb and in half an hour have a working solution for my tiny problem while knowing little about android development. This is something google should embrace, not kneecap.

Re: Android Developer Verification: Threat masquerading as protection

#119
post #114
post #41

Earlier quoted context omitted.

I know Graphene has innovative security measures, do you happen to know whether that includes anything wrt. phishing or social engineering? (For those who haven't been following along: this whole affair started with phishing. People were social-engineered into installing an app and a little later their bank accounts were empty. A big issue in various poor countries.)

It is not an OS with bubblewrap, you can still mess up your privacy / security if you want to, that includes phishing and social engineering.

Is anything bulletproof against the user signing away their data? I think the question was whether it has any measures in this regard, not whether it's impossible to get phished

Re: Android Developer Verification: Threat masquerading as protection

#120
post #41
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

I know Graphene has innovative security measures, do you happen to know whether that includes anything wrt. phishing or social engineering? (For those who haven't been following along: this whole affair started with phishing. People were social-engineered into installing an app and a little later their bank accounts were empty. A big issue in various poor countries.)

> do you happen to know whether that includes anything wrt. phishing or social engineering?

Yes. For example if you install an apk from an unknown source (like a random website via browser or messenger) it will warn you what you are about to do and what effects that has.

You don't need to block stupid behavior. Just make sure users are well aware of their actions as long as they actually read warnings.

Post reply on HN