Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

121–130 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#121

Earlier quoted context omitted.

> Android users need to switch to Graphene. Doesn't GrapheneOS supports only Google Pixel smartphones now? For most of the users, that would mean changing their phones beforehand. And if we're talking about common people (especially not in US), it's not even everyone who can afford that. Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

> Doesn't GrapheneOS supports only Google Pixel smartphones now? For good reasons. Most other devices arent secure enough to guarantee privacy. Especially not if loaded with a custom operating system (most devices don't allow to verify the boot chain with a custom OS) > And if we're talking about common people (especially not in US), it's not even everyone who can afford that. You can get a new Pixel 9a here in europ…

> Google phones are surprisingly open and work well. Google takes a pro-user stance here that is extremely rare in the ecosystem, so why not support this product?

Because they will pull the rug here one day too. Why on earth should we trust them to keep this approach to their hardware?

Re: Android Developer Verification: Threat masquerading as protection

#123
post #102
post #62

Earlier quoted context omitted.

well they can swat you, order pizza, send you packages (who knows with what inside), spread false info about you if you've given out more info etc... all it takes is one guy who gets too mad for some reason and it's gonna be a lot more costly for you to do anything about it vs. that guy who gets to be completely anonymous about it

How? I don't see the address published. They can sue you and Google will give your address to the court, clearly. But swat? Send packages? How?

You need to put a literal physical address and not even a PO Box is allowed.

Re: Android Developer Verification: Threat masquerading as protection

#124
post #82

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

> Well… you can run android without google?

You can only run LineageOS on smartphones that allow unlocking the bootloader (which is more and more rare), and properly release the kernel source-code (many still don't, especially low-end MTK-based phones...)

Re: Android Developer Verification: Threat masquerading as protection

#125
post #111

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

> We need to resist this! I agree. What do you suggest? How can we contribute to the resistance?

This started with phishing, poor people being tricked to install apps that then drained their bank accounts. So to resist, maybe focus on that evil? Better international cooperation, better prosecution?

Re: Android Developer Verification: Threat masquerading as protection

#126
post #82

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

Yet on LineageOS you're not affected. It seems you can build Android that isn't affected by Google, at least if you're willing to personally adjust the code to do what you want. You'd have to get exceptionally busy before it's not recognisable as an Android distribution anymore

Re: Android Developer Verification: Threat masquerading as protection

#127

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

This is worse than Apple. With Apple you knew where you stood day 1.

[flagged]

Re: Android Developer Verification: Threat masquerading as protection

#128
post #125
post #111

Earlier quoted context omitted.

> We need to resist this! I agree. What do you suggest? How can we contribute to the resistance?

This started with phishing, poor people being tricked to install apps that then drained their bank accounts. So to resist, maybe focus on that evil? Better international cooperation, better prosecution?

We can't even get India and Turkey sanctioned for evading the anti-Russian sanctions... good luck holding them accountable for the scam callcenters.

Re: Android Developer Verification: Threat masquerading as protection

#129

Earlier quoted context omitted.

https://www.eu-digital-markets-act.com/Digital_Markets_Act_A... Art 6 (4). Read it to the end. That's how.

I don't get what part of that your think enables them to deny access to third parties distributing their apps on alternate stores. If you're referring to the last paragraph, that very explicitly says that any such security must be an optional setting that is not default. So unless users opt into verified only apps, Google can't force that, according to the DMA.

Maybe not, but reading their blog posts about ADV next to the DMA text, that's certainly the angle they are trying. And it will be years if it ever comes to a court hearing.

And the setting is "optional", just do the 24h-waiting song and dance to change it, or use ADB. /s

Re: Android Developer Verification: Threat masquerading as protection

#130
It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile:

- SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the most stable/bug-free in this list.

- Ubuntu Touch: fully open source and community driven, it uses snap packages for security, you might be able to run android apps. Last time I run it also seemed fairly stable/bug-free.

- PureOS: fully open source and privacy focused. I think it's the only one that, released with the Librem 5, can avoid using proprietary blobs for interfacing with the hardware. Seems less stable than SailfishOS and Ubuntu Touch. You would need to buy a fairly expensive-but-old phone(librem 5) to run it.

- PostmarketOS: fully open source, focused on being lightweight and revive old phones, has a huge amount of phones it has been tested on, is based on Alpine.

- Mobian: mobile version of Debian, it's fairly new on this list.

There are many more linux mobile OSes, but as far as I know these are the main ones. There might also be some inaccuracies on this post, I tested some of these a long time ago, and I never actually run the last 2.

Post reply on HN