Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

141–150 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#141

Earlier quoted context omitted.

There's no such requirement for publishing a website

There is - every server host does KYC and so does every domain registrar (by law). If you're found to have provided incorrect details, it allows them to immediately remove your server or domain without notice.

No there isn't, Google's requirement is to put that information publicly for everybody to see. That's not nearly the same thing as being available on court request.

With that policy, Google encourages stalkers and put developers in danger.

Re: Android Developer Verification: Threat masquerading as protection

#142
post #34

Earlier quoted context omitted.

Does Huawei not use android or Google play services?

It's Android but without Google's services, there's an alternative app store. The irony of Chinese vendors providing a breath of fresh low-DRM air.

It seems like China is becoming the "freedom superpower" while USA is getting "corporate superpower" vibes. Huh

Re: Android Developer Verification: Threat masquerading as protection

#143

Earlier quoted context omitted.

> Android users need to switch to Graphene. Doesn't GrapheneOS supports only Google Pixel smartphones now? For most of the users, that would mean changing their phones beforehand. And if we're talking about common people (especially not in US), it's not even everyone who can afford that. Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

> Doesn't GrapheneOS supports only Google Pixel smartphones now? For good reasons. Most other devices arent secure enough to guarantee privacy. Especially not if loaded with a custom operating system (most devices don't allow to verify the boot chain with a custom OS) > And if we're talking about common people (especially not in US), it's not even everyone who can afford that. You can get a new Pixel 9a here in europ…

So to avoid google's android I buy google phone to not run android?

Re: Android Developer Verification: Threat masquerading as protection

#144
post #56

Earlier quoted context omitted.

It all depends on how you define malware. If malware is software doing something that is contrary to the user's interests, then for many users it is indeed malware.

>this malevolent process has exactly one goal: to block you from running software by developers who haven’t been approved centrally by Google. This claim is made by FDroid with no evidence. They make this scary claim which goes against everything Google has claimed so far. They are a biased party, and I can't trust their opinion. I would appreciate if they shared a more in depth investigation or a way to verify there…

Google wrote their plans as blog posts.

Re: Android Developer Verification: Threat masquerading as protection

#145
post #109
post #41

Earlier quoted context omitted.

I know Graphene has innovative security measures, do you happen to know whether that includes anything wrt. phishing or social engineering? (For those who haven't been following along: this whole affair started with phishing. People were social-engineered into installing an app and a little later their bank accounts were empty. A big issue in various poor countries.)

That's one of its primary arguments: besides the hardening against exploits, they're considered such a safe OS because you cannot access your data either and give the wrong app root access. Everything lives in a sandbox. Whether not being able to grant full access to e.g. adb shell, Termux, or Restic is what you want is a personal choice, but it adds a layer of security against any malware that tries to get you to gr…

So it doesn't actually do anything to give control of the device back to the user?

One of the core tenets of truly free software is that I as user must be able to run, access, edit, and view everything.

Re: Android Developer Verification: Threat masquerading as protection

#146

Earlier quoted context omitted.

> Android users need to switch to Graphene. Doesn't GrapheneOS supports only Google Pixel smartphones now? For most of the users, that would mean changing their phones beforehand. And if we're talking about common people (especially not in US), it's not even everyone who can afford that. Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

> Doesn't GrapheneOS supports only Google Pixel smartphones now? For good reasons. Most other devices arent secure enough to guarantee privacy. Especially not if loaded with a custom operating system (most devices don't allow to verify the boot chain with a custom OS) > And if we're talking about common people (especially not in US), it's not even everyone who can afford that. You can get a new Pixel 9a here in europ…

It's alright, whatever the reasons might be, but let's not pretend there are no other ways out. I'm content with newest LineageOS on my 7 year old mid-range Xiaomi. I don't mind the loss of privacy guarantee. I don't have to spend any extra 350 euros and lose the headphone jack in the process.

Re: Android Developer Verification: Threat masquerading as protection

#147

My Android 15 handset doesn't have com.google.android.verifier process. It could be a Ulefone thing. They're especially pro-user (ex:root friendly).

Ex means "example" here right? Or do you mean ex as in the dictionary meaning of ex, as in, "formerly"?

Re: Android Developer Verification: Threat masquerading as protection

#148
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

GrapheneOS is currently the blessed child. Like CyanogenMod previously. They are "permitted" to access to Google Play Services because their work hardening Android currently benefits Google.

Once Google feels like there is sufficient stability and compatibility with hardened memory allocator and tagged memory (and when they can get Qualcomm to support it across their range), they will make harder, until impossible, for Graphene.

An old article [1] but:

> Google’s Android—and [Open Handset Alliance] members are contractually prohibited from building non-Google approved devices

So to compete you'd have to create a compatible Google Play Services as well as find a supporting manufacturer. Samsung managed their own competing apps and store [2] for a while along with Tizen, likely for leverage or theoretical pivot. But has since dropped that effort.

[1] https://arstechnica.com/gadgets/2018/07/googles-iron-grip-on...

[2] https://arstechnica.com/tech-policy/2021/07/google-bought-of...

Re: Android Developer Verification: Threat masquerading as protection

#149
post #106

Earlier quoted context omitted.

It's Android but without Google's services, there's an alternative app store. The irony of Chinese vendors providing a breath of fresh low-DRM air.

Partially true, HarmonyOS NEXT is its own thing, with a Typescript based language ArkTS. https://developer.huawei.com/consumer/en/arkts/ And now they are adding yet another one, AOT compiled, Cangjie https://cangjie-lang.cn/en Using Android fork has been a transition step.

Neat, thanks for this correction! Interesting, an entire new programming language.

Re: Android Developer Verification: Threat masquerading as protection

#150
post #61

Earlier quoted context omitted.

The point is that it is said to tamper with your installations. If it does, it is malware.

It doesn't tamper with your installations.

Oh? Maybe you could comment on what part of the f-droid article is wrong
Post reply on HN