Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

231–240 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#231
post #213

Emotional talk aside, there's not many good solution to this problem, unless of course F-Droid starts to make their own phones. But then, Librem 5 Phone was just failed few years ago, telling the story that people who care about their rights are still sensitive to how much they would pay (which is a form of rights too). Also but, there is the thing, making a phone is not easy. If you reach deep enough, you'll eventua…

There is a good solution. A big disclaimer and the user accepting the risk of running the software they want. The same solution they've been doing for years that did not need change. The new developer program is only here because it is more convenient to Google and governments.

Re: Android Developer Verification: Threat masquerading as protection

#232

Earlier quoted context omitted.

There's no such requirement for publishing a website

There is - every server host does KYC and so does every domain registrar (by law). If you're found to have provided incorrect details, it allows them to immediately remove your server or domain without notice.

does GitHub require KYC for .github.io pages? does neocities? does 111freewebhosting?

Re: Android Developer Verification: Threat masquerading as protection

#233
Btw. This whole debacle made me to stop installing any Android updates. I've done my best to avoid installing even the security updates, so my diabetes apps continue working in the future.

I really need to take the time and go with Graphene OS in this device. My bank N26 kind of still allows it, but they made it harder and harder to use with certain custom checks. Looks like in the future I need a separate banking phone and my daily driver.

The device works right now how I want it. I don't want anything to change.

Re: Android Developer Verification: Threat masquerading as protection

#235
post #53

Earlier quoted context omitted.

It does with reCaptcha: https://www.androidauthority.com/grapheneos-google-apple-app...

Yes, Google could do a lot of things, in theory. Doesn’t mean they’re doing it.

They are doing it now. You can already see that captcha around online, and cannot get past it without surrendering your identity to them.

Re: Android Developer Verification: Threat masquerading as protection

#236
post #181
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

> Android users need to switch to Graphene. Which supports only Pixel devices.

The resason is that only Google bothers to put enough hardware security features to build software on top that allows to make a really secure device that blocks tampering.

Re: Android Developer Verification: Threat masquerading as protection

#237
While I sympathize with the general negative outrage towards this change, I truly believe that people here fail to empathize with the mainstream users of Android phones.

I personally have seen every single older relative and non-tech friend, end up installing bloateare, spyware, and malware inadvertently - because they have no idea how anything in the tech domain works. And given the widespread popularity of Android (globally 70% vs iOS at 30% market share) and even moreso in lower income demographics, it also leads to rampant piracy of obviously non-essential apps like games and streaming (eg Spotify). In fact, even here on HN, almost everyone who has given their parents an iPhone has extolled the virtues of a secured AppStore/device and the peace of mind it brings.

While there may someday be a way to support both the average user and the HN power user, we are not there yet. It’s hard for me to outright reject Google/Android attempts to secure people’s devices.

Re: Android Developer Verification: Threat masquerading as protection

#238
post #150

Earlier quoted context omitted.

It doesn't tamper with your installations.

Oh? Maybe you could comment on what part of the f-droid article is wrong

>If you are running Android 8 or higher, a virus has been installed on your device and is silently awaiting remote activation.

I have such a phone and the "virus" has not been installed to it. There is no evidence behind this claim.

>with as many as 4 billion Android handsets and tablets estimated to have already been contaminated

This is misleading wording. It's just as true to say that as many as 1 trillion devices have been contaminated. It is state an impossible upper bound to drum up fear.

>this trojan horse runs surreptitiously in the background as a system service with full root privileges

Services in Android do not run with root privileges. Android practices the principal of least privilege where individual permissions are granted instead of giving it blanket access to everything.

>The service cannot be blocked, disabled, or removed.

This is unlikely to be true. You can most likely use "am" to disable it.

>In fact, Play Protect is itself the vector through which this virus is transmitted and installed.

This is probably false. Realistically it's going to be transmitted via the google play store like all other play service components.

>There are many things we don’t know about what to expect on September 30

>What will happen if I try to install or launch the F-Droid app?

Once active if FDroid not verified the user has to use adb or have enabled sideloading by unverified developers. If it's already installed the user can launch it.

>What will happen to all the apps I’ve installed through F-Droid? Will they be disabled? Deleted?

Nothing will happen to them.

>If apps that I rely on are suddenly disappeared, what happens to the data they contain? Can I still retrieve it?

Nothing will happen. But if Play Protect were to flag malware it manually asks you if you want to delete the app. If you delete the app the data will be lost.

Re: Android Developer Verification: Threat masquerading as protection

#240
post #125

Earlier quoted context omitted.

This started with phishing, poor people being tricked to install apps that then drained their bank accounts. So to resist, maybe focus on that evil? Better international cooperation, better prosecution?

> This started with phishing It didn't. Phishing is just a pretext. Google didn't care about Phishing for the first 20 years of Android. Why do they now? Because it serves as argument to close their platform a little more (which is a trend that has been going on for years).

I think they care now because of pressure from the governments of the countries involved.

And perhaps because ten and twenty years ago, the sums stolen were small. Now they're in the billions.

Post reply on HN