Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

241–250 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#241
post #213

Emotional talk aside, there's not many good solution to this problem, unless of course F-Droid starts to make their own phones. But then, Librem 5 Phone was just failed few years ago, telling the story that people who care about their rights are still sensitive to how much they would pay (which is a form of rights too). Also but, there is the thing, making a phone is not easy. If you reach deep enough, you'll eventua…

There is a good solution. A big disclaimer and the user accepting the risk of running the software they want. The same solution they've been doing for years that did not need change. The new developer program is only here because it is more convenient to Google and governments.

We've known for literally decades that that doesn't actually work, for several reasons:

1. People are conditioned to ignore warnings. There are way too many benign warnings in the world; you can't read them all.

2. Even when people wouldn't ignore them, in cases where they are being tricked by scammers it's easy for the scammer to talk people into accepting them.

3. Those sorts of warnings aren't actionable. You're installing a new app. It appears legit. You want to use it. You get a warning like "this app hasn't been verified; it might be malware!". What can you do with the information? Absolutely nothing. 99.9999% of users have zero way of doing any deeper check to see whether it actually is malware. Their only options are to give up and go home, or just hope that the warning is wrong. Even I - a highly technical user - get zero value from things like Windows' smart screen. "The app you're running hasn't been signed! It might be malware!". Err yeah sure. I'm not going to reverse engineer it to check am I?

I think their solution of allowing you to disable the restriction with a one-time one-day delay is actually a really reasonable solution. As long as they don't go further than that - the risk is that it is just a temporary placation and they'll ditch that option in a few years.

Re: Android Developer Verification: Threat masquerading as protection

#242
post #217

Earlier quoted context omitted.

If you've accidentally become a persona non grata, then obviously because you've not exercised sufficient self-censorship. This is real already. Recently saw a petition for EU to rein in big tech (there are several initiatives advocating this). Had this nagging voice at the back of my head ... what if signing that gets your Google Account terminated. I'll leave it open to you whether I signed it. For developers relyi…

Google had Don’t be evil motto just between 2000 and 2018. Other companies don’t even try to pretend it. You are owned by them. „Power tends to corrupt, and absolute power corrupts absolutely.“ - Lord Acton, 1887

Like how Tony Chocolonely dropped their 100% slave free claim after finding out just how difficult that is to achieve.

Nowadays they are using the slogan “Crazy about chocolates, serious about people”

Re: Android Developer Verification: Threat masquerading as protection

#243

Earlier quoted context omitted.

> Google phones are surprisingly open and work well. Google takes a pro-user stance here that is extremely rare in the ecosystem, so why not support this product? Because they will pull the rug here one day too. Why on earth should we trust them to keep this approach to their hardware?

Don’t defeat yourself in a one person battle. After all, it might rain tomorrow - but you should still go outside today.

My stance isn’t “give up.” My point is we should explore and expand non-Google alternatives for hardware.

Re: Android Developer Verification: Threat masquerading as protection

#245
post #185

Earlier quoted context omitted.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

Over the long term, we definitely need something like Linux phones. I find it bizzarre by how little companies support this mission of Linux phones.

I don’t want to be too pedantic but Android uses the Linux kernel. Degoogled Android is basically what you want.

Re: Android Developer Verification: Threat masquerading as protection

#247
post #185

Earlier quoted context omitted.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

Over the long term, we definitely need something like Linux phones. I find it bizzarre by how little companies support this mission of Linux phones.

Why do you need a Linux phone (as if Android is not a Linux phone), when there is also AOSP. If Google closes it up, it can be forked, but I don't see any fundamental benefit of throwing away decades of development done on AOSP.

Re: Android Developer Verification: Threat masquerading as protection

#248
post #185

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

You are right - now greedy corporations decide who is an "acceptable" human and who is perma-banned.

Governments need to wake up to this insane level of Evil. And other governments also need the US government responsible here, since they allow this to happen.

In objective terms this can be called a fascist system.

> A temporary workaround like using alternatives like GrapheneOS

The issue still is that so many services and functionalities are tied into private companies. States simply need to wake up now.

Re: Android Developer Verification: Threat masquerading as protection

#249
post #108

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

The blast radius is far worse than any "malware" Google could protect you from. TFA is playing it up, but it is arguable that this is a real virus, except the shady hackers are Google.

I don't think 'virus' is the right term, since it should self-replicate. 'Malware' or 'spyware' are probably better terms.

Re: Android Developer Verification: Threat masquerading as protection

#250
post #75
post #40

Earlier quoted context omitted.

Graphene OS user here. Almost all of the apps I tried work fine. All the banking apps I use work. Have you tried reaching out to the app developer or the service and explaining what Graphene OS is and asking them to support it? I was able to persuade one app to do it. [1] https://privsec.dev/posts/android/banking-applications-compa...

Problem is that all banks require a national centrale controlled service for login (BankID in Norway). And it is this service that I cannot get to work running GrapheneOS. It worked a couple of months ago, but not anymore. And all customer services and complaints are directed to your bank who 1) has no idea what i am talking about and 2) no control over BankID verification requirements.

I did actually alert BankID about this potential lock-in issue back when they announced they would be abandoning the SIM-based (and thus phone-independent) solution, to little understanding and just general comments about the cost of keeping the SIM-based solution alive. I guess now with eSIM being prevalent it wouldn't have made much difference anyway.

But just the thought of the potential to be completely locked out of everything from banks to online payments, logins to the public health system, tax filings (and basically all public sector services) just at the whim of Google or Apple's automated algorithms misunderstanding some random account activity, is a thought that should make everyone (and especially those in countries dependent on systems like BankID) afraid and demand at minimum:

Rights to:

- Due Process

- Accountability from Google & Apple and fines for when they do wrong

- Multiple warnings (with a right to know what you're being accused of) before being locked out

- Well-functioning complaint procedures with strict time frames

- Make the mere concept of banning users "for life" illegal

...from Google and Apple (and strict fines for them not adhering to them). Feel free to add more to the list.

Else we as a society can't depend on a smartphone as the main key to our lives anymore.

Post reply on HN