Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

261–270 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#261
post #185

Earlier quoted context omitted.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

Over the long term, we definitely need something like Linux phones. I find it bizzarre by how little companies support this mission of Linux phones.

It's not Linux phones that we need. We already have alternatives, like graphene and other AOSP forks.

We need corporations and governments to stop locking down and gatekeeping vital software to closed ecosystems.

A Linux phone doesn't help me when my government's 2FA system (BankID) only runs on Android and IOS phones and can only be acquired with an app store account.

Re: Android Developer Verification: Threat masquerading as protection

#262
post #185

Earlier quoted context omitted.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

You are right - now greedy corporations decide who is an "acceptable" human and who is perma-banned. Governments need to wake up to this insane level of Evil. And other governments also need the US government responsible here, since they allow this to happen. In objective terms this can be called a fascist system. > A temporary workaround like using alternatives like GrapheneOS The issue still is that so many service…

> Governments need to wake up to this insane level of Evil.

I’m not even being cynical — it would probably just increase the amount of government contract cash awarded to them. Control makes governing a lot easier, control is what tech companies have, and to varying degrees, it’s for sale.

Re: Android Developer Verification: Threat masquerading as protection

#263
post #53

Earlier quoted context omitted.

It does with reCaptcha: https://www.androidauthority.com/grapheneos-google-apple-app...

Yes, Google could do a lot of things, in theory. Doesn’t mean they’re doing it.

The point is, they are doing it...

Re: Android Developer Verification: Threat masquerading as protection

#264
While attribution is a strong weapon in fighting malicious software, persevering the ability to install and run anonymous software is essential to fight authoritarian regimes and corrupt systems. If we accept that only signed, permitted software can be installed and run on users’ phones, democracy and our freedom are doomed. Regardless if it is in the West or the East, or it’s against an AI overlord.

Re: Android Developer Verification: Threat masquerading as protection

#265
post #39
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

The only reason I have not switched Graphene is because for reasons I do not understand, Graphene OS is very closely tied with Google hardware. I bought a /e/os Fairphone instead.

Sigh, /e/OS.

Your phone is running proprietary Google DroidGuard blobs in a privileged process every time an app initiates a Play Integrity request.

If you install some Google apps like Google Maps, they are run with more privileges than other apps (their microG fork gives apps elevated privileges when they match certain Google signing key fingerprints).

Also, your device is running a firmware bundle provided by Fairphone's Chinese ODM, including TCL image processing blobs. Your phone will soon run an ancient kernel and firmware tree with many known critical CVEs.

But this all doesn't matter anyway, because security hardening is only for spies and pedophiles according to the CEO of Murena (the company that makes /e/OS).

Re: Android Developer Verification: Threat masquerading as protection

#266

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

One of my best friend has a Jolla phone.

He never had WhatsApp. He refuses to use google. Only till recently he started using signal. He has been using an old Nokia phone till he was forced to upgrade by his operator. He is European and here in Europe WhatsApp dominates. Despite all that and having a very social life, driven by work, he manages.

I recently ordered a Jolla phone. I don’t want to know about android. I might tolerate iOS. But shelling thousands of $ for a phone that is controlled by an external company…

I am looking out for messaging alternatives. I am at a point where I think linking your identity to a phone number is not right either.

Let’s say we should all wake the fuck up. This is not right. Having a phone with such spyware is a potential attack vector I don’t want to have on the most important device I own.

Re: Android Developer Verification: Threat masquerading as protection

#267

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

I don't have a mandatory bank or gov id app. Where are you living?

Re: Android Developer Verification: Threat masquerading as protection

#268
post #217

Earlier quoted context omitted.

Google had Don’t be evil motto just between 2000 and 2018. Other companies don’t even try to pretend it. You are owned by them. „Power tends to corrupt, and absolute power corrupts absolutely.“ - Lord Acton, 1887

Like how Tony Chocolonely dropped their 100% slave free claim after finding out just how difficult that is to achieve. Nowadays they are using the slogan “Crazy about chocolates, serious about people”

[dead]

Re: Android Developer Verification: Threat masquerading as protection

#269
post #252

Android developer verification program, together with recent reCAPTCHA push [1], and Manifest v2 force depreciation on chrome [2], make one thing crystal clear. When companies like GOOGLE talks about things in the name of "your security", it's a sign that they want you to sacrifice your own things, e.g., privacy, freedom, etc., for their own security. And if you trust them and show your consent by doing nothing, you…

Google has been attempting to license the right to write. There are a lot of poor people, mostly brown people, who do not have the ability to get one of these licenses. Some of them are feeding themselves with their ability to write, and Google is literally stealing that food from their mouths.

Can I ask what you mean when you say "write"? Are you talking about literature / articles, or software?

This is new to me, want to stay on top of it.

Re: Android Developer Verification: Threat masquerading as protection

#270
post #108

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

The blast radius is far worse than any "malware" Google could protect you from. TFA is playing it up, but it is arguable that this is a real virus, except the shady hackers are Google.

Malware on Android causes more harm, both to individuals and collectively to all Android users, than Google locking people out of their accounts. These aren't even in the same order of magnitude. There are countless examples of people who have lost their life savings, all their data, etc. Losing access to your Google account sucks too, and I don't necessarily agree with what Google is doing here, but you're completely off base here.
Post reply on HN