Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

281–290 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#281

We finally live in an age when I can tell a clanker that I want an app that does something that I need, connect the phone with adb and in half an hour have a working solution for my tiny problem while knowing little about android development. This is something google should embrace, not kneecap.

Installing via adb is not affected.

Re: Android Developer Verification: Threat masquerading as protection

#282

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

AFAIK you can still install any random APK but the process will require enabling developer mode and one time 24 hour wait period. But the problem is many stupid Apps check that developer mode is on and refuse to work.

> many stupid Apps check that developer mode is on and refuse to work

Do you have some examples? I have developer mode enabled and have never seen any apps complaining (and I have used a lot of different banking apps).

Re: Android Developer Verification: Threat masquerading as protection

#283
post #213

Emotional talk aside, there's not many good solution to this problem, unless of course F-Droid starts to make their own phones. But then, Librem 5 Phone was just failed few years ago, telling the story that people who care about their rights are still sensitive to how much they would pay (which is a form of rights too). Also but, there is the thing, making a phone is not easy. If you reach deep enough, you'll eventua…

> because the average people don't know how to properly secure their system, and Linux is not a restrictive-by-default system. It will be a malware nightmare if you ship Linux on a phone as is.

Linux is a kernel. A Linux-based distribution decides what the defaults would be. Why, in your opinion, would a Linux distro targeting phone-ish ARM64 hardware be problematic? Why would it be a "malware nightmare"?

Re: Android Developer Verification: Threat masquerading as protection

#284
post #49

I just launched an app in the Google Play Store. I did find it a bit weird that I had to provide my physical home address to get my app listed. Not sure what I would do if someone turned up to complain. Make them a cup of tea?

You should not distribute apps via the Google Play Store. Using alternative means, including F-Droid as relevant. And it was a mistake of you to register, because you're helping Alphabet exert more pressure and control on others.

Re: Android Developer Verification: Threat masquerading as protection

#285

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

> And you’ll never reach a human to sort it out. Unless you blog about it angrily enough that you somehow make it to the HN front page and some insider sees it and solves the problem for you. Getting my own domain and setting up email on it is one of the best things I've ever done.

About to go down that route as well, just need to find a email provider with ideally servers in the EU

Re: Android Developer Verification: Threat masquerading as protection

#286

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

AFAIK you can still install any random APK but the process will require enabling developer mode and one time 24 hour wait period. But the problem is many stupid Apps check that developer mode is on and refuse to work.

I'm not aware of any apps that check for developer mode, that's mainly root.

Re: Android Developer Verification: Threat masquerading as protection

#287

Earlier quoted context omitted.

Over the long term, we definitely need something like Linux phones. I find it bizzarre by how little companies support this mission of Linux phones.

It's not Linux phones that we need. We already have alternatives, like graphene and other AOSP forks. We need corporations and governments to stop locking down and gatekeeping vital software to closed ecosystems. A Linux phone doesn't help me when my government's 2FA system (BankID) only runs on Android and IOS phones and can only be acquired with an app store account.

> We need corporations and governments to stop locking down and gatekeeping vital software to closed ecosystems.

If you can't get the government to do this for you in Norway the US has very little hope currently.

We need some standard of minimal digital accessibility. Too much of our lives mediated by digital interactions with capricious systems.

Re: Android Developer Verification: Threat masquerading as protection

#288
post #198
post #105

Earlier quoted context omitted.

It was indeed! And Google removed it in 2018. - https://en.wikipedia.org/wiki/Don%27t_be_evil

and it is still there https://abc.xyz/investor/board-and-governance/google-code-of...

Section "2. Competition Laws"

https://www.nytimes.com/2024/11/20/technology/google-antitru...

Re: Android Developer Verification: Threat masquerading as protection

#289
post #185

Earlier quoted context omitted.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

You are right - now greedy corporations decide who is an "acceptable" human and who is perma-banned. Governments need to wake up to this insane level of Evil. And other governments also need the US government responsible here, since they allow this to happen. In objective terms this can be called a fascist system. > A temporary workaround like using alternatives like GrapheneOS The issue still is that so many service…

> Governments need to wake up to this insane level of Evil

Governments are made up of people. People who have at best median level understanding of the things they are ruling about but great self-interest in following the biggest purse to which they can attach themselves.

Re: Android Developer Verification: Threat masquerading as protection

#290
post #185

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

It's terrifying, yeah.

To some degree, the closest we have to these situations besides getting flagged with TOS violations (whether real or false-flagged) in these companies are residents of countries that are either trade or economically sanctioned by the USA.

Thankfully we haven't seen something like an account ban and deletion incident for such cases, but the severe ones I can remember usually prohibit access entirely and that'd be scary if it extended to primary services that others rely on for auth.

You will be effectively locked out to services if it's all that's linked and that identity provider just decided you'd be persona non grata.

Post reply on HN