Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

311–320 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#311
post #266

Earlier quoted context omitted.

One of my best friend has a Jolla phone. He never had WhatsApp. He refuses to use google. Only till recently he started using signal. He has been using an old Nokia phone till he was forced to upgrade by his operator. He is European and here in Europe WhatsApp dominates. Despite all that and having a very social life, driven by work, he manages. I recently ordered a Jolla phone. I don’t want to know about android. I…

It's all good until your European bank starts requiring unrooted Android and iOS for their mobile banking app, then tries to force you to use that app instead of letting you sort things out at their building. Then the government starts requiring you use unrooted Android or iOS to sign into their website for administrative tasks, and so on.

The endgame is that I will keep a phone in a drawer next to a 20 yo hardware token I still use to access a bank. When on the move, we will see.

Re: Android Developer Verification: Threat masquerading as protection

#312
post #266

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

One of my best friend has a Jolla phone. He never had WhatsApp. He refuses to use google. Only till recently he started using signal. He has been using an old Nokia phone till he was forced to upgrade by his operator. He is European and here in Europe WhatsApp dominates. Despite all that and having a very social life, driven by work, he manages. I recently ordered a Jolla phone. I don’t want to know about android. I…

Not sure Jolla deserves to be trusted, you'd be much better off with GrapheneOS. In any case, try out SimpleX for a messenger. You can also take a look at https://xn--gckvb8fzb.com/an-overview-of-privacy-focused-dec...

Re: Android Developer Verification: Threat masquerading as protection

#313
post #229

Earlier quoted context omitted.

There was a more direct case where someone’s child had been interacting with Gemini inappropriately resulting in Google nuking the entire families Google accounts.

Google has been nuking accounts since their inception. I have seen people being locked out as early as 2011 of accounts that could only be unlocked by sending a copy of an ID. Due to regulatory change of saving of information based on age (first 13 and above was ok, then became 16 and above).

> Google has been nuking accounts since their inception

Google has been dealing with accounts opened for fraud, spam and other evil bots since their inception. They should be nuking those. What's needed is some way of reverifying an account that was closed incorrectly, maybe some kind of independent ombudsman service or something to get the account back.

Re: Android Developer Verification: Threat masquerading as protection

#314

Earlier quoted context omitted.

There was a more direct case where someone’s child had been interacting with Gemini inappropriately resulting in Google nuking the entire families Google accounts.

It was a fake story on reddit.

Si non e' vero, e' ben trovato.

Re: Android Developer Verification: Threat masquerading as protection

#315

Earlier quoted context omitted.

iOS can be used without an account. iPhones can be acquired outside of Apple. The EU has the alternative App Store option that doesn’t require an Apple account.

But I can't use my Norwegian BankID unless I have an apple store or play store account. This is required for every aspect of society. Heathcare, banking, taxes, driving, using my debit card online. They removed SMS 2FA options recently, the only non-tech monopoly method is a 2fa codebrick that's getting harder and harder to acquire (there are new ridiculous facial ID and passport scanning requirements, run by a priva…

That's on your bank and not necessarily because of Apple/Google duopoly. I think it is crazy to put the whole banking system on foreign, private company though

Re: Android Developer Verification: Threat masquerading as protection

#316
post #240

Earlier quoted context omitted.

> This started with phishing It didn't. Phishing is just a pretext. Google didn't care about Phishing for the first 20 years of Android. Why do they now? Because it serves as argument to close their platform a little more (which is a trend that has been going on for years).

I think they care now because of pressure from the governments of the countries involved. And perhaps because ten and twenty years ago, the sums stolen were small. Now they're in the billions.

How do you explain that all the scammers I've entertained used apps that are already on the store?

Re: Android Developer Verification: Threat masquerading as protection

#317

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

I've seen multiple stories of people buying phones from Fi, the phones never arriving, google refusing a refund, and on a chargeback, their entire google account gets shut down.

Re: Android Developer Verification: Threat masquerading as protection

#318

Earlier quoted context omitted.

iOS can be used without an account. iPhones can be acquired outside of Apple. The EU has the alternative App Store option that doesn’t require an Apple account.

But I can't use my Norwegian BankID unless I have an apple store or play store account. This is required for every aspect of society. Heathcare, banking, taxes, driving, using my debit card online. They removed SMS 2FA options recently, the only non-tech monopoly method is a 2fa codebrick that's getting harder and harder to acquire (there are new ridiculous facial ID and passport scanning requirements, run by a priva…

That's much worse than I expected. Is it a hard play store requirement or can you install the apk? Are there really no other workarounds?

Re: Android Developer Verification: Threat masquerading as protection

#320
post #201

How does this affect the Fairphone? If I buy a Fairphone now (which I've been considering for months now) will I continue to be able to run F-Droid and load arbitrary apps, or does it come with “official” Android that will contain the restrictions?

I would in general recommend against getting a Fairphone. They traditionally have a lot of hardware issues. Some of the early issues on the FP6 (fried logic board while charging and broken volume button) are not user replaceable. Many people have had to wait a month before they get a reply from customer support and even longer to get their hardware fixed. They also completely fail to communicate about issues.

They also have a bad reputation when it comes to updating their software. E.g. their initial Android 15 builds for FP4 had bad memory management issues, with a result that many people could only have one app in memory at the time, which made it impossible to switch between e.g. an app/browser and a password manager/payment app. Some of their updates would cause boot loops when there were fingerprint reader issues, etc. Currently a lot of users are dealing with an issue where apps hang when used over WiFi because IPv6 gets misconfigured when a router sends an IPv6 router advertisement with lifetime 0 (which e.g. Fritz!Boxes that are popular in Europe do). The issue has been there for over three months without any acknowledgement or fix from Fairphone.

Also, even though they do Android Security Bulletins and major releases (though very late), their phones often run ancient kernels and firmware with many known vulnerabilities. This is also the case if you run an alternative OS, because pretty much all of them use upstream trees. Also their firmware has Chinese TCL image processing blobs (might be a security/privacy issue for some people).

I think many of these issues stem from the fact that the development of both the hardware and the software is largely outsourced to a Chinese ODM (T2Mobile), who maintain everything, so there is a lot of delay in everything. My guess is that Fairphone as a company is mostly a PR/support/supply chain auditing (as in minerals/labor, not software supply chain) company, with all the development outsourced.

Post reply on HN