Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

351–360 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#351

Earlier quoted context omitted.

iOS can be used without an account. iPhones can be acquired outside of Apple. The EU has the alternative App Store option that doesn’t require an Apple account.

> The EU has the alternative App Store option that doesn’t require an Apple account. I cannot install any iOS software without being logged into my Apple account, not even an alternative app store. It would be perfect on my older iDevices, but they don't let me log in anymore “because the OS is too old”. And guess what: I cannot update the OS without being logged in. I never logged out of those iDevices, Apple did th…

I tried to install onside.io through Safari and it doesn’t seem to use my Apple credentials.

Have you tried updating your older iOS devices through a Mac?

Re: Android Developer Verification: Threat masquerading as protection

#352

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

I switched banks and made sure it doesn't require Android/iOS. Many banks propose FIDO2 + SMS, even bank of america does.

Re: Android Developer Verification: Threat masquerading as protection

#353
post #267

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

I don't have a mandatory bank or gov id app. Where are you living?

Apparently much of Europe is a strange banking dystopia.

Perhaps the antiquity of the US banking system is finally coming in handy. I’ve still got my checkbook ready to go!

Re: Android Developer Verification: Threat masquerading as protection

#354

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

All of which have beyond horrific security. GrapheneOS is the only acceptable alternative from mainstream Android.

Re: Android Developer Verification: Threat masquerading as protection

#355

All talk, no solutions from F-droid. What are they actually doing to solve it? Why not stand up their own vetting system? I'd love some technical solutions, instead this is just childish.

Because as designed they have to live under whatever google puts into Android because they have inordinate control over the whole ecosystem? I'm not sure why or how you would possibly describe that as "childish".

Re: Android Developer Verification: Threat masquerading as protection

#356

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

I would strongly advise using your personal account to access the developer-side of the Play Store.

No, these services shouldn’t all be bundled under a single account…

Re: Android Developer Verification: Threat masquerading as protection

#357

Earlier quoted context omitted.

iOS can be used without an account. iPhones can be acquired outside of Apple. The EU has the alternative App Store option that doesn’t require an Apple account.

But I can't use my Norwegian BankID unless I have an apple store or play store account. This is required for every aspect of society. Heathcare, banking, taxes, driving, using my debit card online. They removed SMS 2FA options recently, the only non-tech monopoly method is a 2fa codebrick that's getting harder and harder to acquire (there are new ridiculous facial ID and passport scanning requirements, run by a priva…

The App Store account doesn’t need to be the same as the Apple iCloud account. You can create an account without a credit card associated to it.

Re: Android Developer Verification: Threat masquerading as protection

#358
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

GrapheneOS is currently the blessed child. Like CyanogenMod previously. They are "permitted" to access to Google Play Services because their work hardening Android currently benefits Google. Once Google feels like there is sufficient stability and compatibility with hardened memory allocator and tagged memory (and when they can get Qualcomm to support it across their range), they will make harder, until impossible, f…

> They are "permitted" to access to Google Play Services because their work hardening Android currently benefits Google.

Very little in GrapheneOS has gone back upstream post-Copperhead.

> Once Google feels like there is sufficient stability and compatibility with hardened memory allocator and tagged memory (and when they can get Qualcomm to support it across their range), they will make harder, until impossible, for Graphene.

What are you talking about? Google doesn't use hardened_malloc, and they literally invented MTE.

Re: Android Developer Verification: Threat masquerading as protection

#359
post #185

Earlier quoted context omitted.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

You are right - now greedy corporations decide who is an "acceptable" human and who is perma-banned. Governments need to wake up to this insane level of Evil. And other governments also need the US government responsible here, since they allow this to happen. In objective terms this can be called a fascist system. > A temporary workaround like using alternatives like GrapheneOS The issue still is that so many service…

As proven by history, it's convenient to have a big well-known external entity to blame as a source of any trouble, but in reality it's orders of magnitude easier to be a digital dissident in the US compared to the EU. And European Commission + European national governments are exactly the ones you should blame first. They are openly proud of how it works, they call it successful digitalization for a positive spin.

Re: Android Developer Verification: Threat masquerading as protection

#360

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

This is worse than Apple. With Apple you knew where you stood day 1.

Its worse in a different way.

I mean when people complained about Apple, the standard reply was "if you don't like Apple use Android,it's open! ".

Now when people complain about Android doing the same, the answer is how is it wrong if Google does it, when Apple has been doing this forever.

Post reply on HN