Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

391–400 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#391
post #252

Earlier quoted context omitted.

Google has been attempting to license the right to write. There are a lot of poor people, mostly brown people, who do not have the ability to get one of these licenses. Some of them are feeding themselves with their ability to write, and Google is literally stealing that food from their mouths.

[flagged]

This is a textbook “bad faith” argument.

Just because someone is part of a particular demographic doesn’t mean they are suddenly incapable of harming them.

Re: Android Developer Verification: Threat masquerading as protection

#392
post #339
post #316

Earlier quoted context omitted.

How do you explain that all the scammers I've entertained used apps that are already on the store?

I think there's a misunderstanding here. The attack in question doesn't use apps on the store, or even any attempt to get them on the store. There are also other attacks, but the one that prompted this change uses social engineering to get people to tap the build number seven times, sideload something and get a keylogger that then picked up their banking details and used them. Several governments raised the issue, Go…

But it is suspicious they want to defend vs attacks that don't happen while doing absolutely nothing to stop the attacks that do happen. Seems like security isn't a goal here?

(I didn't get scammed, I sometimes am curious on what the scam is so i lead them on a bit)

Re: Android Developer Verification: Threat masquerading as protection

#393

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

To avoid this, I tried to close my Google Play Developer account. A decade ago I published a free app on it, which was online for half a year. It was to no avail. They will not close the account. I received only automated responses about bringing my old app into compliance with current policy, to then transfer it to another developer account. Only then would Google graciously allow me to close my Developer account. M…

really? I have to keep making useless updates (just a version number bump) on one of the accounts i manage, because i keep receiving thread emails every 6 months that the developer account sees no activity and if i don't do anything they will remove and close.

that app is a done project and need only to be udpated when the target SDK becomes too old for the play store

Re: Android Developer Verification: Threat masquerading as protection

#394

Earlier quoted context omitted.

But they did. EU formally allows all these measures by Google in the name of "security" as described in Digital Markets Act Art. 6 (4) fourth paragraph. https://www.eu-digital-markets-act.com/Digital_Markets_Act_A...

They're allowed to do it "to the extent that they are strictly necessary and proportionate ... provided that such measures are duly justified". It remains to be seen whether the EU decides that this measure is strictly necessary, proportionate and duly justified. They sometimes do the right thing but I'm not getting my hopes up.

EU will likely want something like this for ChatControl (or whatever it's called in its current draft iteration) enforcement anyway. And Google will no doubt be happy to have its highly paid lobbyists testify on how it will help catch child predators and terrorists.

Re: Android Developer Verification: Threat masquerading as protection

#395

Earlier quoted context omitted.

So it doesn't actually do anything to give control of the device back to the user? One of the core tenets of truly free software is that I as user must be able to run, access, edit, and view everything .

You are free to make your own build of GrapheneOS with root access and have extremely reduced security. Just don’t expect support on the forums and waste everyone’s time when something happens.

"extremely reduced security"

That's such a fun statement.

Any security measures taken always remove agency from one person and give it to another.

iOS takes my control away, and in turn gives that control to Apple. GrapheneOS takes my control away and gives that to the GrapheneOS developers.

The "security" you're talking about doesn't prevent certain data from being accessed, it just changes who controls the access.

If the user cannot be trusted with their own data, then there is no solution anyway. They'll just tell their private data to a scammer on the phone instead.

There is no solution against a user that wants to give their own data away, but if you try to prevent that, the only thing you'll accomplish is destroying general purpose computing.

Re: Android Developer Verification: Threat masquerading as protection

#396
post #185

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

What happens if you "accidentally" become persona non grata with both Google and Apple? If you want to participate in the society, you will forever have to resort to shady tactics. Shady can be defined something as arbitrary as using GrapheneOS. A temporary workaround like using alternatives like GrapheneOS for those affected will only delay the inevitable but it doesn't stop it at all.

[deleted]

Re: Android Developer Verification: Threat masquerading as protection

#397
post #385

Why not replace F-Droid with a catalogue of links to open-source apps hosted in play store?

Most F-Droid apps are built from source. A link to Google Play may point to a newer version that has changed and could contain undesirable behavior.

Re: Android Developer Verification: Threat masquerading as protection

#398

> How long before they designate all ad-blocking software as malware, block installation on all Android certified devices worldwide, and permanently designate all developers of this class of software as malware creators? Classic slippery slope fallacy. https://en.wikipedia.org/wiki/Slippery_slope History shows that when a "slope" appears... regulation steps in, technology evolves to solve the problem, or the culture…

I don't know which timeline you live in, but in mine I've stopped counting how many slippery slopes ended up exactly where the critics said they would.

Re: Android Developer Verification: Threat masquerading as protection

#399

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…

[deleted]

Re: Android Developer Verification: Threat masquerading as protection

#400

Earlier quoted context omitted.

[flagged]

This is a textbook “bad faith” argument. Just because someone is part of a particular demographic doesn’t mean they are suddenly incapable of harming them.

You were so close to realizing class is the only thing that matters. But thankfully a good western education make that thought impossible.
Post reply on HN