Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

461–470 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#461
post #454

Earlier quoted context omitted.

"extremely reduced security" That's such a fun statement. Any security measures taken always remove agency from one person and give it to another. iOS takes my control away, and in turn gives that control to Apple. GrapheneOS takes my control away and gives that to the GrapheneOS developers. The "security" you're talking about doesn't prevent certain data from being accessed, it just changes who controls the access.…

>If the user cannot be trusted with their own data, then there is no solution anyway. They'll just tell their private data to a scammer on the phone instead. Security isn't binary. Putting up barriers makes it harder for scammers to steal money. There's a reason why they exploit malware to steal money, rather than asking their victims to send them crypto directly.

> There's a reason why they exploit malware to steal money, rather than asking their victims to send them crypto directly.

The vast majority of scams literally work by them asking their victims to buy cryptocurrency or gift cards directly. Malware is exceedingly rare.

You know what would really help against scams? Avoid putting people in situations where they need to decide right now or they'll face punishment.

Modern society has created far too many situations where people need to react without being able to think through the consequences.

The only reason scams work is because there are enough actual situations with unnecessary life-or-death decisions.

Re: Android Developer Verification: Threat masquerading as protection

#462

Android developer verification program, together with recent reCAPTCHA push [1], and Manifest v2 force depreciation on chrome [2], make one thing crystal clear. When companies like GOOGLE talks about things in the name of "your security", it's a sign that they want you to sacrifice your own things, e.g., privacy, freedom, etc., for their own security. And if you trust them and show your consent by doing nothing, you…

Article got developer verification completely wrong. The point of developer verification is to be able to install apps outside the app store without warning, which brings Google Android builds in compliance with the antitrust ruling. Third party Android builds can choose other trust roots or disable ADV completely and require warnings for everything because they are not subject to the judgment. Separately, the proces…

That's only the consumer side of it though. As the post states:

> Should a developer[...] elect to register themself with Google as a “verified” developer, they should expect to sign up for an account and pay a fee, surrender detailed personal information and upload government-issued identification, and then proceed to register the identifiers and signing keys for all the apps they intend to distribute (now or ever).

Those are big impediments to open development. The agreement developers sign states:

> 6.5 If You violate any of the Terms or if You distribute malware or other harmful applications, Google may terminate Your access to the ADC…

But they don't actually define "malware" anywhere in the document. Search HN if you want to hear horror stories about how google handles loose definitions and peoples' accounts.

Re: Android Developer Verification: Threat masquerading as protection

#463
I wanted to use an alternative mobile OS, but they only support expensive devices like Pixels or outdated models. So I am planning to port some open Android variant. Obviously, all Google Services will be removed and most proprietary apps too. I also want to be able to manually edit permissions and remove Internet access from most of the apps, even open source. It is inconvenient that Android actually has "Internet" permission but doesn't allow the user to revoke it.

I do not need Google Play (a collection of spyware, covertly collecting Wifi points and cell towers location in my country and sending them abroad), I do not need bank apps (I have a laptop for that) so I guess I will be fine. Obviously there will be no developer verification on my device as well, and I mostly use apps from F-Droid anyway.

Good thing about F-Droid is that they build apps themselves and you can always get the sources - unlike Google Play and Apple Store that provide no sources and unlike PyPi/NPM which allows sources to not match the binary distribution.

Re: Android Developer Verification: Threat masquerading as protection

#464
post #21

Earlier quoted context omitted.

Apple's policies were established when you purchased the phone. Apps come through registered developers and their vetting. Google has changed the game on something you already own. I'm sure their lawyers have done their homework, but in some jurisdictions this is certainly actionable.

They already lost a lawsuit and were fined a hundred billion dollars in the EU for locking down Android. Maybe they think since they already lost once, they can't lose again.

This is the remediation to that case and therefore has already been run by the EU. Notably, Apple did not get fined for the way they run their ecosystem which is far more locked down.

Re: Android Developer Verification: Threat masquerading as protection

#465
If they go through with this, I will make it my life's mission for the coming months to de-google my personal life and break any dependencies on google at work. Done with this nonsense. Shouldn't take more than a month to remove the tumor.

On my android phone:

My own launcher

My own keyboard

My own sync tool for local net

My own net tools to WoL some devices on my lan.

My own tool to control 3 proxmox servers

My own tool that parses groceries slips

My own tool that keep tracks of my vehicles events/lifecycle/purchases etc.

If they break my launcher/keyboard and my ability to use my phone in my customized way, they will NEVER see me as a client again. None of these apps are in the Play Store, they are signed with my own signing keys, which have never been uploaded to google, in fact, no google account is linked to these apps. These apps are also privacy-oriented (even the keyboard, I ship a 1mb dictionary with and it learns my own words, never transmits anything).

I will not give google my ID , neither Persona or anyone else. I'm very happy to go back to using bank card + chip + pin than use google wallet. Trust me I will walk away. I already move 4 family members off of Windows in the last 2 years, I will get them off google too.

Re: Android Developer Verification: Threat masquerading as protection

#466

Earlier quoted context omitted.

> We need corporations and governments to stop locking down and gatekeeping vital software to closed ecosystems. If you can't get the government to do this for you in Norway the US has very little hope currently. We need some standard of minimal digital accessibility. Too much of our lives mediated by digital interactions with capricious systems.

The irony is none of this is a problem in the US. We still have a ton of banks that you can use without a smartphone. Even my bank's app works fine on a rooted Android or GrapheneOS. Europeans are doing this to themselves.

> Europeans are doing this to themselves.

I mean, tbf the situation was fine until the US transitioned to an autocracy, and the companies went full surveillance state evil, completely supporting the autocracy. Which is a relatively recent development.

But sure.

Most places here are working as fast as possible to decouple from any reliance on the US, and I would expect Norway to switch to the new EU digital ID system currently in development.

Re: Android Developer Verification: Threat masquerading as protection

#467
post #236

Earlier quoted context omitted.

The resason is that only Google bothers to put enough hardware security features to build software on top that allows to make a really secure device that blocks tampering.

That's not a reason. When the hardware doesn't have those "security features", then don't "really secure", just run without being "really secure". I never treat my (Android) phone as secure anyway.

Security is GrapheneOS's raison d'être. If you don't want security, you can run another Android build that does run on the hardware you have.

Re: Android Developer Verification: Threat masquerading as protection

#468
post #69
post #11

Earlier quoted context omitted.

I thought the same thing but he apparently has a point. The stated purpose covers only a tiny sliver of the capabilities. The agreement points to the TOS where it (last time I looked) says service may be terminated at any time without stating a reason. Nothing guarantees it won't be used for things other than security. And finally he has a point where it also doesn't really do much for security. If we ask their fine…

I'd usually say it'd be far fetched but I can totally see Google banning developers and removing their apps for political reasons, where some lobbying group bombs them with emails because with this they're explicitly saying they're now choosing who gets to be in or out, there's no way for them to say we can't do anything about it I do think this would improve security, but I also think it's sort of a Trojan horse to…

Banning it from the app store is different from banning from distributing their app on any surface. It's closer to Walmart choosing to not carry a product vs the government saying no one may carry that product. Of course both can happen for political reasons but generally the latter is a bigger hammer applied less often.

Re: Android Developer Verification: Threat masquerading as protection

#469
post #285

Earlier quoted context omitted.

> And you’ll never reach a human to sort it out. Unless you blog about it angrily enough that you somehow make it to the HN front page and some insider sees it and solves the problem for you. Getting my own domain and setting up email on it is one of the best things I've ever done.

About to go down that route as well, just need to find a email provider with ideally servers in the EU

Infomaniak (swiss) has a decent deal of a couple of free mailboxes with any domain you own through them. The webmail client kinda sucks but I just sync it with native clients. Using username:password for SMTP feels pretty weak tho they don't have Oauth2 support. lol now I'm talking myself out of it but it's worked great for years.

Re: Android Developer Verification: Threat masquerading as protection

#470

Earlier quoted context omitted.

Gotta move to the EU and sue based on right to be forgotten

Suing a company will almost certainly result in them exercising their right to not do business with you and shutting down all your accounts - exactly what OP was trying to avoid

In some EU countries - it could be seen as retaliation if you sue for something and then Google closes your accounts, some EU countries have strong protections here.

More importantly for Google though it's under extra scrutiny under the DSA at the EU wide level - so it doesn't have a clear right to not do business, it has to do terminations correctly with clear reasons set out in terms, there are mandatory notice periods etc.

Post reply on HN