Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

501–510 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#503
post #380

Earlier quoted context omitted.

If you've accidentally become a persona non grata, then obviously because you've not exercised sufficient self-censorship. This is real already. Recently saw a petition for EU to rein in big tech (there are several initiatives advocating this). Had this nagging voice at the back of my head ... what if signing that gets your Google Account terminated. I'll leave it open to you whether I signed it. For developers relyi…

It doesn't even have to be censorship of speech. If you are wrongly charged a significant amount by either Google or Apple and their service is of no help, what would you do? Most people would weigh the options, then just eat the cost than anger them with a chargeback and lose their email/phone access. That's self-censorship financially too. What if Google reinstates their old G+ and YouTube real name policy for its…

> What if Google reinstates their old G+ and YouTube real name policy for its accounts.

G+ was a failure; people refused to provide real names. Even Facebook's "real name policy" wasn't (and still isn't AFAIK) enforced at all. At one point, I had multiple phantom Google and Facebook accounts. Now I just self-host and eschew social media.

Re: Android Developer Verification: Threat masquerading as protection

#504

Earlier quoted context omitted.

The irony is none of this is a problem in the US. We still have a ton of banks that you can use without a smartphone. Even my bank's app works fine on a rooted Android or GrapheneOS. Europeans are doing this to themselves.

> Europeans are doing this to themselves. I mean, tbf the situation was fine until the US transitioned to an autocracy, and the companies went full surveillance state evil, completely supporting the autocracy. Which is a relatively recent development. But sure. Most places here are working as fast as possible to decouple from any reliance on the US, and I would expect Norway to switch to the new EU digital ID system…

which as of now seems to depend on google/apple services being in control of your device and thus gets us half a tiny step closer to freedom at most..

Re: Android Developer Verification: Threat masquerading as protection

#505

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank.

I do not have any bank apps on my phone (it is not even connected to the Internet) and I have no problem.

Re: Android Developer Verification: Threat masquerading as protection

#506

Earlier quoted context omitted.

Over the long term, we definitely need something like Linux phones. I find it bizzarre by how little companies support this mission of Linux phones.

I don’t want to be too pedantic but Android uses the Linux kernel. Degoogled Android is basically what you want.

no, because screw all that java crap, they optimized for control and developer quantity, not for ux, customizability, performance...

Re: Android Developer Verification: Threat masquerading as protection

#507

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

We're moving to a world where it makes sense to have one cheap locked down phone with the society mandated garbage apps on it, and another device that you use for real computing.

Yes!

But as a Plan B, why aren’t we emulating Android on these devices (or is it the Secure Enclave that’s the spicy bit that these apps need)?

Re: Android Developer Verification: Threat masquerading as protection

#508

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

All of which have beyond horrific security. GrapheneOS is the only acceptable alternative from mainstream Android.

Don’t they have standard Linux security? Does my phone need to be more secure than my production web server?

Re: Android Developer Verification: Threat masquerading as protection

#509

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

App can work as digital money without card reader, maybe even free, like bitcoin.

Re: Android Developer Verification: Threat masquerading as protection

#510
post #146

Earlier quoted context omitted.

It's alright, whatever the reasons might be, but let's not pretend there are no other ways out. I'm content with newest LineageOS on my 7 year old mid-range Xiaomi. I don't mind the loss of privacy guarantee. I don't have to spend any extra 350 euros and lose the headphone jack in the process.

An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security. It would theoretically be possible to port it to a newer kernel but that's not within the scope of LineageOS. It doesn't do that so there aren't Linux kernel updates since the kernel branch has been end-of-life for years…

> An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security.

Your very rigid view of the world is so distorted to the point of being absurd. You know damn well that the vast, vast majority of spying on Android is done in userspace.

A good OS that allows you to remove permissions from apps and further isolate things does a lot for privacy.

I respect your desire to refuse supporting anything but pixels, but please don't pretend that alternate OS on old devices don't improve privacy and security.

Frankly, that kind of rigid attitude/black and white thinking might be why you find it so hard to collaborate with upstreams.

Post reply on HN