Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

511–520 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#511
post #476
post #42

Earlier quoted context omitted.

Those reasons are explained clearly and openly. Ironically, your /o/OS is way less open than GOS on Google hardware.

I just want to be as far from Google as I can. I do not want to buy google hardware. Graphene does not allow me to do that.

Not only you use Android OS developed by Google, somehow you choose a less open OS distribution, exposing you MORE to Google and their shit, only because you don't want to use their hardware that happens to actually be as open as it gets, including the firmware?

Why do you choose to die on that hill? It's ridiculous!

Re: Android Developer Verification: Threat masquerading as protection

#512
post #126
post #82

Earlier quoted context omitted.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

Yet on LineageOS you're not affected. It seems you can build Android that isn't affected by Google, at least if you're willing to personally adjust the code to do what you want. You'd have to get exceptionally busy before it's not recognisable as an Android distribution anymore

How’s LineageOS compatibility these days? And besides F-droid, is there a place where mobile apps are plentiful without being full of malware?

Also, how’s isolation on LineageOS for mobile apps? I think I’m getting to the point where I’m thinking of ditching Apple again

Re: Android Developer Verification: Threat masquerading as protection

#513

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

We're moving to a world where it makes sense to have one cheap locked down phone with the society mandated garbage apps on it, and another device that you use for real computing.

How about saying no to these "mandates"?

Re: Android Developer Verification: Threat masquerading as protection

#514
post #267

Earlier quoted context omitted.

I don't have a mandatory bank or gov id app. Where are you living?

Apparently much of Europe is a strange banking dystopia. Perhaps the antiquity of the US banking system is finally coming in handy. I’ve still got my checkbook ready to go!

I'm still living in the Netherlands without a bank app. It's occasionally less convenient, but quite doable.

Re: Android Developer Verification: Threat masquerading as protection

#516
post #186
post #39

Earlier quoted context omitted.

The only reason I have not switched Graphene is because for reasons I do not understand, Graphene OS is very closely tied with Google hardware. I bought a /e/os Fairphone instead.

Pixels are consistently "third party Android builds friendly", plus GrapheneOS has a list of required security features (beyond their control): https://grapheneos.org/faq#future-devices e.g. first one in the list: > Support for using alternate operating systems including full hardware security functionality GrapheneOS wants users to lock the bootloader (≈enable Secure Boot) after install by providing user signing key…

Why don't they support Fairphone and Nothing, then?

Re: Android Developer Verification: Threat masquerading as protection

#517
post #479
post #63

Earlier quoted context omitted.

It's because only Pixel devices have proper hardware security to build anything secure on top.

Hardware security is irrelevant to me. I just want to leave Google behind me. I do not want Google's hardware.

So you chose to use Google OS, still? What the hell? Just switch to Apple!

Re: Android Developer Verification: Threat masquerading as protection

#518

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

I mean gov id app really doesn't matter (for now) you can just use you id card which is credit card sized. (For now has things might change wrt. age verification.)

But banking apps are a problem.

It's not even about the main online banking (you can use a web portal) or storing a EC digitally in you phone (convenient but really unneeded).

The problem is dump, misguided 2FA apps. E.g. credit card 2FA which already mostly required Android/iOS to work or even online banking login 2FA, transaction 2FA etc. with same requirement.

Currently for the later I can still use other methods but for a huge amount of Banks where I live you can't use a credit card (reliably) without Android or iOS as "carrier" for an 2FA app.

Re: Android Developer Verification: Threat masquerading as protection

#519

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

In a town nearby me (not really near me but within an hour's driving distance), sometimes I will see old people selling fresh fruit/vegetables in their front yard. They typically take cash, Cashapp, or Venmo. It's super convenient to be able to use Venmo in that situation. These are people I haven't met before.

Re: Android Developer Verification: Threat masquerading as protection

#520

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

All of which have beyond horrific security. GrapheneOS is the only acceptable alternative from mainstream Android.

It's a pity DivestOS has stopped.
Post reply on HN