Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

541–550 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#541
post #419

Earlier quoted context omitted.

>If you are running Android 8 or higher, a virus has been installed on your device and is silently awaiting remote activation. I have such a phone and the "virus" has not been installed to it. There is no evidence behind this claim. >with as many as 4 billion Android handsets and tablets estimated to have already been contaminated This is misleading wording. It's just as true to say that as many as 1 trillion devices…

Thanks, I appreciate the elaborate response. If you can just disable it with the activity manager or similar, I don't think Google would provide another workaround with a wait time and everything - and that only after a lot of public pressure. It's claimed to be a security feature against scams, and scammers can theoretically let you open up an adb shell and run an am command, so that would negate the safety. (That t…

>and scammers can theoretically let you open up an adb shell and run an am command

It requires a lot more steps to do this. Finding another computer, installing Android dev tools, finding a cable to connect them. In reality this adds a lot of friction.

>How do you know nothing will happen to already-installed apps and their data, when the user hasn't had time yet to go through the annoyance unlock procedure?

Extrapolation based off how play services has handled things so far and how Google has explained what will happen. Of course without looking at the actual code I can't say for 100% certainty, but from my perspective fdroid is fear mongering here as there is no evidence that supports this viewpoint. If they had evidence to back these dramatic claims up I would be less critical on them.

Re: Android Developer Verification: Threat masquerading as protection

#542

We finally live in an age when I can tell a clanker that I want an app that does something that I need, connect the phone with adb and in half an hour have a working solution for my tiny problem while knowing little about android development. This is something google should embrace, not kneecap.

Then tell the courts to stop fining them and start fining all the closed platforms.

There is a clear legal asymmetry where allowing competitors on your platform makes you liable if they complain, but blocking out everyone except for yourself is a totally ok and legally rosy way to do business.

Re: Android Developer Verification: Threat masquerading as protection

#543

Earlier quoted context omitted.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

> Also why do you need bank app on your phone? Many banks gate features like mobile check deposit behind the native app. The nearest ATM is 20 minutes away from my house, so unfortunately I consider this feature essential.

How often are you still receiving physical cheques that mobile deposit is an essential feature? I could probably count on one hand the number of cheques I've deposited or written in the past ~15 years, nor can I say I've been so desperate to access said money that I feel the need to deposit the cheque within moments of receiving it.

Re: Android Developer Verification: Threat masquerading as protection

#544
post #257

Earlier quoted context omitted.

I do think it's about Google trying to squeeze profits out of Android, but is there more direct evidence of this? Cause I always have to wonder if it's something else like KYC.

Of course Google generally tries to squeeze profits out of… whatever it does, but eh, by closing something? Google is the company that makes a million in profit from the openness of the web in the time it takes me to write this paragraph, why would that company think that closing something improves its competitive stance?

By imposing Google Play, rather than letting people use Android without any of Google's ecosystem.

About Google squeezing profits out of everything, yes but that's a kinda new thing, mostly starting 2023. They did their first mass layoffs ever, then started cutting costs and milking products more. I'm not saying they were better before or something, it's just that it was growth time before. That was also the same time they started talking about locking down Android, and even WEI.

Re: Android Developer Verification: Threat masquerading as protection

#545

Earlier quoted context omitted.

We're moving to a world where it makes sense to have one cheap locked down phone with the society mandated garbage apps on it, and another device that you use for real computing.

Yes! But as a Plan B, why aren’t we emulating Android on these devices (or is it the Secure Enclave that’s the spicy bit that these apps need)?

Fortunately Google thought about this, so government ID and banking apps usually check that they are running on a sufficiently locked down and officially blessed phone through the Play Integrity API.

This makes emulation basically impossible.

Re: Android Developer Verification: Threat masquerading as protection

#546
post #344

Earlier quoted context omitted.

Don’t know about US, but in EU you legally have to publish your address and it will be shown on the store page if your app has ads or in-app purchases.

I see. I looked at https://play.google.com/store/apps/details?id=eu.faircode.em... and saw nothing. I can see why your address is shown if you offer something for sale. Ads, that puzzles me.

> I see. I looked at https://play.google.com/store/apps/details?id=eu.faircode.em... and saw nothing.

I can see?

FairCode B.V. marcel+play@faircode.eu

Anyway, ads are just a sidechannel for purchase. There is a product advertised, someone buys it and developer gets the cut from the seller of the product. This is how ads work.

Re: Android Developer Verification: Threat masquerading as protection

#547

Earlier quoted context omitted.

An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security. It would theoretically be possible to port it to a newer kernel but that's not within the scope of LineageOS. It doesn't do that so there aren't Linux kernel updates since the kernel branch has been end-of-life for years…

> An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security. Your very rigid view of the world is so distorted to the point of being absurd. You know damn well that the vast, vast majority of spying on Android is done in userspace. A good OS that allows you to remove permissions…

An objective and accurate assessment of the available options is not absurd, its the bare minimum.

As the userspace improves, more attacks will be (and are) directed at the kernel, the linux kernel is already really bad for security, and it is absolutely vital to keep updating due to its architectural deficiencies and constant issues.

Alternative OSs on subpar hardware do not improve privacy or security. They do the opposite. Other hardware does not provide vital hardware security features, and many OEMs do not provide yellowboot or any proper way to relock the bootloader with another OS. Verified boot is very important for security.

Note that the OEM provides firmware images, an end of life device can never be secure because it lacks critical firmware updates.

This isnt subjective, this isnt rigid, and this isnt a matter of attitude. This is fact.

Re: Android Developer Verification: Threat masquerading as protection

#548

Earlier quoted context omitted.

> Also why do you need bank app on your phone? Many banks gate features like mobile check deposit behind the native app. The nearest ATM is 20 minutes away from my house, so unfortunately I consider this feature essential.

How often are you still receiving physical cheques that mobile deposit is an essential feature? I could probably count on one hand the number of cheques I've deposited or written in the past ~15 years, nor can I say I've been so desperate to access said money that I feel the need to deposit the cheque within moments of receiving it.

Checks are still common in the good ole USA.

Re: Android Developer Verification: Threat masquerading as protection

#549

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

Online banking is a thing. A heck of a lot more secure than an app on a certified android device passing play integrity but having last received security updates years ago and with a ton of privilege escalation exploits. Gov id? Just say no.

Re: Android Developer Verification: Threat masquerading as protection

#550

Earlier quoted context omitted.

You are free to make your own build of GrapheneOS with root access and have extremely reduced security. Just don’t expect support on the forums and waste everyone’s time when something happens.

"extremely reduced security" That's such a fun statement. Any security measures taken always remove agency from one person and give it to another. iOS takes my control away, and in turn gives that control to Apple. GrapheneOS takes my control away and gives that to the GrapheneOS developers. The "security" you're talking about doesn't prevent certain data from being accessed, it just changes who controls the access.…

Root access takes agency away from you and gives it to 3rd party software. It doesnt expand freedom at all, it just allows other software to abuse the user.

With a proper security model and verified boot, you can be certain you, the user, are running exactly the OS you expect to run. You can also properly revoke permissions to software and gate access as you see fit. With root, you cannot guarantee you are running what you expect and apps have to exploit much less to get root access, or just keep root access if given by the user. You cannot revoke godhood, it can just lie and say you revoked it. There is nothing enforcing any security features.

Post reply on HN