Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

561–570 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#561
post #233

Btw. This whole debacle made me to stop installing any Android updates. I've done my best to avoid installing even the security updates, so my diabetes apps continue working in the future. I really need to take the time and go with Graphene OS in this device. My bank N26 kind of still allows it, but they made it harder and harder to use with certain custom checks. Looks like in the future I need a separate banking ph…

I have an old $70 test device with stock Android/Google that hasn't seen security updates in half a decade yet all banking apps, electric car charging, Google services, you name it, work absolutely fine. Meanwhile the daily driver phones of my privacy-aware family members running up-to-date Lineage or Graphene OS with recent kernels and frequent updates constantly run into apps refusing to work for "security" reasons…

To pass MEETS_STRONG_INTEGRITY a device needs to have a security patch within the last year. Most apps don't check for storng integrity, though.

Re: Android Developer Verification: Threat masquerading as protection

#562

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

Which phones are supported by which of these operating systems? And can you provide some relevant links?

- https://sailfishos.org - https://docs.sailfishos.org/Support/Supported_Devices

They have few devices of their own (new one coming out this October) and they officially support many Sony Xperia devices. There are also many community ports.

- https://ubuntu-touch.io - https://devices.ubuntu-touch.io

They have 33 supported devices, some are being shipped directly with the OS or have an official agreement with the phone maker, while others are community ports. Even if community ports, they all seem to have high hardware support, and is all very clearly documented.

- https://puri.sm/products/librem-5 / https://pureos.net

They focus just on the Librem 5, and not everything is fully working but as I said they prioritised privacy and FOSS. The phone is old but the OS is still in active development.

- https://postmarketos.org - https://wiki.postmarketos.org/wiki/Devices

They focus on supporting as many devices as possible, currently they don't have "main" devices they support, but they plan to. They too have a very clear documentation on features available for each device.

- https://mobian.org - https://wiki.debian.org/Mobian/Devices

They target devices made with the intent of running linux, but also have a few ports to android devices.

---

You'll notice that there are a few devices that are more "linux-friendly" and that are supported by many of these OSes. Phones from Pinephone and Fairphone being the main ones.

Re: Android Developer Verification: Threat masquerading as protection

#563

Earlier quoted context omitted.

Pragmatically speaking, I doubt that the percentage of users currently choosing Android over iOS for this reason would add up to even 1%. Android dominates worldwide by and large because of cost, and unless Apple pulls another Neo this shall remain regardless of how locked down they make it.

An older iPhone is already better than most new cheaper Android phones.

Many people disagree.

Re: Android Developer Verification: Threat masquerading as protection

#564

Earlier quoted context omitted.

[flagged]

GrapheneOS does not run anything through google services. Nowhere in the "terms" is this stated. GrapheneOS uses first party servers for all default OS connections.

[flagged]

Re: Android Developer Verification: Threat masquerading as protection

#565

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

This bogus "justification" for not considering any alternative, non-corporate mobile OS on any phone makes no sense

HN commenters will not let it go

Most HN readers have multiple computers, including multiple phones

There is no requirement that one has to run a closed-source banking or government ID app on the same phone as open-source apps, e.g., apps from F-Droid

And it ignores countless people who do not and will never use banking or government ID apps

I tested a banking app for depositing a paper cheque and it was incredibly convenient. At the same time, the app tried to make a plain, unencrypted HTTP connection to www.google.com

I blocked these connection attempts and the app still worked, with plenty of phoney error warnings. I would not be comfortable leaving one of these apps installed on a phone that's charged, powered on and has a cinnection to the internet

Every user is different but it makes no sense to argue on HN of all places that these closed-source banking apps are essential for everyone. Many HN users are never going to use these apps, and rightfully so

Re: Android Developer Verification: Threat masquerading as protection

#566

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

Usability-wise, they are no match for Android and iOS—or even versions of them from five years ago.

UI/UX is costly, and most FOSS projects cannot get it right without massive investments from enterprises (e.g., Red Hat's UX designers heavily contributed to GNOME) or startups (e.g., Zed, Element, Bluesky).

Projects without that backing are mostly unusable, at least from a Gen Z perspective.

Re: Android Developer Verification: Threat masquerading as protection

#567

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

That's a nice digital content you have there. It would be a shame if something happened to it...

Re: Android Developer Verification: Threat masquerading as protection

#568

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

I really wish SailfishOS supported more hardware. I love sony phones, but the sony phone I love the most isn't supported despite being nearly identical to a supported one

Re: Android Developer Verification: Threat masquerading as protection

#569
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

> Linux based mobile OS So, Android?

yet another reason why the distinction between Linux and GNU/Linux is important

Re: Android Developer Verification: Threat masquerading as protection

#570

Earlier quoted context omitted.

> An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security. Your very rigid view of the world is so distorted to the point of being absurd. You know damn well that the vast, vast majority of spying on Android is done in userspace. A good OS that allows you to remove permissions…

I don't think its rigid at all. Its important to continue to be able to receive security updates. If a device can't, mostly because qualcomm/firmware no longer wants to bother 6 months after release, it's DoA. We don't go around telling people that it's OK to still run Windows XP for the same reason. Why is/should mobile be any different? Stop being OK with manufacturers having garbage support. It's completely unacce…

The dichotomy here isn't grapheneos or updates, it's grapheneos or android.
Post reply on HN