Android Developer Verification: Threat masquerading as protection
571–580 of 793 posts
Re: Android Developer Verification: Threat masquerading as protection
#572I've just stopped using smart phones. If they aren't going to give me more freedom than a dumb phone, I have no reason not to use one
Re: Android Developer Verification: Threat masquerading as protection
#573Earlier quoted context omitted.
GrapheneOS does not run anything through google services. Nowhere in the "terms" is this stated. GrapheneOS uses first party servers for all default OS connections.
[flagged]
You are conflating default OS domains with google play services. Google play services is not bundled or installed by default, and is not given any kind of privileged access when it is installed. It does not handle OS domains or functionality, and GrapheneOS does not proxy its connections in any way.
As for the default domains of the OS, most are to GrapheneOS servers, not proxies. The only default OS connection that is proxied to google is remote key provisioning.
As for non-default connections, the only google proxies are widevine, for apps that use widevine, and SUPL, for location locking. SUPL can be disabled, and GOS is considering removing SUPL if network location is effective enough, or if they can host their own SUPL server viably.
https://grapheneos.org/faq#default-connections https://grapheneos.org/faq#other-connections
These connections do NOT contain identifiable information. That is false.
Note RCS chats are also not proxied.
Re: Android Developer Verification: Threat masquerading as protection
#574If they go through with this, I will make it my life's mission for the coming months to de-google my personal life and break any dependencies on google at work. Done with this nonsense. Shouldn't take more than a month to remove the tumor. On my android phone: My own launcher My own keyboard My own sync tool for local net My own net tools to WoL some devices on my lan. My own tool to control 3 proxmox servers My own…
I still use the play store for some apps unfortunately. Also google maps, gmail, google messages (for rcs) and google fi. I'm not sure if theres anything close to the quality of traffic reporting as google maps, so it's hard to give up. The rest I will eventually move away from... Hopefully.
I have a home server with a reverse wireguard proxy for self hosting photos, calendars, etc.
I also have firefox with noscript blocking everything by default, but that's a big pain for an average person. Also it doesn't seem like firefox does a good job of anti-fingerprinting, but I haven't looked too deeply into that.
I even bought a tv that has adb access, and I removed a bunch of bloat, but it doesn't seem possible to remove the google launcher without causing huge system instability. I might just firewall it off.
There are a ton of open source alternatives to google products now, way more than the last time I tried moving away. It's time to leave.
Re: Android Developer Verification: Threat masquerading as protection
#575Earlier quoted context omitted.
How about saying no to these "mandates"?
We aren't given the choice, in many cases. For example I remember a poster here who was forced to have an Android or Apple phone because his kids' school required an app to pick up the kids after school. So his options were to get a big tech phone, or get in trouble for not picking up his kids. "Get the school to come to their senses" was, unfortunately, not an option available to him.
Re: Android Developer Verification: Threat masquerading as protection
#576Earlier quoted context omitted.
It is not an OS with bubblewrap, you can still mess up your privacy / security if you want to, that includes phishing and social engineering.
Is anything bulletproof against the user signing away their data? I think the question was whether it has any measures in this regard, not whether it's impossible to get phished
This particular attack requires getting users to sideload apps that would be rejected by the play store, and most users don't have developer mode enabled. Therefore, the cost of persuading someone to enable developer mode matters. If the procedure to enable developer mode changes from "open settings, scroll down, tap, scroll down, tap seven times" to include e.g. a 96-hour wait for developer mode to be enabled, then the cost of the attack rises by whatever it costs to stay in close contact with the victim for 96 hours, close enough to react if the victim comes close to realising the truth.
This isn't a guarantee. You can still get phished even if the phisher has to spend 96 hours in intensive contact with you. Some victims are worth that effort, maybe you are, and maybe the phisher made a mistake and puts in the effort to phish you based on the mistaken assumption that you're a millionaire.
There are also other things like that. If Google can ban the keylogger you use quicker than you can deploy new builds, for example. Still no guarantee.
Re: Android Developer Verification: Threat masquerading as protection
#577Earlier quoted context omitted.
How often are you still receiving physical cheques that mobile deposit is an essential feature? I could probably count on one hand the number of cheques I've deposited or written in the past ~15 years, nor can I say I've been so desperate to access said money that I feel the need to deposit the cheque within moments of receiving it.
Checks are still common in the good ole USA.
Re: Android Developer Verification: Threat masquerading as protection
#578Earlier quoted context omitted.
And all are useless because you can't use your mandatory bank or gov id app.
Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…
Re: Android Developer Verification: Threat masquerading as protection
#579Earlier quoted context omitted.
Apparently much of Europe is a strange banking dystopia. Perhaps the antiquity of the US banking system is finally coming in handy. I’ve still got my checkbook ready to go!
I'm still living in the Netherlands without a bank app. It's occasionally less convenient, but quite doable.
Re: Android Developer Verification: Threat masquerading as protection
#580Earlier quoted context omitted.
FWIW, I submitted an EU DMA complaint (Art 27 report) against Alphabet for unfair gatekeeping against third-party distributions like GrapheneOS via Play Integrity. More info: https://github.com/AlexAltea/blog/blob/master/posts/2026-06-... Convincing developers, especially bank and gov apps, is near impossible and won't scale well. Going after Alphabet for not meeting DMA obligations seems the easier path. Might not g…
I can tell you it has NOTHING to do with developer, but more the business/content protection people say unlocked bootloader is not secured.