Earlier quoted context omitted.
"Apps running in those compatibility layers are much less contained with less isolation from the Linux kernel, not more." Being isolated a little bit more from the kernal offers an illusion of privacy meanwhile where you are, what you have installed, your photos and friends are available to other apps at a much higher level. I understand being able to slow down a nation state actor is important but most privacy conce…
This claim is false. Isolation and protection from the kernel is vital and it is already targeted for exploitation, and will be targeted even more as time goes on. Properly updating the kernel and improving its isolation and security is the bare minimum for even below average users, not just for high threat models. The claims you are making are unsubstantiated.
Android Developer Verification: Threat masquerading as protection
751–760 of 793 posts
Re: Android Developer Verification: Threat masquerading as protection
#752Earlier quoted context omitted.
The problem is that the usage of Android should not be at the expense of users and developers rights to choose, freedom, or privacy. With that line crossed, Android becomes an unattractive option. With an increase in mobile Linux (e.g. Mobian and others), they can and will get better. Customers and developers choice and freedom are being nullified, because there are few other options. That has to change.
Android is not at the expense of either freedom or privacy. Desktop Linux OSs come at the cost of both. It would be better to direct effort to AOSP projects as it is a much better base to build from.
Re: Android Developer Verification: Threat masquerading as protection
#753Re: Android Developer Verification: Threat masquerading as protection
#754Earlier quoted context omitted.
We've known for literally decades that that doesn't actually work, for several reasons: 1. People are conditioned to ignore warnings. There are way too many benign warnings in the world; you can't read them all. 2. Even when people wouldn't ignore them, in cases where they are being tricked by scammers it's easy for the scammer to talk people into accepting them. 3. Those sorts of warnings aren't actionable. You're i…
There's already a restriction that requires going into the settings and flipping a toggle, with a warning. I think that's enough. To be clear, enough does not mean that will stop every trojan/scam. People send Starbucks gift cards to callers claiming to be from the IRS calling to collect overdue taxes despite the obvious absurdity. Enough means that someone who doesn't know anything about computers but who reads and…
Neither approach are going to be perfect of course, but I would expect the current system to be nearly useless and the 24h delay to be very effective, and it seems like a very minor inconvenience to most users.
(All of that is caveated on this not being the start of a slippery slope, which I wouldn't bet on.)
Re: Android Developer Verification: Threat masquerading as protection
#755Earlier quoted context omitted.
The Android family of operating systems and the forks made from the android open source project are all linux distributions, and linux phones. Using desktop linux phones and trying to force that as a norm would set privacy and security back substantially. The inverse of what you suggest, which is Android with desktop linux app compatibility, would be a huge step forward, and is already much closer than you might thin…
Personally I think that Android AOSP relies too much on the support from google, that has demonstrated to happily use anti-competitive practices and not be afraid to close and centralise AOSP as much as possible. In a possible future where google decides to continue any new update of Android as closed source, will the community have enough people stepping in to support the development of AOSP? Will google allow the P…
Re: Android Developer Verification: Threat masquerading as protection
#756Re: Android Developer Verification: Threat masquerading as protection
#757Re: Android Developer Verification: Threat masquerading as protection
#758It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…