Live data from Hacker News

Android is almost dead – OSnews

osnews.com

21–30 of 41 posts

Re: Android is almost dead – OSnews

#21

Earlier quoted context omitted.

Ok, that's some good news. Still leaves the attestation API though. Which makes using a non-Google sanctioned device a non-viable option. Also don't forget that the source code for Android is now, since 2026, only released twice a year (i.e. every 6 months). So overall it's quite clear which direction Google is moving in. They are clamping down on the ecosystem.

> Still leaves the attestation API though. Which makes using a non-Google sanctioned device a non-viable option The attestation API isn't Google 'being evil', it exists as part of legal requirements that exists, namely for financial and banking applications. Any alternative platform that wanted similar kind of apps would almost certainly have to implement a similar system. > Ok, that's some good news The fact you tho…

What legal requirements are you referring to?

Re: Android is almost dead – OSnews

#22

I really don't see how Google will make Samsung and the big Chinese Android phone manufacturers (Xiaomi, OnePlus, ...) put this crap on their own custom Android distributions, especially because all these guys know that if they do it will have a very severe cost -- Besides Play and the Galaxy Store F-Droid is probably the third most popular distribution channel for Android apps on Galaxy devices, for example. So I do…

It's already installed on every Google-certified Android device through the Google Play Services

Re: Android is almost dead – OSnews

#23

Earlier quoted context omitted.

Ok, that's some good news. Still leaves the attestation API though. Which makes using a non-Google sanctioned device a non-viable option. Also don't forget that the source code for Android is now, since 2026, only released twice a year (i.e. every 6 months). So overall it's quite clear which direction Google is moving in. They are clamping down on the ecosystem.

> Still leaves the attestation API though. Which makes using a non-Google sanctioned device a non-viable option The attestation API isn't Google 'being evil', it exists as part of legal requirements that exists, namely for financial and banking applications. Any alternative platform that wanted similar kind of apps would almost certainly have to implement a similar system. > Ok, that's some good news The fact you tho…

> as part of legal requirements that exists, namely for financial and banking applications.

Please cite the laws or regulations you’re referring to, because I don’t think there are any.

Re: Android is almost dead – OSnews

#25

Earlier quoted context omitted.

> Still leaves the attestation API though. Which makes using a non-Google sanctioned device a non-viable option The attestation API isn't Google 'being evil', it exists as part of legal requirements that exists, namely for financial and banking applications. Any alternative platform that wanted similar kind of apps would almost certainly have to implement a similar system. > Ok, that's some good news The fact you tho…

> as part of legal requirements that exists, namely for financial and banking applications. Please cite the laws or regulations you’re referring to, because I don’t think there are any.

PCI-DSS (enforced by banks/payment processors) means the EMV token store on your Android phone must be in an isolated uncompromised location (usually the TEE).

If your phone is rooted or has an unlocked bootloader then it's possible that trusted store is no longer secure or can be snooped on by a third party. Given Google Wallet/Pay handles EMV tokens and stores them on the phone, it has to pass PCI-DSS before banks will allow it.

This is the biggest reason why Google tries as much as possible to block Google Pay on rooted/unlocked devices. If a device fails compliance (a rooted phone certainly does), as far as banks are concerned it's not safe.

But people just find it easier to say "Google is Evil".

You also have the EUs Payment Services Directive (so a law) which require strong customer authentication, rooted devices can also fail up here. If anyone else than the user is able to unlock the screen (and thus authenticate a payment), you've failed the Payment Services Directive.

Re: Android is almost dead – OSnews

#26

I really don't see how Google will make Samsung and the big Chinese Android phone manufacturers (Xiaomi, OnePlus, ...) put this crap on their own custom Android distributions, especially because all these guys know that if they do it will have a very severe cost -- Besides Play and the Galaxy Store F-Droid is probably the third most popular distribution channel for Android apps on Galaxy devices, for example. So I do…

pixel users can lean on GraphineOS, for now

Re: Android is almost dead – OSnews

#27
post #12

Earlier quoted context omitted.

Oh no, hyperbole! How ever will you recover?! This has the same energy as “I lost a lot of sympathy for these political protests when they mildly inconvenienced me on my commute.” If you don’t agree with something, just say so. You don’t need to hide behind fake pearl clutching.

It does as much good for the cause as those climate activists who glue themselves to motorways and block ambulances.

Martin Luther King wrote about that attitude:

> First, I must confess that over the last few years I have been gravely disappointed with the white moderate. I have almost reached the regrettable conclusion that the Negro’s great stumbling block in the stride toward freedom is not the White citizens’ “Councilor” or the Ku Klux Klanner, but the white moderate who is more devoted to “order” than to justice; who prefers a negative peace which is the absence of tension to a positive peace which is the presence of justice; who constantly says “I agree with you in the goal you seek, but I can’t agree with your methods of direst action” who paternalistically feels that he can set the timetable for another man’s freedom; who lives by the myth of time and who constantly advises the Negro to wait until a “more convenient season.” Shallow understanding from people of good will is more frustrating than absolute misunderstanding from people of ill will. Lukewarm acceptance is much more bewildering than outright rejection.

Certainly, the stakes are lower in this case, but the claim that the use of hyperbole causes you to "lose a lot of sympathy" is an obvious excuse for a position that you would have taken anyway.

Re: Android is almost dead – OSnews

#29

Earlier quoted context omitted.

> as part of legal requirements that exists, namely for financial and banking applications. Please cite the laws or regulations you’re referring to, because I don’t think there are any.

PCI-DSS (enforced by banks/payment processors) means the EMV token store on your Android phone must be in an isolated uncompromised location (usually the TEE). If your phone is rooted or has an unlocked bootloader then it's possible that trusted store is no longer secure or can be snooped on by a third party. Given Google Wallet/Pay handles EMV tokens and stores them on the phone, it has to pass PCI-DSS before banks…

> You also have the EUs Payment Services Directive (so a law) which require strong customer authentication, rooted devices can also fail up here.

Plain wrong. PSD3 does not apply to "digital wallets" [1] ("This Directive also does *not* cover, in its scope, the provision of technical services including processing or the operation of digital wallets.").

> If your phone is rooted or has an unlocked bootloader then it's possible that trusted store is no longer secure or can be snooped on by a third party.

That's also wrong. Even with a rooted phone you can't mess or snoop on data in the trusted execution environment. The isolation is enforced in hardware.

> If a device fails compliance (a rooted phone certainly does), as far as banks are concerned it's not safe.

If this were about security, then why allow phones which have known security vulnerabilities (and no longer receive updates) to pass the Google Play Integrity API tests?

> But people just find it easier to say "Google is Evil".

Apparently you also find it easy to forgo about the history of Android. Like how Google introduced the Google Play API about a decade ago and did a "Embrace, extend, extinguish" thing. You also conveniently stay silent on things like the fact that Google now only releases the Android sources only twice a year.

[1] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52...

Re: Android is almost dead – OSnews

#30

Earlier quoted context omitted.

PCI-DSS (enforced by banks/payment processors) means the EMV token store on your Android phone must be in an isolated uncompromised location (usually the TEE). If your phone is rooted or has an unlocked bootloader then it's possible that trusted store is no longer secure or can be snooped on by a third party. Given Google Wallet/Pay handles EMV tokens and stores them on the phone, it has to pass PCI-DSS before banks…

> You also have the EUs Payment Services Directive (so a law) which require strong customer authentication, rooted devices can also fail up here. Plain wrong. PSD3 does not apply to "digital wallets" [1] ("This Directive also does *not* cover, in its scope, the provision of technical services including processing or the operation of digital wallets."). > If your phone is rooted or has an unlocked bootloader then it's…

> Even with a rooted phone you can't mess or snoop on data in the trusted execution environment

A rooted phone can have a modified runtime/kernel that can inject code into whatever processes it sees fit, including Google Pay.

Which can expose information being sent to and read from the TEE by the app.

> Plain wrong. PSD3 does not apply to "digital wallets" [1] ("This Directive also does not cover, in its scope, the provision of technical services including processing or the operation of digital wallets.").

The legislation still applies to the bank behind Google Pay.

Post reply on HN