Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

21–30 of 535 posts

Re: Android may soon restrict on-device ADB

#22

Earlier quoted context omitted.

Toxic max security. Not everyone has the same threat model as you, $BIGTECHCORP.

Isn't security just an excuse to push user hostile features? Like, if security was a concern we would have simpler systems and still use 2fa devices for banks etc.

Sometimes it's truly useful featutes, but having no toggle in settings making it terrible.

Like iPhone idle auto-reboot every 3 days. After a while they added "Allow Idle Reboot" flag but it only accessible via MDM and require device wipe and for switching it to be a managed device.

Re: Android may soon restrict on-device ADB

#23
Step back to the other issue (referenced in the page*), that Google would pushing on devices something that blocks applications that do not come from play.google.com . Was it not established that Google can only push that update on devices with a google account?

* https://keepandroidopen.org/

Re: Android may soon restrict on-device ADB

#26
post #18

> Spamming the thread will only cause Google developers to lock the issue, ignore valuable community feedback, or stop sharing public updates about this change entirely. So nothing would change (they can also lock away your "valuable community feedback" because what bothers them is the criticism itself), thus feel free to express your approval

The implication in the blog post that Google developers somehow “overlooked” or “misunderstood” important use cases here, and if only they were informed about them they would reconsider, is frankly insulting.

Re: Android may soon restrict on-device ADB

#27

Of course this was bound to happen, next you're telling me people will be surprised that the 24 hour limit for side loading will turn into some indefinite time period.

It can and will most probably turn to indefinite time depending on the answer to the question "will we have a viable alternative to jump ship before that happens ?".

We don't need anything to completely capture the market, it has to be just enough to make Google hesitate or make it hard for Google to do it for legal reasons. Like how Firefox is ideally supposed to be for Chrome.

Re: Android may soon restrict on-device ADB

#30
I am generally in favor of security improvements, but I do not really see much of a benefit here. This attack vector requires both that the user enabled developer settings and that they have remote adb enabled. So, this does not seem to be a realistic attack vector for 99.9% of the users and most of the other 0.1% probably know what they are doing.

The other proposed change (to restrict access to certain interfaces or IP addresses) seems good, but why not allow developers to restrict access localhost?

It reeks of trying to block Shizuku, Canta, etc. using a way that only makes it look like a side-effect.

Post reply on HN