Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

231–240 of 535 posts

Re: Android may soon restrict on-device ADB

#231
post #228
post #220

Earlier quoted context omitted.

>Not before connecting it to the internet, even Pixels will go through hundreds of megabytes of data before allowing you to unlock them (see 0). What's the problem here? Are you roaming all the time and that imposes a unreasonable cost on you? You want to stay totally off the grid and using VPN/tor isn't enough? >Also, will Google let me browse the web with "my own OS" without their proprietary services installed on…

>What's the problem here? Are you roaming all the time and that imposes a unreasonable cost on you? You want to stay totally off the grid and using VPN/tor isn't enough? It depends on a remote endpoint that can go down at any point, and depends on the company's policies present and future. It is functionally asking for permission to another party to unlock it, and that would not fall under the umbrella of ownership t…

Practically speaking none of what you brought up are actually issues because once the phone connects to the internet once, it's unlocked forever, including after relocks/flashing. It's like saying you don't "own" the stuff you bought on bandcamp, because there's a split second between when you bought the song and when you could download it, therefore "It depends on a remote endpoint that can go down at any point, and depends on the company's policies present and future" and "It is functionally asking for permission to another party".

Re: Android may soon restrict on-device ADB

#232

Earlier quoted context omitted.

> many banks in the UK no longer offer a web portal Same in Norway.

Is it that dire? I'm in with DNB and Nordea and they both have functioning netbanks. But I don't know how the rest are. I've been getting by with a bankid codebrick and web browser access (although Nordea and DNB apps work fine on GrapheneOS).

> I'm in with DNB and Nordea and they both have functioning netbanks.

And both are banks I'd never want to associate with. I would have used Sbanken before the DNB buyout (and I even did for a bit!), but now that's of the table too.

There are a few more options, but many are just worse if you look at their fees and interest rates.

I've been very happy with Bulder. The only thing they're missing is a web portal. The fact that they're missing that annoys me greatly, but they've been good to me in every single other aspect, so it's hard to be dissatisfied (especially compared to the other banks where I and others have been burned). Their app works fine on de-Googled Android, and so long as that's true, I can live with my choices.

Re: Android may soon restrict on-device ADB

#233
post #192

If they stop sideloading and adb why should I even stay with Android?

adb is not being stopped, the bug is talking about a niche way folks use it without a secondary device. There is also no conclusion from the bug on what action will actually be taken.

Re: Android may soon restrict on-device ADB

#235
post #153
post #145

Earlier quoted context omitted.

> In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. Have you ever worked with someone who barely knows how to use a mobile phone? They will hand their phone over to someone they barely even know to do something they don't understand. They will follow instructions from a stranger over the phone, without understanding what the phone is…

Can we freaking sell them dumbphones, then, and stop destroying portable computers for everyone else with that excuse? Which incidentally is often just a pretense for other motives? If computers have suddenly become so dangerous for normal people, and they want smartphones nonetheless, add to them a dumb-mode encouraged at the initial setup, and requiring some third party assistance to turn it off once enabled..! (an…

Lots of dumb phones are trojaned on a firmware level. Trojans are different, but in general they allow the third-party (malware author) to accept SMS and forward them over internet. This is used to register accounts on a services which requires a phone number.

Here's my article about that from 2021. It's for the devices sold in Russia, but this issue is worldwide: https://habr.com/ru/articles/575626/

And here's more detailed research of two particular devices: https://notes.valdikss.org.ru/trojan-digma/

Re: Android may soon restrict on-device ADB

#236
post #70
post #32

Earlier quoted context omitted.

They dont care about security; only about control. There are hundreds of millions of outdated Android devices that all Google attestation systems consider secure even though they all running Linux kernel that was never ever updated and can be rooted by anything. Now try to install your own firmware on them without said outdated kernel... How dare you.

Technically the security works, just for their threat model. An exploit would need root and root means you likely cannot pass attestation AFAIK. The fact that this same exploiter can download all your contacts photos and texts is immaterial to, say, Disney, who want attestation only to prevent ripping of their content.

No it doesnt actually work because its possible to do privilege escalaction without tampering with firmware or filesystem or triggering other markera. OS will be practically rooted while passing attestation just fine.

Only things attestation do is security theater and messing up people ability to use software of their choosing.

Re: Android may soon restrict on-device ADB

#237
post #206

Earlier quoted context omitted.

Google just got hit by yet another record antitrust fine by the EU [1]. But as long as they see these fines as cost of doing business, nothing will change. Especially if it always takes almost a decade to push this through the judicial system. Their net income last year alone was $130 Billion. [1] https://www.reuters.com/world/eu-top-court-dismisses-google-...

The EU shouldn't be regulating Google like this. The US should.

Why not both? Countries should be able to signal which business practices are undesirable.

Re: Android may soon restrict on-device ADB

#238
post #73

Earlier quoted context omitted.

It would break exactly 0 apps because none of the apps should be using this API to access your private data and phone call audio.

So why do Google Play Services, etc. have full privileged access to a phone, including private data and phone call audio, but the user doesn't? It is tech feudalism - you don't own anything anymore, you just get to live on the digital land of a bunch of ~trillion dollar companies. At least, that is the goal. IMO either everyone gets access at the user's discretion or Google has to sandbox their own GMS services as we…

  Quod licet Iovi, non licet bovi
And yes, bovi is as in bovine

Re: Android may soon restrict on-device ADB

#239
post #221
post #192

If they stop sideloading and adb why should I even stay with Android?

TINA - https://en.wikipedia.org/wiki/There_is_no_alternative

And people wonder why we're in the rut that we are.

Sidenote: The poster in that article is insane to me. Imagine advertising yourself as the only alternative. I'd rather vote for an empty seat than for someone who's that arrogant! Then again, I don't really have to imagine it, since there have been quite a few politicians within the last 10 years who have functionally done that same, just without actually saying those words out loud.

Re: Android may soon restrict on-device ADB

#240
post #225

Earlier quoted context omitted.

Google pushes a new feature to Android where phones wake up at 2:22 AM every night to play a blood-curdling scream at maximum volume, regardless of settings. An issue is created and gets assigned, into which Google employees regularly butt in to explain the feature exists to keep users safe from night break-ins. Nothing changes. People have to start modifying their lives around this problem—most have to shut off thei…

>What else should they have done? Use an AOSP fork like grapheneos or lineageos. Barring that, voting with their wallets and buying a HarmonyOS phone. If for whatever reason they're doing that too, there's probably more powerful forces behind this change (eg. government mandates) that won't be helped by spamming an issue tracker.

Downside is those specific forks only work on very specific devices, when there's countless great hardware in the wild with shit software.
Post reply on HN