Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

251–260 of 535 posts

Re: Android may soon restrict on-device ADB

#251
post #231
post #228

Earlier quoted context omitted.

>What's the problem here? Are you roaming all the time and that imposes a unreasonable cost on you? You want to stay totally off the grid and using VPN/tor isn't enough? It depends on a remote endpoint that can go down at any point, and depends on the company's policies present and future. It is functionally asking for permission to another party to unlock it, and that would not fall under the umbrella of ownership t…

Practically speaking none of what you brought up are actually issues because once the phone connects to the internet once, it's unlocked forever, including after relocks/flashing. It's like saying you don't "own" the stuff you bought on bandcamp, because there's a split second between when you bought the song and when you could download it, therefore "It depends on a remote endpoint that can go down at any point, and…

I don't think the bandcamp analogy applies. I may purchase a device with the intent of eventually unlocking the bootloader, but not doing so immediately for whatever reason, such as it still being supported by official updates, or the nth feature not being yet removed. Then the possibility of the option being taken away before you've exercised it remains.

Re: Android may soon restrict on-device ADB

#252
post #119

Earlier quoted context omitted.

It seems to require the user to: 1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times 2. Enable USB ADB debugging in the Developer Options 3. Establish an actual USB ADB session 4. Enable TCP/IP ADB debugging in the Developer Options 5. Unknowingly download a malware app from the official Play Store 6. Blindly click "Yes" on the permission prompt. In other words: this…

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

On multiple occasions I had trouble getting people to accept a self signed cert to show them something on a local webpage. It seems that elderly nowadays are super vary of any hacking or scams. YMMV.

Re: Android may soon restrict on-device ADB

#253

Earlier quoted context omitted.

Kimwolf exploits vulnerable Android Debug Bridge (ADB) services. Many low-cost TV boxes come "pre-infected" with proxy SDKs; Kimwolf then scans these residential proxy networks and exploits the devices within minutes as it propagates. https://www.cloudflare.com/learning/ddos/glossary/aisuru-kim... This is like saying that SSH is insecure because some device vendors install SSH, permitting root login with a default pa…

Yeah let's block port 80, too many people expose unprotected api.

This is what several cellular ISP to (block ports You can unlock it with additional free option.

Re: Android may soon restrict on-device ADB

#254

I just installed CachyOS on one of my laptops. I like Open Suse a bit more, but my vpn and a few other applications work better on Arch. Android is turning into the iOS/OSX/Win11 model. It’s not your device, you’re just renting it. You need permission to install applications, or do anything else outside of consuming subscription services. Where are the Linux phones ?

Linux phones exist but work on a limited number of devices (see PostMarketOS) or Linux primary devices like Purism or Pinephone (which I've heard are expensive). That's the primary issue, you either need to buy an expensive and potentially underpowered phone OR have one that is supported most of the way with PostMarketOS (Wifi, SIM card, GPU, etc. sometimes may not work even though the phone can boot PostMarketOS).

I personally don't have a problem with a mediocre-performance phone but it should not be expensive. Not to mention app ecosystems - there aren't a lot of Linux apps for Linux phones.

Re: Android may soon restrict on-device ADB

#257
post #225

Earlier quoted context omitted.

>What else should they have done? Use an AOSP fork like grapheneos or lineageos. Barring that, voting with their wallets and buying a HarmonyOS phone. If for whatever reason they're doing that too, there's probably more powerful forces behind this change (eg. government mandates) that won't be helped by spamming an issue tracker.

Downside is those specific forks only work on very specific devices, when there's countless great hardware in the wild with shit software.

And apparently a lot of people can't access their savings with grapheneOS. I know eventually I'm going to end up carrying 2 devices.

Re: Android may soon restrict on-device ADB

#258
post #237
post #206

Earlier quoted context omitted.

The EU shouldn't be regulating Google like this. The US should.

Why not both? Countries should be able to signal which business practices are undesirable.

Yes, laws are laws but one affects a branch, the other a root.

Re: Android may soon restrict on-device ADB

#259
post #119

Earlier quoted context omitted.

It seems to require the user to: 1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times 2. Enable USB ADB debugging in the Developer Options 3. Establish an actual USB ADB session 4. Enable TCP/IP ADB debugging in the Developer Options 5. Unknowingly download a malware app from the official Play Store 6. Blindly click "Yes" on the permission prompt. In other words: this…

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

A long time ago, I fixed Windows machines for pocket change. I can confirm some users will make bad decisions no matter what warnings they're given.

I think the impulse for an OS vendor to try to make such mistakes impossible is about as wrong as selling knives dull so people can't hurt themselves. A knife that can't cut its user is useless as a knife.

Re: Android may soon restrict on-device ADB

#260

Earlier quoted context omitted.

Follow up question: how many of those still let you log in and authorize transfers without relying on their mobile app as required second factor?

Good point. They don't. Huh, that's really worrying. My bank started requiring phone for web portal only about a few years ago. They don't allow to use an alternative MFA method. This should be made illegal.

It should be. How screwed are you if you lose your phone?
Post reply on HN