Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

281–290 of 536 posts

Re: Android may soon restrict on-device ADB

#281
post #119

Earlier quoted context omitted.

It seems to require the user to: 1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times 2. Enable USB ADB debugging in the Developer Options 3. Establish an actual USB ADB session 4. Enable TCP/IP ADB debugging in the Developer Options 5. Unknowingly download a malware app from the official Play Store 6. Blindly click "Yes" on the permission prompt. In other words: this…

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

Well the messaging we’re told is that the google play store exists for safety - such an app would never exist on there.

Of course this isn’t true, the play store, and yes even the apple App Store to a lesser extent, is riddled with malware.

But what this demonstrates is that, clearly, Google doesn’t care too much about security or safety. It’s a pretense, not a goal. If it was a goal, they’d dump money into fixing the play store, but they won’t and they don’t.

So, we should be highly skeptical when they say something is for “safety” and “security”. At this point, it’s a lot like saying something is for “national security”.

Re: Android may soon restrict on-device ADB

#282
post #220

Earlier quoted context omitted.

>Not before connecting it to the internet, even Pixels will go through hundreds of megabytes of data before allowing you to unlock them (see 0). What's the problem here? Are you roaming all the time and that imposes a unreasonable cost on you? You want to stay totally off the grid and using VPN/tor isn't enough? >Also, will Google let me browse the web with "my own OS" without their proprietary services installed on…

> Having control of something isn't the same as third party services granting you access. Many online games only supports windows with secureboot and TPM enabled, but that would be a silly excuse to say that you don't really "own" your PC. Your example is about one developer's decision, which is not really what we're talking about. The damage goes way up when you start talking about an arbitrary number of application…

>Your example is about one developer's decision, which is not really what we're talking about.

Is it? Many games outsource their anticheat to a third party developer, similar to how many apps outsource their app security to play integrity.

>The damage goes way up when you start talking about an arbitrary number of applications. A more apt analogy is, what if you couldn't install any applications except through the Windows Store?

What about (nearly) all the games that only support windows, and worse yet, are exclusives on one distribution platform? Yes, there's wine/proton and cracks, but that's a "solution" in the same way that using a modded apk to get past the play integrity requirements is a "solution".

Re: Android may soon restrict on-device ADB

#283
post #224

Does anyone have any doubt left that we're headed for a future where you need a government ID to use any computing device, and only allowed to do government-approved tasks and view government-approved content? Not a rhetorical tinfoil question: Does anyone still believe there's some hope for personal freedoms?

> Does anyone still believe there's some hope for personal freedoms? as long as such personal freedoms gives users the ability to skirt the profit motives of companies making these devices, there will always be a force to try restrict it. The internet, as it has been, is quite an anomaly, but inevitably, power that the people have gets usurped one way or another. It's just a matter of time.

What's ironic is that these news are something you'd expect to hear from China or former Soviet countries. But frogs still believe that "putting America in the same sentence as Russia" is stupid

Re: Android may soon restrict on-device ADB

#284

Earlier quoted context omitted.

Following this logic, shouldn't we just ban smart phones for everyone then? If we need to dumb down all technology to the absolute lowest level, we should probably ban computers or at least require an official government-controlled license to get access to one. Is this a world you want to live in? Me neither.

> ban computers or at least require an official government-controlled license to get access to one People seem to be ok with needing a license to operate a motor vehicle and those are far less dangerous.

Cars are far more dangerous and they kill people. It’s the number one cause of death for some demographics in the US.

Re: Android may soon restrict on-device ADB

#285
post #27

Earlier quoted context omitted.

It can and will most probably turn to indefinite time depending on the answer to the question "will we have a viable alternative to jump ship before that happens ?". We don't need anything to completely capture the market, it has to be just enough to make Google hesitate or make it hard for Google to do it for legal reasons. Like how Firefox is ideally supposed to be for Chrome.

Many alternative AOSP-based systems work fine today and do not have the new Android Developer Verifier (wow, already rolled out to 500M+ devices [1], though still dormant). To be honest, it is quite scary that Google is able to remotely roll out an app like that to all GMS Android phones. Of course, we all knew that, but it highlights again that Google can remotely take away functionality that you had before, brick y…

> To be honest, it is quite scary that Google is able to remotely roll out an app like that to all GMS Android phones.

Are any commercial mobile phone vendors not able to do such a thing? Do remember that this giant kerfuffle is all over the seeming preparation for the apparent removal of a developer feature that iPhones have never had at all.

Re: Android may soon restrict on-device ADB

#286
post #214

There's only one reason for anyone, or for me, at least, to choose Android, and it's the only reason I've consistently chosen Android from the very first Google Developer Phone: It's more open. So, they don't want me to even have that one reason to keep choosing Android, I guess.

the question isn't whether you still have a reason to choose android - the question is what alternative do you have but android (or iOS).

If my phone is going to be locked down anyway, I'm choosing the platform that at least pairs with my AirPods properly and doesn't get me weird looks at social events.

Google is really stretching their goodwill with this one. The ability to sideload and debug my phone is the only marginal benefit to these janky Java relics. If that's gone, no reason not to switch to a wholely better platform.

Re: Android may soon restrict on-device ADB

#287

Earlier quoted context omitted.

Is it that dire? I'm in with DNB and Nordea and they both have functioning netbanks. But I don't know how the rest are. I've been getting by with a bankid codebrick and web browser access (although Nordea and DNB apps work fine on GrapheneOS).

> I'm in with DNB and Nordea and they both have functioning netbanks. And both are banks I'd never want to associate with. I would have used Sbanken before the DNB buyout (and I even did for a bit!), but now that's of the table too. There are a few more options, but many are just worse if you look at their fees and interest rates. I've been very happy with Bulder. The only thing they're missing is a web portal. The f…

I appreciate the info. Re: the banks I'm with, I have no choice.

I'm an immigrant and most banks refused to give me an account when I moved here. Or ghosted me during the months long process. These are the banks that let me live here, and actually gave me an account and bank id. It's the only real choice I have until I get citizenship.

Re: Android may soon restrict on-device ADB

#288
post #242

I am generally in favor of security improvements, but I do not really see much of a benefit here. This attack vector requires both that the user enabled developer settings and that they have remote adb enabled. So, this does not seem to be a realistic attack vector for 99.9% of the users and most of the other 0.1% probably know what they are doing. The other proposed change (to restrict access to certain interfaces o…

It seems to me a lot of Google lately is to block things they don't like using ways that only look like side effects. The introduction of Manifest V3 API in Chrome for extensions, and disabling Manifest V2 for security reasons. It just so happened that ad blockers were made incompatible with the Manifest V3 API. It's a little blatant considering this came right around the time that YouTube began showing warning messa…

I still can’t believe that an advertising company was able to effectively neuter ad/content blocking for 80% of the world under the guise of wholly invented safety issues.

Re: Android may soon restrict on-device ADB

#289
post #259

Earlier quoted context omitted.

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

A long time ago, I fixed Windows machines for pocket change. I can confirm some users will make bad decisions no matter what warnings they're given. I think the impulse for an OS vendor to try to make such mistakes impossible is about as wrong as selling knives dull so people can't hurt themselves. A knife that can't cut its user is useless as a knife.

Eh, this is a tough conversation for engineering-minded folks because the right answer is probably somewhere in the middle of a few different variables.

Too far towards trying to make mistakes impossible (which is easy for corporations to talk themselves into because it also makes them money and moat) and you make devices useless. Too far towards full user control and you get difficulties in support and security issues (which are tractable if you’re an enthusiast, but not so much if you’re a normie on a corporate-maintained device).

Truthseeking here is further complicated by ordinary end users’ dislikes and usability issues not always overlapping.

Re: Android may soon restrict on-device ADB

#290
post #145

Earlier quoted context omitted.

> In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. Have you ever worked with someone who barely knows how to use a mobile phone? They will hand their phone over to someone they barely even know to do something they don't understand. They will follow instructions from a stranger over the phone, without understanding what the phone is…

Following this logic, shouldn't we just ban smart phones for everyone then? If we need to dumb down all technology to the absolute lowest level, we should probably ban computers or at least require an official government-controlled license to get access to one. Is this a world you want to live in? Me neither.

I suspect this is in bad faith, but assuming not: how does that follow?

“Large numbers of people will uncritically follow sketchy instructions and get hacked” doesn’t in any way lead to “and therefore they cannot be trusted with devices”.

“People keep dying in auto accidents” doesn’t imply “ban cars” on the first order, it implies “seat belts and airbags”.

Post reply on HN