Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

371–380 of 536 posts

Re: Android may soon restrict on-device ADB

#371

Earlier quoted context omitted.

That's why they're going to fully locked down devices.

So, they will use other vectors, like convincing people to transfer money. Set up fake webshop. Run scams through online marketplaces, etc. The solution is not to make everything impossible. The solution is to educate people.

Right, and for the few people who can’t be educated, there’s always the option of making dedicated idiot-proof devices. Some people need to wear helmets and knee pads while walking around, but that doesn’t mean that all of us do. Some people shouldn’t be allowed near sharp objects, etc.

Stop trying to flatten the human experience, Harrison Bergeron style.

Re: Android may soon restrict on-device ADB

#372
post #119

Earlier quoted context omitted.

It seems to require the user to: 1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times 2. Enable USB ADB debugging in the Developer Options 3. Establish an actual USB ADB session 4. Enable TCP/IP ADB debugging in the Developer Options 5. Unknowingly download a malware app from the official Play Store 6. Blindly click "Yes" on the permission prompt. In other words: this…

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

> Have you guys never done IT tech support for your elderly parents' computers?

This kind of comment is frequently made on HN and elsewhere. However, more than a few "elderly parents" are as computer-sophisticated as their grown children. A safe bet it's not rare to be exchanging ideas with an elderly person sophisticated enough to make comments on HN.

AFAIK there's no shortage of careless, uninformed, non-elderly individuals who get scammed into doing stupid things. Age is only one possible factor out of many contributing to scam vulnerability. And let us not forget that youthful, well-trained professional IT workers, developers and software engineers are not immune to scams via misunderstanding elements of the systems or processes they supervise.

"Ageism" is a word as ugly as what it signifies.

Re: Android may soon restrict on-device ADB

#373

Earlier quoted context omitted.

Sometimes attacks happen from users being instructed to enable settings in order to achieve something regardless of whether you’d expect them to have a reason to use the setting

The solution to social engineering can't be to remove useful features - you can socially engineer people to do literally anything, you can have someone walk to their bank, withdraw cash & fly to you with it with a dating scam: there are literally no boundaries once you get into that area of security. Digitally, you combat that through UX, messaging & education.

[deleted]

Re: Android may soon restrict on-device ADB

#374
post #310

Earlier quoted context omitted.

You're splitting hairs in this case, while that's unquestionably true, it's irrelevant if there tariffs are only set on one party. That's why Trump's tariffs on everything was so ... Uh ... "Interesting". If only one party gets the tariffs, you end up with other parties selling the goods instead, which does cause meaningful damage to the tariffed party

Or the tariffing party just continues buying very nearly the same amount of things at higher prices in many categories because those items don’t have perfectly elastic supply and demand.

Technically true but highly misleading. The amount of good like that are few, less then 30% of the EU -> US trade.

Re: Android may soon restrict on-device ADB

#375

Earlier quoted context omitted.

Sometimes attacks happen from users being instructed to enable settings in order to achieve something regardless of whether you’d expect them to have a reason to use the setting

Then maybe the best course of action is Google adding a warning before enabling certain settings that help normies avoid these attacks. Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."

Nobody reads the warnings and getting to use ADB on a phone is already a quest of epic proportions, soon to become the next Monkey Island sequel.

Re: Android may soon restrict on-device ADB

#376
post #145
post #119

Earlier quoted context omitted.

It seems to require the user to: 1. Enable Developer Mode by going to an obscure settings page and tapping the build number seven times 2. Enable USB ADB debugging in the Developer Options 3. Establish an actual USB ADB session 4. Enable TCP/IP ADB debugging in the Developer Options 5. Unknowingly download a malware app from the official Play Store 6. Blindly click "Yes" on the permission prompt. In other words: this…

> In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. Have you ever worked with someone who barely knows how to use a mobile phone? They will hand their phone over to someone they barely even know to do something they don't understand. They will follow instructions from a stranger over the phone, without understanding what the phone is…

A lot of people are misconstruing what I have said, which is pointing out that this can impact regular users. It not intended as a justification to restrict on-device ADB, and it certainly isn't meant to justify more extreme measures. That being said, we should not ignore what happens in the real world since the consequences are real.

Re: Android may soon restrict on-device ADB

#377
post #42

We need Linux on phones. Bank apps not needed as long as I can use browser. But do need some things like wireless cards, popular apps like Sonos and Spotify working.

Lots of questionable replies to you here, people recommending Android/Lineage/Graphene are being silly, Sailfish is a better answer but with major proprietary components I would still skip it. postmarketOS is the best option I believe. Mobian and some others possibly worth a mention as well. I found Ubuntu Touch/ubports to be disappointing so I wouldn't bother with that either. You can check the pmOS wiki to find compatible devices. Perhaps check first if anything you already own has support, and help them support your device better if you are able. Otherwise look for the devices with the best support and get one off eBay. Librem 5 and PinePhone should be among the best supported devices but you may get better performance / $ with a OnePlus 6T or other formerly-Android phone (again, verify most stuff is already working before buying something if possible).

For the popular apps you mention, there is Waydroid to run Android apps.

Re: Android may soon restrict on-device ADB

#378

Earlier quoted context omitted.

I think expert users on HN seriously downplay the ability and willingness of "regular users" to do very stupid things on their devices. If grandma wants that app that gives her a beautiful horse as a lock screen image, she will follow every one of those six steps that the malware HorseLockScreen app developer presents to her. She will tap a button that has a skull and crossbones icon, that says "tapping this will dra…

On multiple occasions I had trouble getting people to accept a self signed cert to show them something on a local webpage. It seems that elderly nowadays are super vary of any hacking or scams. YMMV.

> It seems that elderly nowadays are super vary of any hacking or scams. YMMV.

I'm sure you meant "wary". How amazing, education really does work. There is such a thing as overabundance of caution. But it's possible further education could encourage users to apply more balanced caution policies.

Re: Android may soon restrict on-device ADB

#379
post #155

Earlier quoted context omitted.

Huh? Why the hell would you use a bank that doesn't offer a web portal or have branches if there are banks that still do?!?! I bank with HSBC in the UK and there's still branches (worldwide) and banking via web. I assume you mean things like Starling and Monzo in this case? Banking with them is simply dangerous .

What's wrong with Starling/Monzo?

They’re only ok until something goes wrong or you end up with an overdraft. Then they screw you with poor customer service. Like the worst.
Post reply on HN