Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

511–520 of 536 posts

Re: Android may soon restrict on-device ADB

#512
There is a reason that I am considering switching to IOS because google keeps pulling this shit. Atleast with Apple I know what I get.

Which is not the most flexible system, with apple only implementing the mandatory minimum of interoptability and features required by EU rules. But other than that delivering a rather solid product with excellent vertical integration. And at least i know that unlike Google their main business is not in advertising. (but in pricing their incremental upgrades ridiculously)

Re: Android may soon restrict on-device ADB

#513

Earlier quoted context omitted.

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition),…

I'm begging, please let me use password "asdfasdf" on throwaway accounts. I accept full responsibility for the fallout. Seriously, many web admins need to hear this message: "Chill. Your site is not that important."

You have a throwaway account?

Can't have that! We wouldn't have any data to sell!

We need ID, email verification address, phone number, and a selfie of yourself holding a handwritten sign saying, "I love " now.

And you have to do a captcha at every step. Click on every crosswalk, sucker.

Re: Android may soon restrict on-device ADB

#514

I am worried that this might happen to websites soon. If you want your website to be openable on Apple devices, you would have to pay Apple a fee each month. If you want your website to be openable on Android devices, you would have to pay Google a fee ecah month, etc.

I am worried that this might happen to websites soon. You mean the new recaptcha that requires remote attestation? https://www.eff.org/deeplinks/2026/07/googles-new-remote-att... Obviously, it doesn't have the fee part. But Google can decide soon for a substantial number of websites which devices can visit them and which not.

That's not a new version, that's a variant of v2. v3 is still completely non-interactive.

Re: Android may soon restrict on-device ADB

#515

Earlier quoted context omitted.

> But it helps against account sharing This is actually a feature , very common in real world, that security maximalists keep insisting is a bug.

My wife's insurance provider requires SMS 2FA, which is incredibly annoying for this reason - there's no way for me to submit my massage (or w/e) benefits even though my wife hates dealing with insurance admin and I have the login info and am authorized to do so - I have to wait until my wife is home and then get her to read off an SMS code for me.

Setup a Google voice number as her number in the system and have it forwards to you, with your wife's consent.

Re: Android may soon restrict on-device ADB

#516
post #375

Earlier quoted context omitted.

Then maybe the best course of action is Google adding a warning before enabling certain settings that help normies avoid these attacks. Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."

Nobody reads the warnings and getting to use ADB on a phone is already a quest of epic proportions, soon to become the next Monkey Island sequel.

Log in to Facebook.com and hit developer console. Can't totally idiot proof it, but people do read enough warnings if you yell loud enough. Which puts it on them.

Re: Android may soon restrict on-device ADB

#517

I am generally in favor of security improvements, but I do not really see much of a benefit here. This attack vector requires both that the user enabled developer settings and that they have remote adb enabled. So, this does not seem to be a realistic attack vector for 99.9% of the users and most of the other 0.1% probably know what they are doing. The other proposed change (to restrict access to certain interfaces o…

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition),…

Well said, security enthusiasts don't understand that the optimal amount of security breaches is not zero.

Re: Android may soon restrict on-device ADB

#518

Earlier quoted context omitted.

That's why I mentioned "and also enabling authorised access to that same resource". Passkeys are great at preventing unauthorized access. But that comes at the expense of preventing authorised access. For example, using another device or even moving to another device. Replacing a stolen or damaged device is also nearly impossible with a reasonable quantity of Passkeys.

Well that's why they can sync between devices. I don't really see the problem. Even if you don't like to rely on big tech (google/apple), I don't either, there are many options now for full FOSS implementations like bitwarden and KeepassXC. If you use a yubikey as a passkey then yes, that's not a great option also because most services don't allow you to enroll more than one passkey. But with bitwarden that doesn't m…

  > Well that's why they can sync between devices.
What Passkey implantation syncs between devices? I've only ever seen "cloud sync", e.g. syncing with someone else's computer. Can a user sync iPhone passkeys with her Boox E-ink tablet (Android)? Can either sync with a Debian desktop?

Re: Android may soon restrict on-device ADB

#519

Earlier quoted context omitted.

Every bank here had that. Now they all require apps. For the banks I understand. Now they don't have to supply millions of code calculator devices. And they force their apps which they can stuff full of tracking to mine their customers for data they can sell. It's sad but part of the usual enshittification cycle

They provided you with one? My bank made me buy my own device. It's an online bank, so I'm not sure if using the app allows for better tracking than simply using their normal website. So far I haven't been forced to use an app, so I guess not.

Yes here they always provided one. And yes an app gives a tracker much more capability especially on Android.

Re: Android may soon restrict on-device ADB

#520

Earlier quoted context omitted.

Well that's why they can sync between devices. I don't really see the problem. Even if you don't like to rely on big tech (google/apple), I don't either, there are many options now for full FOSS implementations like bitwarden and KeepassXC. If you use a yubikey as a passkey then yes, that's not a great option also because most services don't allow you to enroll more than one passkey. But with bitwarden that doesn't m…

> Well that's why they can sync between devices. What Passkey implantation syncs between devices? I've only ever seen "cloud sync", e.g. syncing with someone else's computer. Can a user sync iPhone passkeys with her Boox E-ink tablet (Android)? Can either sync with a Debian desktop?

Yes you can do that with Bitwarden or KeepassXC.

Not sure if either works on iOS, I don't use that but they work on desktop and Android (you use KeepassDX there to read them).

Post reply on HN