Live data from Hacker News

A big win for Android interoperability

openhomefoundation.org

121–130 of 194 posts

Re: A big win for Android interoperability

#121

Earlier quoted context omitted.

IMO the most annoying thing is that Google could solve this problem today by just adding the GrapheneOS signing keys to the whitelisted keys. Instead they decide to exclude GrapheneOS because security , while attesting phones that are still on Android 13 (multiple years without fixes for vulnerabilities that are not marked high/critical) and did not apply ASB patches for up to 12 months. A first step would be requiri…

POSIWID: the purpose of remote attestation is to force people to buy devices that pay Google license fees.

>that pay Google license fees

Source? I thought it was free for OEMs?

Re: A big win for Android interoperability

#122
post #50

I don't care about any of these, I just want to be able to have whatever Google pay does without Google. You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?

Because people have different priorities than you do, and just because you can't imagine something, it doesn't mean it's not real or reasonable.

Re: A big win for Android interoperability

#123
post #64

Earlier quoted context omitted.

I agree, it's very convenient to have a phone full of corporate malware. But I thought the point of GrapheneOS was to escape that. My corporate malware only runs on my secure card processor which sits in a pocket glued to my phone.

The very moment it becomes possible to create a Google Pay alternative, there will be at least a dozen choices, some of them fully open source and privacy conserving. The only reason why we don’t have them is Google / Apple duopoly.

I seriously doubt that. There used to be more NFC payment apps, but most banks abandoned them since it was cheaper to just pay Google their cut through Google Pay. Or Wallet, or whatever the hell they renamed it to.

Banks letting an open source project run transactions through them... that's... hilarious.

Re: A big win for Android interoperability

#124
post #47
post #42

Earlier quoted context omitted.

Because a normal card is superior in most practical cases?

No it’s not, all of my and my extended family cards (for… like a decade!) are never even leave the envelope they come in. I’m not sure I personally know people who use physical cards over Google or Apple Pay. I have seen the cards being used in the wild, of course. But I’m having hard time remembering anyone I personally know who does that.

> I’m not sure I personally know people who use physical cards over Google or Apple Pay.

You live in a pretty weird bubble. (And I live in San Francisco, so I know about weird bubbles.)

Re: A big win for Android interoperability

#125
Will be interesting to see how Google implements a more open DSP wake-word detection. The requirement for it to work without the app holding a default role suggests needing to recognize multiple wake-words for each of the non-default apps that uses one.

From an openness perspective this is excellent. Technically it seems challenging with a DSP designed to detect a single thing using as little power as possible. Currently this balances doing as little work as possible to detect plausible utterances of the wake-word on the DSP while minimizing the costs of spurious wake-ups on the CPU. At the very least multiple wake-words seems to need the DSP to do more work and wake up the CPU more often.

Re: A big win for Android interoperability

#126

I don't care about any of these, I just want to be able to have whatever Google pay does without Google. You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

Walt https://walt.is/ is building exactly that in Europe. They claim first tap to pay will happen later this year.

Some European banks including mine offer NFC payments via their app as well. You don't need Google services.

Re: A big win for Android interoperability

#127
post #49
post #46

Earlier quoted context omitted.

Banks and card networks will only accept proprietary shitware as payment. Would you rather keep the malware confined to a separate processor chip or would you let it run on your phone?

In other words, would you like to have your physical card to be lost or stolen and someone paying with it? As small amounts don’t ask for a pin confirmation. Having my phone stolen is pretty much another level of attack.

> would you like to have your physical card to be lost or stolen and someone paying with it?

I don't really care, as I'm protected from fraud by the card issuer and regulations in my country.

> Having my phone stolen is pretty much another level of attack.

Stealing a wallet or a phone seems just about the same level of difficulty.

And you can trick an iPhone into believing you're a transit terminal and charge arbitrary amounts to real credit cards, without unlocking the phone. (And Apple thinks this is a feature.) The attack requires specialized hardware and physical access, but if you've stolen the phone, that's fine.

(Yes, I know, this article is about Android. But most people where I live have iPhones, even if I don't.)

Re: A big win for Android interoperability

#128
post #50

I don't care about any of these, I just want to be able to have whatever Google pay does without Google. You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?

Well it's going to be a matter of time anyway, I'm already forced to use an app when I'd rather not.

But more than that I want to have a choice.

Re: A big win for Android interoperability

#129
post #21

Earlier quoted context omitted.

Who wants a bootleg Android that sends all your call logs who knows where? xD

Ah, yes, the Google/Apple narrative of "if we open the ecosystem, all users' data is at risk". Meanwhile, they are the companies that continuously harvest behavioral data from phones, put backdoors for law enforcement through weak defaults (iCloud backups are not E2E encrypted, unless you enable ADP), etc. All this while, GrapheneOS, LineageOS, etc. provide real, provable privacy. Please stop parroting surveillance t…

You didn't get it. I'm talking about fake Android. Not GrapheneOS or similarly a whole other OS that doesn't try to pass as Android.

Re: A big win for Android interoperability

#130
post #121

Earlier quoted context omitted.

POSIWID: the purpose of remote attestation is to force people to buy devices that pay Google license fees.

>that pay Google license fees Source? I thought it was free for OEMs?

I think there's a fee and also a long list of requirements - such as you must not sell any phone without Google Play Store.
Post reply on HN