Live data from Hacker News

A big win for Android interoperability

openhomefoundation.org

151–160 of 194 posts

Re: A big win for Android interoperability

#151
post #148

Earlier quoted context omitted.

"Bootleg" is a meaningless word in this context, so I ignored it. You can't "bootleg" an open-source product; you can only branch it, which is completely legitimate.

So pedantic, you must be fun at parties. Or maybe are you arguing for the sake of arguing? Fake Android if it suits you better.

I'm arguing against the actual point you made. You made the pedantic argument about "bootlegs" to distract from my argument. Now you've also decided to insult me.

To what end? Do you think that kind of approach convinces anyone?

There is no "fake android," either. Your whole argument is based on two false premises.

Re: A big win for Android interoperability

#152

The monopoly/gatekeeping effect of an OS developer making apps that compete with independent apps has such an easy solution. The OS must not give private api's or special permissions to its in-house apps. Don't try to fight the gatekeeping feature by feature, that is whack-a-mole. Bonus points if you require the primary UI (window manager in the language of the ancients) to be an installable app.

[deleted]

Re: A big win for Android interoperability

#153

Earlier quoted context omitted.

The very moment it becomes possible to create a Google Pay alternative, there will be at least a dozen choices, some of them fully open source and privacy conserving. The only reason why we don’t have them is Google / Apple duopoly.

It's possible right now, but you have to (as Google did) convince all banks, merchants, and card networks to let them use your system.

Merchants and card networks don't need to be convinced. From their PoV Google Pay device is just a regular payment card.

Re: A big win for Android interoperability

#154

Earlier quoted context omitted.

Is this an AI response? I get why people want a de-googled phone. What I don't get is why they would want to use tap to pay, one of the payment methods with increased attack vectors.

> Is this an AI response? Probably not but you’re doing a bad job explaining what wanting to de-google your phone has to do with the choice of wireless payment methods. It’s in the name, “de-googling”, not “de-attack-vectoring”. People want to break away from Google specifically. They’ll still use tap to pay because it’s convenient, secure enough, at least as private as any card/bank payment, and ideally not Google,…

Well, why do people want to de-google? Likely peivacy and security. There is significant overlap in that reasoning and not doing tap to pay.

Re: A big win for Android interoperability

#155
post #148

Earlier quoted context omitted.

So pedantic, you must be fun at parties. Or maybe are you arguing for the sake of arguing? Fake Android if it suits you better.

I'm arguing against the actual point you made. You made the pedantic argument about "bootlegs" to distract from my argument. Now you've also decided to insult me. To what end? Do you think that kind of approach convinces anyone? There is no "fake android," either. Your whole argument is based on two false premises.

I din't make an argument about "bootleg", I just used the term and you argued it.

Besides, depending on the actual OSI license, you can definitely have bootlegs if you really care to argue.

A bootleg does not need to be exploited commercially. It can just be counterfeit.

I am not insulting you. I am telling you that you are being overly pedantic while being wrong at the same time. You might find this difficult to accept but I'm just calling it.

Re: A big win for Android interoperability

#156

Earlier quoted context omitted.

Is this an AI response? I get why people want a de-googled phone. What I don't get is why they would want to use tap to pay, one of the payment methods with increased attack vectors.

Is this an AI response? No. I hate AI writing, so I never use AI for writing. Randomly throwing in accusations in discussions sucks. I don't think my comment had any of the hallmarks of AI writing either, unless bulleted lists are also not-done these days. I guess I should be happy that people don't recognize me as a non-native speaker anymore?

The accusation was not random. That writing had an AI tone to it with the bulleting etc, and didn't address the actual point being questioned.

Re: A big win for Android interoperability

#157
post #117

Earlier quoted context omitted.

Is this an AI response? I get why people want a de-googled phone. What I don't get is why they would want to use tap to pay, one of the payment methods with increased attack vectors.

> with increased attack vectors. I don't follow. If you mean against fraudulent spending phone based tap to pay is probably the most secure. It demands user authentication (biometric or code) for any transaction so there's no real way to trigger a fraudulent spend without the user knowing. Pretty much any other system allows for at least some amount of unauthorized spending if it's stolen. If you just mean it's less…

You might want to look into NGate.

Re: A big win for Android interoperability

#158

Now if only these rulings also covered attestation.

Android has an accessible hardware attestation API already ( https://developer.android.com/privacy-and-security/security-... ). It's what powers the attestation API that GrapheneOS made as an alternative to Play Integrity and friends (demo app: https://github.com/GrapheneOS/Auditor ) It's up to third party app developers to choose what library to use, of course. A court case between the EU and Google isn't going to c…

I personally have found great use from the little notifications that graphene OS pops up when the integrity API is accessed and it tells me the application. I saw Instagram accessing the integrity API probably entirely by coincidence while doing something in another app and so Instagram got immediately removed even though I never use it anyway.

feel free to keep your why did you have Instagram on your graphene OS phone to yourself. I know. I know. I know. I know. XD

and a little message when you tap on those notifications is exactly what the parent commenter stated encouraging users to contact app developers so that they can use basic integrity attestation and allow their apps to work on graphene OS.

and some apps do work and use the integrity API. maybe a little too much in my opinion. chatgpt I'm looking at you. my local credit Union's banking app doesn't even bother with the integrity API and they updated their tech stack recently which included app redevelopment.

Re: A big win for Android interoperability

#159
post #50

I don't care about any of these, I just want to be able to have whatever Google pay does without Google. You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?

Tap to pay apps, if the developer is trustworthy or if it’s from your bank, are significantly more secure than even carrying a physical card around as your payment is now locked behind biometrics/a pin.

Also de-googling isn’t the point of GrapheneOS.

Re: A big win for Android interoperability

#160

Earlier quoted context omitted.

Are you prepared to protect customers by refunding them if they are victims of fraud when using your payment system? Visa and MasterCard are prepared to do that. That's how they could convince consumers to use their cards without worrying.

Clearly consumers do worry, since the ones found in this comment section are saying they refuse to use a card as it could be stolen.

Millions of card transactions are made every day. If consumers worried, they wouldn't have credit or debit cards and they wouldn't use credit or debit cards.

What a single hacker writes is on the other hand just what he wrote.

Post reply on HN