Live data from Hacker News

On non-rooted Android 17, ADB uninstall of system apps fails

github.com

111–120 of 204 posts

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#111
post #76

-cough- Shizuku + ShizuTools pseudo-root via system-user * https://github.com/timschneeb/awesome-shizuku * https://github.com/legendsayantan/ShizuTools * https://github.com/RikkaApps/Shizuku/discussions/462

Aren't they going to break that too? https://news.ycombinator.com/item?id=49045159

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#112
post #29

Earlier quoted context omitted.

And Graphene OS is also anti-user by being tremendously rude about NOT providing root and using the same tired "suck-u-rity" crap Google and Apple also use. If you're smart enough to buy a phone that supports GrapheneOS, AND install it, yeah you should have root. And tools like XPrivacy and plugins allow control of subsystems like GPS spoofing and lying to apps.

If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates. I think the decision of GrapheneOS to maintain the attestation features and not providing user root is what gives it a fighting chance of being accepted as legitimate 3rd choice. See: Revolut and others adding GrapheneOS keys and trusting th…

> Someone downloading a photo editing app and then having a rootkit installed in the background that waits to empty their bank account is not a workable situation.

Yes, that would be absurd. Thankfully, that isn't how root access has worked in a very very long time if ever. If photo editing app requests root access... you click deny and uninstall it.

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#113

Earlier quoted context omitted.

I fully agree with it. But I think Google also understands that the platform is unatractive for businesses. In my case I just don't do Android app because I know it is easy to just take and hack. It is not the case on iPhone. And my app is one time payment so the ability to just copy out the APK leaves me not doing an app at all...

The people that go through the trouble of installing apks from random websites to not pay $1 are in the minority. What's more, most of them wouldn't pay that dollar if they couldn't find the cracked apk. So the only thing you're realistically doing is cutting yourself off of a huge market. Convenience sells, the Play Store does that

$1 - most probably. What about $20?

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#114
post #60

Earlier quoted context omitted.

You can't sideload iOS applications. Meaning there's no point to doing any of the listed things.

Of course you can. How do you think developers test their apps?

Normal people can't. I'd bet more people run jailbroken than bothering with developer-mode sideload.

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#116

Earlier quoted context omitted.

Device attestation is how you can use private keys you don't actually have access to. It has a lot of value to literally anyone who wants to store tokens or use one time authentication codes. Linux folks need to implement the full stack and offer an open alternative to payments, secrets, and tokens. In the age of LLMs there is no excuse. It is annoying as hell that I can't buy a System76 or Framework laptop with a fi…

"Device attestation is how you can use private keys you don't actually have access to." Read that phrase back and then ask "is this the future of computing that we wanted?" The likes of passkeys, essentially user-hostile ssh keys that live on your device but aren't accessible by you, would have been an unbelievable dystopia to us in the 90s. "Linux folks need to implement the full stack" Nah it's fine thanks, I'd rat…

That's just your opinion. Has nothing to do with Linux. And yes I would like a device like a soldered in tpm device that can generate private keys and verify signatures signed with the public key. Your misunderstanding of the technology not withstanding it does appear to me to be quite a valuable technology since it's in basically every computer these days.

Stop speaking for Linux.

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#117

I don't understand why ensuring general-purpose computing is not a priority of the European Union. All that talk about sovereignty, and we are giving full control of our digital lives to 2 American companies.

Because the EU wants attestation for age verification, digital surveillance and censorship, not free software platforms that wont implement any of those.

lobbyist from the usual american companies are convincing "politicians" to sponsor those bills.

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#118

Earlier quoted context omitted.

If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates. I think the decision of GrapheneOS to maintain the attestation features and not providing user root is what gives it a fighting chance of being accepted as legitimate 3rd choice. See: Revolut and others adding GrapheneOS keys and trusting th…

> Someone downloading a photo editing app and then having a rootkit installed in the background that waits to empty their bank account is not a workable situation. Yes, that would be absurd. Thankfully, that isn't how root access has worked in a very very long time if ever. If photo editing app requests root access... you click deny and uninstall it.

Because so-called “trusted” apps that you do give root to have no chance of getting compromised, right?

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#119

Earlier quoted context omitted.

If you are technical and want root its very easy to patch a build of GrapheneOS to include whatever mechanism you want. You can even automate this to continue to receive updates. I think the decision of GrapheneOS to maintain the attestation features and not providing user root is what gives it a fighting chance of being accepted as legitimate 3rd choice. See: Revolut and others adding GrapheneOS keys and trusting th…

> Someone downloading a photo editing app and then having a rootkit installed in the background that waits to empty their bank account is not a workable situation. Yes, that would be absurd. Thankfully, that isn't how root access has worked in a very very long time if ever. If photo editing app requests root access... you click deny and uninstall it.

Some percentage will click Allow.

Re: On non-rooted Android 17, ADB uninstall of system apps fails

#120
post #29

GrapheneOS has minimal, private [1] system apps so you don't have to debloat anything yourself. Manual debloating is not a good solution at the user level. Some system apps are being overhauled, so that's something to look forward to. Gallery will be [2] based on ReFra [3]. [1] Except phone and messaging but that's the cell network. GrapheneOS recommends Signal/Molly or SimpleX instead. [2] https://nitter.net/Graphen…

And Graphene OS is also anti-user by being tremendously rude about NOT providing root and using the same tired "suck-u-rity" crap Google and Apple also use. If you're smart enough to buy a phone that supports GrapheneOS, AND install it, yeah you should have root. And tools like XPrivacy and plugins allow control of subsystems like GPS spoofing and lying to apps.

Software freedom is about freedom of choice, not philosophically mandated security holes. You are free to take the GrapheneOS code and introduce a huge vulnerability in the form of a privilege escalation path from sandboxed apps if you wish, it is open source and you can easily compile and flash your own build.

Mobile phones store incredibly intimate data and are incredibly vulnerable to seizure. It stores my message history, pictures I've taken, so many other records that together would provide an incredibly detailed view into my private life. And it is on my person at all times, even through checkpoints where I have minimal protections against search and seizure like borders! This is not a device that I want a broad surface for modification of system software on.

Post reply on HN