Live data from Hacker News

F-Droid version of KDEConnect uninstalled by PlayProtect

discuss.kde.org

101–110 of 192 posts

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#101
post #94

Earlier quoted context omitted.

It is for me. And there is nothing important on my phone so it is not a huge concern. And why do we have to accept that phones just turn into garbage after a few years? Even my old 2009 laptop* still runs an up-to-date OS but my 2016 phone is obsolete after 2-3 years? * but I have to admit that the hardware is quite slow

> And why do we have to accept that phones just turn into garbage after a few years? Even my old 2009 laptop* still runs an up-to-date OS but my 2016 phone is obsolete after 2-3 years? It is because computers run one of a few available OS's. The OS is being maintained by the distributer (MS, Apple, Google) and your hardware is good as long as the drivers are still receiving updates. Phones are different because even…

I mean, I know why it happens, but that doesn't mean I'm happy about accepting it.

It is really annoying how every vendor cobbles together a Frankenstein abomination of a kernel with just the right drivers and patches and good luck trying to run anything else. But I also understand that they (except maybe for Google) have no interest or incentive to clean up this mess.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#102

Earlier quoted context omitted.

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

I'm running lineageOS, and I had to root the phone to make one banking app work (and Netflix and some games.) It actually passes SafetyNet out of the box, but there's a CTS profile check that some apps do in addition to SafetyNet, and I had to root the phone to make it provide a profile that those apps are happy with. And then I had to install a SafetyNet bypass, because fixing the CTS profile broke SafetyNet. It un-…

Would you mind saying what phone you have, and which script? I'm using a (by now rather old) OnePlus 5 and potentially in the market for an upgrade -- and easy rootability is more my key feature than bling or a 50 megapixel camera....

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#103
post #2

One way to be a little less constantly violated by your phone is to run GrapheneOS, instead of iOS or ordinary Android: https://grapheneos.org/

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

Device attestation works for banking applications on GrapheneOS.

The only thing which doesn't work is google wallet because they explcitly expect a Google signed operating system.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#104

Earlier quoted context omitted.

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

I'm running lineageOS, and I had to root the phone to make one banking app work (and Netflix and some games.) It actually passes SafetyNet out of the box, but there's a CTS profile check that some apps do in addition to SafetyNet, and I had to root the phone to make it provide a profile that those apps are happy with. And then I had to install a SafetyNet bypass, because fixing the CTS profile broke SafetyNet. It un-…

Yeah, I probably tried all those scripts people guarantee to work. Even with all profiles I tried to load somehow most of those apps knew I was rooted.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#105
post #2

One way to be a little less constantly violated by your phone is to run GrapheneOS, instead of iOS or ordinary Android: https://grapheneos.org/

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

I use GrapheneOS daily and use banking, government, and other sensitive apps without problem. It's a common myth that you can't use those apps on GrapheneOS.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#106
post #2

One way to be a little less constantly violated by your phone is to run GrapheneOS, instead of iOS or ordinary Android: https://grapheneos.org/

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

In my experience, most banking apps are horrible and not worth using over accessing the bank's browser version.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#107
post #71

Earlier quoted context omitted.

Is that even legal ? Banking and public services are too important to be restricted to people with smartphone ownership (even regardless of OS). It's even more important to refuse to use them, publicly shame them, and complain about them failing at their duties.

Before smartphones some banks used a hardware token to authenticate web transactions, but now that is being moved to (non rooted) smartphones.

I was given a hardware device by my bank to do my online banking. If they want to move to smartphones I expect them to provide me one of those as well.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#108
post #6

Earlier quoted context omitted.

You make a convincing argument. I'm switching to GrapheneOS for my next phone upgrade. Here is the source code: https://grapheneos.org/source > “he used GrapheneOS” is 100% going to be used against you in court. I look forward to using this as a litmus test for legal representation.

Are you personally capable of ensuring: A. The builds match the code? B. The NSA hasn’t stolen the signing key and isn’t feeding you customized images? True, you can’t verify that with iOS or Android either. I am saying though that trusting my security because it’s safer… by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least.

Even if this was true, it seems harder to compromise a single paranoid coder working out of his garage than any one of 1,000 corporate developers, their workstations, or associated networking, or servers in any (even high-security) company.

Weakest link in the chain and all that. There are just a lot fewer links in the chain. More likely that a vuln is introduced as part of Android and makes its way into GrapheneOS than directly into a tiny project.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#109
post #106

Earlier quoted context omitted.

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

In my experience, most banking apps are horrible and not worth using over accessing the bank's browser version.

You don't get payment notifications when you use the browser version and you can't log in with a fingerprint scanner.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#110

Earlier quoted context omitted.

I'm running lineageOS, and I had to root the phone to make one banking app work (and Netflix and some games.) It actually passes SafetyNet out of the box, but there's a CTS profile check that some apps do in addition to SafetyNet, and I had to root the phone to make it provide a profile that those apps are happy with. And then I had to install a SafetyNet bypass, because fixing the CTS profile broke SafetyNet. It un-…

Would you mind saying what phone you have, and which script? I'm using a (by now rather old) OnePlus 5 and potentially in the market for an upgrade -- and easy rootability is more my key feature than bling or a 50 megapixel camera....

What I would do is make a short list of phones that interest you and go check the XDA developers forum for each model
Post reply on HN