Live data from Hacker News

F-Droid version of KDEConnect uninstalled by PlayProtect

discuss.kde.org

131–140 of 192 posts

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#131

Earlier quoted context omitted.

Sadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.

I'm running lineageOS, and I had to root the phone to make one banking app work (and Netflix and some games.) It actually passes SafetyNet out of the box, but there's a CTS profile check that some apps do in addition to SafetyNet, and I had to root the phone to make it provide a profile that those apps are happy with. And then I had to install a SafetyNet bypass, because fixing the CTS profile broke SafetyNet. It un-…

Once google only accepts hardware attestation it's over unfortunately

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#133

Earlier quoted context omitted.

The only acceptable phone for me has been a Pixel phone, with GrapheneOS installed. I do wish the permission to install/uninstall were separated for something like this (I may be naive). I have everything installed to a work profile in Android (using the Shelter app). I can globally pause all work-profile apps. It's not the best, because when unpaused I'm not getting some notifications. I need to figure that out.

Graphene is not acceptable either, since it requires putting trust in someone who does not exibit enough stability or rationality to justify that kind of trust. I mean it's only the keys to your whole life, no big.

I agree but he's not involved anymore since even Louis Rossman called him out on his behaviour.

Edit: apparently according to a post below he's still involved just not lead dev anymore. Sorry I missed that part.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#134

Earlier quoted context omitted.

They only seem to support pixel, although pixels can be bought for cheap when compared to iphones, they're still expensive for countries which are still developing. For example Im using a device which is 1/4th the price of cheapest first hand pixel that I can get :(

LineageOS is supported on a bit more devices, and works with microG if you're willing to sacrifice Google Pay for better battery life and less privacy violations: https://lineage.microg.org/

Yeah I love MicroG. But I really wish there was a big-tech-free payment solution :(

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#135

Earlier quoted context omitted.

I use GrapheneOS daily and use banking, government, and other sensitive apps without problem. It's a common myth that you can't use those apps on GrapheneOS.

It's not a myth. I run GrapheneOS, and my bank app doesn't work, the Blind app doesn't work, and another common marketplace app (not amazon) has shadow banned me for using it on a device without hardware attestation. I only found out after reaching out to support and having a lengthy conversation with them. It's idiotic that they require hardware attestation, but let's not fall into the trap of "it worked for me". Ev…

Even the McDonald's app doesn't work if you install it through Aurora store lol. Even though it's the same signed version distributed through Google play and I have Google play on the device, just not signed into a Google account.

Somehow it detects that it was not installed through Google play and refuses to work with an explicit message stating this reason. I really wonder why they care. The app doesn't even take payment, at least not in this country. You still have to pay at the order portal thing.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#136

Earlier quoted context omitted.

This worked ok, but wasn't as nice as grapheneos' solution so I ended up upgrading to a pixel once my cheap chinesium phone was sufficiently old and haven't looked back since. If you do the microg route you should be using a throw away gmail account you don't care about losing with the aurora store (if you need access to the google play store) because there is a non zero chance they ban your account.

> a throw away gmail account you don't care about losing with the aurora store They also have a pool of accounts you can use by clicking “anonymous”. They do get banned frequently, and you have to re-login once in a while (for me it's almost every time I want to download something new again), but it is definitely usable.

It's a lot less usable lately because of the "Oops this account is rate limited" error unfortunately. Sometimes it takes me 10 tries. Updates are fine though, it's just searching for new apps that trigger it.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#137
post #6

Earlier quoted context omitted.

… as long as you trust the developers, and their ability to secure themselves, of course. I mean, if I was a three letter agency, sneaking into some GrapheneOS developer’s basement to add a camera to record his keystrokes would be the easiest trade ever for all the paranoid people using it. It’d be way easier than sneaking into Apple or Google. Might even be worth violating internal law to do it; because getting caug…

You make a convincing argument. I'm switching to GrapheneOS for my next phone upgrade. Here is the source code: https://grapheneos.org/source > “he used GrapheneOS” is 100% going to be used against you in court. I look forward to using this as a litmus test for legal representation.

The sad thing is that this is exactly what might happen in the EU since spyware will soon be mandatory.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#138

Earlier quoted context omitted.

it's not a waste of money, that android version is a security mess

It is for me. And there is nothing important on my phone so it is not a huge concern. And why do we have to accept that phones just turn into garbage after a few years? Even my old 2009 laptop* still runs an up-to-date OS but my 2016 phone is obsolete after 2-3 years? * but I have to admit that the hardware is quite slow

Even if your phone really has no access to anything that you wouldn't want leaked (although most people would object to a third party having access to their phone calls, text messages, and location data), a compromised device is still a great way to launch attacks on other devices including taking part in botnets. None of this is an objection to old devices, mind; I'm a big proponent of running new software on old hardware, but the security patches are important.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#139
post #100

We should be able to install any OS that we want on our phones.

This is precisely one of the perks of rooting. Unless you mean as a right, without needing to root? I'd disagree (from a corporate/warranty perspective), but I'll bite

> This is precisely one of the perks of rooting.

Rather, it's a benefit of an unlocked bootloader; you can root a device with a locked bootloader, and you can use an unlocked bootloader to install an unrooted OS (or, for that matter, you can unlock the bootloader without rooting, depending on the device).

> Unless you mean as a right, without needing to root? I'd disagree (from a corporate/warranty perspective), but I'll bite

Why? I mean, sure, if the manufacturer can show that damage resulted from the user modifying the device then fine, but otherwise there's no reason for modifying software to affect a warranty on hardware.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#140
post #45

Is this proven? Some days ago I saw the reddit thread which is actually the first and only reply in the link and in that reddit thread there is no conclusion yet on who is actually affected why this conclusive title then?

I can speak from experience that I woke up yesterday with KDE Connect missing from my device.
Post reply on HN