Live data from Hacker News

A theoretical way to circumvent Android developer verification

enaix.github.io

141–150 of 185 posts

Re: A theoretical way to circumvent Android developer verification

#141

Earlier quoted context omitted.

The same EU that's doing Chat Control?

It appears that you are an American who has conveniently forgotten about FISA, EARN IT, CLOUD act, PATRIOT act, LAED, etc, etc, and wants to take a dig at the EU for what, exactly? NOT passing Chat Control? Seriously..

I do not think it is righteous or enlightened when the American government flexes control over the tech sector. I can see how Europeans might have thought this about the EU when it was just GDPR, but subsequent developments have recast all of this as being about government control and keeping the tech industry “in its place” rather than a commitment to privacy and freedom in and of themselves. I think that ought to temper the righteousness.

Re: A theoretical way to circumvent Android developer verification

#143

Earlier quoted context omitted.

It's not a good, secure project by a longshot. There's a good comparison floating around: https://images.squarespace-cdn.com/content/v1/60f1421e1afcf4...

That looks like someone made a list of mostly features specific to GrapheneOS so they could make a chart where all of the other alternatives (including stock Android) are full of red boxes. Several of those are the opposite of security features, like SafetyNet support, which might be a convenience in some cases but it mostly makes it so you can't upgrade certain parts of the system to newer versions even when the old…

Or, far more playsibly, they added to the table features GrapheneOS has, but others don't.

Here's the up-to-date comparison: https://eylenburg.github.io/android_comparison.htm

As far as I know, there is no significant features other distros have that increase their privacy or security over what GOS has. I'm not entirely sure about the SafetyNet thing, but GOS is by far the most up-to-date to the AOSP out of these distros.

Re: A theoretical way to circumvent Android developer verification

#144

Earlier quoted context omitted.

For all the disdain I have for her, Von Der Layen is the candidate put forward by the PPE, the majoritarian party in the EU parliament. So, yes, people were indeed allowed to vote.

She was primarily nominated by the EU council. The parliament would have picked Weber, but nobody cared since its just there to rubber stamp predetermined decisions. He was the leader of the party which won the plurality in the elections and had its support. EU had a real chance to move towards becoming a real parliamentary democracy if it went that way.

That was the election before the current one. She was the one out forward by the PPE this time and even then she was the second candidate put forward by the PPE after Weber was vetoed by France the previous time.

That’s the new Spitzenkandidate system. The council is supposed to pick the candidate put forward by the main political force in the parliament.

The EU is a real democracy anyway. All the members of the council are themselves democratically elected. It has a weird three parts political system but everyone in it is elected or appointed by people elected.

Re: A theoretical way to circumvent Android developer verification

#145

Earlier quoted context omitted.

But the parliament isn't the government in a parliamentary democracy.

Yes, and? It forms the government and can dismiss it.

They can also vote on bills, while we're bringing up irrelevant gotchas.

Re: A theoretical way to circumvent Android developer verification

#147

Earlier quoted context omitted.

> A secure OS is a prerequisite for secure digital services. We can agree on that, right? Secure for who, and from whom? Remote Attestation and Developer Verification both make Android OS and platform more secure against malicious actors that would want to defeat the guarantees the platform gives, guarantees that enable secure digital services. Yes, this includes protecting the banking services and DRM media services…

> Chat Control improves security of the society against threats such as sexual predators who want to hurt children, no it doesn't. Chat Control is single-use.

It does, to some extent. These projects wouldn't have the support they had if they didn't have a plausible way to deliver some improvement along the metrics they market. It's the outsized harmful impact that's usually just left unspoken.

Also, I'm not saying Chat Control is dual-use, I'm saying crypto is. Chat Control actually needs working crypto to be properly implemented.

Re: A theoretical way to circumvent Android developer verification

#148

I think this means we need to rely on web technologies more. PWAs are looking pretty good on mobile devices these days and you can publish any web app you want with no reviewing authority. The web has a bunch of crazy APIs now that let you build crazy things and for everything else you're a hosted server away somewhere that can run more complex jobs. I believe devices I own should let me do whatever I want with them…

PWAs are at the mercy of Gapple have always been handicapped in just the right places to not be viable vs installed apps. Most people don't even know how to install one.

Re: A theoretical way to circumvent Android developer verification

#149

I am not a app developer however from what I read on the android developer site you just need to provide some form of id, the singing key and the app id. You don't have to distribute via the app store, you dont have to get Googles permission to publish the app or have them sign it. This looks like purely app validation, we only run apps we can prove originate from the author.

So if Google doesn't like the app in question (such as ReVanced, NewPipe, etc), they can simply target that signing key to completely disable the app on all devices, even if it's not distributed by them.

Having the file signed by a relatively centralized authority makes it much easier for Google to gain control outside of their realm.

Re: A theoretical way to circumvent Android developer verification

#150

Earlier quoted context omitted.

They are trying to stop crime, including sex/drug trafficking and child exploitation. If you want to have an intellectually honest debate, you need to be clear that private communication apps do make it more difficult for police to conduct legitimate investigations. You do yourself no favours painting all politicians as power-hungry caricatures.

If chat control is a good-faith effort to stop crime, why can't Android developer verification be a good-faith effort to stop cybercrime? If politicians are not all power-hungry caricatures, is it possible that the same is true for businesses? Android has millions of users worldwide, many of whom are far less computer-literate than HN users. I think it's very reasonable for Google to put speed bumps in front of malwa…

I think the issue is not about distribution in the Play Store (I don't actually have any problem with that: their playground, their rules) but the fact that they are going to break sideloading and alternative app sources like F-Droid.

I struggle to see any good-faith need to erect additional barriers to protect users from running the programs they want on devices they own, when you already have to be fairly expert to enable developer mode, install via adb, etc.

Post reply on HN