Live data from Hacker News

De-Googling my phone

piware.de

161–170 of 192 posts

Re: De-Googling my phone

#161
post #52

Earlier quoted context omitted.

Do they do the same kind(s) of scans the google store does on apps? Sure, reproducible builds, but reproducible with holes isn't an upside. How does a bad app get removed? Who decides? When?

Givent the recent track records of many fishy apps on the PlayStore, I'll take my risk with the OSS of FDroid. https://www.zdnet.com/article/phony-android-security-apps-in... https://blog.malwarebytes.com/cybercrime/2017/11/new-trojan-... https://thehackernews.com/2017/12/google-playstore-malware.h... https://thenextweb.com/hardfork/2018/04/20/google-play-crypt...

When you've got millions of apps, this tends to happen on occasion.

Re: De-Googling my phone

#162

Earlier quoted context omitted.

Consider the incentives. Google: track every detail of your life and use it to serve up ads that support their bottom line. Implements changes that serve themselves at your expense. F-Droid et al: build cool open-source software cause they like cool open-source software. Implements changes because they make the software better.

>Google: track every detail of your life and use it to serve up ads that support their bottom line. Implements changes that serve themselves at your expense. I think you're missing the part where a user benefits from their services. I mean, it's not as if users get nothing out of this arrangement. The vast majority of users feel they're getting a good deal. Just because you don't think it's a good deal for you, don't…

I feel that, for the most part, what google offers is fair enough. There are some instances, however, where they completely ignore the needs/desires of their users though.

Google Home Page and Reader are the big two... both extremely popular, and plenty of opportunity there. Hell, at this point, I'd like to see Google offer a website similar to what I get on my phone's new tab screen now (articles of interest). I find it hard to actually trust any google services beyond search and gmail (only hoping they don't nix gmail without a LOT of notice).

Re: De-Googling my phone

#163

I am adopting a different approach. It seems likely that I may not be able to de-BigBrother myself without tremendous efforts. There are all kinds of devils out there, why not at least sell the soul only to a single devil? So I am going all Google. Nothing else. I exclusively use all their products (even Google+). I don't have FB, Twitter etc. Google is the devil I have sold my soul to.

besides everything else mentioned before, i feel like this is a double-sword situation. centralizing every aspect of your life into 1 company gives them a much more refined picture about yourself than if your info were scattared around with other companies.

Re: De-Googling my phone

#164

Great list! NewPipe is really good, far better than the proprietary YouTube app. K9 is also a superb app and holds up very well against the proprietary options. I have to recommend andOTP over FreeOTP, though, it's more featureful and does some important things like backups.

I used NewPipe for a while and then switched to SkyTube - anecdotally I found it had fewer issues with higher-res formats and audio than NewPipe did. It uses the Youtube APIs though, so isn't as Google-free as NewPipe.

Anyway, worth a look if you just want to ditch the Youtube app.

https://f-droid.org/en/packages/free.rm.skytube.oss/

Re: De-Googling my phone

#165
post #128

Earlier quoted context omitted.

> If you want, you can build and sign your own apps and put them on your device on an iPhone. HA! Sure. For $100 a year. And from a Mac. > I presume you’re talking about the headphone jack, which google followed up by removing from their pixel phone 12 months later? Why does apple get the hate here and not google? Because Pixel is not the only choice one has inside the Android ecosystem, as opposed to iOS one? Samsun…

You can actually now self-sign apps without being a developer now. There is a caveat however, you have to resign it every seven days. Edit: I also want to say there’s a limit to the amount of apps you can do this with. It’s not a great solution, but I have a feeling it’s as good as we’ll ever get.

If they can prevent it Apple will of course not allow you to run any pirated app you want. That’s the flip side of being on the platform where developers actually earn money.

Re: De-Googling my phone

#166
post #66

Maybe I can help, I have written this in google context, but it is general privacy enabled configuration. This is what I am using: https://lineage.microg.org/ (get rid of google play (and save 1/3 of battery)) apps have a dependancies to google framework and just not having it breaks lots of stuff (this is google true vendor lock-in). Microg is opensource reimplementation of it, but it needs patches into android to f…

Xposed shouldn't be used carelessly, see e.g. here: https://www.reddit.com/r/Android/comments/1y4u1p/can_xposed_...

Well, as long you are using only xprivacylua, it shouldn't be a problem. I have reviewed the code for it and netguard (doesnt need root) and it is clean (for netguard there are some callhome functionalities, but it doesn't submit anything relevant back or doing something fishy - I am talking only for paid version). Also Bokhorst is donationwaring it, so there is a money trail to physical person.

Regarding softbricking, TWRP should solve that.

Re: De-Googling my phone

#167
post #43

Earlier quoted context omitted.

Interesting. Because with Firefox 59 for Android, both kinetic and inertial scrolling work as expected (just tested). Odd that it does not work for iOS Safari.

I don't know about this specific case, but mobile Safari versions have a history of doing special things like CSS position: fixed works entirely different on that platform.

Adding `-webkit-overflow-scrolling: touch;` to the #content selector will fix it :)

Re: De-Googling my phone

#168
post #3

Nice setup. I would just recommend andOTP instead of FreeOTP.

If your Android phone supports USB-C, there's another alternative: you can embed your TOTP tokens on a Yubikey and access it via USB-C and the Yubico Authenticator on F-Droid: https://f-droid.org/en/packages/com.yubico.yubioath/

You can also use GPG keys embedded on the Yubikey for encrypted emails via OpenKeychain and K-9.

Re: De-Googling my phone

#169
post #69

Earlier quoted context omitted.

drivers. really. we are back to being limited to one OS because of drivers. this is also the reason lineageOS and other android roms can't just keep updating older phones to new releases. they need the oem to upgrade so they can extract drivers from the binaries.

They can and do. For example, you can get Marshmallow on the Samsung s2, which didn't officially didn't get even Lollipop.

I bet that this isonly possible because someone got the drivers for display, touch, camera, radios, etc, ...in binary form from the last oem image and put in the new one. sometimes they will backport the last kernel from android 5.1 into a 6.0 image so the binary drivers still work

Re: De-Googling my phone

#170
post #71
post #68

Earlier quoted context omitted.

that's a big falacy, akin to saying "you might now those debian people, but it's safer to just use windows"

no, its "you might know those debian people but I know those google people, and don't know those debian people" its "if you know people, maybe you are safe to use what they do" not "because you don't know x use y, you don't also know. ie, I "know" as much about google, as I do about debian people (btw, I run a lot of debian hosts. I also run google cloud hosted stuff)

you're missing the main difference.

I dont trust anyone working with debian or google.

but debian I can be sure if someone saw a bug/malware happening or in the source, I'd benefit from that. with closed systems the source option is gone. also nobody can report a ISP MitM the binary packages because no one knows the actual build output.

so, trust noone, but acept that open source gives you an edge. always.

Post reply on HN