Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

161–170 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#161
post #60

I know I risk being down voted remorselessly but I have to put this in context. Where in the real world is anonymity considered ok? If I only put a flyer through someone's letterbox here in the UK, I have to identify myself. If I sell a physical product I not only have to identify myself but take on serious legal liability. An author can take on a pseudonym but only via an identified publisher. In fact that latter ex…

The thing is that so many people are used to doing whatever they want from behind the safety of their screen and are now able to do a lot of things they don’t want anyone to know about. Now the law and common sense is catching up and we’re starting to see things we take for granted in the physical world are coming to the digital world. And I think a lot of people are scared of not being able to do what they used to o…

Yea, cus when I write a fanfic I should show my id to the company that owns the printer I purchased and own, before I print out a copy to give for my friend, ffs. Does that analogy make sense to you?

Re: Uncomfortable Questions About Android Developer Verification

#162
post #133
post #19

Earlier quoted context omitted.

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

> Why is it so complex to have a foss mobile OS. This is not too hard. What is hard is to trust it enough. A FOSS OS, by definition, allows to install whatever software, and allows for modification of itself. It is built to overcome limitations, not impose them. In this regard, it's a perfect tool for a criminal who wants to circumvent security measures, because these are limitations. It's the same problem as with ch…

All this is true about Linux on desktop, though my bank still allows me to log in to online banking.

At least for now.

I'm not aware of any major issues this has caused.

The trust isn't the issue. Google and Apple has made DRM easy for these companies to integrate, and therefore they do it. There isn't more to it than that.

Re: Uncomfortable Questions About Android Developer Verification

#163
post #73

Earlier quoted context omitted.

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

Write them. My bank's app had safetynet, but they disabled it and now it is usable over GrapheneOS. Unfortunately no NFC Payments though, since they are only available for Google Wallet (which uses safetynet)

> Unfortunately no NFC Payments though, since they are only available for Google Wallet (which uses safetynet)

A workaround for NFC payments I've heard about for folks running OSes on their Androids that don't support that feature is a smartwatch with NFC.

Re: Uncomfortable Questions About Android Developer Verification

#164
post #154

Earlier quoted context omitted.

My bank blocks my mobile with Lineage OS, and it's not even possible to login to the web site without the mobile app. Absolutely pathetic. Now I have to keep my 4 year old phone with 2 year outdated Android to access the bank application. Which deemed more safe then my mobile with latest security updates. Haha

last time I walked into the bank to do something, they tried to peddle their app. I giggled and said no, their developers don't understand security. my phone is rooted and their app won't work.

Unfortunately, I can say with 100% confident, the customer service of my bank will not freaking understand what is a rooted phone, or LineageOS ...

And my bank's web app developer couldn't even fix their log in bug for several months. I realize, now, it's because they want to sunset their web portal.

Which is extremely annoying ... what if I don't have my mobile!!

Lazy, and greedy corporates, just trying to save their costing with shortcuts, never realizing security is never achieved by taking shortcuts.

Re: Uncomfortable Questions About Android Developer Verification

#165

I'm a nobody, but let me answer these questions in 60 seconds. 1: None, no anonymous accounts allowed. 2: None. Civil what?. 3: It's the Google's company policy, don't use our products if you don't agree to it. 4: If devs write apps for this nearly impossible to develop Mac AppStore ecosystem, I don't see even a slightest problem here. 5: Just change package IDs. Thank you for listening, see you again next time.

Do you work for Google?

No, but I was a developer of an app for iPhone, so I know the thought process.

Re: Uncomfortable Questions About Android Developer Verification

#166

Earlier quoted context omitted.

> He is the kind of guy who makes zero concessions for practicality Didn't he give some wiggle room in GPL license ?

Inasmuch as the GPL itself is not Stallman's preferred state of affairs (he would prefer to see copyright abolished altogether, at least for software, and copyleft is just a compromise for now), I suppose so. Otherwise I'm not aware of any wiggle room, was there something specific you had in mind?

> [H]e would prefer to see copyright abolished altogether, at least for software...

Oh? From the "Finding the right bargain" section of this 2002 essay [0]

> So perhaps novels, dictionaries, computer programs, songs, symphonies, and movies should have different durations of copyright, so that we can reduce the duration for each kind of work to what is necessary for many such works to be published. Perhaps movies over one hour long could have a twenty-year copyright, because of the expense of producing them. In my own field, computer programming, three years should suffice, because product cycles are even shorter than that.

Has his opinion changed since then?

[0] https://www.gnu.org/philosophy/misinterpreting-copyright.htm...>

Re: Uncomfortable Questions About Android Developer Verification

#167

Earlier quoted context omitted.

Foss people are on the spectrum and so never understand the common man. Simple as that I guess.

Well the nice thing about the spectrum is that we are all on it and that we draw imaginary lines ourselves. All wisdom aside... I think you're right. I takes a certain grit to start to appreciate the ultimate effect of software freedom culture and licensing. Never mind the the whole philosophy. It's like explaining CRISPR (yeah I'm a biologist) to a normie... Ok, so lets start with what DNA is... proceeds to guide so…

This is irremovable tension - FOSS in its ideals is democratic, yet it can never succeed in democratization. This is why I think preaching freedom and agency is a bad strategy for the FOSS, even if its members believe them.

Re: Uncomfortable Questions About Android Developer Verification

#168
post #19

Earlier quoted context omitted.

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

It's the ecosystem. Without an ecosystem there will be less adoption and consequently less investment in the OS. Where I stay, so many services offered exclusively through Android/iOS apps with no alternative. Even government services are slowly excluding the web and becoming app only. There is an implicit expectation from everyone that one will have either an Android/iOS device and this only becomes stronger with ti…

Interestingly, we are, and have been, at a point were you can publish applications that run on any OS for a while, with PWAs.

There are very few software examples, that couldn't be distributed as PWAs, including secure things like banking, etc. With WASM in the mix as well, theoretically the sky should be the limit.

Even more interestingly it hasn't happened - mainly because Apple and Google haven't got behind PWAs for obvious reasons, so the app ecosystem just doesn't exist. It's hard to see how this will changes, when mobile operating systems are dominated by two players, with very obvious incentives to make things worse for consumers but better for themselves, by grabbing as much control of the apps on their system as possible.

Re: Uncomfortable Questions About Android Developer Verification

#169
I'd guess that the main reason Googel has done this is to prevent side-loading of messenger apps, such as Signal, with true end-to-end encryption. Such messengers would be very difficult to surveil at scale. You might ask why not to simply install these apps from Play Store? The reason is Google demands signing keys for all apps, so it can impersonate the developer, inject any spyware, rebuild the app, sign it and make it look untampered. Side-loading bypasses this entirely.

Re: Uncomfortable Questions About Android Developer Verification

#170

Earlier quoted context omitted.

Linux is 30 years old, and still it has a laughable percentage of desktop usage. Plus, the only reason it's even usable is because of the relentless work by thankless developers for reverse engineering device drivers. On smartphones this is orders of magnitude more difficult. How do you properly profile and debug a random modem in a phone? What about the cameras? So, how can anyone expect FOSS mobile OSs to ever exis…

I know this isn’t what you meant but it’s important to remember there is some hope. Thirty years ago I was required by my CTOs to use Windows, Borland, AIX, and Solaris. Linux, FreeBSD, and Free dev environments were viewed with deep suspicion. In 2025 you’d be viewed just as much suspicion for not building your stack on Freedom. I still have hope that we’ll get there with phones, too, some day.

> In 2025 you’d be viewed just as much suspicion for not building your stack on Freedom.

Tell me you live in the web bubble without telling it.

Post reply on HN