Live data from Hacker News

A theoretical way to circumvent Android developer verification

enaix.github.io

171–180 of 185 posts

Re: A theoretical way to circumvent Android developer verification

#171
post #97

This is actually a non-issue with tons of unnecessary fear mongering going around, see my comment here: https://github.com/enaix/apk-loader/issues/1

The OP addressed this: `adb` works ... *for now*. Other than google's pinky promise, what assurance do we have that adb will continue to work in a year or five?

The settings app lets you disable package verifiers for adb installs. The settings app is part of the operating system and can not be updated via the play store. This means that Google can not update the settings app.

Re: A theoretical way to circumvent Android developer verification

#172

Earlier quoted context omitted.

It appears that you are an American who has conveniently forgotten about FISA, EARN IT, CLOUD act, PATRIOT act, LAED, etc, etc, and wants to take a dig at the EU for what, exactly? NOT passing Chat Control? Seriously..

I do not think it is righteous or enlightened when the American government flexes control over the tech sector. I can see how Europeans might have thought this about the EU when it was just GDPR, but subsequent developments have recast all of this as being about government control and keeping the tech industry “in its place” rather than a commitment to privacy and freedom in and of themselves. I think that ought to t…

What subsequent developments? It sounds like you are alluding to the DMA.

The DMA is an attempt to reclassify what “market” means in the modern age where we have a global tech oligopoly. This is because a simple “test” for monopolism doesn’t work in this world of multinational megacorps.

Again, your complaint is a double standard. You are doing similar in the USA - albeit without an actual structured act - as per the recent rulings on the Google Play store.

The EU has simply codified the rules for their vision of the future where people aren’t beholden to a handful of tech overlords, whereas the USA is making similar incremental “changes” through case-law. I’m not saying either way is correct, but it seems like they are both headed in the same direction.

Re: A theoretical way to circumvent Android developer verification

#173

Earlier quoted context omitted.

The point isn't that GrapheneOS is bad but rather that it doesn't imply there is anything wrong with LineageOS when it's still better than Android itself. Moreover, some of the stuff with green boxes is still kind of a privacy fail. For example, with GNSS (i.e. GPS) your device calculates its location from the timing of radio broadcasts emitted by a network of satellites. It has extremely good privacy properties beca…

GOS developers have said on multiple occasions that they think LineageOS is worse for security than the stock OS on multiple devices, as it doesn't keep up with current privacy/security patches or provide all of the standard protections. The comparison also does bring up these faults. See also https://www.kuketz-blog.de/lineageos-weder-sicher-noch-daten...

"Device does not force you to update" isn't a bug. The bug is "device forces you not to update" which is the thing you get with stock Android on the large majority of Android devices.

Their objections in general seem to be fairly pedantic, e.g. objecting to a connectivity check which could be improved in a theoretical sense but in practice that shouldn't be leaking anything you're not already giving up by having a phone which is turned on and connected to a cellular network.

Re: A theoretical way to circumvent Android developer verification

#174
post #135
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

It would be hard to find manufacturers to use it. None of the existing Android phone manufacturers would be able to release phones with this fork without also abandoning the official Android platform on all markets. Google are very strict with this in their tos. You cannot release devices using non official Android builds without losing your right to use GMS and Android Brandice on your other Android devices.

This can also easily be framed as anticompetitive.

Re: A theoretical way to circumvent Android developer verification

#175
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

> Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task if Google would want to go that route. This is actually the advantage of doing it. You make the thing (call it a "personal app loader" or something rather than a "circumvention tool"), they ban it, now you campaign against them or make antitrust arguments presenting the ban as an anti-…

They (google) could cite the loader being "exploited" to run "dangerous" apps like viruses/malware, and bypass the monopoly issue.

I do think having a technical bypass is good - it isn't mutually exclusive with also having a legal bypass. I just hope that the gov'ts are smart enough, and agile enough, to make this happen before it becomes too late (aka, once the gates close, it will never open again, like apple's ecosystem).

Re: A theoretical way to circumvent Android developer verification

#176
This is a neat hack, and I don't want to diminish the effort. But I fear that any such loader apk would be marked as malware by Google and nuked by Play Protect Services.

And as others mention, using adb (or Shizuku) might also be a workaround for tech-savvy users (for the time being). We list some other potential temporary workarounds at https://keepandroidopen.org. But none of it is viable for the other 99%.

There's really no solution to the dilemma other than stopping Google from implementing it altogether. And for that, we need regulatory action — which means we need to advocate and educate consumers and lawmakers about the threat that this poses.

Re: A theoretical way to circumvent Android developer verification

#177
post #26

Earlier quoted context omitted.

Then Apple should get sued for bundling Safari, and also for forcing all browser engines on iOS to use Safari - which is way worse than anything Microsoft ever did with IE.

Apple does not have a platform monopoly on smartphones the way Microsoft did on PCs.

Why do you think Apple blocks all web browsers from using their own browser engines and forces all browsers on iOS to use Safari? And no, the answers do not include "because privacy" or "because power usage".

People should be free to use other browsers and accept higher power usage, or "privacy risk" without Apple forcing their own browser engine, which limits functionality of all web browsers on iOS.

What Microsoft did by bundling IE with windows was far less egregious. Could you imagine if Microsoft forced all browsers on Windows to use IE as a webview? Holly shit people would be rightly pissed.

Apple does this specifically to prevent competition from web applications so that developers have to use Apple's app store, where Apple can charge the developer/customer money. It's spelled out in the DOJ lawsuit against Apple.

https://www.justice.gov/archives/opa/media/1344546/dl?inline

Re: A theoretical way to circumvent Android developer verification

#178

Earlier quoted context omitted.

PWAs are at the mercy of Gapple have always been handicapped in just the right places to not be viable vs installed apps. Most people don't even know how to install one.

Yeah but as I understand it Apple has become a lot more progressive on PWAs in the last few years. I’m under the impression theyre viable

The recent change is you can do push notifications with them now, but still

Re: A theoretical way to circumvent Android developer verification

#179
post #169

Earlier quoted context omitted.

If you're happy to purchase a SIM card, register it in your name, and hand it to someone else for them to use, go right ahead. Q: Who's paying the bills for that SIM?

I was referring to this part > > The ID presented at time of purchase does not have to be the ID of the actual user of the card >In some EU member states this might be fine, but definitely not all It seems hard if not impossible to prevent or stop?

> It seems hard if not impossible to prevent or stop?

Thought experiement: you can buy and register a car, and then lend it to someone else to use.

That's certainly "hard if not impossible to prevent or stop" and might seem fine ... right until the point when it isn't fine any more.

At which point the police will come to knock on your door (first).

Re: A theoretical way to circumvent Android developer verification

#180
post #77

Earlier quoted context omitted.

Surely others may use your phone?

If you're happy to purchase a SIM card, register it in your name, and hand it to someone else for them to use, go right ahead. Q: Who's paying the bills for that SIM?

> Q: Who's paying the bills for that SIM?

You can anonymously buy top-up vouchers in supermarkets for pay-as-you-go SIMs.

Post reply on HN