Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

191–200 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#191

The requirement of verification to side-load any app is fascist control. It is clear as night and day. Shame on Google and Apple, it was always clear this was the end goal and next up is also your PC. Right after will come the removal off apps they don't like and there is nothing you can do about it. Stallman was right

I asked an LLM, so I think I get it but could you try to mention what is meant with "Stallman was right"? The reason I'm asking you and not posting the LLM answer is because it still feels a bit icky to post an LLM answer for everything I don't understand [1]. [1] Feel free to discuss this too, if you want. I'm developing my opinion on it.

In this case it worked out well as a rhetorical device to make you look it up and learn something. Sometimes leaving out something for the reader to wonder about is more powerful.

Re: Uncomfortable Questions About Android Developer Verification

#192
post #153

Earlier quoted context omitted.

> For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. Why are you only listing DEs and not operating systems? (You also missed SXMo and more.) There are many more operating systems [0] and two working GNU/Linux phones, Librem 5 and Pinephone. Why people are ignoring them on HN? [0] https://pine64.org/documentation/PinePhone/Software/

PostmarketOS is, as the name implies, an OS. And I don't think OP was trying to make an exhaustive list. The point is, there's plenty of "competing" options, but hardly anyone uses them.

The parent started their message with "Why is it so complex to have a foss mobile OS", which is not wrong but pretty misleading, as there are many existing mobile OSes that work quite well.

Re: Uncomfortable Questions About Android Developer Verification

#193

Earlier quoted context omitted.

Stallman's fallacy is thinking every system is perfect and unbreakable and that people have a perfect understanding of software and systems (for better or for worse) People will be running pirated debugger copies if that comes to shove 99.9% of people DNGAF about OSS. They do care about doing what they need on their phone without malware/bloatware/nagware Also publishing and development are separate activities

I wouldn't bet on hackers saving us from everything. There are 150 million Nintendo Switches in the world, and nobody has figured out how to jailbreak one without getting into the hardware and shorting some wires (and even then only on early unpatched models). I don't think its out of the realm of possibility to make a best-selling phone that stays uncrackable for the general population for its entire lifecycle.

> I don't think its out of the realm of possibility to make a best-selling phone that stays uncrackable for the general population for its entire lifecycle.

It is surely possible if only because the general population is not interested in infosec.

On the gripping hand,firmware writing practices being that they are; it is impossible to produce an uncrackable phone.

Re: Uncomfortable Questions About Android Developer Verification

#194
post #40
post #14

I used to run Shizuku for my phone to run Hail (an app suspension tool). Now that my credit card bank start checking for USB Debugging I stopped using the app (and now my 3DS OTP has to be over SMS). I believe there's only two banks left in Thailand that do not check for one and it is just a matter of time, because any time these banks could have hired any of those "security" people who will ask why don't we block th…

Perhaps using the bank's website is an option? I don't have a banking app installed on my phone. When I need to make a bank transfer I sit down at the computer.

It's not an option on most Thai banks due to Bank of Thailand's regulations.

They requires that for any transaction past 50k THB per day (not per transaction) you'll need to provide face recognition. This means banks need to develop its internet banking solution past Web 1.0 era. From what I know (and I didn't do much research) most banks simply just shutdown internet banking instead of complying with that, only business banking get a separate website. My bank they simply merge the personal banking and corporate banking into a new system, but you still need to approve the transaction on a push notification (and perform face recognition).

It doesn't help that I believe many online casinos and scammers are scraping internet banking and even mobile banking APIs. There was a bank that apparently you could find PHP classes on GitHub that emulate their mobile app, and when that was in the news people were saying that the bank doesn't have proper security even though to use the class you'd need to provide exact same information in the app itself. Scammers used those code to move money from mules to mules, obfuscating the money's movement. The banks doesn't talk to each other either, so once the money goes through a few banks the chance you could trace it is almost none.

There was a court case that the court have ruled that if you were to get scammed to install apps on your phone that scam you for money, the bank is at fault as they have improper security. So they're heavily incentivize to protect users from themselves.

As for facial recognition, disabled people sent letters to Bank of Thailand, as legally blind people are not compatible with the liveness checks, the bank apps do block screen captures and refuse to work when any accessibility services is on and all BoT says about that is "we already told banks to do something" and the disabled people just send a second open letter this week, as many banks did nothing, some banks probably have a backend account flag to bypass the checks but didn't train the branch agents to perform such changes on the account.

Also Thailand has move into cashless - most local people don't use cash now except for small mom & pop shops that are doing dodging tax. Of course credit card is not accepted (or with minimum) - Thai business owners doesn't like fee no matter how small it is.

Re: Uncomfortable Questions About Android Developer Verification

#195
post #73

Earlier quoted context omitted.

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

My bank blocks my mobile with Lineage OS, and it's not even possible to login to the web site without the mobile app. Absolutely pathetic. Now I have to keep my 4 year old phone with 2 year outdated Android to access the bank application. Which deemed more safe then my mobile with latest security updates. Haha

You do have the option to change your bank when they consistently do dumb stuff you don't approve of. Shopping around will probably get you a better savings rate anyway.

Re: Uncomfortable Questions About Android Developer Verification

#196
post #69

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

You can buy a completely open RISC-V chip and debug to your heart's content. x86 is also completely open, with only special outliers like XBox/PS5 even half-heartedly trying to disable third-party access. So the "Right to read" is still bonkers.

"You [technically] can" is not good enough to declare the victory here. The downsides are so heavy that nobody can actually do it.

Re: Uncomfortable Questions About Android Developer Verification

#197
post #80
post #19

Earlier quoted context omitted.

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

> Why is it so complex to have a foss mobile OS. In a way it's not. As you mention, we have several of them. But they won't have mass-market appeal until they can run the same sorts of apps that Android and iOS can run. And no, "just use the mobile website" is not an answer. How do I deposit a check with my bank on my phone without the app? I can't; the mobile website doesn't have that functionality. How do I send so…

> Emulating Android sufficiently well enough to run Android apps is a decent start, but so many apps rely on Play Services and Play Integrity that it's a losing battle, or at best a cat-and-mouse game to keep things working.

This is where antitrust laws are supposed to come into play. Play Services are a pain but in principle you can implement alternatives to them. It's the attestation stuff which is aggressively anti-competitive -- literally setting up a system with the primary function of excluding competing implementations from compatibility.

We can't let corporations get away with the fraud that competing with them is a security vulnerability.

Re: Uncomfortable Questions About Android Developer Verification

#198

The requirement of verification to side-load any app is fascist control. It is clear as night and day. Shame on Google and Apple, it was always clear this was the end goal and next up is also your PC. Right after will come the removal off apps they don't like and there is nothing you can do about it. Stallman was right

One day people on the internet will learn what the term „fascism“ entails. This is just plain old government overreach.

"Government overreach" by a private corporation? Let's see what wikipedia has to say about that:

> A fascist corporation can be defined as a government-directed confederation of employers and employees unions, with the aim of overseeing production in a comprehensive manner.

https://en.wikipedia.org/wiki/Corporatism#Fascist_corporatis...

Google goes even further than that: they do not only control and oversee all production via the Play Store, they also control all usage of their products. And while it may currently not be government-directed, they certainly are government-protected as long as they're allowed to run the only app store in town.

Re: Uncomfortable Questions About Android Developer Verification

#199

Earlier quoted context omitted.

>I'm not aware of any major issues this has caused Decades of desktop malware used to drain bank accounts are not a major issue?

You'd need to make a case that proprietary OSes such as Windows or MacOS lessen the issue compared to FOSS OSes such as Linux. I doubt it considering that Windows is / was known to be the worst offender here. In any case my bank has not banned the use of Linux to do homebanking. Why? Because there isn't a easy to plug-and-play API to do DRM and remove consumer rights. This is largely for historic reasons, but there i…

In all fairness, a FOSS mobile os does for the most part work. Banking is pretty much the only big mainstream acception here. Most other exceptions are games with aggressive anti-cheat, or app simply not distributed outside a closed down store like Google play.

Re: Uncomfortable Questions About Android Developer Verification

#200

The requirement of verification to side-load any app is fascist control. It is clear as night and day. Shame on Google and Apple, it was always clear this was the end goal and next up is also your PC. Right after will come the removal off apps they don't like and there is nothing you can do about it. Stallman was right

I'm absolutely against this and for similar reasons have boycotted Apple for my entire life on hard ideological grounds, but not everything is "fascist" lol. Don't misuse the term.

In any case, I hope this blows up in Google's face hard, ROMs like LineageOS become as popular they were back in their heyday, and root hiders get extra attention too so banking apps etc work seamlessly as on non-rooted phones. Requiring some developer ID crap is essentially as bad as Apple has it, reason for which I've always considered developers having Apple phones quite unserious.

Post reply on HN