Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

221–230 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#221
post #73
post #19

Earlier quoted context omitted.

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way.

I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

Re: Uncomfortable Questions About Android Developer Verification

#222
post #60

I know I risk being down voted remorselessly but I have to put this in context. Where in the real world is anonymity considered ok? If I only put a flyer through someone's letterbox here in the UK, I have to identify myself. If I sell a physical product I not only have to identify myself but take on serious legal liability. An author can take on a pseudonym but only via an identified publisher. In fact that latter ex…

> If I only put a flyer through someone's letterbox here in the UK, I have to identify myself. Has the UK gotten rid of public postboxes? Do you have to present government-issued ID to post a letter, flyer, or other mailpiece? Do the UK post-handling companies check the sender's claimed name and address on the mailpiece and toss it in the trash if it doesn't correspond to a registered combination of name and address?…

> I've not seen anyone talking about the significance of the set of countries where this is rolled out to first: Brazil, Indonesia, Singapore, and Thailand

This was really interesting and somewhere there was a comment/quote that these countries are affected most with the malware distributed with side-loading, I can't find this comment now. But while trying to find some information, I found the info about 2023 Alphabet/states $700 m. settlement. It came mostly unnoticed on HN [1] (two posts, 2 comments), but there is interesting timings coincidence in the settlement text ([2])

  ...6.9.2 For a period of at least four (4) years from the Effective Date, Google will maintain the following functionality in Android version 14+ for Mobile Devices:
  (a) Google will support APIs that enable sideloaded app stores that have received User consent to install apps to avoid automatic updates taking place while the User is using the app....
2023 (settlement) + 4 years = 2027 (mentioned for other countries). This can be related to apps like F-Droid, this ruling might prevent Google from making F-Droid comply if the US was announced to meet the new rules earlier (before 2027). There are other formulas that might end up 2026/2027 when calculating so to be on the (legal) safe side, Google probably made US join later. Probably those countries are also for beta-testing both in the technical and legal sense.

The settlement might be interesting in other other respects also. Even the forces (the states, U.S Attorney) that drove the suit in 2021-2023 might join here though during this admin it's really questionable.

[1]: https://news.ycombinator.com/item?id=38691926

[2]: https://www.oag.state.tx.us/sites/default/files/images/press...

Re: Uncomfortable Questions About Android Developer Verification

#223

Earlier quoted context omitted.

> For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in them, is it on me? IDK, our government even has an identity app for iOS and Android. I should not be using it, I should stick to web. But its so much more convenient. I'm just weak, aren't I? Don't forget GrapheneOS, LineageOS and other de-googled FOSS Android Versions

These aren't GNU/Linux, they have to follow Google's development strategy. It's like fighting with Chrome by using Chromium.

Nobody was talking about GNU. Most don't care if the userspace utilties are gnu coreutils/libc or musl/busybox for example.

AOSP is free and open source software.

Re: Uncomfortable Questions About Android Developer Verification

#224
post #114

Earlier quoted context omitted.

> The requirement of verification to side-load any app is fascist control. Even the language we are using to describe the situation is problematic. Why do we say "side-load an app"? It should be just "run a program"! An OS that doesn't let you run programs of your choice is laughable.

I think I have an old comment about this, but there is an actual `adb sideload` command for installing an apk on your phone from your computer . Since it's from your computer and not the phone itself, it's sideloading and not frontloading, I guess. Weirdly, and wrongly, people have also started to use the term to refer to just installing apps from outside the official appstores, but that's not sideloading. It's just…

Yeah, words just change meaning and it's frustrating because people generally change them in ways that make their usage more sloppy, less precise. I've had multiple arguments on HN about this with the term open source, but unfortunately you've already lost the battle with sideloading, at least according to Wikipedia.

> When referring to Android apps, "sideloading" typically means installing an application package in APK format onto an Android device. Such packages are usually downloaded from websites other than the official app store Google Play. For Android users sideloading of apps is only possible if the user has allowed "Unknown Sources" in their Security Settings.[1]

Re: Uncomfortable Questions About Android Developer Verification

#225

Earlier quoted context omitted.

I have been running AOSP-based LineageOS and now GrapheneOS for more than a decade now. While some apps are restricted to Google-certified operating systems, most are definitely not. I can use my countries eID apps and my banking app without issue. The only thing not working is nfc payments (since they are limited to Google Wallet)

It doesn't matter if it's only some apps if those apps are critical. MyGov in Australia for example requires Play Integrity or it crashes. Your government's app does not... for now. The grip of Google, Microsoft and Apple are tightening. Microsoft's TPM requirements for Windows 11 are ostensibly for security, but they're also a mechanism to enforce hardware/software integrity and authentication. Google wants to exten…

> Your government's app does not... for now.

My govt's app did, but after bugging them a lot they removed safetynet.

Re: Uncomfortable Questions About Android Developer Verification

#226

This is intolerable. You own the device. You must be able to run whatever you want on it. Locking or limiting your access to the stuff you bought is not only unacceptable, it's basically like saying you don't really own anything. You're basically leasing a device until the OEM decides you can't run anything on it anymore. Would people accept if a car manufacturer prohibited you from driving their cars in certain plac…

What's crazy is I can buy a video game license on steam and am permitted to mod it. Leasing precedence seems hidden in there sonewhere

Re: Uncomfortable Questions About Android Developer Verification

#227
post #221
post #73

Earlier quoted context omitted.

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

> I have never heard of a bank that has a hard requirement of a mobile app

My bank's app recently started warning me that I should "Turn off developer mode" for """security""" on every sign-in. This warning doesn't stop me from using the app yet, but I'm sure it'll get there.

Re: Uncomfortable Questions About Android Developer Verification

#228
post #221
post #73

Earlier quoted context omitted.

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

In Sweden we use BankID (there is a similar service with the same name in each Scandinavian country).

It's impossibly convenient to be perfectly fair with you, however I know that my bank has stopped issuing the "BankID Card" (which was a card and pin device that allowed you to generate challenge numbers)- and now forces you to use the BankID app -- which will not run on rooted phones of course.

It's even slightly worse as the App requires NFC; so I can't keep a backup on my iPad (which is what I was doing before).

Re: Uncomfortable Questions About Android Developer Verification

#230

Earlier quoted context omitted.

Back in the 90s Sun sold you computers with X amount of space. There was an option to upgrade. If you took it, they sent a technician around to do the upgrade. All they did was making the already existing space available. Sun always sold hardware with all the space installed but gave you only what you paid for.

I wonder if such actions can become a reason for persecution. Let me make an allegory: if I sold someone thing that is designed to break on purpose, and then requested pay for fixing it, it would be a felony. Why the remote downgrading is not considered a felony?

Has someone ever tried this in the court? Only question is the definition of 'broke'.
Post reply on HN