Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

231–240 of 345 posts

Re: Android Developer Verification

#231
post #168

Earlier quoted context omitted.

My government ID card expired and I was too lazy to renew it but I had my passport at hand so why not? BTW both the id card and the passport have cryptographic authentication and you are able to open a bank account or use govt services completely online by scanning it with the phone Rfid . They could have make me scan that, scan my face and be done with the identity verification. My identity is already verified and t…

That all makes perfect sense but consider that if they simply punted to the bank as I described they would still get the same benefits only with even less complexity. The bank fundamentally has to do robust identity verification. Any party that needs to handle payments while also lacking a reason to be good at performing in house identify verification really ought to make use of the bank because you are highly unlike…

I agree, in Europe(EU, UK, Turkey and other countries) banks are considered perfect for proof of ID. In UK a bank statement is as good as an ID, in Turkey for example, you can sign in into the government portal through your online banking and it is considered higher level secure authentication and you can take high risk actions(like signing legally binding contracts) that you can't do by signing in just with password and 2FA.

Re: Android Developer Verification

#232
post #229

Earlier quoted context omitted.

I'm wondering if the EU is complicit in this somehow, despite claiming that they want to fight back against tech companies. The EU Commission is currently pushing the shitty EU Identity Wallet for mandatory age verification, and it requires GooglePlay Services to be installed for "anti-tampering". That also means a ban on non official versions of Android like LineageOS and GrapheneOS.

The DMA team replied to me that they did not see any legal issues with Google enforcing mandatory ID for sideloading apps. We need an urgent upgrade of the DMA v2.O, in the fast paced Omnibus package. Feel free to post proposals here.

On the DMA, I have said that it does not go far enough, the Operating System (OS) market should be opened up, with a regulation in place so that alternative mobile and non-mobile OSes can be installed by the end user, notably by the mandatory registration and publication of technical hardware specifications, unlocking of bootloaders, etc...

30 years ago, the Linux community fought the pre-installed Windows tax and mostly lost that fight.

Re: Android Developer Verification

#233
post #216
post #209

Earlier quoted context omitted.

Are you really unable to comprehend just how small of a userbase F-droid represents for Android ecosystem?

If it’s that small, how does killing it help anything?

Nobody said it did. Google is not doing this to kill F-Droid.

Re: Android Developer Verification

#234
post #211

Earlier quoted context omitted.

Is it because people genuinely don't care, or because the barrier to become a power user is becoming taller and taller every passing year?

Is it because Android literally has billions of users across the world.

Especially once you start counting car entertainment systems, POTS terminals, digital signage, and hundreds of other classes of devices that are not genera-purpose toys.

Re: Android Developer Verification

#235
post #168

Earlier quoted context omitted.

My government ID card expired and I was too lazy to renew it but I had my passport at hand so why not? BTW both the id card and the passport have cryptographic authentication and you are able to open a bank account or use govt services completely online by scanning it with the phone Rfid . They could have make me scan that, scan my face and be done with the identity verification. My identity is already verified and t…

That all makes perfect sense but consider that if they simply punted to the bank as I described they would still get the same benefits only with even less complexity. The bank fundamentally has to do robust identity verification. Any party that needs to handle payments while also lacking a reason to be good at performing in house identify verification really ought to make use of the bank because you are highly unlike…

The bank has to perform the authorization and identity checks, but the bank will not make them for you, they do them for themselves based on their own risk analysis. The scope of authorization could also be different based on who it's presented to.

The authorization is not transitive so to say.

>As an aside, I suspect that leaving it to the bank would also provide additional legal protection

If it would, they will have to pay the bank for it and the bank should also be willing to accept the liability (spoiler alert -- the will not be willing to accept the liability)

Re: Android Developer Verification

#236
post #177

Earlier quoted context omitted.

I’ve never found a malicious app on F-Droid.

To be honest the limited popularity of F-Droid also helps it be less targetted by bad actors. If it was more popular I would bet the situation would surely be different

This argument can be refuted by considering Debian repositories. No malware exists there despite it being a good target. It's the FLOSS that solves the malware problem, with a bit of moderation.

Re: Android Developer Verification

#237

Earlier quoted context omitted.

Yeah I would imagine that the value the get out of a passport is not anything to do with validating a company (they’re cheap and easy to make anyway) but validating the person (which is not a throwaway entity)

Fair point. However that invites those bad scenarios where someone gets blacklisted by BigTech in some manner, later gets hired by a small business, the new employer adds an association to the blacklisted account, and suddenly the company app is banned from the app store seemingly without reason. At least a few such stories have appeared on HN over the years. I feel like pay to play ought to be sufficient because in…

>suddenly the company app is banned from the app store seemingly without reason. At least a few such stories have appeared on HN over the years.

Which is not that unreasonable even. If a person is flagged for making scam apps, them having publishing rights in a reputable place makes taints the reputation of such place.

You should be able to appeal of course and the oauth should not be towards google in the first place, but being associated with known fraudsters and scammers is not what you want.

Re: Android Developer Verification

#240
post #213
post #60

Earlier quoted context omitted.

F-Droid is in fact what an app store concerned about user safety looks like. Nobody gets hoodwinked into installing apps that track them or sell their data or otherwise abuse them on F-Droid.

F-Droid is so irrelevant that it doesn't even begin being targeted by supply chain and scam attacks. Being obscure always help with this, but pretending that it's the same threat model is absolutely false.

Are Debian repositories also irrelevant? If not, why aren't they targeted?
Post reply on HN