Earlier quoted context omitted.
My government ID card expired and I was too lazy to renew it but I had my passport at hand so why not? BTW both the id card and the passport have cryptographic authentication and you are able to open a bank account or use govt services completely online by scanning it with the phone Rfid . They could have make me scan that, scan my face and be done with the identity verification. My identity is already verified and t…
That all makes perfect sense but consider that if they simply punted to the bank as I described they would still get the same benefits only with even less complexity. The bank fundamentally has to do robust identity verification. Any party that needs to handle payments while also lacking a reason to be good at performing in house identify verification really ought to make use of the bank because you are highly unlike…
Android Developer Verification
231–240 of 345 posts
Re: Android Developer Verification
#232Earlier quoted context omitted.
I'm wondering if the EU is complicit in this somehow, despite claiming that they want to fight back against tech companies. The EU Commission is currently pushing the shitty EU Identity Wallet for mandatory age verification, and it requires GooglePlay Services to be installed for "anti-tampering". That also means a ban on non official versions of Android like LineageOS and GrapheneOS.
The DMA team replied to me that they did not see any legal issues with Google enforcing mandatory ID for sideloading apps. We need an urgent upgrade of the DMA v2.O, in the fast paced Omnibus package. Feel free to post proposals here.
30 years ago, the Linux community fought the pre-installed Windows tax and mostly lost that fight.
Re: Android Developer Verification
#233Re: Android Developer Verification
#234Earlier quoted context omitted.
Is it because people genuinely don't care, or because the barrier to become a power user is becoming taller and taller every passing year?
Is it because Android literally has billions of users across the world.
Re: Android Developer Verification
#235Earlier quoted context omitted.
My government ID card expired and I was too lazy to renew it but I had my passport at hand so why not? BTW both the id card and the passport have cryptographic authentication and you are able to open a bank account or use govt services completely online by scanning it with the phone Rfid . They could have make me scan that, scan my face and be done with the identity verification. My identity is already verified and t…
That all makes perfect sense but consider that if they simply punted to the bank as I described they would still get the same benefits only with even less complexity. The bank fundamentally has to do robust identity verification. Any party that needs to handle payments while also lacking a reason to be good at performing in house identify verification really ought to make use of the bank because you are highly unlike…
The authorization is not transitive so to say.
>As an aside, I suspect that leaving it to the bank would also provide additional legal protection
If it would, they will have to pay the bank for it and the bank should also be willing to accept the liability (spoiler alert -- the will not be willing to accept the liability)
Re: Android Developer Verification
#236Earlier quoted context omitted.
I’ve never found a malicious app on F-Droid.
To be honest the limited popularity of F-Droid also helps it be less targetted by bad actors. If it was more popular I would bet the situation would surely be different
Re: Android Developer Verification
#237Earlier quoted context omitted.
Yeah I would imagine that the value the get out of a passport is not anything to do with validating a company (they’re cheap and easy to make anyway) but validating the person (which is not a throwaway entity)
Fair point. However that invites those bad scenarios where someone gets blacklisted by BigTech in some manner, later gets hired by a small business, the new employer adds an association to the blacklisted account, and suddenly the company app is banned from the app store seemingly without reason. At least a few such stories have appeared on HN over the years. I feel like pay to play ought to be sufficient because in…
Which is not that unreasonable even. If a person is flagged for making scam apps, them having publishing rights in a reputable place makes taints the reputation of such place.
You should be able to appeal of course and the oauth should not be towards google in the first place, but being associated with known fraudsters and scammers is not what you want.
Re: Android Developer Verification
#238Re: Android Developer Verification
#239Re: Android Developer Verification
#240Earlier quoted context omitted.
F-Droid is in fact what an app store concerned about user safety looks like. Nobody gets hoodwinked into installing apps that track them or sell their data or otherwise abuse them on F-Droid.
F-Droid is so irrelevant that it doesn't even begin being targeted by supply chain and scam attacks. Being obscure always help with this, but pretending that it's the same threat model is absolutely false.