Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

241–250 of 927 posts

Re: Your phone is about to stop being yours

#241

Earlier quoted context omitted.

Just to play devils advocate, the petition is a bit of FUD too, no? I ask as an F-droid user and downloader of unofficial apks. Speaking purely from my own experience, all the side-loaded apps I care about are fungible; I could get them or similar quality equivalents from GPS. With the exception of a 4chan reader, that hasn't been hosted there and likely won't be. I don't mind the 1 day wait too much. I understand po…

> I don't mind the 1 day wait too much. I do. It's my device. And I've been in the position of having to buy a replacement phone in a pinch; having to wait an extra day before having a usable replacement is not acceptable. In terms of apps I might not be able to get from the Play store: - Signal, depending on what country I'm in in the future and whether they've tried to restrict things they can't backdoor. - Vanilla…

I'm gonna try out Vanilla Music now. FWIW I use Musicolet from GPS and it's quite nice. I hope to learn whether and how our criteria intersect by exploring Vanilla....

Update: out of the box it seems to be reading tags strangely. Maybe I could fix this studying the settings more, but I'd say you have an upgrade opportunity switching off Vanilla. Signal is hard to replace though.

Re: Your phone is about to stop being yours

#242
post #211

Earlier quoted context omitted.

Or choose freedom. I've been enjoying GrapheneOS for a couple of years now and recommend it.

Graphene sounds great in theory. Until you read the device compatibility page and see you're still at the mercy of Google. In order to support graphene you must first pay Google for one of the most expensive android devices on the market. Oh and Google never sold this device in my country so I guess I'm out of luck even if I wanted to do that.

This will not help you in your country, but in places where it is sold, you can buy used one of the prior generation phones, which are also supported.

Re: Your phone is about to stop being yours

#243

The author as well as commenters in this thread are claiming that people choose Android over iOS or vice versa One could argue this is false dichotomy These people are actually choosing a particular form factor with particular specifications that, more or less, only runs corporate mobile OS^1 instead of form factors that run non-corporate OS 1. Or some derivative of one that relies on the corporate distributor and re…

Right on the nose. And to make that problem worse we've integrated a fair share of our lives into these devices, for which there is only 2 terrible choices. I can't tell you how many friends have expressed to me that they'd love to try GrapheneOS or get out of the mobile ecosystem entirely, but all of them use mobile apps for banking which effectively locks them in. It's basically the devil's bargain because we've added so much ease of use functionality to our day to day lives through these devices. In exchange Google is now showing us it was never ours to begin with.

Re: Your phone is about to stop being yours

#244

Earlier quoted context omitted.

Includes status symbol and ecosystem lock!

So does Android, but without the status symbol, the high res screen, or the integration with your laptop.

I haven't found the need for deeper integration with my laptop beyond what KDE connect is capable of, and my Pixel has a high enough resolution that I can't notice pixels :)

Re: Your phone is about to stop being yours

#245

Earlier quoted context omitted.

The openness of Android also acts as a check of sorts on how restrictive the walled garden can get. If google were to clamp down on useful functionality in the play store, then you could always install apks yourself. But if the latter is no longer an option, then there's much more temptation to google for the former.

I get the feeling that clamping down on useful functionality is often an unfortunate side-effect of closing down paths that are being exploited by criminals to harm users. What should Google do when a change they are making to protect regular less-technical users breaks functionality needed by more advanced users?

The problem with the toxic max-security[0] arguments is that it is always possible to invent a more gullible fool. There is no security measure that will perfectly protect a user from getting scammed out of everything, save for scamming them first and then treating their property as your own. That's the Apple argument. The only way you can keep people secure without falling into the same rhetorical trap Apple employs is with bright red lines that you swear not to cross, no matter how many people wind up getting scammed, because at the end of the day, people are adults, and their property is theirs.

Furthermore, we have to acknowledge that scam-fighting is not Google's job. They can assist with law enforcement (assuming they do not violate the rights of their customers while doing so) but they should not be making themselves judge, jury, and executioner in the process.

If you want a more concrete technical recommendation, locking down device management profiles would be a far more effective and less onerous countermeasure than putting a 24-hour waiting period on unknown app installs. Device management exists almost exclusively for the sake of businesses locking down property they're loaning out to employees, but a large subset of scams abuse this functionality. Part of the problem is that installing a device profile is designed to sound non-distressing, because it's "routine", even though you're literally installing spyware. Ideally, for a certain subset of strong management profile capabilities, the phone should wipe itself (and warn you that it's going to wipe itself) if you attempt to install that profile.

[0] https://tom7.org/httpv/httpv.pdf

Re: Your phone is about to stop being yours

#246

Earlier quoted context omitted.

I'm considering switching to GrapheneOS... What's this about RCS not working?

RCS can be hit or miss on GrapheneOS, but they have made significant progress recently. It requires using Google Messages rather than any other messaging app, and may require enabling an ICC authentication option that is disabled by default. And it may depend on your carrier. RCS is kind of a pain in the butt but the messaging improvements over SMS are substantial which is why I wanted it. When I first tried last fal…

I've found that RCS works ok-ish on the Owner user, but doesn't work at all on any other (it appears as an empty message). Moving to the Owner account you can tap to redownload the message and then it appears correctly in all accounts. It's a mess that makes daily driving a secondary account not worth it

Re: Your phone is about to stop being yours

#247
post #199
post #91

Earlier quoted context omitted.

I will say, an underrated use case for even small, local LLMs is making command line tools drastically more accessible to laypeople I now know zero people I don't think should use linux, and people I know seems to run quite a gamut of technical know-how compared to most other technical folks I know

Having an LLM directly and autonomously drive command line tools outside of a strict sandbox sounds like a ticking time bomb. Thinking tokens: "The files I'm trying to read are missing, I need to figure out why. I see the problem, I accidentally ran rm -rf /home/user. Let me run git restore. No that didn't work. Let me try git reset --hard origin/HEAD. That still didn't work. I should inform the user." Output: "I was…

I tend to set people up with a chat interface, which is pretty good for asking for commands or scripts that the user will then copy into their terminal. Most people I've gotten to try linux do pretty well with just a wiki, but once they run into something they want to do that's kind of idiosyncratic they tend to ask me for help. While I think running models that have access to a shell is dangerous and should be handled carefully, the fact that they've been trained for this use case generally means they're pretty good at shell commands and can give you one a decent chunk of the time. I'm never willing to inject an external dependency controlled by a company into people's computing needs unless they specifically ask for it, so this is usually a lightweight local model specialized in tool use, but not given shell access. This isn't much different from how they'd use search engine for this purpose these days, but if running locally, it can be more fault-tolerant to issues that affect their internet access as well as offering better privacy guarantees, albeit obviously a little less capable

Re: Your phone is about to stop being yours

#248
post #186

Earlier quoted context omitted.

Because it's their creation.

I don't know if that is sarcasm, but a chair I buy is mine to do whatever I want with it. Same goes for clothes, a mattress, paint, or any other non-software enabled physical item. Why does having software/hardware make a difference?

Because your clothes and paint do not need security updates, since they do not talk to the internet. Your mattress cannot be made part of a botnet.

Re: Your phone is about to stop being yours

#249

Earlier quoted context omitted.

For how long will ADB work? Obviously Google doesn't want user to install apps outside of their control

Google doesn't want millions of people to have every cent of their money stolen. This measure is about making it harder to pull off a specific type of scam that is plaguing South East Asia. No conspiracy. For actual information on the purpose of this change rather than conspiracies, I refer you to https://android-developers.googleblog.com/2026/03/android-de... Since the victims of these scams do not typically own a t…

With that reasoning every action would be justified to stop scammers. Google should capture all your calls and check if there could be scamming going on, right?

The current malware situation at android store situation does not help to carry that point:

> https://www.forbes.com/sites/daveywinder/2025/03/18/60-milli...

> https://www.theregister.com/2025/08/26/apps_android_malware/

> https://www.androidheadlines.com/2026/04/novoice-android-mal...

Re: Your phone is about to stop being yours

#250

My position regarding devices is that only 2 out of 3 should be satisfied: 1. Used as a proof of identity (for banks, govt services, etc.) 2. Is distributed to laypeople who have more pressing concerns in their lives than security. 3. Is an open platform where you can download apps arbitrarily from the Internet that can read your data and exfiltrate them to a malicious actor. The mainstream today chooses 1&2. Novelty…

I take issue with the idea that openness and freedom to install arbitrary software cannot occur without strong safety mechanisms. Android/GrapheneOS/iOS have sandboxing and permissions systems that put most desktop OSes to shame. The base platform can control apps' access to every resource, and an app store can put its own caveats and reminders to users for what kind of access is needed for the functions of a given a…

Sandboxing and permissions provide a different type of security than application signatures. Sandboxing can limit app capabilities, but it doesn't change the fact that you can accidentally grant a malicious application permissions.

Application signatures and developer identification bring a different kind of application security. It provides the security of societal legal systems and legal ramifications for malicious actors.

In the end, you still have the choice to trust the "system" or your own judgment.

Post reply on HN