Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

251–260 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#251
post #242
post #228

Earlier quoted context omitted.

In Sweden we use BankID (there is a similar service with the same name in each Scandinavian country). It's impossibly convenient to be perfectly fair with you, however I know that my bank has stopped issuing the "BankID Card" (which was a card and pin device that allowed you to generate challenge numbers)- and now forces you to use the BankID app -- which will not run on rooted phones of course. It's even slightly wo…

BankID works great on GrapheneOS fortunately.

Interesting. Does this mean that it is using a lower level of Play Integrity API checking (ie not hardware attestation), or are they using the open hardware attestation API (which... exists but is almost never used)?

https://grapheneos.org/articles/attestation-compatibility-gu...

Re: Uncomfortable Questions About Android Developer Verification

#252

Earlier quoted context omitted.

It's the ecosystem. Without an ecosystem there will be less adoption and consequently less investment in the OS. Where I stay, so many services offered exclusively through Android/iOS apps with no alternative. Even government services are slowly excluding the web and becoming app only. There is an implicit expectation from everyone that one will have either an Android/iOS device and this only becomes stronger with ti…

Interestingly, we are, and have been, at a point were you can publish applications that run on any OS for a while, with PWAs. There are very few software examples, that couldn't be distributed as PWAs, including secure things like banking, etc. With WASM in the mix as well, theoretically the sky should be the limit. Even more interestingly it hasn't happened - mainly because Apple and Google haven't got behind PWAs f…

If banks were to offer PWAs, they would probably demand something like Google's Web Environment Integrity proposal - or would be convinced by Google that they need it.

Re: Uncomfortable Questions About Android Developer Verification

#253
post #221
post #73

Earlier quoted context omitted.

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

In Europe there are, e.g. at least some subsidiaries of Societe Generale, which have closed their Web sites on which their online banking services were previously available, and which refuse to provide their mobile apps otherwise than through the Google Store.

I doubt very much that it is possible for this practice to be legal, i.e. to condition the services of an European bank of the existence of a contractual relationship with a third party, which is non-European.

Nevertheless, nobody has enough spare time and money to challenge legally such banks.

Now I do my operations mostly through other banks that still have browser-based online banking, but I have not closed yet my last account at such a Societe Generale subsidiary, because I have regressed to use an antique SMS-based substitute for online banking, which is good enough for that account, which I keep only for a credit card used mostly for shopping in supermarkets or the like.

Re: Uncomfortable Questions About Android Developer Verification

#254

The requirement of verification to side-load any app is fascist control. It is clear as night and day. Shame on Google and Apple, it was always clear this was the end goal and next up is also your PC. Right after will come the removal off apps they don't like and there is nothing you can do about it. Stallman was right

I'm all for calling out fascist behavior when it is spotted, but let's not muddy the waters further. This word is already denatured enough. This is not fascism, this is just a rational move from Google in a market economy. It feels like every time something like this happens, Americans rediscover what capitalism is and implies, then blame it on "human nature", "greed" or "fascism".

Google's stated reason for doing this says nothing about it being for market reasons, but rather for "security".

Re: Uncomfortable Questions About Android Developer Verification

#255

The requirement of verification to side-load any app is fascist control. It is clear as night and day. Shame on Google and Apple, it was always clear this was the end goal and next up is also your PC. Right after will come the removal off apps they don't like and there is nothing you can do about it. Stallman was right

I'm all for calling out fascist behavior when it is spotted, but let's not muddy the waters further. This word is already denatured enough. This is not fascism, this is just a rational move from Google in a market economy. It feels like every time something like this happens, Americans rediscover what capitalism is and implies, then blame it on "human nature", "greed" or "fascism".

> This is not fascism, this is just a rational move from Google

Google is not very separable from the US government, and they use illegal monopoly everywhere without any oversight.

Re: Uncomfortable Questions About Android Developer Verification

#256
post #228
post #221

Earlier quoted context omitted.

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

In Sweden we use BankID (there is a similar service with the same name in each Scandinavian country). It's impossibly convenient to be perfectly fair with you, however I know that my bank has stopped issuing the "BankID Card" (which was a card and pin device that allowed you to generate challenge numbers)- and now forces you to use the BankID app -- which will not run on rooted phones of course. It's even slightly wo…

It is quite possible that you still may be able to obtain it by annoying them - in some cases provisions related to supporting disabled peoples can prevent them from fully getting rid of it.

On the last change my bank made me call to their hotline (even though everything else is possible to be done online) to keep using a separate hardware device - which ended up being just "so, you don't want to do it on a phone?" - "yep" - "ok, should be with you in a week or so".

I nowadays consider my phones pretty much throwaway devices - I don't have full control, I can't fully trust them. Plus they could be stolen, break when I drop it into water outside, ... - so I think it's ridiculously stupid to tie anything important to a phone as main authenticator.

Overall the usefuleness of a phone has been declining steadily - the selling point of a smart phone originally was that I have an app, and because it's a reasonably trusted device it'll store credentials, and I can use the app without logging in every time. By now most of the apps are just repackaged websites, and because of that - and because they don't trust their backends - we now have quickly expiring tokens in use in the apps as well. Most of the apps I don't use every day - and over the last few months every single one wanted me to log in again next time I used it.

Adding to that the nonsense of "there's a new app available, download that first before using" which typically doesn't add anything of value to me, and we're now at a state that not only does the typical smart phone app not offer a benefit over just using a website - it now often is even worse than just using a website.

Re: Uncomfortable Questions About Android Developer Verification

#257
post #154

Earlier quoted context omitted.

last time I walked into the bank to do something, they tried to peddle their app. I giggled and said no, their developers don't understand security. my phone is rooted and their app won't work.

It's their security and not your security, don't mix up

and yet their website works fine on my desktop Linux using a browser...

Re: Uncomfortable Questions About Android Developer Verification

#258
post #189

Earlier quoted context omitted.

Mobile OSs are very consumer focused. I have criticized the FSF for, in there lengthily argued ways, abandoning the consumer. You have to commercialize openness if you want the muscle of the consumer to be able to produce it. Short presentation of the basic concept: https://youtu.be/SO46oEdlkY8 Some things with massive value in excess of the cost of production cannot be pursued by capital nor bought by the individual…

That's a very clear vision on how to solve this kind of funding/cooperation problem outside of government and mission-focused nonprofits. And incidentally would be an existential threat to surveillance capitalism should it reach critical mass. BTW your password-based signup flow isn't working (on iOS Safari at least).

:-) Yeah. Only SSO was working because while email would double my users, I was doing an experiment and looking for at least some signs of life. Doubling nothing would be useless.

Turns out, some new enrollments topped up their accounts and dropped off before the final step that makes it show up on the home page, so now I know it's something, and something is worth doubling.

> existential threat to surveillance capitalism

Should I buy a gun? I'm an American.

Re: Uncomfortable Questions About Android Developer Verification

#259
post #114

Earlier quoted context omitted.

> The requirement of verification to side-load any app is fascist control. Even the language we are using to describe the situation is problematic. Why do we say "side-load an app"? It should be just "run a program"! An OS that doesn't let you run programs of your choice is laughable.

I think I have an old comment about this, but there is an actual `adb sideload` command for installing an apk on your phone from your computer . Since it's from your computer and not the phone itself, it's sideloading and not frontloading, I guess. Weirdly, and wrongly, people have also started to use the term to refer to just installing apps from outside the official appstores, but that's not sideloading. It's just…

I always used "adb install" to install programs on my phone from my PC. I never heard of the "adb sideload" command, but my search results [1][2] indicate that the second command is for installing things from the recovery mode, when you don't have the full Android system running. So "install" is the command for installing programs under normal circumstances using the Android installer.

[1] https://android.stackexchange.com/a/84248

[2] https://www.androidauthority.com/how-to-use-adb-android-3260...

Re: Uncomfortable Questions About Android Developer Verification

#260
post #221
post #73

Earlier quoted context omitted.

I could be one of the people running an ungoogled phone, but my bank refuses to have an app that runs on an ungoogled OS for "security"

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

Bunq comes to mind, I'm guess N26 and Revolut are similar, app first "fin-tech" banks.
Post reply on HN