Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

261–270 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#261
post #19

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

Because it's actually your telco's phone. They're the one that has the license to run the baseband computer and RF transceiver. The 'pad' computer device is sort of yours. But there's no legal way to have ownership of a cell phone unless you yourself bid for and get the RF spectrum and set up your network in a way that accomplishes the FCC coverage and timing requirements. Then run your own telco for your phone. Basically, impossible.

Smart phones try to limit and firewall the interface between the two but tight integration is required for energy efficiency. So a smart phone, or a cell phone, can never be yours. They aren't good choices for doing computing and this legal reality is becoming more and more obvious with time.

Re: Uncomfortable Questions About Android Developer Verification

#262

Earlier quoted context omitted.

Thanks, I wasn't trying to cherry pick or anything. But I don't think that the full text changes the substance of what is laid out in the first couple of paragraphs. The FSF (and by extension Stallman) refrains from calling the user names if he chooses to use nonfree software, presumably because they recognize that freedom must include the freedom to run any software at all, even if they consider it harmful. But they…

> But they are quite clear that they do consider it harmful both to oneself and others to run nonfree software, even if it is useful. As we're seeing, time and time and time again, it is harmful. The benefits may outweigh the harms today, but unless the steward of that nonfree software is extraordinarily careful and forward-thinking (as it were), those relationships inevitably go bad and become coercive over time. As…

> As we're seeing, time and time and time again, it is harmful.

It certainly is not harmful, in my view. I think that the FSF's position on this topic is ridiculous. No harm whatsoever is done by running a piece of closed source software on your computer.

> The last paragraph of the opening section is a plain and obvious concession to practicality

No, it's not, at all! It is ideological, not practical, to say that the only reason to deviate from one's ideology is if doing so advances the ideology even faster.

Re: Uncomfortable Questions About Android Developer Verification

#263
post #200

The requirement of verification to side-load any app is fascist control. It is clear as night and day. Shame on Google and Apple, it was always clear this was the end goal and next up is also your PC. Right after will come the removal off apps they don't like and there is nothing you can do about it. Stallman was right

I'm absolutely against this and for similar reasons have boycotted Apple for my entire life on hard ideological grounds, but not everything is "fascist" lol. Don't misuse the term. In any case, I hope this blows up in Google's face hard, ROMs like LineageOS become as popular they were back in their heyday, and root hiders get extra attention too so banking apps etc work seamlessly as on non-rooted phones. Requiring s…

They're not going to publish device trees for pixel phones, so what hardware will you use?

Commercial apps and services will require passkeys and device attestation, so you'll only be able to use open source software even if you have a device to run it.

The walls are closing in, and it's not just mobile. It's only a matter of time before passkeys are used to block Linux users from the commercial Internet as well.

Re: Uncomfortable Questions About Android Developer Verification

#264
post #221

Earlier quoted context omitted.

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

> I have never heard of a bank that has a hard requirement of a mobile app. It shouldn't be a thing, but it is. In the Netherlands the newer digital-only banks are allowed to do this. No smartphone, no service. The more established banks ( systeembanken ) do have alternatives, but realistically not using their app for login auth and transaction approval is a huge pain in the ass. (My bank, ABN AMRO, has an app which…

That sounds like it's a hard requirement for checking your bank balance/etc over the internet. Can't you just not do that and phone them up or go in person or read the monthly sent paper balances? Or just keep track yourself... A bank without a physical location is something I'd steer well clear of.

I barely use my bank's website and could easily not use it at all and still have all the functionality that a bank provides.

Re: Uncomfortable Questions About Android Developer Verification

#265
post #19

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

"Why is it so complex to have a foss mobile OS."

What does "foss mobile OS" mean

(a) installed on a portable form factor,

(b) integrates with a cellular modem. or

(c) all of the above

For discussion purposes, assume "portable" means pocket-sized and battery-powered

When the RPi first came out I remember a blog where someone had rigged up a makeshift battery making RPi portable. At the time, HN commenters seemed impressed. Today, I connect a "phone" to an RPi running NetBSD^1 and use the phone as a battery

1. Linux provides wider assortment of drivers NB. I'm not using NetBSD to make phone calls

Today there are

non-portable VoIP phones with PoE, and

portable cellular modems running OpenWRT

Tomorrow, who knows

Convenience and control are mutually exclusive; this seems unlikely to change. Choosing the later over the former is personal preference. Every user is different

Trying to control a "phone" might be a waste of time, an exercise in futility, especially when it is running a corporate OS. Whereas controlling a gateway running an OS of the user's choice might prove to be relatively easy. Phones provide convenience, not control

Re: Uncomfortable Questions About Android Developer Verification

#266
post #189

Earlier quoted context omitted.

That's a very clear vision on how to solve this kind of funding/cooperation problem outside of government and mission-focused nonprofits. And incidentally would be an existential threat to surveillance capitalism should it reach critical mass. BTW your password-based signup flow isn't working (on iOS Safari at least).

:-) Yeah. Only SSO was working because while email would double my users, I was doing an experiment and looking for at least some signs of life. Doubling nothing would be useless. Turns out, some new enrollments topped up their accounts and dropped off before the final step that makes it show up on the home page, so now I know it's something, and something is worth doubling. > existential threat to surveillance capit…

> Should I buy a gun? I'm an American.

No, that's unnecessary. Nobody will be taking you that seriously.

> some new enrollments topped up their accounts and dropped off before the final step that makes it show up on the home page

Did they actually put money in?

Re: Uncomfortable Questions About Android Developer Verification

#267
post #266

Earlier quoted context omitted.

:-) Yeah. Only SSO was working because while email would double my users, I was doing an experiment and looking for at least some signs of life. Doubling nothing would be useless. Turns out, some new enrollments topped up their accounts and dropped off before the final step that makes it show up on the home page, so now I know it's something, and something is worth doubling. > existential threat to surveillance capit…

> Should I buy a gun? I'm an American. No, that's unnecessary. Nobody will be taking you that seriously. > some new enrollments topped up their accounts and dropped off before the final step that makes it show up on the home page Did they actually put money in?

Yeah, there were two streams that I tried so far. Interestingly, PrizeForge itself initially got $105, a $100 and a $5 enrollment. The UI was even shittier. I took one look at that $100 and knew I've got to f&*#ing go.

So, for a second experiment, I was actually running a stream for Emacs (yeah, yeah, I know, I know). They managed to raise all of $10 for themselves. The premise was to pay out a weekly prize for whoever developed something cool. Super simple.

There's so little data, but it very clearly, very, very clearly seems to say the enthusiasm is for PrizeForge to get good more than it was to use PrizeForge for something else.

And I'm going to keep expanding in various directions because there's no way I'm oriented yet, but it's not nothing. It's terrible UX, terrible everything, but just clearly enough on top of something.

Re: Uncomfortable Questions About Android Developer Verification

#268

Earlier quoted context omitted.

> I have never heard of a bank that has a hard requirement of a mobile app. It shouldn't be a thing, but it is. In the Netherlands the newer digital-only banks are allowed to do this. No smartphone, no service. The more established banks ( systeembanken ) do have alternatives, but realistically not using their app for login auth and transaction approval is a huge pain in the ass. (My bank, ABN AMRO, has an app which…

That sounds like it's a hard requirement for checking your bank balance/etc over the internet. Can't you just not do that and phone them up or go in person or read the monthly sent paper balances? Or just keep track yourself... A bank without a physical location is something I'd steer well clear of. I barely use my bank's website and could easily not use it at all and still have all the functionality that a bank prov…

Paper balances and visiting your local branch are mostly a thing of the past. Calling them is an exercise in extreme patience. My bank all but discontinued actually visiting them except for certain specific things.

In the Netherlands (and beyond) online payments (shops, Steam, etc.) are made via the IDEAL platform run by the Dutch banks collectively. That is a good thing, because payments are secure and easy, and no one needs a credit card. But that does mean using your bank's web service to approve those payments.

Using the bank's offline OTP hardware (where you insert your debit card and enter a PIN and the code generated by the bank's website for an OTP) is possible, but using the app is significantly less effort than that. There is very little point in resisting it. It's not a healthy situation, but it is the reality.

Re: Uncomfortable Questions About Android Developer Verification

#269

Earlier quoted context omitted.

Because the baseband chipset protocols and drivers are extremely patent encumbered. Any FOSS project will have to rely on on proprietary blobs for this part, and licensing deals from the existing patent holders, Quallcom. Nokia, Ericsson etc. . You can see this is sort of adverserial to the FOSS way of doing things.

The licensing should (in theory) have FRAND terms and so might not be impossible. Couldn't someone just create their own chips? In the worst case, could someone be able to come up with a new protocol and start a new network (assuming they had the money?)

You can create your own chips but you will have issues obtaining a license to use spectrum in some countries. Often, licenses for spectrum where the device is licensed instead of the end user, require the device itself to comply with spectrum use requirements....since the user isn't licensed.

Re: Uncomfortable Questions About Android Developer Verification

#270

Earlier quoted context omitted.

As Microsoft how is it so difficult to have a mobile os

Microsoft has the problem that nobody likes them or trusts them, which makes it hard to get people to use their platform in a context where they're not the default.

Windows Mobile was great and people loved it at the time. Most people I knew in 2007/2008 were laughing at how the iPhone was an expensive toy phone because you couldn't even install apps or use MS Exchange.

Of course, the problem for MS was that Apple (and Google) quickly closed those gaps, and they just simply had better overall products.

Post reply on HN