Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

281–290 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#281
You americans are strange. Your government makes arbitrary arrests, illegally searches phones, massively de-funds science and health projects, and only a handful of people demonstrate.

Now a company wants the identity of the companies it works with because it distributes their software, and it looks like a massive "scandal". Well at least I am realistic that the "scandal" is only within certain circles.

Re: Uncomfortable Questions About Android Developer Verification

#282

Earlier quoted context omitted.

Windows Mobile was great and people loved it at the time. Most people I knew in 2007/2008 were laughing at how the iPhone was an expensive toy phone because you couldn't even install apps or use MS Exchange. Of course, the problem for MS was that Apple (and Google) quickly closed those gaps, and they just simply had better overall products.

> Windows Mobile was great and people loved it at the time. But that wasn't the problem. The iPhone and Android became popular because they were, respectively, good and "good enough" but free, and both Apple and Google had a good reputation at the time. Users were willing to buy those phones and developers were willing to make apps for them because they didn't expect those companies to screw them. The screwing only h…

In 2007 or 2008, defining "users" in this context isn't that straightforward of an exercise.

Apple and Google might have had a good reputation with consumers who were using feature-phones at the time... but they both had bad reputations with most existing smartphone users at the time. Those users were primarily business business users or power users who had requirements that weren't met by most of anything that Apple or Google was putting out at the time. RIM and Microsoft were building the smartphones that were most trusted at the time.

The mass consumer market for smartphones really didn't exist until Apple took phones in that direction. Before that, they weren't entertainment or consumer-focused devices, they were productivity devices.

iOS and Android, by their second or third release, were already better products than Windows mobile 6.5, both for entertainment and productivity. That's the reason they won. Neither of them were "free" to users -- and in fact the devices that they ran on were more expensive than Windows Mobile devices. People were only willing to pay more for these devices because they were doing something entirely different than what Windows Mobile did. They were consumer smartphone devices -- a new category of device that didn't exist.

This is not to be confused with Windows Phone -- which failed because it was way too late to market, way too far behind in ecosystem support, and didn't solve any new problems.

Re: Uncomfortable Questions About Android Developer Verification

#283

You americans are strange. Your government makes arbitrary arrests, illegally searches phones, massively de-funds science and health projects, and only a handful of people demonstrate. Now a company wants the identity of the companies it works with because it distributes their software, and it looks like a massive "scandal". Well at least I am realistic that the "scandal" is only within certain circles.

Google always knew the identity of companies whose software it distributed (via Google Play), now it also want to know the identity of software developers it has nothing to do with. Get your facts straight next time before writing a snarky comment!

Re: Uncomfortable Questions About Android Developer Verification

#284
post #266

Earlier quoted context omitted.

> Should I buy a gun? I'm an American. No, that's unnecessary. Nobody will be taking you that seriously. > some new enrollments topped up their accounts and dropped off before the final step that makes it show up on the home page Did they actually put money in?

Yeah, there were two streams that I tried so far. Interestingly, PrizeForge itself initially got $105, a $100 and a $5 enrollment. The UI was even shittier. I took one look at that $100 and knew I've got to f&*#ing go. So, for a second experiment, I was actually running a stream for Emacs (yeah, yeah, I know, I know). They managed to raise all of $10 for themselves. The premise was to pay out a weekly prize for whoev…

> ...stream for Emacs...

> ...terrible UX, terrible everything...

I think I accidentally enrolled for emacs and can't unenroll on the site. I guess I'll have to finally start using emacs now

Re: Uncomfortable Questions About Android Developer Verification

#285
post #200

Earlier quoted context omitted.

I'm absolutely against this and for similar reasons have boycotted Apple for my entire life on hard ideological grounds, but not everything is "fascist" lol. Don't misuse the term. In any case, I hope this blows up in Google's face hard, ROMs like LineageOS become as popular they were back in their heyday, and root hiders get extra attention too so banking apps etc work seamlessly as on non-rooted phones. Requiring s…

They're not going to publish device trees for pixel phones, so what hardware will you use? Commercial apps and services will require passkeys and device attestation, so you'll only be able to use open source software even if you have a device to run it. The walls are closing in, and it's not just mobile. It's only a matter of time before passkeys are used to block Linux users from the commercial Internet as well.

I did manage to run banking apps, and after some work, even Fortnite just for principle (they had a crazy anti hacking system) on my rooted Oneplus 7 Pro. I do want to believe if there's a will there's a way. Google has really overstepped here.

Re: Uncomfortable Questions About Android Developer Verification

#286

Earlier quoted context omitted.

That sounds like it's a hard requirement for checking your bank balance/etc over the internet. Can't you just not do that and phone them up or go in person or read the monthly sent paper balances? Or just keep track yourself... A bank without a physical location is something I'd steer well clear of. I barely use my bank's website and could easily not use it at all and still have all the functionality that a bank prov…

Paper balances and visiting your local branch are mostly a thing of the past. Calling them is an exercise in extreme patience. My bank all but discontinued actually visiting them except for certain specific things. In the Netherlands (and beyond) online payments (shops, Steam, etc.) are made via the IDEAL platform run by the Dutch banks collectively. That is a good thing, because payments are secure and easy, and no…

The point in resisting it is to waste their valuable time on whatever the worst appless methods are, so they are forced to improve the efficiency to keep profits high if enough people do it.

If you install the app then you are complicit in normalizing the requirement of signing terms of service and data sharing agreements to US technology companies in order to do banking.

Be the person that demands better. Be the squeaky wheel. Call politicians and press if needed. Stop this shit now before it becomes expected for school and healthcare too.

Re: Uncomfortable Questions About Android Developer Verification

#287
post #228
post #221

Earlier quoted context omitted.

I have never heard of a bank that has a hard requirement of a mobile app. Certainly none of the major banks like Wells Fargo or Chase require one. I do not own a phone and managers at times have to come up with undocumented fallback methods, but there is always a way. I cannot imagine a legal defense for forcing someone to accept the terms of service of Apple or Google to use their bank account.

In Sweden we use BankID (there is a similar service with the same name in each Scandinavian country). It's impossibly convenient to be perfectly fair with you, however I know that my bank has stopped issuing the "BankID Card" (which was a card and pin device that allowed you to generate challenge numbers)- and now forces you to use the BankID app -- which will not run on rooted phones of course. It's even slightly wo…

If you install the app then you are complicit in normalizing the requirement of signing terms of service and data sharing agreements to US technology companies in order to do banking.

Feel free to say you are a member of the Church of Cryptography and that installing proprietary corporate controlled apps is against your religion.

Never been asked to install an app for banking, but a health care clinic dropped me as a patient for not buying a phone that can install their app. I was the first case where a patient refused to conform. Found a new clinic who was willing to earn my business with phone and email correspondence. The original clinic escalated the case to corporate HQ when I filed a public medical malpractice complaint, and they ultimately responded by adding a webapp.

DEMAND the right to live your life without corpotech in your pocket. I am now 5 years without a smartphone working as an engineer and founder with an active social life who frequently travels and it can absolutely be done.

Re: Uncomfortable Questions About Android Developer Verification

#288
post #169

I'd guess that the main reason Googel has done this is to prevent side-loading of messenger apps, such as Signal, with true end-to-end encryption. Such messengers would be very difficult to surveil at scale. You might ask why not to simply install these apps from Play Store? The reason is Google demands signing keys for all apps, so it can impersonate the developer, inject any spyware, rebuild the app, sign it and ma…

Google doesn't demand your signing keys, and transforming your app in that way is easily detectable by the developer.

Re: Uncomfortable Questions About Android Developer Verification

#289

[flagged]

I don't think anyone is arguing that they want app developers to break the law, but rather that Google must not take away the device owner's choice to install any app he so chooses. But even to the extent that does involve lawbreaking... yes, that's the price you have to pay for freedom. You cannot give people freedom without some people misusing it to do bad things, but that does not mean freedom should therefore be…

>but rather that Google must not take away the device owner's choice to install any app he so chooses.

This is fair to make and a better strategy. My comment was about calling out the messaging or strategy that the author went with. Choosing an idea of people should be able to decide the apps they are able to run is more agreeable of a message than a message of "think about developers who want to avoid consequences of breaking the law." The latter is an antisocial message that I do not think is as agreeable.

>We all agree that some amount of criminal activity must be tolerated

I don't agree with that. Especially with the upcoming rise of AI law enforcement. Much more freedom than a cell can be given while maintaining effective law enforcement.

Re: Uncomfortable Questions About Android Developer Verification

#290
post #19

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

Why is it so complex to have a foss mobile OS. I only have Linux PCs (laptops) and servers, 100% of my work and personal stuff is done there (though for work I do need to hop into MS365, Google Workspace, Zoom, etc, hooray for browsers, my final firewall between me and the walled gardens, though we can have a whole discussion on that). For mobile, we have PostmarketOS, Phosh, Ubuntu Touch. I really must try living in…

The hardware and boot process for every phone is different, and some vendors block users from installing other OSes. Then most mobile apps are proprietary, and some of the apps only allow you to run them on official Google builds of Android, via attestation.

https://grapheneos.org/articles/attestation-compatibility-gu...

Post reply on HN