Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

281–290 of 345 posts

Re: Android Developer Verification

#281

Earlier quoted context omitted.

That all makes perfect sense but consider that if they simply punted to the bank as I described they would still get the same benefits only with even less complexity. The bank fundamentally has to do robust identity verification. Any party that needs to handle payments while also lacking a reason to be good at performing in house identify verification really ought to make use of the bank because you are highly unlike…

The bank has to perform the authorization and identity checks, but the bank will not make them for you , they do them for themselves based on their own risk analysis. The scope of authorization could also be different based on who it's presented to. The authorization is not transitive so to say. >As an aside, I suspect that leaving it to the bank would also provide additional legal protection If it would, they will h…

> The bank has to perform the authorization and identity checks, but the bank will not make them for you

We aren't talking about authorization, only about identity verification. I'm no domain expert but it is my understanding that banks provide these sorts of services. They certainly already have all the necessary information on hand both for practical reasons (security) as well as legal (KYC and AML laws).

> If it would, they will have to pay the bank for it ...

For the identity verification? Probably, depending on how you went about it. What's the issue? This is already a paid process we're talking about here.

For the additional legal assurance that I described? No, that doesn't cost extra. Please read what I wrote more carefully. It's a transitive property due to the penalties involved in addition to the degree to which the legal system and the bank care (at least assuming my understanding of that legal environment is correct).

Re: Android Developer Verification

#282

Earlier quoted context omitted.

To be honest the limited popularity of F-Droid also helps it be less targetted by bad actors. If it was more popular I would bet the situation would surely be different

This argument can be refuted by considering Debian repositories. No malware exists there despite it being a good target. It's the FLOSS that solves the malware problem, with a bit of moderation.

I'd argue OSS isn't sufficient on its own and that I suspect moderation only plays a small role. I think it's primarily the separation of roles. For a complete outsider whose only interest is exploiting users publishing a sufficiently popular piece of software and also gaining the ability to add things to the debian repos is a huge barrier. You'd have to invest years of work to do both of those things and then hope that no one happened to notice anything before it was too late.

Of course the FLOSS aspect adds an additional hurdle that this popular piece of software will have to somehow avoid having much of a contributor community around it since that would greatly increase the risks of your malicious changeset being reviewed. I guess what happened with XZ was about the best case scenario that an attacker could realistically hope for.

Re: Android Developer Verification

#283
post #239

Earlier quoted context omitted.

Why do you think they are doing it?

To stop scammer-guided malware installation, and probably those "download whatsappupdate.apk for free new emoji" ads that pop up all the time. Google doesn't care about F-Droid one way or the other. It's a niche project that barely registers on the scale of all Android users.

They don't care about F-Droid but they do care to choke out any potential competitors to their ecosystem before they can get a foothold. See their behavior surrounding device certification for example. They want to abuse the network effects of their ecosystem to prevent consumers from leaving. This is just more of that - vendor lock-in masquerading as an unfortunate necessity.

Re: Android Developer Verification

#284
post #256

Earlier quoted context omitted.

"Jaywalking" is one of those things that's uniquely American. Most other countries have realized that the risk of being hit by a car is its own deterrent. Or restrict the legal ban on crossing to highways, not all streets. The UK Highway Code has a RFC-like use of MUST/SHOULD; MUST parts are legally binding, the parts relating to pedestrians are SHOULD.

The German regulation is also really interesting: Jaywalking is only illegal if there's a crossing less than 50m away. (And even then it's only a misdemeanor, not a crime). That also means that city planners have to balance between people jaywalking, putting crossings everywhere, and how crossings slow down traffic. And every time a car makes a turn, pedestrians automatically have priority. Which creates an implicit…

I believe most jurisdictions in the US have largely the same framework. At least everywhere I've lived all street corners were implicit pedestrian crossings with a legal requirement (often blatantly ignored) that vehicles yield. Similarly jaywalking is a misdemeanor and only applies within a certain distance of a crossing.

The only situations where it's enforced (from what I've seen so obviously biased) is major highways, city streets with dense traffic and a marked crossing within half a block, and when they want to search someone for contraband. In the latter case it's just an excuse to stop and harass you in the hopes they will manage to generate sufficient articulable suspicion to justify a search.

Re: Android Developer Verification

#285
post #136

Earlier quoted context omitted.

What? So you dont value freedom at all? Theres other alternatives too.. graphene, lineage

GrapheneOS is Android's last hope. They're making great progress with deals with smartphone manufacturers. However, the threat of remote attestation looms eternal. I have essential apps that I cannot afford to lose and if they refuse to work on a non-Google phone the usefulness of GrapheneOS is severely degraded.

If attestation ever became ubiquitous the difference between iOS and Android would cease to exist for me. I'd need a black box that lived in a desk drawer for interfacing with specific services and otherwise I'd cart around a camera in my pocket that happened to double as a linux tablet.

Re: Android Developer Verification

#286
In the last few years all apps I install in a phone come outside of Play Store, because either they are full of ads, throttle their usage or simply similar ones don't exist. Without them the phone loses half of it's functionality, which is pretty much. So, I am willing to wait a day in the "advanced flow" to keep a multi-year experience.

Re: Android Developer Verification

#287
post #108

Earlier quoted context omitted.

Being able to side load apps was why I switched to android 10 years ago

Please call it what it is and always has been: I.N.S.T.A.L.L.I.N.G S.O.F.T.W.A.R.E "side load" is like "jay walking' seeks to stigmatize humans being human.

Please don't try and police my language

Re: Android Developer Verification

#288

> Android is for everyone. It’s built on a commitment to an open and safe platform. Users should feel confident installing apps, no matter where they get them from. This intro immediately tells me that whatever comes after will be horrible for users and developers. Surprise surprise, I was right. Software to "verify" side loaded apps is a bad, anti user idea.

I am waiting for Google to require bodily fluid sample to verify identity.

Re: Android Developer Verification

#289
post #209
post #177

Earlier quoted context omitted.

I’ve never found a malicious app on F-Droid.

Are you really unable to comprehend just how small of a userbase F-droid represents for Android ecosystem?

Likely true, but also many technically oriented people (myself included) would turn away from Android if f-droid stopped working. And I would actively start recommending friends and family against it. What is the benefit of Android at this point? an extended Ads platform, controlled by Google.

Re: Android Developer Verification

#290

Earlier quoted context omitted.

To be honest the limited popularity of F-Droid also helps it be less targetted by bad actors. If it was more popular I would bet the situation would surely be different

This argument can be refuted by considering Debian repositories. No malware exists there despite it being a good target. It's the FLOSS that solves the malware problem, with a bit of moderation.

There were a few mishaps with PyPI and npm - including in the past week and even today. Not sure if those meet your criteria of FLOSS, but if it does I wouldn't call it solved.
Post reply on HN