Live data from Hacker News

Uncomfortable Questions About Android Developer Verification

commonsware.com

291–300 of 311 posts

Re: Uncomfortable Questions About Android Developer Verification

#291
post #284

Earlier quoted context omitted.

Yeah, there were two streams that I tried so far. Interestingly, PrizeForge itself initially got $105, a $100 and a $5 enrollment. The UI was even shittier. I took one look at that $100 and knew I've got to f&*#ing go. So, for a second experiment, I was actually running a stream for Emacs (yeah, yeah, I know, I know). They managed to raise all of $10 for themselves. The premise was to pay out a weekly prize for whoev…

> ...stream for Emacs... > ...terrible UX, terrible everything... I think I accidentally enrolled for emacs and can't unenroll on the site. I guess I'll have to finally start using emacs now

Hey at least customer support is still pretty good when I can twiddle the database for each one. Shoot something to support@prizeforge.com.

Re: Uncomfortable Questions About Android Developer Verification

#292
post #284

Earlier quoted context omitted.

Yeah, there were two streams that I tried so far. Interestingly, PrizeForge itself initially got $105, a $100 and a $5 enrollment. The UI was even shittier. I took one look at that $100 and knew I've got to f&*#ing go. So, for a second experiment, I was actually running a stream for Emacs (yeah, yeah, I know, I know). They managed to raise all of $10 for themselves. The premise was to pay out a weekly prize for whoev…

> ...stream for Emacs... > ...terrible UX, terrible everything... I think I accidentally enrolled for emacs and can't unenroll on the site. I guess I'll have to finally start using emacs now

Oh I see your username. You were over the subreddit. Welcome aboard.

Re: Uncomfortable Questions About Android Developer Verification

#293
post #115

Earlier quoted context omitted.

I agree. we should be able to install apps we want to install. But if you're installing them from the Google Play store (which is what is discussed) then you should be allowed to know who you're doing business with.

> But if you're installing them from the Google Play store (which is what is discussed) Maybe there's been a miscommunication somewhere but Android Developer Verification (what this thread is about) applies to all apps, even those installed outside of Google Play store.

I understand. The author is critiquing a specific part of this policy: forcing developers to identify themselves. Their main point is not about allowing app developers to sideload.

Re: Uncomfortable Questions About Android Developer Verification

#294

Earlier quoted context omitted.

Fidesmo Pay is another option, though the bank support is limited: https://fidesmo.com/consumer/fidesmo-pay/ Basically it’s a passive variant of smartwatch payments: you can pay with a ring, or bracelet, or a mechanical watch. The cheapest option is this plastic thingy (currently out of stock): https://eu.k-pay.com/product/mavericks I’m thinking about implanting one into my hand :^)

> I’m thinking about implanting one into my hand :^) On the one hand, I approve of self-administered biohacking. On the other hand, you might need a Faraday glove to prevent tap to pay shenanigans by folks with a mobile card reader who bump check you. I would not do this type of biohacking myself, but if you go down this path, look into how NFC skimmers work, because that and compromised card readers and unauthorized…

It is possible, but very unlikely. You’ll need to know where my chip is (I guess for an average thief an implant is not the first idea of where to look for an NFC card), and then get quite close to me to pull this off. Even if you do, I think it’ll take about one chargeback to get your merchant account blocked.

> roll out tap to pay from card to phone and phone to phone

It’s already here! Stripe has supported it for a while now, and I’ve seen a bunch of other payment providers have it, too: https://stripe.com/terminal/tap-to-pay

Re: Uncomfortable Questions About Android Developer Verification

#295

Earlier quoted context omitted.

> But they are quite clear that they do consider it harmful both to oneself and others to run nonfree software, even if it is useful. As we're seeing, time and time and time again, it is harmful. The benefits may outweigh the harms today, but unless the steward of that nonfree software is extraordinarily careful and forward-thinking (as it were), those relationships inevitably go bad and become coercive over time. As…

> As we're seeing, time and time and time again, it is harmful. It certainly is not harmful, in my view. I think that the FSF's position on this topic is ridiculous. No harm whatsoever is done by running a piece of closed source software on your computer. > The last paragraph of the opening section is a plain and obvious concession to practicality No, it's not, at all! It is ideological, not practical, to say that th…

> No harm whatsoever is done by running a piece of closed source software on your computer.

So, I'm confused. What do you believe that Stallman is right about? If there's never any harm done by running nonfree software on your computer, then what's the problem? I must have misunderstood your commentary here [0] because this statement

> The thing is... he seems to have been right the whole time. Companies really do want to lock you out of controlling the devices you own, and do so at the first opportunity. So... Stallman was right.

certainly seems like you were claiming that there are harms inherent in the practice.

> It is ideological, not practical, to say that the only reason to deviate from one's ideology is if doing so advances the ideology even faster.

Not making a concession to practicality would be saying "There is no circumstance in which one should use nonfree software. Not even in the service of replacing that nonfree software with free software.". You're simply incorrect about this... especially when you also consider point #2 of the section you've quoted from.

[0] https://news.ycombinator.com/item?id=45036440>

Re: Uncomfortable Questions About Android Developer Verification

#296

This shouldn't just be "questions"; this should be a full-on opposition. Do not give them even an inch, or they'll take a mile. "debugger vendors in 2047 distributed numbered copies only, and only to officially licensed and bonded programmers." - Richard Stallman, The Right to Read , 1997

Great justification for switching to Graphene OS, more secure, more control, and google has to ask permission to install things and the play store is optional.

Re: Uncomfortable Questions About Android Developer Verification

#297
post #286

Earlier quoted context omitted.

Paper balances and visiting your local branch are mostly a thing of the past. Calling them is an exercise in extreme patience. My bank all but discontinued actually visiting them except for certain specific things. In the Netherlands (and beyond) online payments (shops, Steam, etc.) are made via the IDEAL platform run by the Dutch banks collectively. That is a good thing, because payments are secure and easy, and no…

The point in resisting it is to waste their valuable time on whatever the worst appless methods are, so they are forced to improve the efficiency to keep profits high if enough people do it. If you install the app then you are complicit in normalizing the requirement of signing terms of service and data sharing agreements to US technology companies in order to do banking. Be the person that demands better. Be the squ…

There are only so many things you can actively fight. I can choose to actively pursue a number of topics and be the annoying squeaky wheel there, but not everything. This is one topic I cannot invest more time in, and which won't yield any significant returns even if I did. There are a number of topics where my voice can still make a difference, I focus on those.

Re: Uncomfortable Questions About Android Developer Verification

#298
post #243
post #242

Earlier quoted context omitted.

BankID works great on GrapheneOS fortunately.

Really? I never even installed the play store because it didn’t work on LineageOS. I guess I absolutely need the play store to get BankID on the phone- so I’ll try that now with my Pixel 7.

Yes.

The only issue I had on GrapheneOS was that I had to play with the location permissions a bit when I wanted to copy the BankID to GrapheneOS from another phone (I've got some pictures of that in this blog post: https://www.jonashietala.se/blog/2025/08/28/ill_only_buy_dev...).

All other Swedish bank accounts I've tried have also worked great (including Swish).

Re: Uncomfortable Questions About Android Developer Verification

#299

Earlier quoted context omitted.

Then the app gets no notification permissions. Also why does a gas station app need to send notifications? :)

To tell you the gas prices are low? (Don't know for sure, wouldn't use one myself.)

More likely to tell you to come in and buy a half price slushie, and hopefully grab a bag of chips too. Which is probably where they make their real profit.

Re: Uncomfortable Questions About Android Developer Verification

#300
post #242

Earlier quoted context omitted.

BankID works great on GrapheneOS fortunately.

Interesting. Does this mean that it is using a lower level of Play Integrity API checking (ie not hardware attestation), or are they using the open hardware attestation API (which... exists but is almost never used)? https://grapheneos.org/articles/attestation-compatibility-gu...

I have no idea, but I've never gotten the "this app is using Play Integrity" warning with BankID so maybe it doesn't use Play Integrity?
Post reply on HN