Live data from Hacker News

Keep Android Open

f-droid.org

301–310 of 764 posts

Re: Keep Android Open

#301
post #247

Earlier quoted context omitted.

Desktop OSes and their derivatives are woefully behind in this regard, and unfortunately the will to bring them up to par is incredibly weak. Of those in mass use (Qubes OS is neat but its user base isn’t even a rounding error), macOS probably does the most, but it’s still lagging behind iOS and what’s been implemented has come with much consternation from the technically inclined peanut gallery. I understand some am…

Fun fact - on most Linux distros any user program can see almost any event, yes including key presses, by reading from the right /dev/... file. This is not surprising. The desktop Linux community reacted with hostility to the well funded security efforts (selinux, apparmor, grsecurity, etc)

Security is a tradeoff (fucking always...)

It's the same reason I choose to keep my front door unlocked basically all the time - I know my neighborhood, the risk is really low and the convenience is high.

Further... practically everyone agrees that they don't need bank vaults as front doors. It makes zero practical sense: The cost is incredibly high, and the convenience is very low.

There are ALL sorts of wonderfully cool things you can do on a system where applications are allowed to trust each other, and the system is permissive by default.

You can customize behavior more easily, you can extend software more easily, you can add incredibly detailed & functional accessibility support, you can create incredibly powerful macros and commands.

This is so important that fundamental OS design from the early 90s actually prioritized and catered to exactly this style of open, trusted, platform (ex - all of COM in windows...). This is what made personal computing a reality...

All of those fall flat when you try to impose "well funded" security efforts.

Those efforts have a place, in the same way that bank vaults have a place. Whether that place is a personal computer is a different question.

Implying those folks are hostile for no reason is... at best a woeful misunderstanding of the situation, and at worst a malicious mischaracterization.

Re: Keep Android Open

#302

It is a disgrace how Google has managed this situation. To recap the storyline, as far as I understand it: last August, Google announced plans to heavily restrict sideloading. Following community pushback, they promised an "advanced flow" for power users. The media widely reported this as a walk-back, leading users to assume the open ecosystem was safe. But this promised feature hasn't appeared in any Android 16 or 1…

The only reason I was sticking to Android for years is this. And I think there is no moat for Android. I would rather switch to iOS if both platforms are same restrictive.

Re: Keep Android Open

#303

Earlier quoted context omitted.

Strong disagree. Linux, its permission system and its (barely existent) application isolation are lightyears away from the security guarantees that Android brings.

Desktop OSes and their derivatives are woefully behind in this regard, and unfortunately the will to bring them up to par is incredibly weak. Of those in mass use (Qubes OS is neat but its user base isn’t even a rounding error), macOS probably does the most, but it’s still lagging behind iOS and what’s been implemented has come with much consternation from the technically inclined peanut gallery. I understand some am…

Flatpak and Snaps are built to solve this. They do conflict with some expectations from users to be able to play around with things, though, so they do not have the penetration one might want.

Re: Keep Android Open

#304

It is a disgrace how Google has managed this situation. To recap the storyline, as far as I understand it: last August, Google announced plans to heavily restrict sideloading. Following community pushback, they promised an "advanced flow" for power users. The media widely reported this as a walk-back, leading users to assume the open ecosystem was safe. But this promised feature hasn't appeared in any Android 16 or 1…

Good thing restricting side-loading isn't legal in the European Union! Not a problem here. Apple had to enable side-loading on their EU-based phones and so will Google if they restrict it.

If a lawsuit tackles this problem in the EU, will we finally also see somebody go after MS for their obnoxious code signing certificates?

While MS code signing certs are more circumventable for power-users than Android's new approved developer program, their pricing is far more prohibitive for independent OSS developers and hobbyists, costing hundreds of USD per year.

Re: Keep Android Open

#305

Earlier quoted context omitted.

Personally I'm excited about the death of Android, now resources can be put toward mainstreaming and maturing the Linux Phone ecosystem Hopefully 2026 or 2027 will be the year of the Linux Phone

> death of Android death of personal computing freedom, sovereign compute, and probably soon our ability to meaningfully contribute to the field as ICs? A lot of really bad things are happening to our field, and Google is one of the agents responsible for much of it.

> A lot of really bad things are happening to our field, and Google is one of the agents responsible for much of it.

I mean, breaking news from 2010, but of course never assume things are so bad that they can’t get worse.

Re: Keep Android Open

#307

Earlier quoted context omitted.

Personally I'm excited about the death of Android, now resources can be put toward mainstreaming and maturing the Linux Phone ecosystem Hopefully 2026 or 2027 will be the year of the Linux Phone

Strong disagree. Linux, its permission system and its (barely existent) application isolation are lightyears away from the security guarantees that Android brings.

This might be a strange take in these times, but I feel like the browser largely solved the "I need to run potentially adversarial application code in a sandbox". For native applications, stick to stuff that's vetted and in well-maintained repositories, or well-known open source projects that you trust. All of this technical work just to be able to run hostile native code ignores that you don't have to, and probably shouldn't want to, run sketchy code on your device. Installing random untrusted software is bad, even with the most advanced security model in the world. At the very least it will probably abuse whatever permissions it has to spy on you to any degree it can (which is a lot, even for web pages) and to send you advertising notifications.

Re: Keep Android Open

#308
post #230

Earlier quoted context omitted.

My understanding is that how Apple is restricting the alternative app stores is also illegal in EU, so I don't thinkt this is the end of this story.

It's almost two years and they are still doing it. So they are moving mighty slow if that is the case.

Yes, these things move slowly, but they do move =)

Re: Keep Android Open

#309
post #232

Earlier quoted context omitted.

Desktop OSes and their derivatives are woefully behind in this regard, and unfortunately the will to bring them up to par is incredibly weak. Of those in mass use (Qubes OS is neat but its user base isn’t even a rounding error), macOS probably does the most, but it’s still lagging behind iOS and what’s been implemented has come with much consternation from the technically inclined peanut gallery. I understand some am…

> We really need to get past the 90s-minded paradigm of everything having access to everything else all the time I do agree with that, and I strongly believe that the iOS and Android security model is way ahead of Desktop Linux. But what I observe is that nobody seems to care about the security model. A recurrent complaint I see against anything AOSP-based (including Android) is that people "want to be root".

It comes from a history of using mostly trusted application sources like Debian/Ubuntu package archives with manual review being the norm. And few supply chain attacks.

But both Flatpak and Snap offer this new model from the two biggest desktop players in the Linux world: Red Hat and Canonical.

As the sibling comment said though, being an administrator for your own computer (including a phone) does not mean that you will be running untrusted applications as one: on the contrary, if you assume an administrator role and run an untrusted application, naturally, all bets are off. But even as a power user, I'd love to be able to safely run programs I do not necessarily trust, feeding it only data it needs and no more.

Again, Snap/Flatpak provide this model, but we need to see more application authors take them up to ship their software.

Re: Keep Android Open

#310

Earlier quoted context omitted.

or alternatively we can just stop using products/services of said companies

I can ban persons from doing things, I rather not have them do. Companies are legal persons, so why shouldn't this apply to them? At some point ignoring behaviour is not making it go away, it needs to be actively worked against, otherwise it will become (practically) mandatory.

the core problem with banning is who is doing it and why, right? once we allow it, it goes into the hands of the “politicians” and then books get banned today, ice scream gets banned tomorrow, math gets banned the next day…
Post reply on HN