Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

301–310 of 345 posts

Re: Android Developer Verification

#301

It's kinda funny. I used to run custom roms all Android phones came with a shit OS. I stopped because Pixel AOSP phones were actually decent. Now I guess i'll be buying phones based on which I can flash with custom roms again.

good luck finding a phone with custom ROM support, when there will be no phones with bootloader unlock available :(

Re: Android Developer Verification

#302

Earlier quoted context omitted.

Are Debian repositories also irrelevant? If not, why aren't they targeted?

The XZ utils backdoor made it into Debian repositories undetected, although it was caught before it was in a stable version. Debian repositories are quite secure, but also pretty limited in scope and extremely slow to update. In practice, basically everyone (I'm sure there are a few counterexamples) using a Linux distro uses it as a base and runs extra software from less tightly controlled sources: Docker hub, PyPI,…

XZ attack is an extremely rare event coming likely from a state actor, which actually proves that GNU/Linux is a very important target. It was also caught not least thanks to the open nature of the repository. Also, AFAIK it wasn't even a change in the repo itself.

In short, using FLOSS is the way to ensure security. Whenever you touch proprietary staff, be careful and use compartmentalization.

Re: Android Developer Verification

#304
post #187
post #156

Earlier quoted context omitted.

That sounds a lot like my experience as an Apple Developer too, with the added bonus (unclear from your description if you experienced this too) that they took my money before the verification process was finished and wouldn't refund it once their AI couldn't connect my face to my ID and wouldn't let me connect with a real person (the first dozen times were on them, but after that it was maybe my fault for including…

Going through hell with Apple Developer too. I didn't have to do much in terms of verification (probably because I created an account as an individual) but app submission is another story: - first time I got rejected for mentioning a name of a third party in my app description. The app description said: DISCLAIMER: not affiliated with xxx - after fixing the app description I got rejected for using my app name(?!), mu…

At this point, my phone is PDA level, mostly useful for quick checks. I use a laptop for computing. I know as a tech nerd, I’m far out of the bell curve, but I can’t really bother with those shenanigans unless they’re paying me for it.

Re: Android Developer Verification

#305

Earlier quoted context omitted.

You are talking not about Apple's walled garden. Don't confuse a skilled power user with a pesky celebrity who always prefers one button over two buttons because of complexity issue.

I am, though. Someone who uses their phone for mail, chat, music, and calls with everything else being done on a proper computer has little to gain from sideloading, and plenty of computer power users use their phones that way. I know because I’m one of them and something like 70% of my SWE colleagues I’ve known — including Android users — fit that description too. Most have never sideloaded anything and maybe 20% ha…

Why installing software for power users should be in a sideloading form?

Maybe the sideloader is a power user in comparison to the celebrities, but who is a real power user is those who can to sideload without the sideloading. Power users of your smartphone are: top-management of the vendor, the Government and 0-day scene. Sideloading actor IMO is just a poser to the idea of a power user.

Snoop-phone useds are powerless.

Re: Android Developer Verification

#306
post #177

Earlier quoted context omitted.

Both things might be true. Sideloaded apps are probably way more likely to be malicious, but also most installed malware/crapware is quite likely coming from Google Play.

I’ve never found a malicious app on F-Droid.

F-Droid is a teeny store and requires extra steps like open sourcing such that it is not an appealing vector for malware authors.

Either you want to target the Play store so that you can get a wider install base but need to deal with tighter controls or you want to distribute flagrantly malicious stuff to people for banking trojans or whatever via social engineering to get them to sideload. F-Droid doesn't help with either of these things.

Re: Android Developer Verification

#307

What % of Android users actually want this? Do they know or care? I've been using Android since 2010 because it was open in ways that the Apple ecosystem wasn't. I do not want this and imagine hardly any other power users (for lack of a better term) do. I'm already using a mostly deGoogled device but this really seals the deal. I have been longing for a true Linux phone for years and now seems like a good time to get…

I suspect that this is less driven by users and more driven by institutions. Banking trojans distributed via sideloading are a big problem. Banks are unhappy that their users are getting their shit stolen because some other app is squatting on 2fa codes or whatever. They'd rather that their apps are not installed alongside apps that are more likely to be malware given that there isn't a private channel for auth codes for the vast majority of users.

Re: Android Developer Verification

#309
> Android is for everyone. It’s built on a commitment to a... safe platform.

These two statements contradict. When something is public, it is not entirely safe; and to make something safe, there is exclusion of practices, behaviors, and often people.

> So as an extra layer of security, we are rolling out Android developer verification to help prevent malicious actors from hiding behind anonymity to repeatedly spread harm.

1. Well, then, surely Google can't be in charge of this process, because they are a malicious actor, known to manipulate social media search results and engage in mass surveillance of its users. And that's in addition to analyzing their personal data to try to manipulate them into buying things; which is called "targeted advertizing", but I would also characterize as harm.

2. To be slightly less tongue-in-cheek: Imagine that a two would prevent entry of unverified people - you know, to prevent malicious anonymous actors from bringing harm. That would be ridiculous - nobody should be able to restrict public space. Well, the space of computation and communications via our handheld phones/computers is enough of a public space to merit the same principle. Which means that it is not acceptable for it to be under Google/Alphabet's control. Government regulation could mitigate this problem, but then, governments collude with large corporations and often approve of such restrictions.

Re: Android Developer Verification

#310
The latest shift to lock down Google's android pushed me recently to install /e/OS. On paper it makes those kind of projects a lot harder, but its prompted me to be a bit more considered about what software projects I want to use/support.

Really glad I have done that - I've been a 'boiled frog' of sorts on Android for a while now. Not happy with being continually more and more locked down, but not quite unhappy enough to shift. Feels like a breath of fresh air to have software that's built to serve me, rather than just to serve me ads.

Post reply on HN