Live data from Hacker News

Everyone knows all the apps on your phone

peabee.substack.com

311–320 of 502 posts

Re: Everyone knows all the apps on your phone

#311

Earlier quoted context omitted.

It's because it stores the files there so you can sync them with other permissions. And also that your notes aren't deleted like they would be if they were stored in the internal app storage. There's more granular options for filesystem access available but if you implement them you limit yourself to the latest Android releases. According to Exodus it has no trackers and it's an open source app also so you can see wh…

Obsidian isn't open source by most reports. Surely Obsidian do not to see all files on the device, it only really needs to see the files the user needs it to see.

> Obsidian isn't open source by most reports.

On FreeBSD I can build a full copy from source (in fact I have to, there is no binary package). The only issue seems to be licensing, not source availability. Personally I don't care about licensing (I completely ignore it all anyway) and it doesn't stop you from inspecting the source code.

I think Obsidian is a really great package, I just happened to have moved over from OneNote which is horrible Microsoft mediocrity and doesn't even have a Linux app. And the web version is really useless, it needs to refresh every day and it can only search within the same tab, not a whole notebook. Such a mess. Obsidian is so quick and efficient <3 And there is full self-hosted syncing available, which I also use.

Re: Everyone knows all the apps on your phone

#312
I don't know if it is just me but I run every class of app in isolated "islands" (like work profiles) on Android. Browsers, banking apps, social media, instant messaging, tools, etc. Almost everything is isolated from another non related group.

Re: Everyone knows all the apps on your phone

#313

Anyone know if GrapheneOS has protection against this?

It doesn't afaik. Only indirectly through multiple profiles I was kind of surprised https://discuss.grapheneos.org/d/13302-query-all-packages-pe... https://discuss.grapheneos.org/d/7800-how-to-mitigate-identi... Later For the wider audience: though don't take this as GrapheneOS doesn't care about privacy. I'm sure there are reasons (I didn't read all of the linked threads) and it gives you plenty of other protections…

A rationale from the core developer [1]:

> I'm sure there are plenty of system APIs providing this information too, and I don't just mean APIs designed to directly provide the information.

> It's not useful to prevent directly getting a list of installed applications without preventing detecting which applications are installed, so this specific feature request has to be rejected. It would have to be part of a larger, much more comprehensive feature preventing apps from finding other apps. That implies outright preventing communication with non-system components which is a much different approach to applications and rules out a lot of things. [...]

> The request should be for preventing apps from discovering which apps are installed, since anything less than that has no privacy / security value. There's no point in disallowing access to a list while not preventing discovering which apps are installed anyway.

The open issue to restrict app visibility is [2].

[1] https://github.com/GrapheneOS/os-issue-tracker/ issues/149#issuecomment-553590002 [2] https://github.com/GrapheneOS/os-issue-tracker/issues/2197

Re: Everyone knows all the apps on your phone

#314

I still, will never understand the need for native "Apps". To this day, I have never seen an "App" that couldn't simply have been a website/webapp. Most of them would likely be improved by being a webapp. The only benefits I can see of "Apps", are the developer get's access to private information they really don't need. Yeah, they get to be on the "App Store". But the "App Store" is a totally unnecessary concept intr…

For one, you couldn't access those webapps without a browser, so that's the need for one app. It would also be a bit annoying if you had to load a webpage when trying to dial a number

Or am I not understanding what you mean when you use the quoted name "Apps"?

Re: Everyone knows all the apps on your phone

#315
post #302

So I downloaded a few dozen Indian apps I could think of on top of my head and started reading their manifest files How do you download apps from the Android app store and read their manifest files? Does this mean one could make a website that lists all those manifest file, so the users could decide against using apps that use this loophole?

Yes, it's called alternative app stores and there's quite a few of them around.

Re: Everyone knows all the apps on your phone

#316
post #277
post #182

Earlier quoted context omitted.

Im sorry. I really just can’t understand or relate to this at all. Mobile web still feels like such a terrible experience, and apps generally don’t. When’s the last time you tried booking a flight on mobile web? And how do you deal with all of the real estate the browser steals? Having to log in every time when the app can just cache my authentication and FaceID me?

> Having to log in every time Sounds like a broken web app. You are currently using a webapp that doesn't do this. It's called Hacker News, and it never asks me to login every time on my phone. > when the app can just cache my authentication and FaceID me Sounds like a broken login form. Hacker News also allows me to login with Face ID on my phone, thanks to my password manager. Optionally webapps can also provide Pa…

> Sounds like a broken web app.

>

> You are currently using a webapp that doesn't do this. It's called Hacker News, and it never asks me to login every time on my phone.

Every time I visit Hacker News on my iPad I'm logged out. Apple has decided that if you don't visit a website often enough it will expire all your cookies for the site.

In practice that means I can log in to HN while I'm at the cafe one weekend and be logged out by the time I visit the next weekend.

Re: Everyone knows all the apps on your phone

#317
You don't have to sacrifice your privacy to use Android. GrapheneOS is a tremendous alternative, and even if you still need some Play Store applications, you can install a GMS compatibility layer and Play Store in either a secondary profile (recommended) or your main profile (not recommended) without granting Google unfettered control over your entire operating system. This compatibility layer offers a better reduction in attack surface and stronger hardening than microG.

Alternatively, you can continue with the standard setup, accepting that you’re willingly providing companies with an unprecedented level of access to your personal data. It’s puzzling that many seem more concerned about breaking a familiar routine than about the risks associated with sharing every detail of their lives with companies that, in turn, share that data with one (or more) hostile government(s).

There is certainly a lot of justified concern about government overreach and abuse of power on HN. It remains difficult to understand why many with these warranted concerns do nothing to adopt a more coherent and rational approach — such as merely attempting to protect their personal data by not deliberately and voluntarily feeding it entirely to companies that are secretly coordinating with the very same hostile governments these people claim to seriously fear and detest.

Re: Everyone knows all the apps on your phone

#318

Earlier quoted context omitted.

Simple, UX. The reality is, most webapps for mobile just suck. The UX is nowhere near that of a native application. I don't want any text to be selectable. I don't want pull to refresh on every page. I don't want the left-swipe to take me to the previous page. You can probably find workarounds for all these issues. The new Silk library ( https://silkhq.co/ ) is the first case I've seen that get's very close to a nati…

>I don't want any text to be selectable. I don't want pull to refresh on every page. I don't want the left-swipe to take me to the previous page. Strange. This inability to select any text has always felt like one of the most hostile things developers could ever do. It feels like pure vandalism. Another thing that causes massive productivity degradation is not being able to keep multiple pages open so you can come ba…

Yeah, the app model of one page open at a time ever is such bad UX. Huge regression from the web. Funnily enough you get around it on an app like Reddit by opening pages in the web browser.

Re: Everyone knows all the apps on your phone

#319
post #310
post #307

Earlier quoted context omitted.

Try to build a more or less serious music synth in the browser that won’t kill your battery.

Heh, I was actually building one. Haven't considered the battery... Are the web audio APIs bad, or are you forced to use the CPU? I guess with webgpu it may be easier?

I think on iOS you need access on the CoreAudio level if you want to be efficient, ie fill audio buffers on a high priority thread with some lower level static language.

Re: Everyone knows all the apps on your phone

#320
post #239

Earlier quoted context omitted.

XPrivactLua and other XposedMod/Magisk extensions break open the app sandbox. It is better to restrict running those on usereng/eng builds (test devices). For prod builds (user devices), I'd recommend using Work Profiles (GrapheneOS supports upto 31 in parallel) or Private Spaces (on Android 15+) to truly isolate apps from one another.

What do you mean by "break open the app sandbox"?

I found this description about the security risks of rooting very eye-opening https://madaidans-insecurities.github.io/android.html It also explains the sandbox.
Post reply on HN