Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

411–420 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#411
post #163
post #133

Earlier quoted context omitted.

They'd have had to start with Apple which is more locked down and has comparable market power. Apple fans (iirc like 30% of the voter population) already scream bloody murder when compatibility increases due to legislation and Apple pushes some marketing about how terrible this is We've accepted that OS vendors can do this for decades. I think that was our mistake: relying on Google as the only available vendor. We c…

They did? There is the whole "alternative app stores" kerfuffle going on right now between Apple and the EU.

Marginally. Apple still approves every app that runs there and can block whatever they don't like for whomever they don't like (or are told to block by a US court, for example). And if you go on holiday abroad and want to take your phone, Apple refuses to tell you what the grace period is during which you're allowed to use the apps on the device.

It's as hostile as they can make it because people apparently keep buying that, even when there's no semblance of the freedoms we have on Android, Windows, Linux, BSD, etc. Google saw that this suffices for the EU and does half a step towards it and people are, unsurprisingly, appalled because the whole FOSS community is here now. I still think it started with Apple demonstrating how successfully hostile you can be in a duopoly where the cards have been dealt.

Few commercial entities will happily re-implement their apps for a third, new, upcoming platform. Google and Apple will never get outcompeted so long as their software ships on the hardware that people want. Even Microsoft (Windows Mobile predated both OSs) threw in the towel, I wouldn't know who else stands a chance. Regulating these entities seems the only path when Google has evidently decided there's no point trying to compete on openness (also demonstrated by the widespread acceptance of GrapheneOS in the FOSS community: people would rather be kept safe than be free - https://news.ycombinator.com/item?id=48758146)

Re: Android Developer Verification: Threat masquerading as protection

#413

Earlier quoted context omitted.

To avoid this, I tried to close my Google Play Developer account. A decade ago I published a free app on it, which was online for half a year. It was to no avail. They will not close the account. I received only automated responses about bringing my old app into compliance with current policy, to then transfer it to another developer account. Only then would Google graciously allow me to close my Developer account. M…

Gotta move to the EU and sue based on right to be forgotten

Suing a company will almost certainly result in them exercising their right to not do business with you and shutting down all your accounts - exactly what OP was trying to avoid

Re: Android Developer Verification: Threat masquerading as protection

#414
>Should a developer — contrary to our recommendation — elect to register themself with Google as a “verified” developer, they should expect to sign up for an account and pay a fee, surrender detailed personal information and upload government-issued identification

Again, there is a tradeoff between protecting consumers and protecting vendors. If you protect the privacy of vendors, you do so at the expense of increasing risk to the consumers.

I don't want to be polarizing, but narcissistic is the best word to describe the position of this article. I'm assuming that when they are consumers, they would find it reasonable that their vendors provide due diligence and be held to higher standards. When they go to the pharmacy, and they buy aspirins, would they choose a tablet of aspirins from a pharmacy that doesn't ask where the aspirins came from or who the distributor or producer is? If such privacy of the producer were respected then the market would open up to actors that provide low quality, counterfeit, or malicious product.

You can't have it both ways. If you are a vendor, you are no longer an anonymous consumer. Installing a VPN, paying with cryptocurrency, using firefox and duckduckgo to avoid tracking, that's not on the table for you once you decide to be on the other side of the production market.

If you want to make software and distribute it anonymously, go ahead and submit it to one of the many malware riddled distributors that don't do any due diligence like npm, github, AUR, why must you insist on being let in a club that doesn't want you? Is it perhaps because the reputation of such club is higher because it doesn't have malware because it performs such due diligence?

At least if you are going to complain about this, do it with standard language don't co-opt cybersecurity terms, adding noise to whoever cares about actual security. If this is really a problem you wouldn't need to exaggerate or plain lie about it.

Re: Android Developer Verification: Threat masquerading as protection

#415
I think it's funny that they look at the phrase "malware or other harmful applications" and then only have an issue with the definition of "malware" rather than "harmful". Like, wouldn't "harmful" be FAR easier to apply in literally any case you feel like? "malware" sounds like it'd need some proof of malicious intent but "harmful" needs no such thing and is much looser.

Re: Android Developer Verification: Threat masquerading as protection

#416
post #392
post #339

Earlier quoted context omitted.

I think there's a misunderstanding here. The attack in question doesn't use apps on the store, or even any attempt to get them on the store. There are also other attacks, but the one that prompted this change uses social engineering to get people to tap the build number seven times, sideload something and get a keylogger that then picked up their banking details and used them. Several governments raised the issue, Go…

But it is suspicious they want to defend vs attacks that don't happen while doing absolutely nothing to stop the attacks that do happen. Seems like security isn't a goal here? (I didn't get scammed, I sometimes am curious on what the scam is so i lead them on a bit)

Are you in Brazil, Indonesia, Singapore or Thailand? Those were the four worst-affected countries IIRC. Although I seen to remember Ecuador or Bolivia as well?

(They do something about other scams too. There was another thing they published recently, I didn't pay attention since no side effect of that concerned me, something to do with caller ID.)

Re: Android Developer Verification: Threat masquerading as protection

#417

All talk, no solutions from F-droid. What are they actually doing to solve it? Why not stand up their own vetting system? I'd love some technical solutions, instead this is just childish.

Solutions from F-Droid? There are none. Like they said, it's an unremovable system service.

Re: Android Developer Verification: Threat masquerading as protection

#418

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

To avoid this, I tried to close my Google Play Developer account. A decade ago I published a free app on it, which was online for half a year. It was to no avail. They will not close the account. I received only automated responses about bringing my old app into compliance with current policy, to then transfer it to another developer account. Only then would Google graciously allow me to close my Developer account. M…

It's not just google. Try removing an unpublished but uploaded iOS app. Wasn't possible for decades and I guess it still isn't. You eventually could hide them. The only way to remove it was to publish it, but that requires app validation, which a failed app is not suited for.

Re: Android Developer Verification: Threat masquerading as protection

#419
post #150

Earlier quoted context omitted.

Oh? Maybe you could comment on what part of the f-droid article is wrong

>If you are running Android 8 or higher, a virus has been installed on your device and is silently awaiting remote activation. I have such a phone and the "virus" has not been installed to it. There is no evidence behind this claim. >with as many as 4 billion Android handsets and tablets estimated to have already been contaminated This is misleading wording. It's just as true to say that as many as 1 trillion devices…

Thanks, I appreciate the elaborate response.

If you can just disable it with the activity manager or similar, I don't think Google would provide another workaround with a wait time and everything - and that only after a lot of public pressure. It's claimed to be a security feature against scams, and scammers can theoretically let you open up an adb shell and run an am command, so that would negate the safety. (That this never happens in practice imo demonstrates that it's just about ecosystem control and not actually for user safety.)

I agree on the root thing though. I don't have a device here that has this service running so I can't check the process permissions for myself, but it seems extremely doubtful that it runs as uid 0. Fdroid could have dumbed the technical permission level down in more accurate way

How do you know nothing will happen to already-installed apps and their data, when the user hasn't had time yet to go through the annoyance unlock procedure?

Re: Android Developer Verification: Threat masquerading as protection

#420

Earlier quoted context omitted.

To avoid this, I tried to close my Google Play Developer account. A decade ago I published a free app on it, which was online for half a year. It was to no avail. They will not close the account. I received only automated responses about bringing my old app into compliance with current policy, to then transfer it to another developer account. Only then would Google graciously allow me to close my Developer account. M…

really? I have to keep making useless updates (just a version number bump) on one of the accounts i manage, because i keep receiving thread emails every 6 months that the developer account sees no activity and if i don't do anything they will remove and close. that app is a done project and need only to be udpated when the target SDK becomes too old for the play store

Yes, unfortunately that has not been the case for me, my account is still active.

My app has already been removed when they added the Privacy Policy requirement for the Advertising ID, where I did not update the app.

Post reply on HN