Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

411–420 of 536 posts

Re: Android may soon restrict on-device ADB

#411

Earlier quoted context omitted.

IT has always been a spectrum with security at one end and convenience at the other. There is no recent trend that’s changed that. That’s just how life works.

"Better things aren't possible" is a terrible outlook. There have been real improvements in this space, such as passkeys, and recognition that some of this stuff, like frequent password changes, is counterproductive.

> Better things aren't possible

Literally no one in security thinks this.

Re: Android may soon restrict on-device ADB

#412

Earlier quoted context omitted.

IT has always been a spectrum with security at one end and convenience at the other. There is no recent trend that’s changed that. That’s just how life works.

Right, but security maximalist are running the asylum now, and they try to sell everyone the lie that more security is possible. Also, the original sin: framing it as "security" vs. "convenience". It's not. The other end of the spectrum is utility - as in, maximally secure computing device is an inert rock. More security means less utility - reduced functionality, constrained capability, reasonable use cases no longe…

> Right, but security maximalist are running the asylum now, and they try to sell everyone the lie that more security is possible.

That’s not what’s happening. Here you have security used as an excuse for vendor lock ins. Just like AI is used as an excuse for layoffs. But you shouldn’t confuse actual security with BS like this.

Re: Android may soon restrict on-device ADB

#413
post #128

Limiting ADB is the obvious next step. Even if this one specific feature request does not come to pass, Google has cornered everyone into relying on a developer interface for any normal personal computing tasks, whether running on-device or through USB/wireless. It's quite clear at some point in the future you will either be required to surrender your identity to them and pay a yearly fee or be severely limited to co…

> As if you didn't need any more proof you don't own "your" devices.

Speak for yourself. Sent from my GNU/Linux phone Librem 5.

Re: Android may soon restrict on-device ADB

#414
post #26

Earlier quoted context omitted.

The implication in the blog post that Google developers somehow “overlooked” or “misunderstood” important use cases here, and if only they were informed about them they would reconsider, is frankly insulting.

Every single time any story has the words "Google developers" in it, they're behaving like arrogant, disconnected, anti-consumer jerks. From constant GCP breakage, to not acknowledging obvious Android bugs, to intentionally braking Chrome. It's a stark contrast to behind the scenes interactions with them.

Exhibit A: https://issues.chromium.org/issues/40093420

Decades of people desperate for a fix, utter stonewall from Google

Some PM somewhere decided that autocomplete belongs on all your fields, and who are you, the poor site developer, to disagree?

Re: Android may soon restrict on-device ADB

#415
post #237
post #206

Earlier quoted context omitted.

The EU shouldn't be regulating Google like this. The US should.

Why not both? Countries should be able to signal which business practices are undesirable.

The EU can't realistically bring Google to its knees. The US could.

I say that as a European that's very much in favor of government intervention to fix market distortions.

Re: Android may soon restrict on-device ADB

#417

Earlier quoted context omitted.

There is a simple and highly accurate heuristic to tell if a security measure is reasonable: Is it an open standard that anyone can permissionlessly implement? When the answer is yes, there is a high probability that it's something reasonable, e.g. TOTP. When the answer is no, what you will find behind the curtain is either a fool or a crook.

This heuristic is not covering the dimensions of interest here, because it fails to address the key security questions (that the industry usually wants people to not even think about): Who is doing the securing, whose interests are being secured, and against who/what? Security isn't an unqualified good thing to have. It's just an instrument of control. Who wields it and how are the paramount questions. You can have a…

Right, and that leads us back to the more-generalized (but very classic) cui bono? Who gets the benefits?

Re: Android may soon restrict on-device ADB

#418

Earlier quoted context omitted.

It requires a nuanced discussion and willingness to compromise to find the right balance. I don't like it myself when, every macOS release, Apple nerfs the system even more and locks down even more, but I also don't like telling my relatives that their system is part of a botnet and that they need to change all their password and call their bank, simply because they saw a popup that told them to download and run Troj…

It used to be common knowledge that downloading stuff could be dangerous. That went away when vendors tried to make it safe.

Many software vendors have deliberately blurred the lines between "on your computer" and "on the internet". When you save something in Application A, is it really being saved on your computer, or is it in the cloud? It used to be obvious, but now you kind of don't know until you do some digging in your filesystem. And, now we actually run some apps from the web!

The phrase "the user doesn't have to know if this is on his computer or the cloud" has done a lot of harm to the software ecosystem.

Re: Android may soon restrict on-device ADB

#419

I am generally in favor of security improvements, but I do not really see much of a benefit here. This attack vector requires both that the user enabled developer settings and that they have remote adb enabled. So, this does not seem to be a realistic attack vector for 99.9% of the users and most of the other 0.1% probably know what they are doing. The other proposed change (to restrict access to certain interfaces o…

In the post iPhone era, a lot of what gets sold as security features is actually just removing functionality from the device. In early days of this, I honestly think it was rooted in the famous Steve Jobs paranoia, the one that shipped without an app store and told users to use Safari, the same Steve Jobs that was said to not want certain medical devices during cancer treatment to touch him because they weren't beaut…

Hard disagree. iPhones are some of the most secure devices available. They are much more secure than desktop computers. This is a good thing because it protects users private data. With how much personal data phones, it seems reasonable to secure them extensively.

That's why I use GrapheneOS.

Re: Android may soon restrict on-device ADB

#420
post #242

Earlier quoted context omitted.

It seems to me a lot of Google lately is to block things they don't like using ways that only look like side effects. The introduction of Manifest V3 API in Chrome for extensions, and disabling Manifest V2 for security reasons. It just so happened that ad blockers were made incompatible with the Manifest V3 API. It's a little blatant considering this came right around the time that YouTube began showing warning messa…

I still can’t believe that an advertising company was able to effectively neuter ad/content blocking for 80% of the world under the guise of wholly invented safety issues.

uBlock origin and Brave shields work great. Never had a problem.
Post reply on HN