Live data from Hacker News

Linux phones are more important now than ever

feddit.org

441–450 of 515 posts

Re: Linux phones are more important now than ever

#441
post #338

Earlier quoted context omitted.

Are you implying that Google is unable to distinguish whether a screenshot is triggered via a combination of hardware buttons vs via a software call from another app that isn't even on the foreground in their own ecosystem? That's a quite sad state of affairs, isn't it?

When you don’t control the hardware a lot is off the table.

This is a fine excuse for most everyone, but not Google. They can control the hardware significantly and in some cases like pixel, completely.

They no longer believe in owner control. Either that or they consider themselves the device owner, which is even worse IMHO

Re: Linux phones are more important now than ever

#442
post #391

Earlier quoted context omitted.

It is not for preventing you from taking screenshots, if you insist, you can do it with another camera. It is to prevent malware and "helpful" AI tools from doing it for you and then uploading the picture to who knows where. Signal does this too, though I think it is optional. Beyond preventing screenshots, it blacks out the window content in the task switcher, which is useful if someone is looking over your shoulder…

I mean if the goal is to prevent potential malicious apps from taking screenshots automatically; instead of saving a clueless user from themselves or worse getting in the way of legitimate users I believe that the proper solution is to disallow programmatic screenshots while still allowing screenshots when there is the correct button press (and ensure that this cannot be emulated). Windows reserves ctrl-alt-delete as…

> the proper solution

includes the ability from a user to take screenshots programmatically in case of need. You do not want third parties to be able to; you want the User (yourself) to be able to.

Re: Linux phones are more important now than ever

#443

Earlier quoted context omitted.

What does it have to do with the regulations? Does they forbid open phones?

Because Apple didn't want to open their ecosystem, they invested a bunch of money (and time) into "exploring what's the bare minimum required to comply with EU regulations". Now Google is locking their ecosystem down the same way because they know they are legally allowed to do so. This is why it's an "unintended side effect" of EU regulations, as the regulations prompted Apple to find out how much user hostile behav…

The DMA triggered reactions from Google and Apple that is worsening the situation for app developers and alternative app stores.

It's a failed legislation already.

Re: Linux phones are more important now than ever

#444
I am surprised that no one criticized kernel architecture as base for a secure mobile OS, yet.

Let me heat up the discussion using this quote

> The Linux kernel has atrocious security. It has an anti-security architecture, implementation and culture. The Linux kernel is not a good base for building any new operating system with a focus on privacy and security

https://grapheneos.social/@GrapheneOS/114665594121762341

Re: Linux phones are more important now than ever

#445

Earlier quoted context omitted.

In some sense they are. But being protected either from a consequence of my own stupidity or a consequence of their lack of security. I think the worst part of all is that these "bandaids" are being used in place of actual security. I don't need to be protected from my own stupidity nor do I need security theater.

I think the threat model here is that a different, malicious app (compromised, installed accidentally or by the means of social engineering) might take screenshots of your screen and forward them to take advantage of you. You can file this under one's "own stupidity" as well, sure, but in the end they're not protecting you, they're protecting themselves, because banks might be liable for these kind of things, and by…

I think you made bad assumptions. If I installed the APK through a third party, sure, my bad. But then I agree with shmel, that there's still some blame on Google. Like why not have a default where we disable screenshots not performed by a physical action and have an advanced option for API based screenshots? It's not bulletproof but neither is the current implementation.

But if I install via the playstore like most people then no, I don't think it's the user's fault. Testing every single app seems like a big ask but we're also talking about a 3 trillion dollar company. I mean FFS a 1 trillion dollar company didn't even exist 10 years ago and 10 years before that a 500b company barely did. So I think they can stand to lose some profits and do harder work. Really, if we don't hold these companies to high standards then that bar just continues lower and it's a race to the bottom. They'll be as lazy as we let them be

Re: Linux phones are more important now than ever

#446
post #338

Earlier quoted context omitted.

Are you implying that Google is unable to distinguish whether a screenshot is triggered via a combination of hardware buttons vs via a software call from another app that isn't even on the foreground in their own ecosystem? That's a quite sad state of affairs, isn't it?

When you don’t control the hardware a lot is off the table.

Sounds like a marketing opportunity to sell more Pixels and get closer to their current dream of becoming Apple

Re: Linux phones are more important now than ever

#447
post #319

Earlier quoted context omitted.

I see this argument everywhere and I've never heard of a case where a bank was liable because a customer was phished. I've even asked for examples and nobody ever provided them. It's one thing to argue in court that they should be liable because they didn't provide you with the necessary security tools (like MFA), but they all provide at least SMS 2FA these days and their apps run on iOS and Android, both of which ha…

In reality what happened is that some security auditor put it into a checklist for the mobile app "Security ISO certificate++" and now everyone implements it for compliance. Fighting against that is insane paperwork and professional exposure for software engineers that do it (since if people get phished, the C-suite will point a finger at a tech lead which went against the "professional security audit"). Most of othe…

So let's have more of these conversations so the idiots making those standards make fewer dumb rules and we can grease the wheels for anyone passionate enough to try to get it changed

Re: Linux phones are more important now than ever

#448
rather than campaigning for open phones, i think we need to actively campaign against the requirements for phones in society.

like, get some laws passed that say "if you require a phone number from someone, that's discriminatory/illegal".

this way we can remove the carriers, remove the population-wide location tracking, and ensure systems such as public transit, government interfaces, finance, etc. are still accessible.

Re: Linux phones are more important now than ever

#449

Earlier quoted context omitted.

> they're protecting themselves [citation needed] The theory here is that it provides a marginal security improvement if there is malware on the phone, but if there is malware on the phone then there are a hundred other things it can do to the same effect and you're likely screwed anyway. And by doing this, you also block the user from taking screenshots, which is bad, because screenshots are harder for computers to…

>because screenshots are harder for computers to parse, and that's a marginal security advantage. If the user is going to send e.g. their account number to someone else (for a legitimate reason), it's better that they do it as a screenshot than that you force them to type it as text, because text is machine searchable. Which is worse when that messaging system gets compromised and then the attacker can do a text sear…

Tbf, one could make the argument that there would have been far fewer resources dedicated to computer vision had companies made the data more accessible and had we modified PDFs to make it easier to copy test.

People will go to great lengths to bypass annoyances. Excessive false alarms is even called "alarm fatigue"

Re: Linux phones are more important now than ever

#450

Earlier quoted context omitted.

It doesn't really protect anything though, because you can always just use an external camera to take a picture of your screen.

Its probably meant to try mitigate damage in case bad actor gets remote access to your phone or you have malware.

Sounds like they need to spend more money on security and their "good enough" solutions aren't actually good enough.
Post reply on HN