Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

451–460 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#451
post #356

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

I would strongly advise using your personal account to access the developer-side of the Play Store. No, these services shouldn’t all be bundled under a single account…

Missing: [not]

Re: Android Developer Verification: Threat masquerading as protection

#453
post #266

Earlier quoted context omitted.

One of my best friend has a Jolla phone. He never had WhatsApp. He refuses to use google. Only till recently he started using signal. He has been using an old Nokia phone till he was forced to upgrade by his operator. He is European and here in Europe WhatsApp dominates. Despite all that and having a very social life, driven by work, he manages. I recently ordered a Jolla phone. I don’t want to know about android. I…

It's all good until your European bank starts requiring unrooted Android and iOS for their mobile banking app, then tries to force you to use that app instead of letting you sort things out at their building. Then the government starts requiring you use unrooted Android or iOS to sign into their website for administrative tasks, and so on.

Then I'd switch bank. A lot of banks work with SFOS [1]. Given the way the US is acting, we are trying to lower our dependence on American services, and I very much doubt all banks will walk the US bandwagon. There's a serious market for something else.

[1] https://forum.sailfishos.org/t/banking-apps-on-sailfish-os/1...

Re: Android Developer Verification: Threat masquerading as protection

#454

Earlier quoted context omitted.

You are free to make your own build of GrapheneOS with root access and have extremely reduced security. Just don’t expect support on the forums and waste everyone’s time when something happens.

"extremely reduced security" That's such a fun statement. Any security measures taken always remove agency from one person and give it to another. iOS takes my control away, and in turn gives that control to Apple. GrapheneOS takes my control away and gives that to the GrapheneOS developers. The "security" you're talking about doesn't prevent certain data from being accessed, it just changes who controls the access.…

>If the user cannot be trusted with their own data, then there is no solution anyway. They'll just tell their private data to a scammer on the phone instead.

Security isn't binary. Putting up barriers makes it harder for scammers to steal money. There's a reason why they exploit malware to steal money, rather than asking their victims to send them crypto directly.

Re: Android Developer Verification: Threat masquerading as protection

#455
post #41

Earlier quoted context omitted.

I know Graphene has innovative security measures, do you happen to know whether that includes anything wrt. phishing or social engineering? (For those who haven't been following along: this whole affair started with phishing. People were social-engineered into installing an app and a little later their bank accounts were empty. A big issue in various poor countries.)

my brother in Christ, people who root their phones don't fall for "Hello sir, I'm sir John from Microsoft, you have virus sir, please do the needful install antivirus and send gift card sir."

Right, instead they download shady magisk modules that promise them free fortnite skins.

Re: Android Developer Verification: Threat masquerading as protection

#456

Android developer verification program, together with recent reCAPTCHA push [1], and Manifest v2 force depreciation on chrome [2], make one thing crystal clear. When companies like GOOGLE talks about things in the name of "your security", it's a sign that they want you to sacrifice your own things, e.g., privacy, freedom, etc., for their own security. And if you trust them and show your consent by doing nothing, you…

Article got developer verification completely wrong. The point of developer verification is to be able to install apps outside the app store without warning, which brings Google Android builds in compliance with the antitrust ruling. Third party Android builds can choose other trust roots or disable ADV completely and require warnings for everything because they are not subject to the judgment.

Separately, the process of installing apps that are outside a system app store and aren't verified has also changed, but this is not required by the developer verification feature, and the result seems like a wash to me. The first time you enable installing apps from other sources is harder, but this setting then persists across device upgrades, so the subsequent times go away completely. This now requires developer mode, but apps that check developer mode (I haven't found any in the US) can be mollified with a Tasker task to disable developer mode when launching those apps and enable it again after.

Re: Android Developer Verification: Threat masquerading as protection

#457

Earlier quoted context omitted.

We've known for literally decades that that doesn't actually work, for several reasons: 1. People are conditioned to ignore warnings. There are way too many benign warnings in the world; you can't read them all. 2. Even when people wouldn't ignore them, in cases where they are being tricked by scammers it's easy for the scammer to talk people into accepting them. 3. Those sorts of warnings aren't actionable. You're i…

The problem is easy to solve by making 99% of all apps normal apps that don't get any special privileges and don't require any developer certification, and having a certified developer program with heavily locked down run mode for the 1% of high security apps like banking and payment apps. It's not hard to attest unambiguously to the user in some way whether they are running one of these rare secure apps or a normal…

>and having a certified developer program with heavily locked down run mode for the 1% of high security apps like banking and payment apps.

How do you determine/enforce whether an app is a "payment app" without a centralized developer program? They don't require any special privileges. After all, most banking apps have web equivalents.

Re: Android Developer Verification: Threat masquerading as protection

#458

Earlier quoted context omitted.

Installing via adb is not affected.

That's great but I want to be able to share such app with my family members coleagues

Are they such new/fleeting friends that they can't wait 24 hours? Otherwise, it might be a good thing that people can't be persuaded to install an app because a "friend" told them to, and it's somehow so urgent that they can't wait 24 hours.

Re: Android Developer Verification: Threat masquerading as protection

#459

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

This has been known for quite a while; when I published an Android app ~10 years ago I saw lots of people advising you to create a separate Google account to publish apps under, because a robot can just terminate your entire online identity for the crime of trying to contribute to Google's app ecosystem.

I left behind Android and as many Google services as I could in 2020 and so far I've only been more vindicated with that decision over time.

Re: Android Developer Verification: Threat masquerading as protection

#460

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

That sounds liberating
Post reply on HN