Live data from Hacker News

Android may soon restrict on-device ADB

kitsumed.github.io

461–470 of 536 posts

Re: Android may soon restrict on-device ADB

#462
post #175

Earlier quoted context omitted.

You keep spamming variations of this comment without explaining how could apps actually bypass security without several steps that the user needs to take in order for it to work . Are you just farming down votes for some weird reason or will you finally get to the technical details instead of one-sentence snarks?

The linked bug explains exactly how. The fact that you angrily slam downvotes when you hear something doesn't like doesn't make it "farming", just like rage and rants and bizarre accusations of conspiracy in this comment thread won't change the underlying issues that this is going to fix.

If it's a bug then the bug needs to be fixed. If the auth process works as intended it's hard enough to make it not something you could do by accident.

Re: Android may soon restrict on-device ADB

#463

Earlier quoted context omitted.

More specifically apps and users have equal agency in the android security model. Which comes down to the fact that if you don't own the app you can't control its experience. This feels grounded to me. Push for more open source apps where you retain control and ownership.

No, I bought the device, I should be able to do whatever I want with it.

It's already hard enough that we can't mess with apps' internal storage without rooting IMO. It's my device. I should be able to inspect what every app is collecting about me. Just like I can on windows.

IMO the user should always be the top admin on a device they own.

Re: Android may soon restrict on-device ADB

#464
post #142

Earlier quoted context omitted.

Currently my bank requires a device where I need to insert my card to get a one time six digit code based on a QR code the banking website serves me that the device scans. I'm not quite sure why they don't support something like a yubikey with FIDO, but maybe there's a good reason.

ING supports hardware keys in some markets, so there's no reason not to.

Every bank here had that. Now they all require apps.

For the banks I understand. Now they don't have to supply millions of code calculator devices. And they force their apps which they can stuff full of tracking to mine their customers for data they can sell.

It's sad but part of the usual enshittification cycle

Re: Android may soon restrict on-device ADB

#465

Earlier quoted context omitted.

You forgot your $3 payout from the class action lawsuit when the company STILL gets hacked and the exec bonus pool increases because the settlement wasn't "that" bad.

$3 payout? You're being generous, last time there was a major breach, I believe Equifax gifted the victims a year of "free subscription" for their service. Accountability is nonexistent in our industry.

The CRAs compete for the opportunity to offer "a year free credit protection" (that a breached company pays for), because to get it, you usually have to provide a credit card and subscribe to the highest tier. You get your free year and then they turn you into a paying member unless you remember to cancel.

Re: Android may soon restrict on-device ADB

#466

I am generally in favor of security improvements, but I do not really see much of a benefit here. This attack vector requires both that the user enabled developer settings and that they have remote adb enabled. So, this does not seem to be a realistic attack vector for 99.9% of the users and most of the other 0.1% probably know what they are doing. The other proposed change (to restrict access to certain interfaces o…

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition),…

Not until we clearly identify the deep root from which all of this is conveyed.

Re: Android may soon restrict on-device ADB

#467

Earlier quoted context omitted.

No, I bought the device, I should be able to do whatever I want with it.

It's already hard enough that we can't mess with apps' internal storage without rooting IMO. It's my device. I should be able to inspect what every app is collecting about me. Just like I can on windows. IMO the user should always be the top admin on a device they own.

It sounds like you are just at odds with the android security model: https://arxiv.org/pdf/1904.05572

Re: Android may soon restrict on-device ADB

#468

Earlier quoted context omitted.

It's already hard enough that we can't mess with apps' internal storage without rooting IMO. It's my device. I should be able to inspect what every app is collecting about me. Just like I can on windows. IMO the user should always be the top admin on a device they own.

It sounds like you are just at odds with the android security model: https://arxiv.org/pdf/1904.05572

Indeed I absolutely am. I don't believe in this model where we have to trust some big commercial party for our security and privacy. And they abuse this all the time, both Google and iOS.

The problem is though that I have no choice. iOS is even more locked down and distrusting of the user. It's never even had a bootloader unlock option for example. And not using a smartphone is not possible in this day and age.

Re: Android may soon restrict on-device ADB

#469

Earlier quoted context omitted.

"Security" is just a scourge on software at this point. It means 2FA on every trivial site, being logged out every few hours for no good reason, having to fuck with settings and type "disable sandbox" to run an agent in YOLO mode which still won't work over mobile, being unable to install an unsigned extension at all in firefox (not behind a setting, literally impossible - you have to get Firefox Developer Edition),…

I'm begging, please let me use password "asdfasdf" on throwaway accounts. I accept full responsibility for the fallout. Seriously, many web admins need to hear this message: "Chill. Your site is not that important."

It’s always interesting to see how fast someone takes a proposal and takes it to some ridiculous extreme.

Websites don’t know your account is a throwaway one, and making an exception for those accounts doesn’t make sense anyway.

Saying “ I accept full responsibility for the fallout” obviously doesn’t work on a large scale and here exceptions don’t make sense either.

Just use a password manager that generates and fills your passwords, and never worry about your passwords for those sites. Don’t tell web admins to drop basic security measures because you don’t know how to manage passwords.

Re: Android may soon restrict on-device ADB

#470

Earlier quoted context omitted.

I'm begging, please let me use password "asdfasdf" on throwaway accounts. I accept full responsibility for the fallout. Seriously, many web admins need to hear this message: "Chill. Your site is not that important."

It’s always interesting to see how fast someone takes a proposal and takes it to some ridiculous extreme. Websites don’t know your account is a throwaway one, and making an exception for those accounts doesn’t make sense anyway. Saying “ I accept full responsibility for the fallout” obviously doesn’t work on a large scale and here exceptions don’t make sense either. Just use a password manager that generates and fill…

Your site is non trivial.
Post reply on HN