Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

531–540 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#531

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

And all are useless because you can't use your mandatory bank or gov id app.

I oppose appdwang (although that can be hard, but until now I managed). Learn more about appdwang at https://appdwang.nl/ (in Dutch).

Re: Android Developer Verification: Threat masquerading as protection

#532

Earlier quoted context omitted.

There is a good solution. A big disclaimer and the user accepting the risk of running the software they want. The same solution they've been doing for years that did not need change. The new developer program is only here because it is more convenient to Google and governments.

We've known for literally decades that that doesn't actually work, for several reasons: 1. People are conditioned to ignore warnings. There are way too many benign warnings in the world; you can't read them all. 2. Even when people wouldn't ignore them, in cases where they are being tricked by scammers it's easy for the scammer to talk people into accepting them. 3. Those sorts of warnings aren't actionable. You're i…

It's 2026. This technology has been out for how long?

We can't keep catering to the lowest common denominator of user. We have lost many computing freedoms over the decades as a result of this. Sorry, but its unacceptable.

If they really want such locked down experience to be the default, they could also just as easily put out a ROM everyone else can flash that has no restrictions. You still get to cater to the lowest common denominator but without taking freedoms away from anyone else that wants to keep them, with official support. No scammer is going to convince someone to plug their phone into their laptop and flash a new ROM in order to scam them. If they can, there's no protections that would have helped in the first place.

Re: Android Developer Verification: Threat masquerading as protection

#533

Earlier quoted context omitted.

> Doesn't GrapheneOS supports only Google Pixel smartphones now? For good reasons. Most other devices arent secure enough to guarantee privacy. Especially not if loaded with a custom operating system (most devices don't allow to verify the boot chain with a custom OS) > And if we're talking about common people (especially not in US), it's not even everyone who can afford that. You can get a new Pixel 9a here in europ…

> Google phones are surprisingly open and work well. Google takes a pro-user stance here that is extremely rare in the ecosystem, so why not support this product? Because they will pull the rug here one day too. Why on earth should we trust them to keep this approach to their hardware?

they are already pulling the rug. Google took months to publish devicetrees for the Pixel 10. they've signaled (iirc) that they'll no longer make the Pixel line capable of running AOSP. the reason they even did at first was to make Pixel a reference implementation that vendors could use to port Android, but now they've announced a switch to an emulated device for that purpose.

Re: Android Developer Verification: Threat masquerading as protection

#535

We finally live in an age when I can tell a clanker that I want an app that does something that I need, connect the phone with adb and in half an hour have a working solution for my tiny problem while knowing little about android development. This is something google should embrace, not kneecap.

What's their interest in you building side-loaded apps instead of using their data hungry services?

Their interests shouldn't matter. If they matter that much to restrict, then they are abusing monopoly power and need broken up.

Re: Android Developer Verification: Threat masquerading as protection

#536

Earlier quoted context omitted.

All of which have beyond horrific security. GrapheneOS is the only acceptable alternative from mainstream Android.

Don’t they have standard Linux security? Does my phone need to be more secure than my production web server?

Linux security is quite bad. Android tries to improve this and GrapheneOS improves it even farther than that.

Which device you need to be more secure depends on your needs and which device you put sensitive data on, but a mobile device is going to provide far better privacy and security than any desktop hardware or OS is currently capable of.

Re: Android Developer Verification: Threat masquerading as protection

#537

Earlier quoted context omitted.

We're moving to a world where it makes sense to have one cheap locked down phone with the society mandated garbage apps on it, and another device that you use for real computing.

How about saying no to these "mandates"?

We aren't given the choice, in many cases. For example I remember a poster here who was forced to have an Android or Apple phone because his kids' school required an app to pick up the kids after school. So his options were to get a big tech phone, or get in trouble for not picking up his kids. "Get the school to come to their senses" was, unfortunately, not an option available to him.

Re: Android Developer Verification: Threat masquerading as protection

#538

Earlier quoted context omitted.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

> Also why do you need bank app on your phone? Many banks gate features like mobile check deposit behind the native app. The nearest ATM is 20 minutes away from my house, so unfortunately I consider this feature essential.

Interesting, I never saw a bank check. The companies typically transfer money directly into the account, and there are P2P transfers by a phone number working between any major banks. So I guess.. I do not need this feature.

Re: Android Developer Verification: Threat masquerading as protection

#539
post #21

Earlier quoted context omitted.

Apple's policies were established when you purchased the phone. Apps come through registered developers and their vetting. Google has changed the game on something you already own. I'm sure their lawyers have done their homework, but in some jurisdictions this is certainly actionable.

They already lost a lawsuit and were fined a hundred billion dollars in the EU for locking down Android. Maybe they think since they already lost once, they can't lose again.

Google had an open (but maybe not perfectly open) platform and is paying out billions in anti-competitive fines because of it.

None of the other platform vendors with totally closed platforms are paying out anything.

So with even a room temperature business IQ, it's pretty clear that closed platforms are the best way to do business, and court rulings in both the US and EU have affirmed this multiple times over the last decade.

Re: Android Developer Verification: Threat masquerading as protection

#540

Earlier quoted context omitted.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

In a town nearby me (not really near me but within an hour's driving distance), sometimes I will see old people selling fresh fruit/vegetables in their front yard. They typically take cash, Cashapp, or Venmo. It's super convenient to be able to use Venmo in that situation. These are people I haven't met before.

I usually pay with cash. As a nice bonus, cash works even if there are mobile Internet shutdowns or blackouts and they cannot block the cash in your wallet unlike a bank account.
Post reply on HN