Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

551–560 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#551
post #516
post #186

Earlier quoted context omitted.

Pixels are consistently "third party Android builds friendly", plus GrapheneOS has a list of required security features (beyond their control): https://grapheneos.org/faq#future-devices e.g. first one in the list: > Support for using alternate operating systems including full hardware security functionality GrapheneOS wants users to lock the bootloader (≈enable Secure Boot) after install by providing user signing key…

Why don't they support Fairphone and Nothing, then?

These devices fall far behind the industry standard hardware security requirements GrapheneOS has.

Re: Android Developer Verification: Threat masquerading as protection

#552

Earlier quoted context omitted.

Suing a company will almost certainly result in them exercising their right to not do business with you and shutting down all your accounts - exactly what OP was trying to avoid

In some EU countries - it could be seen as retaliation if you sue for something and then Google closes your accounts, some EU countries have strong protections here. More importantly for Google though it's under extra scrutiny under the DSA at the EU wide level - so it doesn't have a clear right to not do business, it has to do terminations correctly with clear reasons set out in terms, there are mandatory notice per…

Let us know how that works out for you!

Re: Android Developer Verification: Threat masquerading as protection

#553

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

I can do everything on my bank app from prepaying small amounts of a loan, spend analysis, opening fixed deposits and such.

Re: Android Developer Verification: Threat masquerading as protection

#554

Earlier quoted context omitted.

It's not Linux phones that we need. We already have alternatives, like graphene and other AOSP forks. We need corporations and governments to stop locking down and gatekeeping vital software to closed ecosystems. A Linux phone doesn't help me when my government's 2FA system (BankID) only runs on Android and IOS phones and can only be acquired with an app store account.

[flagged]

GrapheneOS does not run anything through google services. Nowhere in the "terms" is this stated. GrapheneOS uses first party servers for all default OS connections.

Re: Android Developer Verification: Threat masquerading as protection

#555

Earlier quoted context omitted.

An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security. It would theoretically be possible to port it to a newer kernel but that's not within the scope of LineageOS. It doesn't do that so there aren't Linux kernel updates since the kernel branch has been end-of-life for years…

> An end-of-life Xiaomi device with no privacy or security patches for the firmware, Linux kernel, drivers and HALs for years doesn't provide the bare minimum for protecting user privacy and security. Your very rigid view of the world is so distorted to the point of being absurd. You know damn well that the vast, vast majority of spying on Android is done in userspace. A good OS that allows you to remove permissions…

But on a Linux kernel that old userspace is kernelspace. There have been so many privilege escalation exploits in the kernel since then there is no difference. Every app you install effectively runs as kernel or root if it wants to.

Re: Android Developer Verification: Threat masquerading as protection

#556

Earlier quoted context omitted.

my brother in Christ, people who root their phones don't fall for "Hello sir, I'm sir John from Microsoft, you have virus sir, please do the needful install antivirus and send gift card sir."

You’re right, they just fall for installing updates or CLI tools which install compromised dependencies and run wild on a rooted system before getting caught 24 hours later.

on their phones?

also, 'rooted' means you have root access, not that you run everything as root.

Re: Android Developer Verification: Threat masquerading as protection

#557
post #233

Btw. This whole debacle made me to stop installing any Android updates. I've done my best to avoid installing even the security updates, so my diabetes apps continue working in the future. I really need to take the time and go with Graphene OS in this device. My bank N26 kind of still allows it, but they made it harder and harder to use with certain custom checks. Looks like in the future I need a separate banking ph…

Google Play Services is independent of Android releases and will update itself automatically, though I believe you can disable this by uninstalling a specific system app with adb.

Re: Android Developer Verification: Threat masquerading as protection

#558

I think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.

Have a friend lawyer that will send them a proper letter. They will take you seriously that way. And if you live in EU, use GPT... Actually, use Gemini (!) to craft another great response invoking a number of articles etc that they are in violation of.

Re: Android Developer Verification: Threat masquerading as protection

#559

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

Some banks require 2FA through their phone app to login to internet banking on the computer.

Re: Android Developer Verification: Threat masquerading as protection

#560
post #108

Earlier quoted context omitted.

The blast radius is far worse than any "malware" Google could protect you from. TFA is playing it up, but it is arguable that this is a real virus, except the shady hackers are Google.

Malware on Android causes more harm, both to individuals and collectively to all Android users, than Google locking people out of their accounts. These aren't even in the same order of magnitude. There are countless examples of people who have lost their life savings, all their data, etc. Losing access to your Google account sucks too, and I don't necessarily agree with what Google is doing here, but you're completel…

The comparison is not Google app store security vs nothing.

It's app store security vs app store security with verified developer IDs

The fact that the android fraud is not endemic means that the later is not worth the increased risk of losing your Google account.

Post reply on HN