Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

581–590 of 927 posts

Re: Your phone is about to stop being yours

#581

Earlier quoted context omitted.

> I don't think that "computing freedom" means you get to use other people's computers without consent Consent from whom? Consent is already required, why are you discussing this as though consent is not required? Why are you stating it as if people are using other's computers without consent? Right now when I sideload an APK on _my device_, I have to explicitly consent to allowing it to install. And I do not require…

You mentioned surveillance -- I presumed you were talking about the ID requirement. This only applies if you're using Google's computers to push out your app. If you sideload... what "surveillance" are you talking about? > They've now decided you can't sideload until tomorrow A single 24 hour waiting period, only the first time. Or just use ADB. The point is to prevent false-urgency scams. Honestly even this seems to…

If they're not surveilling what apps are being sideloaded, why is the bypass managed by google play services? There are at least 2 better options: - An option to not install the update which would fuck with my device - An option to use the OS layer instead of google play services for this fuckery. i disable gplay services the moment I get my hands on a new phone.

Re: Your phone is about to stop being yours

#582
post #8

I don't care, I run Graphene, and my phone is definitely mine. Most Android apps just work, and the ones that don't are the kind of malware I am happy to do without.

> I don't care, I run Graphene, and my phone is definitely mine.

It helps, but your modems are still closed chipsets you have no ability to control constantly in communication with and controlled by third parties who can execute code on your hardware at any time without your notice or consent.

Re: Your phone is about to stop being yours

#583
Someone here on HN used the term "cloud terminal" for modern electronic devices, and I think that is a very fitting name for phones and tablets. They are definitely not computers because they do not actually give the user access to general purpose computing in the sense that the users can control exactly what computations the device is going to execute. They are just terminals whose production costs we cover but which are actually owned by the cloud providers.

Also: The internet is slowly turning into a handful of clouds, and it is only a matter of time before you cannot meaningfully host anything by yourself outside of these clouds because your cloud terminal will refuse to talk to it.

Re: Your phone is about to stop being yours

#584

Earlier quoted context omitted.

Does the Librem 5 not rely on any non-free code or infrastructure?

It does. They obscure the usage of non-free hardware/firmware by not shipping it as part of the OS, but as a bundle on separate flash storage that is loaded into the OS by initrd. That blob is updatable as "firmware". The 100% free open-source is just marketing. It's just for the OS. A lot of the hardware and firmware is proprietary. https://github.com/linuxboot/heads/blob/c859c28b88b7bc197c16... https://forums.puri.…

> The 100% free open-source is just marketing.

100% FLOSS is in the OS: https://news.ycombinator.com/item?id=25504641. It is not the end of the road, but this is the only phone that can run such OS.

See also: https://news.ycombinator.com/item?id=47943487

Re: Your phone is about to stop being yours

#585

Earlier quoted context omitted.

> Why not go a bit further - the most secure device is the one you can't use to do anything at all. That's not far off a reasonable criticism of Purism's security model, that a device so wholly compromised it requires one to activate all physical kill switches to disable the hardware in order to so much as safely enter one's device PIN (per Purism's own site content), that it's no longer useful. Everyone has to make…

I have absolutely no idea what you're talking about. You're either misunderstanding something or something really needs to be changed in the docs.

Citing an article [0], a post[1] on the site states, "Security researchers over the years have discovered ways to detect what you are typing on the screen simply by looking at variations in the accelerometer." (Infomercial-esque strikethrough not retained here.)

Purism's solution, apparently, is hardware switches. As I understand it, the accelerometer isn't disabled via hardware switches unless all hardware switches are disabled, as there is no discrete accelerometer switch: "To trigger Lockdown Mode, just switch all three kill switches off. When in Lockdown Mode, in addition to powering off the cameras, microphone, WiFi, Bluetooth and cellular baseband we also cut power to GNSS, IMU, and ambient light and proximity sensors."[1]

[0] https://phys.org/news/2013-10-accelerometer-tracking-potenti...

[1] https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...

Re: Your phone is about to stop being yours

#586
post #321

Earlier quoted context omitted.

While not equivalent to a true iOS app, PWA is a decent option that allows you to circumvent the app store restrictions. If you are trying to build apps primarily for yourself, it's a decent option.

Doesn’t that require you to host it and have it available on the open web, though? Is there a host that allows you to, for free, not only HTML/CSS/JS but also access to arbitrary tools and bespoke scripts on the backend?

I'm pretty sure that if you build your PWA in a way it works offline through caching (which is easy if it's just a static website), you could host/serve it temporarily and just install it once.

Re: Your phone is about to stop being yours

#587

> "dismiss more scare screens" This whole website is a scare screen. There's a lot that is not being said on this page, such as the advantages of the new system, and the motivations of the authors of this site. There's a reasonable discussion to be had about trade-offs here, but this is entirely one sided, in somewhat bad faith in my personal opinion.

Sometimes reality is one sided, I personally see zero advantage to the new system. And I don't see how this change adresses the number one source of scams, the Play Store.

Is the Play Store the number one source of scams though? It might be in absolute terms, but Google has said malware off Play is 50x higher, and clearly Google does a huge amount of work to keep scams off Play. It seems logical to have a multi-faceted approach and try to reduce malware distribution elsewhere.

Re: Your phone is about to stop being yours

#588
post #258

This is the most important part: >> Developers Do not sign up. Don't join the program by signing up for the Android Developer Console and agreeing to their irrevocable Terms and Conditions. Don't verify your identity. Don't play ball. Google's plan only works if developers comply. Don't. Talk other developers and organizations out of signing up. Add the FreeDroidWarn library to your apps to warn users. Run a website?…

Unfortunately not gonna work.

Developers either want to make money or work for someone who wants to make money.

In either case they will be forced to.

Re: Your phone is about to stop being yours

#589

> "dismiss more scare screens" This whole website is a scare screen. There's a lot that is not being said on this page, such as the advantages of the new system, and the motivations of the authors of this site. There's a reasonable discussion to be had about trade-offs here, but this is entirely one sided, in somewhat bad faith in my personal opinion.

I agree. I don't like the idea of Android being locked down, but the conversations around this topic are tipping into disingenuous. Your phone is still yours, you can still install third party apps, and you can still develop apps without a verification. But now there's a one-off hurdle to install them. Not ideal, but when we think of the people that it's trying to protect, this feels like a reasonable middle ground.

Exactly. Nuance and good faith is in desperate need here. Google hasn't been perfect here by any stretch, but they are clearly responding to feedback. This side however seems to stick its head in the sand over security, "I wouldn't fall for it therefore it's not a problem" sort of stance, which is just talking cross-purposes. By all means push back on security being a concern, but the numbers don't support this.

Re: Your phone is about to stop being yours

#590

I've resigned to the fact that I'll need to use two phones, one with locked down Android/iOS for banking applications and government services (those require strong bank ID around these parts), another with some kind of a Linux or unlocked Android for literally everything else. Oh well, such is life, most people don't care enough about this to pressure Google/Apple/banks/governments into yielding. A big reason why a n…

Bank apps in India don't run on rooted phones, need developer mode and adb disabled. At the same time, their website works fine on Firefox on Linux where I can literally go through all their front-end source, attach and run debuggers. What even is going on? Why are banks doing this security theatre when all their apps are doing is calling some backend apis?

I think most bank apps in the western world also refuse to run on rooted phones. To my pleasant surprise my banking app worked on GrapheneOS though.
Post reply on HN