Live data from Hacker News

F-Droid version of KDEConnect uninstalled by PlayProtect

discuss.kde.org

61–70 of 192 posts

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#61
post #39

Earlier quoted context omitted.

Yes, and the reasons are instructive. When you get to the lowest level, technically, the banking apps want to store files on the phone that the user can't access. This means that something like lineageos can run banking apps, if the phone tells the banking app what the app wants to hear. It's fiddly but can be done, and in fact it is what I do on my private phone. It also means that a platform that fundamentally give…

While I can understand Google and the banking apps' actions, it doesn't make much sense given how PCs having root is hardly every a concern for a bank. If you can do something bad with banking on a rooted device, it's probably doable on a computer too.

Oh, banks are definitely concerned about PCs having root. There are even some banks that have removed their online banking websites entirely (except, perhaps, for corporate clients) and require customers to do everything through the Android app instead.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#62

Earlier quoted context omitted.

Banks in many countries require an Android phone for online banking. Even if they offer an online-banking website that you can access with any browser, you may still need the Android app for 2FA. This is one of a number of reasons why the PinePhone or Librem is unfortunately not a daily driver. Also, things like paying for parking or interacting with public services are moving to Android apps in some places.

Do not use banking apps on a phone because it is not secure (there is no second factor). Use bank's website on a laptop instead.

Unless you're using a Chromebook or similar device as the laptop, this is kinda out of date, if using best practices.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#63
post #45

Is this proven? Some days ago I saw the reddit thread which is actually the first and only reply in the link and in that reddit thread there is no conclusion yet on who is actually affected why this conclusive title then?

The reddit thread makes it pretty clear that KDE Connect installed through third party sources are what's getting uninstalled. Nobody with it installed from the play store mention it being removed, and though some users that got it from F-Droud mention it still being installed, there are several possible explanations for that. Like me, it wasn't removed on my phone but it turns out I disabled PlayProtect at some poin…

Even if it is like you state, link directly there, to the exact posts that prove this and not in an intermediate site. HN is supposed to keep a higher post standard

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#64

Earlier quoted context omitted.

While I can understand Google and the banking apps' actions, it doesn't make much sense given how PCs having root is hardly every a concern for a bank. If you can do something bad with banking on a rooted device, it's probably doable on a computer too.

Oh, banks are definitely concerned about PCs having root. There are even some banks that have removed their online banking websites entirely (except, perhaps, for corporate clients) and require customers to do everything through the Android app instead.

Huh that's interesting, thanks for mentioning it. I wasn't aware of that.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#65

Earlier quoted context omitted.

While I can understand Google and the banking apps' actions, it doesn't make much sense given how PCs having root is hardly every a concern for a bank. If you can do something bad with banking on a rooted device, it's probably doable on a computer too.

Oh, banks are definitely concerned about PCs having root. There are even some banks that have removed their online banking websites entirely (except, perhaps, for corporate clients) and require customers to do everything through the Android app instead.

My bank and my wife's bank both require 2FA. On the app, one of the Fs is having physical access to the device (the phone/app, which was vetted by the bank when the app was installed). On web browsers, these two banks don't offer any factor like that.

In end effect, the banks treat a non-rootable device as suitable as a "something you have" factor, but will not treat a rootable device as that.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#67
post #12

Earlier quoted context omitted.

Why are you under the impression that since I want to use a more secure OS than Android or the equivocating Apple that I must be wanting to bomb a university? Please.

Absolutely not. But if anything bad happens, or you are attending a protest and suddenly getting investigated for rioting, you might have second thoughts. I do not condone or endorse illegal activity. That does not mean your use of GrapheneOS might not be used against you if you use it at an inopportune time. There is currently almost no discussion online about this, so it’s worth a mention. Edit: I forgot to mention…

People have been trying to stick Linux and the AOSP for the same reasons, but it's quite obviously never worked. Linux and Android are not popular because they are superior security tools, they are popular because they are free and accessible. Governments play poker, they don't want you to know what their hands look like. Condemning any particular software is the equivalent of folding their hand; it's an admittance of defeat. It won't happen unless they face a hopelessly equipped adversary, like Huawei.

GrapheneOS is likely not a secure system, but neither is any smartphone OS. I'll compliment anyone taking steps towards transparency that makes governments and global-scale corporations tremble at the knees.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#68
post #51

Earlier quoted context omitted.

LineageOS is supported on a bit more devices, and works with microG if you're willing to sacrifice Google Pay for better battery life and less privacy violations: https://lineage.microg.org/

Interesting, can I still use the Play Store with mircoG? I already run LineageOS, but with Play services. I would like to be able to ditch Play services, but still need the Play store for things like my banking app, and an app to log in to government services.

You can install apps from Play Store with Aurora Store, which is in F-Droid.

I'd say it's a toss up whether specific apps will definitely work. But if they don't I'd recommending segmenting between different physical devices, and making the one that lives in your pocket as secure as possible. It's likely that you don't need to run banking and government apps on the same device that's privy to your movement.

Re: F-Droid version of KDEConnect uninstalled by PlayProtect

#70

Happened to me, I had to disable Play Protect scanning... interestingly, in ghe deacription in Android settings, it claims Play Protect will scan and WARN, not remove, apps. That is clearly a lie.

My phone forces me to reject "Play Protect" every single time I want to install an app.

If I have to explicitly reject it more than once, it is obviously malware. Once is already arguable.

Post reply on HN