Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

621–630 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#621

Earlier quoted context omitted.

> Europeans are doing this to themselves. I mean, tbf the situation was fine until the US transitioned to an autocracy, and the companies went full surveillance state evil, completely supporting the autocracy. Which is a relatively recent development. But sure. Most places here are working as fast as possible to decouple from any reliance on the US, and I would expect Norway to switch to the new EU digital ID system…

> US transitioned to an autocracy this is too funny coming from a continent constantly at war with itself

Cope all you want, the broad spectrum opinion by most experts and independent research groups holds it to be true.

https://en.wikipedia.org/wiki/Democratic_backsliding_in_the_...

Re: Android Developer Verification: Threat masquerading as protection

#622

Earlier quoted context omitted.

GrapheneOS is currently the blessed child. Like CyanogenMod previously. They are "permitted" to access to Google Play Services because their work hardening Android currently benefits Google. Once Google feels like there is sufficient stability and compatibility with hardened memory allocator and tagged memory (and when they can get Qualcomm to support it across their range), they will make harder, until impossible, f…

Your claims about this don't make sense. Google does not provide compatibility with GrapheneOS for Google Play services. They do not provide support for using it or fix the issues introduced in new releases. GrapheneOS doesn't license Google Mobile Services (GMS), doesn't include it in the OS and doesn't have Google certification. It isn't permitted by the Google Play Integrity API device and strong integrity levels…

    > We're legally allowed to provide compatibility with Google Play via our sandboxed Google Play compatibility layer.
and they are legally allowed to fingerprint grapheneos and block Play functionality.

maybe once that happens grapheneos will finally take anti-fingerprinting seriously.

Re: Android Developer Verification: Threat masquerading as protection

#623
post #82

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

So true.

Maybe a case for the EU? I mean, they like creating laws limiting the power of big tech. Maybe there should be a law that requires all services that are used by public institutions and commercial transaction providers to be transparent to the public and therefore open source. And as a platform provider, they should be required to offer APIs to let users install alternative implementations.

Might require some fine-tuning, but you get the idea.

Re: Android Developer Verification: Threat masquerading as protection

#624

Earlier quoted context omitted.

This is worse than Apple. With Apple you knew where you stood day 1.

lol my god the apple shills are out in full force. this is implementing a tiny fraction of control over probably less than 1% of android users (hint for the hn crowd: you dont represent real people and you need to remember that) in an effort to stop a very real problem that far far far more than the people affected by this face. yet they are worse than apple who has been doing this since day one to 100% of users. you…

I just made a comment. Whether or not you consider it serious or not is for you to decide.

Re: Android Developer Verification: Threat masquerading as protection

#625
post #620

Earlier quoted context omitted.

I just don't get why we need to argue about something — the right to general purpose computing — which has been answered decades ago? The user must be the administrator of their own device. Whether that's a laptop, desktop, PDA, mp3-player, smartphone, tablet, cyberdeck, netbook, or any other kind of computing device. The user must be able to overrule any and all decisions. That's the definition of ownership . Like,…

We're still arguing for several reasons, one of them is that people still confuse the user with the owner, as you do. "The user must be able to override" is implies that if you have physical access to someone's phone, you can install a keylogger before handing the phone back its owner. Nice for you but I imagine the owner might still quibble, even if you quote TRON.

If I hand my windows laptop to someone, they can also install a keylogger.

But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes.

It's ridiculous that changing the settings on my device is protected 10× more than transferring all my money to a random person.

Re: Android Developer Verification: Threat masquerading as protection

#626

Earlier quoted context omitted.

[flagged]

> every app installed is known to the proxy since each app has a unqiue key No such proxy exists in GrapheneOS. GrapheneOS does not intercept or proxy connections made by Google apps or other apps. GrapheneOS doesn't include Google Mobile Services. Sandboxed Google Play is not part of GrapheneOS. Users can choose to install Google Play services, Google Play Store and other Google apps on GrapheneOS. Unlike a standard…

[deleted]

Re: Android Developer Verification: Threat masquerading as protection

#627

Earlier quoted context omitted.

I don't think its rigid at all. Its important to continue to be able to receive security updates. If a device can't, mostly because qualcomm/firmware no longer wants to bother 6 months after release, it's DoA. We don't go around telling people that it's OK to still run Windows XP for the same reason. Why is/should mobile be any different? Stop being OK with manufacturers having garbage support. It's completely unacce…

The dichotomy here isn't grapheneos or updates, it's grapheneos or android.

GrapheneOS uses all of the standard Android security features including hardware-based security features. It also adds major security improvements including features heavily based on hardware security features which are either entirely unused or barely used by AOSP or the Pixel OS. Heavily using hardware memory tagging, integrating our USB protection with the USB controller and other features are core parts of what makes it GrapheneOS. An incomplete port without all the standard security features or the GrapheneOS added security features isn't GrapheneOS.

GrapheneOS closely follows along with Android releases, Linux kernel LTS revisions and driver/firmware updates. It had an experimental release based an Android 17 after only 2 days of it being released earlier this month. It quickly made it through our testing process with many regressions resolved to our Stable channel. This is part of what makes it GrapheneOS and an incomplete port to another device without the same updates wouldn't be GrapheneOS.

GrapheneOS is open source. People can make an incomplete port of GrapheneOS to other devices using their own project name. It's not a port of GrapheneOS to another device without having all the features and updates.

We phase in new hardware requirements for standard security features and the older generation devices without those are eventually gone. Adding a new device without hardware memory tagging would be far different than still supporting 6th/7th gen Pixels without it since we strongly recommend against buying those devices anymore and they're going to end up end-of-life.

Re: Android Developer Verification: Threat masquerading as protection

#628
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

> Android users need to switch to Graphene. Doesn't GrapheneOS supports only Google Pixel smartphones now? For most of the users, that would mean changing their phones beforehand. And if we're talking about common people (especially not in US), it's not even everyone who can afford that. Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.

  > Moreover, in my opinion, by buying Google phones you're feeding Google, and I, personally, would like to avoid that.
I bought an iPhone based on that very decision. TBH, I regret it. The ecosystem is so locked down that I can't even sync my photos to my NAS without a hacky constantly breaking shortcut, building my own app, or paying for an app. Just to replace a small That would all be worth it, but it's been a few years and Google did all the shitty stuff I was protesting anyways and Apple is getting worse.

I'm hoping we get those moto phones with graphene pre installed so I can actually send the right market signal. But what's fucked up these days is you can't send the right market signal. Meanwhile I talk about fixing shit at work and my coworkers ask "what's the value" or say "there probably isn't any money in doing that". Even for problems they are one liner fixes and that they agree we spent more time arguing over than it would be to fix it. I don't think it's a top down problem, it's a bottom up. Those are much harder to solve

Re: Android Developer Verification: Threat masquerading as protection

#629

Earlier quoted context omitted.

You are free to make your own build of GrapheneOS with root access and have extremely reduced security. Just don’t expect support on the forums and waste everyone’s time when something happens.

"extremely reduced security" That's such a fun statement. Any security measures taken always remove agency from one person and give it to another. iOS takes my control away, and in turn gives that control to Apple. GrapheneOS takes my control away and gives that to the GrapheneOS developers. The "security" you're talking about doesn't prevent certain data from being accessed, it just changes who controls the access.…

The sad part is that this has a solution. It's called adb root. Your adb stays locked unless you unlock it, and you're not able to get root on the phone. But you can through the adb shell, meaning that when app X wants to screw your data away from you you can still copy it. There is something deeply wrong about locking filesystems even from read access. GrapheneOS should at the very least give a full read-only access to the fs through (possibly) limited adb access.

Re: Android Developer Verification: Threat masquerading as protection

#630
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

The reality is that these types of problems affect too few people to matter. No appreciable amount of people will switch, or are even capable of it. And even if you made it a no-brainer, most people aren't going to change the OS that came on their device, warranty or not.
Post reply on HN