Live data from Hacker News

Keep Android Open

f-droid.org

651–660 of 764 posts

Re: Keep Android Open

#651
post #291

Earlier quoted context omitted.

Google made the first move with their initial plan to lock it down, so the onus is on Google to calm the fears they caused if they don't want people to distrust them.

But they did. That was the announcement that they would still allow sideloading. If you are still afraid then that's kind of on you. Seems silly to expect Google to put out info about enabling sideloading for a system they haven't even released yet. It could very well be in there day 1. Nobody knows.

Google needs to put hard evidence that they are doing it. Sorry but just saying something isn't enough proof. Talk is cheap show us the code.

Re: Keep Android Open

#652
post #635

Earlier quoted context omitted.

Complain. Mine wanted that, but after complaining they offered me SMS. If not, I'd have closed my account there. At least here in Spain there are plenty of banks that don't force you to use apps. I also leave bad ratings for banking apps from time to time, and bad comments on X.

Since before 2023, MFA has been mandated by the government in Australia [0], for all critical services, including banks. One without, does not exist, or is in violation of their national obligations and likely to be cut off by the RBA. The only "effective" complaint here, would be the gigantic effort to lobby for a change in laws entirely. [0] https://www.apra.gov.au/use-of-multi-factor-authentication-m...

In my country there are regulations in effect too that mandate the use of MFA; however, using an application is not the only way to implement MFA, as I said, in Spain banks can use SMS, coordinate cards, etc., and they are all valid MFA methods. I think what these laws are missing is the obligation for the service (the bank in this case) to provide a MFA device if the user doesn't have one.

Re: Keep Android Open

#653

Earlier quoted context omitted.

> shape a dedicated account type for students and hobbyists. Even that is a step too far in the wrong direction. Doesn't matter if it's free, or whatever, simply requiring an account at all to create and run software on your own device (or make it available to others) is wrong. There exists no freedom when you are required to verify your identity, or even just provide any personal information whatsoever, to a company…

The problem with this mentality is that you're not proposing a solution that solves the problem Google and Apple are trying to solve (or are at least stating they are). Rather than just vent about ideals, showing up to the table and listening to the requirements of all stakeholders (even if they differ from yours) will lead to a more productive result. I would not listen to your concerns if you didn't listen to mine.

They aren't actually trying to solve any real problem.

Re: Keep Android Open

#654
post #542

Earlier quoted context omitted.

And yet the Play Store and App Store are the largest vectors of scams and malware out there, to the tune of billions of dollars a year. We should be prioritizing securing our systems so that they run only what we want them to run, instead of putting all of that trust in gatekeepers who make money when they let you get scammed.

They are the largest vector of scams and malware because they've centralized it and it's hard to deliver malware and scams otherwise. That malevolence will always happen and centralizing it ensures a single avenue that can be controlled and measured and importantly sued when they fuck up. I can't sue f-droid when they allow malware on my device, that's one of many reasons why I don't use it, that's why nobody uses it…

> I can't sue f-droid when they allow malware on my device

How many people have successfully sued Google because of malware on the Play Store? Ever?

Re: Keep Android Open

#656

Earlier quoted context omitted.

> Fully opensource hardware with fully opensource software? Maybe, but also this is wishful thinking. My smartphone runs an FSF-endorsed OS, PureOS. This is reality. It's not open hardware, but it's a long way from Android in the right direction. You can also get a Precursor, which is open hardware.

A Precursor costs about 1000$ and only does cryptography, not Flappy Bird. Most of these supposedly open alternatives make no economic sense.

It does instead, imho. Commercial phone cost also includes the data value it steals continuously.

Re: Keep Android Open

#657

Earlier quoted context omitted.

There's no point. Remote attestation means your device needs to be corporate owned to be trusted. Even if you had your own linux phone, it wouldn't be able to interface with institutions such as banks and governments. They trust Google's keys, not yours. This doesn't quite end free computing, it just kills it for normal people and ostracizes us hackers who insist on owning our systems.

GrapheneOS supports remote attestation: https://grapheneos.org/articles/attestation-compatibility-gu... Some banks have added their verified boot keys. I think it helps that GrapheneOS is well-known by now for great security practices (most likely more secure than all vendor phones out there).

> Some banks have added their verified boot keys.

Seriously?? That was very unexpected... Here's to hoping this becomes standard practice!!

Re: Keep Android Open

#658

Earlier quoted context omitted.

They will.

Credit unions, at least in theory, are known for caring more about their customers. It'd be worth explicitly giving them the feedback that you use them via their website or via an app that works on an Open Source phone, and telling them that that's one reason you're a customer.

Fraud prevention. If they lock things down, they lose less money to fraud. I think they should just have to suck it up and eat the cost but obviously they don't think that way. Only a small minority even understands and cares about these issues. The money they save by trampling over our freedom is no doubt much higher than the value brought in by us. They will no doubt sacrifice us for increased profits if we force the issue. We have no leverage.

There is no reason whatsoever for a major corporation to not use remote attestation technology. Banks will use it because fraud. Streaming services will use it because piracy. Messaging services will use it because spam, bots. If you're the corporation, the user is your enemy and you want to protect yourself from him.

Governments want this too. Encryption. Anonymity. They need to control it all. Free computers are too subversive for them. They cannot tolerate it.

Re: Keep Android Open

#659
post #308

Earlier quoted context omitted.

Yes, these things move slowly, but they do move =)

They have moved much faster on much more complex plans though. If this is a case of Apple breaking the law then surely they wouldn't need over two years to tell them to stop it? The EU regulations seem largely to be, you need to do X and you need to figure out how to comply by Y date. They aren't gently guiding these corporations to compliance. So I'm leaning more towards Apple is in compliance and the common percept…

Can you give an example of where a legal matter on this level has been resolved "much faster"?

Re: Keep Android Open

#660
post #646

[flagged]

I have literally never thought about it like this, but I think you are right. In my mind mobile phones were always separate from other devices, kinda like consoles.

This is actually the main idea of Purism, company producing phones and computers: https://puri.sm/posts/foreshadowing-why-the-purism-logo-is-a...
Post reply on HN