Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

651–660 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#651
post #548

Earlier quoted context omitted.

Checks are still common in the good ole USA.

Common? maybe for seniors. I probably handle a physical check once a year.

My health insurance company sends reimbursement as paper cheques in the mail, so I get multiple cheques per year. Some landlords still aren't recieving rent any other way than by cash or cheque. Happy for your chequeless existence tho!

Re: Android Developer Verification: Threat masquerading as protection

#652
post #566

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

Usability-wise, they are no match for Android and iOS—or even versions of them from five years ago. UI/UX is costly, and most FOSS projects cannot get it right without massive investments from enterprises (e.g., Red Hat's UX designers heavily contributed to GNOME) or startups (e.g., Zed, Element, Bluesky). Projects without that backing are mostly unusable, at least from a Gen Z perspective.

Biggest problem is banking, rideshare, airlines, various other service provider apps- for example, if a cell phone service requires a particular app, etc. It's not as much of a problem in the United States (besides banking), but I've noticed that in Singapore, for example, all sorts of things are tied to mobile apps.

Re: Android Developer Verification: Threat masquerading as protection

#653

Earlier quoted context omitted.

You dont have the ability to guarantee you have overridden anything. The integrity of the OS cannot be verified and anything with root can lie to you that it was revoked. It does not put power in your hands. Installing your own build does wipe the device when you unlock the bootloader, yes, but updating it with a locked bootloader does not. It would be a one time transfer if you have official images already installed…

> Your paths forward are a false dichotomy. These are not the only 2 options. You can simply update your build with the changes you want. Okay, so once I install grapheneOS, how do I update it with my own custom build while keeping my data intact? > You dont have the ability to guarantee you have overridden anything. The integrity of the OS cannot be verified and anything with root can lie to you that it was revoked.…

You would install your own build of GrapheneOS. Not the official images.

Its not advisable to run anything as root, at all. Or expose access to it in any form.

You can make userdebug builds to access a form of root that doesnt undermine the entire security model, in ADB. Afaik this lets you access apps internal directories but is not recommended for production devices.

Re: Android Developer Verification: Threat masquerading as protection

#654

Earlier quoted context omitted.

Which phones are supported by which of these operating systems? And can you provide some relevant links?

- https://sailfishos.org - https://docs.sailfishos.org/Support/Supported_Devices They have few devices of their own (new one coming out this October) and they officially support many Sony Xperia devices. There are also many community ports. - https://ubuntu-touch.io - https://devices.ubuntu-touch.io They have 33 supported devices, some are being shipped directly with the OS or have an official agreement with the phon…

I think this is all a bit optimistic. E.g. when I last looked a the Sony phones supported by SailfishOS, there was only one old model that had reasonable support. Newer phones would boot, but missed support for many hardware features.

E.g., on the XPERIA 10 IV, the camera and mic doesn't work, which makes it hard to use as a phone:

https://forum.sailfishos.org/t/functional-state-of-the-xperi...

Re: Android Developer Verification: Threat masquerading as protection

#655
post #302

All talk, no solutions from F-droid. What are they actually doing to solve it? Why not stand up their own vetting system? I'd love some technical solutions, instead this is just childish.

By analogy, would complaining about any organization ridiculously more powerful than you (e.g. a government) without having a complete alternative ready to go also be "childish"?

If the underdog is directly involved in the -alt business, yes, it is very childish!

Re: Android Developer Verification: Threat masquerading as protection

#656

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…

Probably not the case for most people. I'm living abroad and had to do something on the Brazilian e-gov platform. To log in I had to confirm my ID with an Android app. Not only is it exclusively on Play store, but it also refuses to install on any rooted device, so I had to boot an old non-rooted Android I had stored somewhere.

I'm confident this is a very common experience worldwide, be it with gov IDs or banks.

Re: Android Developer Verification: Threat masquerading as protection

#657
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

> Linux based mobile OS foundation

AOSP is a Linux-based mobile OS. It runs fine on top of standard Linux kernels without downstream changes. Getting rid of the need for closed source userspace drivers for components like a modern Mali GPU can be done with AOSP and will benefit the most people that way. AOSP if many companies and others band together to do it. It could also happen due to government intervention due to Google's antitrust law violations, but that could be done poorly in a way that harms open source.

Re: Android Developer Verification: Threat masquerading as protection

#658

Earlier quoted context omitted.

> and they are legally allowed to fingerprint grapheneos and block Play functionality. No, and you also don't understand how the Play Integrity API is implemented. Google has a bunch of monopolies tied to Android. Antitrust laws put limits on what they're allowed to do which Google has been egregiously violating for many years. Google isn't legally allowed to pull a bait and switch with Android by changing it away fr…

giving the option to completely block attestation and DRM API would be a good start. > hardware attestation, which is not fingerprinting this is false, the attestation middleman Google server can fingerprint your unique device serial (in-silicon key) whenever it wants. the DRM situation is even worse as ANY app can fingerprint your device serial and I don't mean just the DRM ID. anyone who has a license server certif…

The amount of work that goes into tracking you is insane

Re: Android Developer Verification: Threat masquerading as protection

#659
post #479
post #63

Earlier quoted context omitted.

It's because only Pixel devices have proper hardware security to build anything secure on top.

Hardware security is irrelevant to me. I just want to leave Google behind me. I do not want Google's hardware.

/e/ OS with Fairphone is the good choice for that. Don't listen to cromka, /e/ OS is now fully open as the only proprietary app was the map one and they just replaced it. So, 100% free software. It is less secure than Graphene but also leaks less data to advertising companies.

Re: Android Developer Verification: Threat masquerading as protection

#660
post #620

Earlier quoted context omitted.

We're still arguing for several reasons, one of them is that people still confuse the user with the owner, as you do. "The user must be able to override" is implies that if you have physical access to someone's phone, you can install a keylogger before handing the phone back its owner. Nice for you but I imagine the owner might still quibble, even if you quote TRON.

If I hand my windows laptop to someone, they can also install a keylogger. But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes. It's ridiculous that changing the settings on my device is protected 10× more than transferring all my money to a random person.

> But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes.

You use operating systems that have significantly worse security than GOS, iOS and even stock Android as your examples?

Also you literally are the owner with GrapheneOS, lacking security is not "full ownership." You can create your own build of GOS, you can modify it ahead of time, you can literally see all of the source code it's running.

Claiming GOS isn't true ownership is like complaining that you can't change your car's wheel alignment while driving it and saying it means you don't truly own your car.

Post reply on HN