Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

661–670 of 694 posts

Re: Android developer verification: Early access starts

#661
post #658

Earlier quoted context omitted.

Yes, it's all about control. Control the platform. Control the access to the platform, and the world is your oyster. And the political and legislation system are their friends. It is the establishment. The only way to fight is to indoctrinate the next generation, at home, and in school, to use FOSS. People tend to stick to whatever they used in childhood. We the software engineers should volunteer in giving speeches…

I agree with you. But you do realize that it's been like that since about 20 years now. It started because of Microsoft (proprietary software), then Google (propriteary platform), now ChatGPT (proprietary knowledge). And I tried to tell my kids. And it failed mostly. But in the long run (a decade), what is exceptional and proprietary will become common FOSS. And everybody will benefit.

I envision this as an ideology. We don't need every kid to follow it, and I don't expect the majority to follow. A 1-2% is good enough. That's why giving speeches to teenages might be the best bang for the buck. There are always kids who need to escape into some cool ideas and it could be the idea of FOSS.

Re: Android developer verification: Early access starts

#662

Earlier quoted context omitted.

Yeah it's the judge.

I think you missed the point that judges aren't part of the legislative branch. They're in the judicial branch.

Please allow me to correct my bad English and replace it with "the law circle".

Re: Android developer verification: Early access starts

#663
post #630

Earlier quoted context omitted.

Yes, it's all about control. Control the platform. Control the access to the platform, and the world is your oyster. And the political and legislation system are their friends. It is the establishment. The only way to fight is to indoctrinate the next generation, at home, and in school, to use FOSS. People tend to stick to whatever they used in childhood. We the software engineers should volunteer in giving speeches…

So basically you're saying we're fucked. People don't care about FOSS in general, let alone when their phone says it's dangerous.

Yeah we are fucked, but as long as a small percentage of us, like 1% of the population knows, understands and agrees with the idea I think we are fine.

Re: Android developer verification: Early access starts

#664
post #644

Earlier quoted context omitted.

That's like Karcher opening a megamall to sell all their offering, vacuums, pressure washers, floor washers, you name it .. and then you, Bosch, complaining you can't sell your vacuum in Karcher's megamall where all the people go. What are you even saying? Whereas google was letting Bosch sell vacuums in their megamall, but only if it uses Google dust filters and people buy only Google made dust filters and Bosch isn…

It's like a company buying all the land within a 100 mile radius and then nominally "selling" plots to people but with terms of service attached that restrict what you can do with the land you bought and that allow the company to change the terms at any time. And then, after people have moved in, most of them having not even read the terms or realized it wasn't an ordinary sale, they start enforcing the terms against…

> nominally "selling" plots to people but with terms of service attached that restrict what you can do with the land you bought and that allow the company to change the terms at any time.

So, a lease.

Re: Android developer verification: Early access starts

#665
post #630

Earlier quoted context omitted.

So basically you're saying we're fucked. People don't care about FOSS in general, let alone when their phone says it's dangerous.

Yeah we are fucked, but as long as a small percentage of us, like 1% of the population knows, understands and agrees with the idea I think we are fine.

We'll have to initiate solid self defense protocol though. I think the first thing we should do is get a new logical fallacy term officially coined.

Stallman/StallManned Abusing the principles of the Slippery Slope to discredit perfectly rational predictions

Re: Android developer verification: Early access starts

#666
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

This is a big problem with Chrome extensions and Google hasn't done anything about it there, so I don't think they actually care about it. I'm not actually sure how you would solve that problem even theoretically.

Re: Android developer verification: Early access starts

#667
post #540

Earlier quoted context omitted.

> In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected. 1. The Android OS does not allow installing app updates if the new APK uses a different signing key than the existing one. It will outright refuse, and this works locally on device. There's no need to ask some third party server to verify anything. It's a fundamental part of…

>> In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected. > 1. The Android OS does not allow installing app updates if the new APK uses a different signing key than the existing one. It will outright refuse, and this works locally on device You missed the and private keys part of the original claim.

No I didn't. Finish reading the rest of the comment.

Re: Android developer verification: Early access starts

#668
post #329

Earlier quoted context omitted.

Should we ban refilling your own cars oil because some idots keep filling coolant into it? I worked in IT support and I am deeply aware with the issues people are having. Some issues are systemic (aka bad design) and those should be fixed. Other issues are human. It may not seem like it, but I have the patience of an angel, because I remember when computers where new to me. I like people to understand. Understanding…

Well, yeah, everything has limits and this issue seems like a very practical one. Seems like it depends on how much work would be needed to teach the user base, which, at least to me, feels out of reach. As your being in IT, you may agree that teaching a large majority of 60+ year-olds standard things on something like Windows is difficult and extremely slow. Feels like it would take at least a month of dedicated tra…

Shouldn't the logical conclusion be that if it's too much/hard to teach these people how to operate a device safely, they operate the devices in an unsafe way, bare the cost of it by being scammed, learn that it's not safe for them to operate the device for certain use-cases due to the experience, they tell others about it and it's in media -> people who do not feel confident operating such a device securely are scared away from using it due to the potential consequences they heard about -> problem solved (from a banking security perspective)

(except now the bank needs more staff behind the counter)

Re: Android developer verification: Early access starts

#669

"Allow". This is the entirety of the problem. They are allowing things on my machine that I purchased with monies that I leased my soul for. Anyway, I am already planning for a future in which Google does not feature as prominently as did until now. Small steps so far ( grapheneOS ), but to me the writing the wall is unmistakable. Google got cold feet over feedback and now they can allow things. When negative publici…

Consider UbuntuTouch, really nice ecosystem and community, you can run many Android apks.

Ironic suggestion in this context considering how hard Ubuntu has pushed snaps over competing solutions. Canonical is the Google of the Linux ecosystem.

Re: Android developer verification: Early access starts

#670
post #476

Earlier quoted context omitted.

An update can become malicious even without change in permissions. E.g. my now perfectly fine QR reader already has access to camera (obvious), media (to read QR in an image file or photo) and network (enhanced security by on-demand checking the URL for me and showing OG etc so I can more informed choose to open the URL) But it could now start sending all my photo's to train an LLM or secretly make pictures of the in…

See that's what the intent system was originally designed to prevent. Your QR reader requires no media permission if it uses the standard file dialogs. Then it can only access files you select, during that session. Similarly for the camera. And in fact, it should have no network access whatsoever (and network should be a user controllable permission, as it used to be — the only reason that was removed is that people…

> And in fact, it should have no network access whatsoever (and network should be a user controllable permission, as it used to be — the only reason that was removed is that people would block network access to block ads)

Sure, a QR code scanner can work fine without network. E.g. it could use the network to check a scanned URL against the "safe browsing API" or to pre-fetch the URL and show me a nice OG preview. You are correct to say you may not need nor want this. But I and others may like such features.

Point is not to discuss wether a QR scanner should have network-access, but to say that once a permission is there for obvious or correct reasons, it can in future easily get abused for other reasons. Without changing the permissions.

My mail-app needs network. Nothing prohibits it from abusing this after an update to pull in ads, or send telemetry to third parties. My sound record app needs microphone permissions. Nothing prohibits it from "secretly" recording my conversations after an update (detectable since a LED and icon will light up).

If you want to solve "app becoming malicious after an update", permissions aren't the tool. They are a tiny piece of that puzzle, but "better permissions" aren't the solution either. Nor is "better awareness of permissions by users".

Post reply on HN