Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

681–690 of 694 posts

Re: Android developer verification: Early access starts

#681
post #602

Earlier quoted context omitted.

I trust them, at least a lot more than I do Google, which is a known bad actor, and collaborator with "TLAs". F-Droid has been around for a very long time, if you didn't know. They've built and earned the trust people have in them today. > Didn’t F-Droid have 20 or so apps that contained known vulnerabilities back in 2022? Idk what specific incident you're referring to, but since they build apks themselves in an auto…

This incident https://gitlab.com/fdroid/fdroiddata/-/merge_requests/11496

Right, that's literally the team marking 12 apps as having known vulnerabilities (seems like it was because of a WebRTC vulnerability that was discovered). It's the F-Droid system working as intended to inform users about what they're installing.

You're calling it an incident like it was an attack or something, but it just seems like everyday software development. Google Play and the App Store don't let me know when apps have known vulnerabilities. I think F-Droid is coming out way ahead here.

Re: Android developer verification: Early access starts

#682
post #540

Earlier quoted context omitted.

> In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected. 1. The Android OS does not allow installing app updates if the new APK uses a different signing key than the existing one. It will outright refuse, and this works locally on device. There's no need to ask some third party server to verify anything. It's a fundamental part of…

You have to trust somebody. Who is F-Droid? Why should I trust them? How do I know they aren’t infiltrated by TLAs? (Three Letter Agencies), or outright bad-actors. Didn’t F-Droid have 20 or so apps that contained known vulnerabilities back in 2022? Who are all these people? Why should I trust them, and why do most of them have no link to a bio or repository, or otherwise no way to verify they are who they say they a…

So Google and Apple are already known to work with US government agencies. This was revealed in the Snowden leaks in 2013, and confirmed on multiple occasions since. Neither Google nor Apple tell you when apps you're downloading from the store contain known vulnerabilities. We know for a fact that both Google Play and the App Store are filled with scams and malware: it's widely documented.

So to my reading F-Droid comes out ahead on every metric you've listed: It has no known associations with US government agencies. They do inform you when your apps have known vulnerabilities. I'm not aware of any cases of scams or malware being distributed through F-Droid.

I highly recommend it. It's the main store I've been using on my phone for probably more than a decade now.

Re: Android developer verification: Early access starts

#683

Earlier quoted context omitted.

Let's take the "W". This is pretty good news!

I am not english native. Is "The W" a synonym for "A Win", described as a positive outcome after a contest? Is there more nuance or context than that?

I've never seen it in English outside of the USA, but it's very common inside.

Re: Android developer verification: Early access starts

#684
post #680

Earlier quoted context omitted.

> You can't monopolize a market where there is no market. The opposite conclusion would be absurd, that you can invent a market where there isn't one and claim a company has a monopoly over it. There is no such thing as "there is no market". There is always a market. The question is, what's in the market? The typical strategy is to do the opposite -- have Nintendo claim that they're competing with Sony and Microsoft…

You avoided the important part, there is no market for hardware that can play Nintendo Switch games and there is no market for software providers on Nintendo Switch. And they are legally allowed to do that. You can sell appliances that are bound to a single vendor and you are allowed to not license your hardware or software to 3rd parties. Since that is a legally permissible action it would be an odd thing for a cour…

> You avoided the important part, there is no market for hardware that can play Nintendo Switch games and there is no market for software providers on Nintendo Switch.

There is a market for these things. Nintendo sells hardware that can play Nintendo Switch games and people buy it. That's a market.

It seems like you're trying to claim that a monopoly isn't a market, but how can that possibly be how antitrust laws work? Your argument is that they don't apply to something if it is a monopoly?

> And they are legally allowed to do that.

That's just assuming the conclusion. Why should it be legal for them to exclude competitors from selling software to their customers? The obviously anti-competitive thing should obviously be a violation of any sane laws prohibiting anti-competitive practices. The insanity is the number of people trying to defend the practice.

Consider what it implies. 20th century GE could have gone around buying houses, installing a GE electrical panel and then selling the houses with a covenant that no one could use a non-GE appliance in that house ever again, or plug in any device that runs on electricity without their permission. They could buy and sell half of all the housing stock in the country and Westinghouse the other half and each add that covenant and you're claiming it wouldn't be an antitrust violation.

Apple wouldn't have been able to get their start because they'd have needed permission from GE or Westinghouse for customers to plug in an Apple II or charge an iPhone and they wouldn't get it because those companies were selling mainframes or flip phones and wouldn't want the competition. If that's not an antitrust violation then we don't have antitrust laws.

> If they did they would be declaring all locked down hardware effectively illegal.

It's fine for hardware to be locked down by and with the specific permission of the person who owns it. But how is it even controversial for the manufacturer locking down hardware for the purpose of excluding competitors to be a violation of the laws against inhibiting competition? It's exactly the thing those laws are supposed to be prohibiting.

Re: Android developer verification: Early access starts

#685

Earlier quoted context omitted.

>It's not possible to provide a path for advanced users that a stupid person can't be coerced to use. I actually think you might be wrong about this? Imagine if Google forced you to solve a logic puzzle before sideloading. The puzzle could be very visual in nature, so even if a scammer asked the victim to describe the puzzle over the phone, this usually wouldn't allow the scammer to solve it on the victim's behalf. T…

It would also fail for users who are differently abled. That sounds like an absolute nightmare for accessibility. Good news for preventing scams, but bad news for anyone without full mental and physical faculties.

I'm not sure why you couldn't make the flow I describe just as accessible as anything else in Android? But I'll grant your premise and respond anyways.

If the user lacks full mental faculties, they are part of the userbase we need to protect from scams. Most likely, a user without full mental faculties who is trying to sideload will be a scam victim.

If the user lacks the necessary physical faculties to "solve a puzzle on their phone", they probably get help from friends regularly; a friend should be able to help with sideloading. Enabling sideloading should be a one-time operation right?

Re: Android developer verification: Early access starts

#686
post #594

Earlier quoted context omitted.

> Dear Microsoft: fuck off; I refuse to seek your permission-via-signing-key to run my own software on my own computer. No one is stopping you from installing your own keys, though?

I do not want to be in the business of key management. This is not something that needed encryption. More encryption ≠ better than. I also dual-boot Windows and that's a whole additional can of worms; not sure it would even be possible to self-key that. Microsoft's documentation explicitly mentions OEMs and ODMs and not individual end users: https://learn.microsoft.com/en-us/windows-hardware/manufactu...

> This is not something that needed encryption. More encryption ≠ better than.

Securing the boot chain protects against a whole range of attacks, so yes, it is objectively better from a security POV.

Re: Android developer verification: Early access starts

#687

Earlier quoted context omitted.

Well, yeah, everything has limits and this issue seems like a very practical one. Seems like it depends on how much work would be needed to teach the user base, which, at least to me, feels out of reach. As your being in IT, you may agree that teaching a large majority of 60+ year-olds standard things on something like Windows is difficult and extremely slow. Feels like it would take at least a month of dedicated tra…

Shouldn't the logical conclusion be that if it's too much/hard to teach these people how to operate a device safely, they operate the devices in an unsafe way, bare the cost of it by being scammed, learn that it's not safe for them to operate the device for certain use-cases due to the experience, they tell others about it and it's in media -> people who do not feel confident operating such a device securely are scar…

Not 100% sure if you mean this genuinely or joking around a bit. Will assume the former

Well, think just letting the knowledge of user failure expand organically is definite a method of deterrence, and some amount of this probably going to happen to some of the users. But to me, seems like it's a question of what percentage of your user base would be exposed to being scammed. Of course you'd want his to be zero, but if it's significant, yeah, probably should put measures in place to reduce the amount of scamming. Even on a purely practical level, it's bad for the reputation of your product...

...Am thinking, since there is so much resistence to locking down android, one problem might be was it was initially billed as a more open OS that tech people could enhance in whatever way they wanted. But yeah, times have changed, it's now a product that is used by the masses, and guessing the masses are now their most important users. Not saying this is wrong or right, but probably why there is so much push back as compared to say if iOS did the same thing (which they may have already done).

Re: Android developer verification: Early access starts

#688

Earlier quoted context omitted.

> > Keeping users safe on Android is our top priority. Somebody tell them that I do not want to be kept safe by Big Brother.

Your personal data will be kept safe on our servers, citizen, whether you like it or not.

> Your personal data will be kept safe on our servers, citizen, whether you like it or not.

... and our business partners. And app developers that grab your clipboard. And their business partners. and a few more levels of data brokers. The spi^H^H^H data-vacuum must flow

Re: Android developer verification: Early access starts

#689
post #594

Earlier quoted context omitted.

I do not want to be in the business of key management. This is not something that needed encryption. More encryption ≠ better than. I also dual-boot Windows and that's a whole additional can of worms; not sure it would even be possible to self-key that. Microsoft's documentation explicitly mentions OEMs and ODMs and not individual end users: https://learn.microsoft.com/en-us/windows-hardware/manufactu...

> This is not something that needed encryption. More encryption ≠ better than. Securing the boot chain protects against a whole range of attacks, so yes, it is objectively better from a security POV.

Name a single prevented bootkit that wasn't able to avoid the encryption and signature verification toolchain altogether.

Malware developers know how to avoid this facade of an unlocked door.

Users do not.

That's the problem. It's not about development, it's about user experience. Most users are afraid to open any Terminal window, let alone aren't even capable of typing a command in there.

If you argue about good intent from Microsoft here, think again. It's been 12 years since Stuxnet, and the malware samples still work today. Ask yourself why, if the reason isn't utter incompetence on Microsoft's part. It was never about securing the boot process, otherwise this would've been fixed within a day back in 2013.

Pretty much all other bootkits also still work btw, it's not a singled out example. It's the norm of MS not giving a damn about it.

Re: Android developer verification: Early access starts

#690
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

Yes, it's all about control. Control the platform. Control the access to the platform, and the world is your oyster. And the political and legislation system are their friends. It is the establishment. The only way to fight is to indoctrinate the next generation, at home, and in school, to use FOSS. People tend to stick to whatever they used in childhood. We the software engineers should volunteer in giving speeches…

Imagine needing to agree with a TOS that can lock you out of your phone when they change/add some random new policy
Post reply on HN