Earlier quoted context omitted.
> It doesn't solve the current issue These operating systems aren't compatible with most of the apps and services people want to use. It's going to become much worse. The compatibility layers several provide have extremely poor compatibility combined with disabling the Android security model and app sandbox. Apps running in those compatibility layers are much less contained with less isolation from the Linux kernel,…
"Apps running in those compatibility layers are much less contained with less isolation from the Linux kernel, not more." Being isolated a little bit more from the kernal offers an illusion of privacy meanwhile where you are, what you have installed, your photos and friends are available to other apps at a much higher level. I understand being able to slow down a nation state actor is important but most privacy conce…
Android Developer Verification: Threat masquerading as protection
681–690 of 793 posts
Re: Android Developer Verification: Threat masquerading as protection
#682Earlier quoted context omitted.
Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…
There are plenty of banks in Germany which offer over-the-counter services, if you prefer to do banking as if it's 1999. Most of the time, when people say it's impossible to live without a smartphone, it's actually only impossible to enjoy the conveniences of the internet without a smartphone (at least in Germany). Besides these rentable scooters, I can't think of anything that actually requires a smartphone. Sure, y…
Additionally, there are many sports and music venues where i live that require smartphone apps for ticketing.
Giving up my favorite forms of entertainment and transport isn't really reasonable imo
Re: Android Developer Verification: Threat masquerading as protection
#683Earlier quoted context omitted.
In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…
I can do everything on my bank app from prepaying small amounts of a loan, spend analysis, opening fixed deposits and such.
Re: Android Developer Verification: Threat masquerading as protection
#684As user wouldn't you like knowing there is a non-verified app? Is it restricting And still providing way to override if you choose?
IMHO F-Droid is just mad because their store model of "developer publishes source code, F-Droid builds and signs the APK" would put immense liability on F-Droid. After all with that model F-Droid owns the private signing keys and now has to register them with Google. If they let a single malware app slide through, Google might designate F-Droid as a malware provider and block everything ever published on F-Droid. (Sidenote: Last I checked F-Droid had nothing in their policies that forbids publishing malware, just that it has to be open source) If you ask me this store model was always stupid and completely missed the point of having signed APKs. I think they also have a newer model where they don't own the private keys anymore, but there's still tons of legacy apps.
Of course Google might have been open to talks about some kind of verified app store program allowing F-Droid to operate under different terms. But that's certainly out the window after all the fear mongering, hyperbole and straight up propaganda F-Droid has put out in recent months.
Re: Android Developer Verification: Threat masquerading as protection
#685Earlier quoted context omitted.
Checks are still common in the good ole USA.
Common? maybe for seniors. I probably handle a physical check once a year.
Re: Android Developer Verification: Threat masquerading as protection
#686Earlier quoted context omitted.
> Your paths forward are a false dichotomy. These are not the only 2 options. You can simply update your build with the changes you want. Okay, so once I install grapheneOS, how do I update it with my own custom build while keeping my data intact? > You dont have the ability to guarantee you have overridden anything. The integrity of the OS cannot be verified and anything with root can lie to you that it was revoked.…
You would install your own build of GrapheneOS. Not the official images. Its not advisable to run anything as root, at all. Or expose access to it in any form. You can make userdebug builds to access a form of root that doesnt undermine the entire security model, in ADB. Afaik this lets you access apps internal directories but is not recommended for production devices.
Awesome, so you're advising against installing GrapheneOS for anyone that wants control over their own data.
Sorry for twisting the words slightly, but that's the essence of the issue here, isn't it?
> Its not advisable to run anything as root, at all. Or expose access to it in any form.
And then you advise for exposing access to it in pretty much the same form I asked for before.
It'd be funny if it wasn't so exhausting.
Regarding the security model: So adjust the security model.
Any access that an app can have, should also be available to the user. Importantly, they should be able to access and modify any data.
The system documents/files app already has special permissions for that, there's no reason why it shouldn't have access to all files (accessible through the same unlock system as e.g. the security settings)
Re: Android Developer Verification: Threat masquerading as protection
#687Earlier quoted context omitted.
Cope all you want, the broad spectrum opinion by most experts and independent research groups holds it to be true. https://en.wikipedia.org/wiki/Democratic_backsliding_in_the_...
As a natively Russian speaking Jew born in Crimea I really don't need any lectures on democracy from someone who ran away to Europe at the height of it's American enforced century of stability. My childhood was listening to stories from my great grandmother (born in Moldova) losing her entire childhood and several family members to European savagery. European so called Democracy isn't even one lifetime old. It's hila…
Re: Android Developer Verification: Threat masquerading as protection
#688Earlier quoted context omitted.
You would install your own build of GrapheneOS. Not the official images. Its not advisable to run anything as root, at all. Or expose access to it in any form. You can make userdebug builds to access a form of root that doesnt undermine the entire security model, in ADB. Afaik this lets you access apps internal directories but is not recommended for production devices.
> You would install your own build of GrapheneOS. Not the official images. Awesome, so you're advising against installing GrapheneOS for anyone that wants control over their own data. Sorry for twisting the words slightly, but that's the essence of the issue here, isn't it? > Its not advisable to run anything as root, at all. Or expose access to it in any form. And then you advise for exposing access to it in pretty…
To be clear, I am NOT advising root access. I am not contradicting myself. I am telling you it is dangerous but still telling you how it can be done in a less terrible way. To withhold that info would be senseless gatekeeping. GrapheneOS supports being built as a userdebug image but that will not stop them from telling you how bad an idea it is to use it on a production device.
GrapheneOS will not be rolling back aspects of the security model. That would be a massive step backwards for privacy and security.
Re: Android Developer Verification: Threat masquerading as protection
#689Earlier quoted context omitted.
That's only the consumer side of it though. As the post states: > Should a developer[...] elect to register themself with Google as a “verified” developer, they should expect to sign up for an account and pay a fee, surrender detailed personal information and upload government-issued identification, and then proceed to register the identifiers and signing keys for all the apps they intend to distribute (now or ever).…
This is no different from before. If you want consumers to be able to install your app without a warning on Google builds, you have to jump through verification hoops. The only thing that ADV changes for developers is that now they can distribute their apps outside the system app stores without a warning as well, which is a new benefit, not a new restriction. The correct thing to complain about is requiring developer…
>The correct thing to complain about is requiring developer mode for unverified installs, which doesn't seem necessary
I had assumed the friction was to dissuade developers from not going through ADV. Isn't it partly for making malware distribution more traceable and campaigns easier to halt on GMS/certified Android systems?
Re: Android Developer Verification: Threat masquerading as protection
#690Earlier quoted context omitted.
> And you’ll never reach a human to sort it out. Unless you blog about it angrily enough that you somehow make it to the HN front page and some insider sees it and solves the problem for you. Getting my own domain and setting up email on it is one of the best things I've ever done.
About to go down that route as well, just need to find a email provider with ideally servers in the EU