Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

701–710 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#701

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

It's not just shameful, it's stupid. Freedom was the whole point of tolerating the shittiness of Android. If they get rid of that, then there is no point, and I'll just buy an iPhone instead. If I must be in a walled garden, I'll choose the better kept garden, and it sure as hell isn't Google's.

I like Android a lot better. And I really, really like the fact that Android is open source, so that 1) I can read the sources and 2) projects like GrapheneOS can do it right.

Apple does not remotely allow that.

Re: Android Developer Verification: Threat masquerading as protection

#702

We finally live in an age when I can tell a clanker that I want an app that does something that I need, connect the phone with adb and in half an hour have a working solution for my tiny problem while knowing little about android development. This is something google should embrace, not kneecap.

Then tell the courts to stop fining them and start fining all the closed platforms. There is a clear legal asymmetry where allowing competitors on your platform makes you liable if they complain, but blocking out everyone except for yourself is a totally ok and legally rosy way to do business.

Sue them all. Google is every bit as much a monopolist, they just play the game a little differently.

Re: Android Developer Verification: Threat masquerading as protection

#703

Earlier quoted context omitted.

The way out is for people to support the various Linux phones. These Linux distros need to support and push Android compatibility, so that people can load F-Droid, Aurora, and Obtainium on them and get most of the Android apps they want. The ability to use both Linux and Android apps should satisfy nearly everyone. A strong message of consumer defiance needs to be sent.

The Android family of operating systems and the forks made from the android open source project are all linux distributions, and linux phones. Using desktop linux phones and trying to force that as a norm would set privacy and security back substantially. The inverse of what you suggest, which is Android with desktop linux app compatibility, would be a huge step forward, and is already much closer than you might thin…

The problem is that the usage of Android should not be at the expense of users and developers rights to choose, freedom, or privacy. With that line crossed, Android becomes an unattractive option.

With an increase in mobile Linux (e.g. Mobian and others), they can and will get better. Customers and developers choice and freedom are being nullified, because there are few other options. That has to change.

Re: Android Developer Verification: Threat masquerading as protection

#704

Earlier quoted context omitted.

The Android family of operating systems and the forks made from the android open source project are all linux distributions, and linux phones. Using desktop linux phones and trying to force that as a norm would set privacy and security back substantially. The inverse of what you suggest, which is Android with desktop linux app compatibility, would be a huge step forward, and is already much closer than you might thin…

The problem is that the usage of Android should not be at the expense of users and developers rights to choose, freedom, or privacy. With that line crossed, Android becomes an unattractive option. With an increase in mobile Linux (e.g. Mobian and others), they can and will get better. Customers and developers choice and freedom are being nullified, because there are few other options. That has to change.

Android is not at the expense of either freedom or privacy. Desktop Linux OSs come at the cost of both. It would be better to direct effort to AOSP projects as it is a much better base to build from.

Re: Android Developer Verification: Threat masquerading as protection

#705

Let's see some points: 1) side loading, or however it's called, is used by less than 1-2% of global Android users (we can't be more than 50 million). Google made us a favor leaving it open after an only 24h delay. It could be much worse but now it's nothing in our eternal tinkering with developer options. Thank you from me Google. 2) GMS is a huge convenience for any app developer that needs tight control, including…

> 1) side loading or however it's called is used less than 1-2% of global Android users (they can't be more than 50million). Google made us a favor leaving it open after an only 24h delay. It could be much worsa and is nothing in our eternal tinkering with developer options. Thank you from me Google It's wild how far we've come, from IBM trying to lock down the PC to truly open hardware, to you now thanking Google fo…

I don't distinguish a phone from other electronic home devices I also happen to buy. I don't change their firmware for various reasons, like not worth it (eg fridge, washing machine), illegal (eg set top box or car) or impossible. Being able to even enable developer mode in Android and do anything more than designed for a regular user goes already too far in relation to the other devices. Is there any car that you can boost with tapping seven times its gas tank cap? And I am afraid it will be removed someday in the future like the bootloaders became locked one after another. PCs are another story, an open remnant from the past, that the hard and soft tech companies sweared not to leave happen the same mistake again with phones. The term "buy" and it's rights are not inherited from a PC to a phone.

I am not an advocate for the greedy tech companies but I am trying to give some rational perspective of the balance of power between them and us. If we want openness we cannot reach it with wishful saying.

Re: Android Developer Verification: Threat masquerading as protection

#706

Let's see some points: 1) side loading, or however it's called, is used by less than 1-2% of global Android users (we can't be more than 50 million). Google made us a favor leaving it open after an only 24h delay. It could be much worse but now it's nothing in our eternal tinkering with developer options. Thank you from me Google. 2) GMS is a huge convenience for any app developer that needs tight control, including…

> 1) side loading or however it's called is used less than 1-2% of global Android users (they can't be more than 50million). Google made us a favor leaving it open after an only 24h delay. It could be much worsa and is nothing in our eternal tinkering with developer options. Thank you from me Google It's wild how far we've come, from IBM trying to lock down the PC to truly open hardware, to you now thanking Google fo…

Yes, it honestly pathetic reading some of these comments. It should be called "Temporarily Inconvenienced Millionaires News"

Re: Android Developer Verification: Threat masquerading as protection

#707
post #440

Earlier quoted context omitted.

The vast majority of smartphones don't allow installing another OS. Multiple Android OEMs have been restricting or fully phasing out supporting it. Among devices which do permit it, none have provided the hardware-based security features or driver/firmware update support needed by GrapheneOS beyond Pixels. Our hardware requirements are listed here: https://grapheneos.org/faq#future-devices GrapheneOS has an official…

Have you considered being less puritanical about these requirements? Surely there would still be strong benefits for many users on other devices which would only be able to run if these were relaxed.

Other projects (like LineageOS or /e/OS) have lower requirements. My experience is that it makes it very hard to know what kind of security you get. I have used /e/OS for a couple years before realising that it was signed with the Google test keys (so not signed) and the bootloader was not locked. And they were not forwarding the manufacturer updates, so Stock Android had the manufacturer updates and on my /e/OS they were 4 years old (!).

If you have GrapheneOS, you have the best mobile security you can get, period.

Re: Android Developer Verification: Threat masquerading as protection

#708
post #39
post #19

Android users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.

The only reason I have not switched Graphene is because for reasons I do not understand, Graphene OS is very closely tied with Google hardware. I bought a /e/os Fairphone instead.

Is the bootloader locked and signed with reasonable keys? If not, you lose the secure boot, which defeats the point of the Android security model.

Do you get manufacturer updates? My experience with /e/OS was that the Stock Android was up-to-date but /e/OS was 4 years behind, on a Fairphone.

> for reasons I do not understand, Graphene OS is very closely tied with Google hardware

One of the requirements is precisely to be able to add custom keys and relock the bootloader, in order to keep the Android security model. Most other phones don't allow that.

Re: Android Developer Verification: Threat masquerading as protection

#709
post #476
post #42

Earlier quoted context omitted.

Those reasons are explained clearly and openly. Ironically, your /o/OS is way less open than GOS on Google hardware.

I just want to be as far from Google as I can. I do not want to buy google hardware. Graphene does not allow me to do that.

I understand the anti-Google feeling, but...

AOSP is open source and written by Google. If you strictly don't want Google, you don't use Android. But IMO it's a shame because AOSP is actually good.

You could argue that you don't want to buy a Pixel because that would be giving money to Google, but not giving money to Google does not help the good alternatives, does it? IMO, helping the good alternatives means supporting GrapheneOS. The bigger GrapheneOS gets, the more likely it is that they get to work with major manufacturers (they already work with Motorola, which is great).

If you buy a Fairphone and run LineageOS, you are still running Google code (AOSP) and you support Fairphone who do not seem to care so much about security (otherwise they would meet the requirements of GrapheneOS).

Re: Android Developer Verification: Threat masquerading as protection

#710
post #82

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

You are right. I feel much safer now! /s I really need to look into those other versions of Android or even Huawei. I have a feeling they might not quite work in Canada. Part of the reason I am incensed about this, is that right now there are all sorts of measures globally, under the guise of safety, that seem to be about something completely different.
Post reply on HN