Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

711–720 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#711
post #479

Earlier quoted context omitted.

Hardware security is irrelevant to me. I just want to leave Google behind me. I do not want Google's hardware.

/e/ OS with Fairphone is the good choice for that. Don't listen to cromka, /e/ OS is now fully open as the only proprietary app was the map one and they just replaced it. So, 100% free software. It is less secure than Graphene but also leaks less data to advertising companies.

> /e/ OS with Fairphone is the good choice for that.

That's debatable. /e/OS is mostly made of AOSP, which is made by Google.

> It is less secure than Graphene

Most definitely, yes

> but also leaks less data to advertising companies.

This is wrong. If you don't use microg on /e/OS or Play Services on GrapheneOS, then it's equivalent. If you use microg, it still contacts the Google servers even though it is an open source reverse-engineered implementation of Play Services. The added privacy there is to go through a proxy, which GrapheneOS offers.

I actually like it better to run sandboxed Play Services through the GrapheneOS proxy, because in my experience it works a lot better than microg.

Really, the only reason to use LineageOS or /e/OS (which are interesting project, really) is that you cannot run GrapheneOS on your phone. If you have the possibility to use GrapheneOS, there is no good reason not to do it.

Re: Android Developer Verification: Threat masquerading as protection

#712
post #39

Earlier quoted context omitted.

The only reason I have not switched Graphene is because for reasons I do not understand, Graphene OS is very closely tied with Google hardware. I bought a /e/os Fairphone instead.

Sigh, /e/OS. Your phone is running proprietary Google DroidGuard blobs in a privileged process every time an app initiates a Play Integrity request. If you install some Google apps like Google Maps, they are run with more privileges than other apps (their microG fork gives apps elevated privileges when they match certain Google signing key fingerprints). Also, your device is running a firmware bundle provided by Fair…

> security hardening is only for spies and pedophiles according to the CEO of Murena (the company that makes /e/OS).

Confirmed, he says it in video: https://x.com/GrapheneOS/status/2040887784253141142

Re: Android Developer Verification: Threat masquerading as protection

#714

I use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.

That's a nice digital content you have there. It would be a shame if something happened to it...

When a company does something that seems to be out of The Godfather...

Re: Android Developer Verification: Threat masquerading as protection

#715
post #82

Earlier quoted context omitted.

Well… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.

> Well… you can run android without google? You can only run LineageOS on smartphones that allow unlocking the bootloader (which is more and more rare), and properly release the kernel source-code (many still don't, especially low-end MTK-based phones...)

You can run GrapheneOS on Pixel phones, and soon Motorola :-).

Re: Android Developer Verification: Threat masquerading as protection

#716
post #126

Earlier quoted context omitted.

Yet on LineageOS you're not affected. It seems you can build Android that isn't affected by Google, at least if you're willing to personally adjust the code to do what you want. You'd have to get exceptionally busy before it's not recognisable as an Android distribution anymore

How’s LineageOS compatibility these days? And besides F-droid, is there a place where mobile apps are plentiful without being full of malware? Also, how’s isolation on LineageOS for mobile apps? I think I’m getting to the point where I’m thinking of ditching Apple again

> I think I’m getting to the point where I’m thinking of ditching Apple again

I would wholeheartedly recommend going for a Pixel with GrapheneOS. I have been an /e/OS user on a Fairphone for 5 years before reading a lot about GrapheneOS and switching to GrapheneOS. It's honestly so much better!

If you go from iPhone to GrapheneOS, you get better security. If you go from iPhone to anything else, you get worse (to extremely worse) security.

Re: Android Developer Verification: Threat masquerading as protection

#717
post #213

Emotional talk aside, there's not many good solution to this problem, unless of course F-Droid starts to make their own phones. But then, Librem 5 Phone was just failed few years ago, telling the story that people who care about their rights are still sensitive to how much they would pay (which is a form of rights too). Also but, there is the thing, making a phone is not easy. If you reach deep enough, you'll eventua…

There is a good solution. A big disclaimer and the user accepting the risk of running the software they want. The same solution they've been doing for years that did not need change. The new developer program is only here because it is more convenient to Google and governments.

You can put the biggest warning on the phone, make it as annoying as possible. Then, the user sees the warning, as well as the fact that all the other people are ignoring the warning, click "Accept" 10 times and got surprised when someone comes to collect the testicle they just donated by themselves.

That's the same reason why desktop computer has so many malwares, that's why phones now has permission systems to restrict what an app can do on it.

If you want to create a system for everyone, including your 60 years old mom and her mom, you need similar of not better permission systems. Linux currently don't have that, and DON'T except an old fashion car mechanic will delicately configure AppArmor etc with his oily fingers in the middle of fixing a client's car.

Re: Android Developer Verification: Threat masquerading as protection

#718

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

AFAIK you can still install any random APK but the process will require enabling developer mode and one time 24 hour wait period. But the problem is many stupid Apps check that developer mode is on and refuse to work.

I've never encountered this or read about it. I believe you could toggle developer mode off after install.

Re: Android Developer Verification: Threat masquerading as protection

#719
post #566

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

Usability-wise, they are no match for Android and iOS—or even versions of them from five years ago. UI/UX is costly, and most FOSS projects cannot get it right without massive investments from enterprises (e.g., Red Hat's UX designers heavily contributed to GNOME) or startups (e.g., Zed, Element, Bluesky). Projects without that backing are mostly unusable, at least from a Gen Z perspective.

> Red Hat's UX designers heavily contributed to GNOME

Well, IMHO Gnome has worse UX than other linux environments like KDE, Niri witn Dank Materials Shell, etc. That is obviously a matter of opinion, but I don't think you necessarily need a large budget to get decent UX for an open source project.

Re: Android Developer Verification: Threat masquerading as protection

#720

Earlier quoted context omitted.

> 1) side loading or however it's called is used less than 1-2% of global Android users (they can't be more than 50million). Google made us a favor leaving it open after an only 24h delay. It could be much worsa and is nothing in our eternal tinkering with developer options. Thank you from me Google It's wild how far we've come, from IBM trying to lock down the PC to truly open hardware, to you now thanking Google fo…

I don't distinguish a phone from other electronic home devices I also happen to buy. I don't change their firmware for various reasons, like not worth it (eg fridge, washing machine), illegal (eg set top box or car) or impossible. Being able to even enable developer mode in Android and do anything more than designed for a regular user goes already too far in relation to the other devices. Is there any car that you ca…

> I am trying to give some rational perspective of the balance of power between them and us

That should *not be a thing*.

You bought the device.

You own it.

It should be yours to do with as you see fit.

That applies to phones or appliances or cars unless your individual right to modify your devices begins to interfere with the rights of others (think: safety, tragedy of the commons scenarios, etc).

This is how we end up with cars we can't repair, phones we can't upcycle, TVs that advertise to us without our consent.

Its insanity.

Post reply on HN