Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

741–750 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#741

Earlier quoted context omitted.

We are in a dire situation as the world has been going towards the normalization of the pratices of spreading stubs missing crucial information. -- The medicine? "It's good against illness. You'll be fine". ("You want to know the side effects - Due Diligence or OCD?") -- The engine? "It's ecological. Ain't you glad?" ("Three clylinders with consumables inside the engine - really do you want to know?") -- The stats? "…

>charcircuit, could you share what makes you confident (or informed) that the above is what will happen? Google has stated that this is about sideloading apps and has only talked about the sideloading flow being changed. Removing already installed apps is unrelated to the sideloading / package installation flow. Google has not stated anything about deleting apps from unverified developers so I am confident it won't h…

All you do is appreciated. But,

> There is no warranty similar to how there is no warranty

that an OS does not impede the use of self produced software it has never impeded seems to me a basic warranty to be given to its user base.

All kind of related questions from "Will Android Studio (etc.) still work as before in an unmodified workflow" to "Will `adb install` still work, and on which APKs" are questions that Google should have answered preemptively, as part of the news.

Re: Android Developer Verification: Threat masquerading as protection

#742

Earlier quoted context omitted.

That's only the consumer side of it though. As the post states: > Should a developer[...] elect to register themself with Google as a “verified” developer, they should expect to sign up for an account and pay a fee, surrender detailed personal information and upload government-issued identification, and then proceed to register the identifiers and signing keys for all the apps they intend to distribute (now or ever).…

This is no different from before. If you want consumers to be able to install your app without a warning on Google builds, you have to jump through verification hoops. The only thing that ADV changes for developers is that now they can distribute their apps outside the system app stores without a warning as well, which is a new benefit, not a new restriction. The correct thing to complain about is requiring developer…

What happens if Google says "nope" to a developer who applied for ADV? Does the developer retain the ability to distribute their software to end users through whatever non-Google-approved channels they use today?

Re: Android Developer Verification: Threat masquerading as protection

#743

Earlier quoted context omitted.

They already lost a lawsuit and were fined a hundred billion dollars in the EU for locking down Android. Maybe they think since they already lost once, they can't lose again.

Google had an open (but maybe not perfectly open) platform and is paying out billions in anti-competitive fines because of it. None of the other platform vendors with totally closed platforms are paying out anything. So with even a room temperature business IQ, it's pretty clear that closed platforms are the best way to do business, and court rulings in both the US and EU have affirmed this multiple times over the la…

Well, they can't have it both ways. They can either have the more open platform, and continue to get techies to use them as simple convenience tools, serving as advertisers of Google indirectly, or they can be more closed and not even have that initial trust.

Google could only grow like it did, because they did things differently.

Other tech giants pay fines for other crimes. For example Facebook once had to pay a record high 5 billion for violating consumers' privacy. It is not surprising, that different companies with different products pay fines for different things.

Re: Android Developer Verification: Threat masquerading as protection

#744
post #711

Earlier quoted context omitted.

/e/ OS with Fairphone is the good choice for that. Don't listen to cromka, /e/ OS is now fully open as the only proprietary app was the map one and they just replaced it. So, 100% free software. It is less secure than Graphene but also leaks less data to advertising companies.

> /e/ OS with Fairphone is the good choice for that. That's debatable. /e/OS is mostly made of AOSP, which is made by Google. > It is less secure than Graphene Most definitely, yes > but also leaks less data to advertising companies. This is wrong. If you don't use microg on /e/OS or Play Services on GrapheneOS, then it's equivalent. If you use microg, it still contacts the Google servers even though it is an open so…

If you use microg, it still contacts the Google servers even though it is an open source reverse-engineered implementation of Play Services.

Even worse, last time I checked the source code, it downloads Google's proprietary, obfuscated DroidGuard blobs (which they can change between requests) and execute it in the privileged microG process if an app does a Play Integrity request.

Re: Android Developer Verification: Threat masquerading as protection

#745

If they go through with this, I will make it my life's mission for the coming months to de-google my personal life and break any dependencies on google at work. Done with this nonsense. Shouldn't take more than a month to remove the tumor. On my android phone: My own launcher My own keyboard My own sync tool for local net My own net tools to WoL some devices on my lan. My own tool to control 3 proxmox servers My own…

I started de-googling a few weeks ago. I don't really know what I'm doing but it's kind of enjoyable to learn. Graphene OS with F-Droid and I'm most of the way there. I still use the play store for some apps unfortunately. Also google maps, gmail, google messages (for rcs) and google fi. I'm not sure if theres anything close to the quality of traffic reporting as google maps, so it's hard to give up. The rest I will…

Do yourself a favour: install linux (fedora is okay) on a computer; install android sdk + new android cli, install flutter, install claude code. Then, build a basic app, claude can one-shot it for you. Ask claude to make a release build with a real signing key. Leave phone plugged in and connected via adb while claude is coding - it can use the new cli tooling to drive the phone and do full visual testing (can tap, enter text, take screenshot - all by itself). Tell claude you dislike third-party dependencies and to avoid google service and that it must double check with you before adding permissions to the app. Tell it by default to exclude internet access and to opt-out of android/google backup system.

Then, get building. Build a replacement app for each thing you use that don't have an open source equivalent. I'm at the point where I don't even use apps from f-droid anymore. Only my own code, own signing keys, privacy-first. It is awesome.

If you have an extra pc available, setup proxmox with: a container that acts as a build server (install all your sdk's here), gitea (and wire it up with the build server), an S3 compatible storage container (SeaweedFS) & wire it up with gitea. Let claude set it all up. Give claude ssh access to all of it. Then, when you build an app on your local machine, claude will know how to use your development infrastructure and you can automate all of your building your own softwares.

After that, own email server (stalward - rust based email server), owncloud deployment, full-on wireguard with public exit point (don't depend on third party). Get a couple of clean static ip addresses.

After that, become an isp, get an asn, get ipv4 and ipv6 blocks, play with bgp (make friends with your local isp staff..).

Rabbithole goes deep. Point is, fuck all these slimy techbro's. They need to be technologically eviscerated by hackers & get what they deserve for trying to enter our world by force.

Re: Android Developer Verification: Threat masquerading as protection

#746

It doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the…

I miss my N900, meego/maemo was really interesting, it's sad that it just went nowhere :(

Re: Android Developer Verification: Threat masquerading as protection

#747
post #701

Earlier quoted context omitted.

I like Android a lot better. And I really, really like the fact that Android is open source, so that 1) I can read the sources and 2) projects like GrapheneOS can do it right. Apple does not remotely allow that.

The whole point of remote attestation is to ban projects like GrapheneOS which "do it right". If you install such things, you are "tampering" with the phone, it becomes an "untrusted" device and you are banned from digital society, completely ostracized. It's not your phone, it's the corporation's phone, they're only generously allowing you to use it, on their terms. If you install GrapheneOS, or any other system tha…

But that's different: if your bank is stupid (most banks are, let's be honest), it's not the fault of Android.

Sure, remote attestation allows your bank to do it, but at the end of the day, it's your bank that pulls the trigger, not Google.

Re: Android Developer Verification: Threat masquerading as protection

#748

Earlier quoted context omitted.

The same way Apple is allowed to do it presumably.

It's not.

Oh? I'm not familiar with any fines or ongoing cases against Apple in the EU over their implementation of alternative app store support.

Re: Android Developer Verification: Threat masquerading as protection

#749

Earlier quoted context omitted.

It's not.

Oh? I'm not familiar with any fines or ongoing cases against Apple in the EU over their implementation of alternative app store support.

Why would they get a fine for complying? You can install alternative app stores on iPhone perfectly well.

Re: Android Developer Verification: Threat masquerading as protection

#750
post #252

Earlier quoted context omitted.

Google has been attempting to license the right to write. There are a lot of poor people, mostly brown people, who do not have the ability to get one of these licenses. Some of them are feeding themselves with their ability to write, and Google is literally stealing that food from their mouths.

Can I ask what you mean when you say "write"? Are you talking about literature / articles, or software? This is new to me, want to stay on top of it.

> Can I ask what you mean when you say "write"?

To "write", I mean the precursor to "read".

https://www.gnu.org/philosophy/right-to-read.en.html

> Are you talking about literature / articles, or software?

All of the above.

> This is new to me, want to stay on top of it.

I am sorry to tell you it is not too new. Google tried this before recently with something called WEI (which you might be able to find on ddg or other search engines): It failed for reasons few people know for sure[1], but the initiative had the same basic bullshit about security, and the same outcomes.

[1]: The story I heard was a couple South-American countries noticed that this would prevent their people from being able to work on software that runs in the Google ecosystem and threatened to block Google en masse. Since then, one of the countries that Google has a lot of offices in invaded one of those South American Countries for conveniently unrelated reasons.

Post reply on HN