Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

761–770 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#761

Earlier quoted context omitted.

> Traditional Linux distributions don't have a standard set of core components or configuration Huh? Of course they do. A standard set of components and configuration is at the core of (most) OS distributions.

System administrators of a traditional Linux distribution assemble their own OS out of their package and configuration choices. There isn't a well defined standard base OS. That's part of what makes it the traditional approach and is inherently incompatible with the privacy and security approach of AOSP or iOS in many ways. Linux distributions use different implementations of init systems, shells, command-line tools…

Ah, I see, you mean an exclusive standard set of packages and its singular corresponding configuration.

Re: Android Developer Verification: Threat masquerading as protection

#763
post #656

Earlier quoted context omitted.

Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…

Probably not the case for most people. I'm living abroad and had to do something on the Brazilian e-gov platform. To log in I had to confirm my ID with an Android app. Not only is it exclusively on Play store, but it also refuses to install on any rooted device, so I had to boot an old non-rooted Android I had stored somewhere. I'm confident this is a very common experience worldwide, be it with gov IDs or banks.

Are you saying the e-gov platform cannot be accessed using their website on a computer? So people without smartphones are excluded?

Re: Android Developer Verification: Threat masquerading as protection

#764

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

We're moving to a world where it makes sense to have one cheap locked down phone with the society mandated garbage apps on it, and another device that you use for real computing.

If 'society' can mandate garbage on us, that is a bigger problem.

Re: Android Developer Verification: Threat masquerading as protection

#765

Earlier quoted context omitted.

In my country, partially due to sanctions, you can access the bank via browser and receive 2FA codes on $15 dumb phone. Also why do you need bank app on your phone? Do you like to give money to random strangers on the street? Only scammers need money urgently. Also it is not secure to use the phone as a single factor to access the bank. I do not have any bank apps on my phone (it is not even connected to the Internet…

Some banks require 2FA through their phone app to login to internet banking on the computer.

Yeah, all of them claim that... but I just walk into the bank and say I don't have an Android or Apple 'smart' phone, only a Linux pocket computer (Librem 5). So they could either buy me a duopoly smart phone, or let me log in via web browser with physical token or other MFA... or I take my money elsewhere.

I have several bank accounts in 2 different countries, and all of them backed down either gave me a hardware token or let me use the web app.

If an institution is holding your money hostage until you are forced to run their surveillance-tracker-infested malware on your personal device, that is a much bigger problem than what OS or device you choose.

That's why I understand the appeal of permission-less Open Source freedom money like Bitocin (BTC) and Monero (XMR).

Re: Android Developer Verification: Threat masquerading as protection

#766

Earlier quoted context omitted.

I keep hoping for something more radical like Jolla and SailfishOS taking off or postmarketOS becoming a true viable alternative but as things are looking like now there's a better chance we'll ditch phones altogether in 10 years when smart glasses will replace them instead.

> we'll ditch phones altogether in 10 years when smart glasses will replace them instead. Billions are spend right now to make sure the glasses also run Android or iOS. So far, Google, Samsung, Magic Leap, RealWear and Vuzix are working with/on Android XR, and obliviously Apple is working on AR/VR iOS. Meta and a couple of smaller startups are doing something in-house, but I don't give them much chances to get an eco…

Linux is coming there too, see Raven Prism and Monaco Glass for example.

Re: Android Developer Verification: Threat masquerading as protection

#767
post #213

Emotional talk aside, there's not many good solution to this problem, unless of course F-Droid starts to make their own phones. But then, Librem 5 Phone was just failed few years ago, telling the story that people who care about their rights are still sensitive to how much they would pay (which is a form of rights too). Also but, there is the thing, making a phone is not easy. If you reach deep enough, you'll eventua…

I was surprised to hear Librem failed, but a quick search show this is not true. Quite alive and hopefully well.

Librem 5 / Liberty Phone will be working well after many of these Androids reach 'EoL' and end up in the landfill.

That is because it is modular and supports hardware upgrades (like a computer which it is), something unheard of in the mobile world.

Purism already released a Wifi/Bluetooth hardware upgrade, and according to their newsletter, a cellular modem upgrade is in the works.

Re: Android Developer Verification: Threat masquerading as protection

#768

Earlier quoted context omitted.

Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…

Good for Germans then. Slovenian banks won't let you use physical 2FA authenticators (for personal accounts and maybe even business ones at this point) anymore and will also require you to constantly update their stupid app (I've had to replace some otherwise good phones because the OS version wasn't supported anymore).

Is that because of some regulatory requirements that they don't support physical 2FA?

Re: Android Developer Verification: Threat masquerading as protection

#769
post #111

What Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resis…

> We need to resist this! I agree. What do you suggest? How can we contribute to the resistance?

Opt out of the duopoly by getting a freedom Linux phone like FLX1s from FuriLabs, or the Mecha Comet with cellular modem. Or if you're technical, you can install postmarketOS on a Fairphone 5 or OnePlus 6. Sendero Linux sells refurbished ones with pmOS preloaded.

Re: Android Developer Verification: Threat masquerading as protection

#770
post #458

Earlier quoted context omitted.

That's great but I want to be able to share such app with my family members coleagues

Are they such new/fleeting friends that they can't wait 24 hours? Otherwise, it might be a good thing that people can't be persuaded to install an app because a "friend" told them to, and it's somehow so urgent that they can't wait 24 hours.

Until it gets lengthened to 48 hours, then one week, then ome month and then it gets removed alltogether in the name of "security".
Post reply on HN