Live data from Hacker News

Keep Android Open

keepandroidopen.org

771–780 of 907 posts

Re: Keep Android Open

#771
post #247
post #7

No matter how this turns out, I'm sure GrapheneOS will make a smart effort. https://grapheneos.org/ But long-term, Android is such a massive code base, and was designed more for surveillance and consumption, than for privacy&security and the user's interests. I think getting mainline Linux on viable and sustainable on multiple hardware devices is warmer, fuzzier foundation. (Sort of a cross between Purism's work on t…

> Android was designed more for surveillance and consumption, than for privacy&security and the user's interests I disagree. The Android security model is better than the Linux one. I am very happy with GrapheneOS, I don't have much to complain about. The problem is that Google sucks and nobody enforces antitrust laws. But it's not just Google: how many Android manufacturers don't suck, really? Do they contribute to…

> I disagree. The Android security model is better than the Linux one.

In some ways it probably is, but it still isn't that good in my opinion (although some of the problems have to do with the way the settings and controls are working rather than the security model itself, there are also problems with the security model itself too). (I think there are other problems with Android (and other operating systems) too.)

Re: Keep Android Open

#772
post #145

While I understand the reasons behind this campaign, I have mixed feelings about it. As an iPhone user, I find it frustrating that deploying my own app on my own device requires either reinstalling it every 7 days or paying $100 annually. Android doesn't have this limitation, which makes it simpler and more convenient for personal use. However, when it comes to publishing apps to the store, I take a different view. I…

> In my opinion, stricter oversight is beneficial.

I agree; stricter oversight is beneficial for the official app store. It should not be necessary (and neither should Google's (or Apple's, or Microsoft's, or the government's, etc) verification be necessary) for stuff you install by yourself.

> The Maven Central registry for Java libraries, by contrast, requires developers to own the DNS domain used as a namespace for their library.

This means that you will need to have a domain name, and can verify it for this purpose. (It also has a problem if the domain name is later reassigned to someone else; including a timestamp would be one way to avoid that problem (there are other possibilities as well) but I think Java namespaces do not have timestamps.)

> I hope that Google's new approach is motivated by security concerns rather than purely economic reasons.

Maybe partially, but they would need to do it a better way.

Re: Keep Android Open

#773
post #626

Earlier quoted context omitted.

> What about when your smartphone is required to verify your identity so you can work / earn a paycheck? What about when it's required in order for you to engage in commerce? In some cases, it already is. We're already far on the path you described, and there is no choice to make on it, not for individuals. To stop this, we need to somehow make these technologies socially unacceptable. We need to walk back on cyberse…

The US is not nearly as far down that path as is, for example, China. But two forces are at play here: 1. Near-term concern: F-Droid is getting too popular for Google's comfort and Android revenue ambitions 2. Longer term goal: Control. Much of Chinas's social credit scoring is mediated by their phones. Not an issue yet here in the US but assuredly, if not explicitly on the current's government's list of aspirations.…

> Near-term concern: F-Droid is getting too popular for Google's comfort and Android revenue ambitions

That's good to hear.

I'm entirely on F-Droid, with no Google account.

Re: Keep Android Open

#774
post #751

Earlier quoted context omitted.

I seem to remember Venmo and Cash App had near useless web portals. TikTok's web app is very poor. Reddit's mobile app has functions not available on web. I bet the McDonald's web site doesn't let you order for pickup and get the deals (does Starbucks?). CapCut's web site sucks, and their desktop app is missing a bunch of features the mobile app has. I'd guess an absolute ton of betting apps don't work on the web bec…

I think you're misunderstanding my conjecture. My point is that there is no technical reason these features can't live on the web. I'm not talking about the incidental or intentional decision by some company to force user behavior by not providing a web solution.

Yes, theoretically anyone could build anything. Building it is not, nor was it ever the hard part.

There’s no financial, political, or mass market incentive for browser APIs to have feature parity with mobile OS APIs. Approximately nobody wants to do what you’re asking for. If anything, there are incentives against doing this.

Re: Keep Android Open

#775
post #738
post #505

Earlier quoted context omitted.

Hmm... that looks like a pretty skewed comparison. It's as if somebody took the security features that make Graphene stand apart and compared everything else to them. No contention that Graphene is safe, but categorizing other OSes as "pretty bad when it comes to security" because they don't copy Graphene is a bit of a stretch.

Eylenburg's site is focused on privacy and security for the comparisons. GrapheneOS is the only privacy and security hardened OS included in the Android-based OS comparison. None of the other operating systems listed in that comparison keep up with Android privacy/security patches or provide significant OS level privacy or security improvements. Many GrapheneOS features aren't listed by the table or are grouped in hu…

So, what you are saying is that Lineage has bad security because they are doing their best to support old devices as long as possible?

Interesting position. It is a valid criticism but brings its own problems.

Re: Keep Android Open

#776
post #694

Earlier quoted context omitted.

Maybe you didn’t read your own comment? > That 100 dollars is just the fee to even make an app. Even if your iPhone never has an Internet connection. And even if you literally load the app via USB to your iPhone only. Someone reading this would get completely the wrong information.

Are you purposefully ignoring the things I'm writing to try to appear right? Because I can still see the words on my screen. To reiterate, semantic arguments are meaningless and do nothing to serve you. If anything, with each passing comment, I am doubting your human-ness, because I don't believe human brains typically act this way.

May I make the humble suggestion that you avoid calling people unhuman just because they point out the gaps in your arguments.

Re: Keep Android Open

#777
post #554

Earlier quoted context omitted.

A lot of these pushes for attestation are coming from regulators and security audits though.

If that's inevitably the case, then we should all enjoy the ability to install user-controlled, open source operating systems while we still can. However, if it's not inevitable, then those who cherish such freedoms should forcibly push back against the attempts to strip them away.

It's absolutely not inevitable since even opensource operating systems can work on providing attestation systems that aren't owned by big corporations and serve the user.

But just like with something like secure boot, they're missing the train and letting corpos dictate the implementation.

Re: Keep Android Open

#778
post #681
post #390

Earlier quoted context omitted.

Ubuntu controls a big voting block in debian’s organization. They forced systemd in, for example. Devuan is a good enough compromise for me. The OS is stable, and the only issues I’ve had involve hacking curl|bash scripts that fail to realize they should just install the debian version. (Steam and docker run well.)

Even without counting Ubuntu, was there a significant number of people against systemd in Debian, with convincing arguments?

Summary of some of them can be read at https://lwn.net/Articles/452865/

Debian’s debate page can be read at https://wiki.debian.org/Debate/initsystem/systemd

Re: Keep Android Open

#779

Will this impact forks od AOSP? Like lineage os or graphene os?

I'm not familiar with lineageOS but with GrapheneOS any off the apps don't have privileged permissions this includes the Google play services. Google play services works like a normal app via Sandboxed Google play compatibility layer. The layer teaches the play services work like a normal app in standard app sandbox. Because of that, the check of side loaded apps whether or not have been verified by a ID via privileged GSM services are not possible. https://grapheneos.org/features#sandboxed-google-play

Re: Keep Android Open

#780

Earlier quoted context omitted.

This works only as long as the webapp allows you to log in using a username/password and/or 2FA which is not tied to a smartphone app. More and more countries are moving to digital identity solutions, and while many of them offer hardware tokens as alternatives to apps, the future looks like one where smartphone apps will be only option.

Banking websites will tell you that you need 2FA. Of course you need to use not just any 2FA you need to use their app and of course you don't need a 2FA if you use the app directly for banking. My companys equity app does not even want to run on lineageos. At the moment it looks like a 2 phone will be necessary at some point.

The revised Payment Services Directive (PSD2) in EU describes standards of strong authentication and for the end user it means that mostly the bank's mobile app is being used as 2FA for logins and operations within the account

I'm not sure if physical tokens are being used anywhere but if they are, that's rather rare nowadays. It may be an option reserved in bigger banks or for business customers - I can see one of banks in my country offers it for a request and not by default.

Edit: it seems it's a feature for business indeed and banks opted for Cronto system - https://www.onespan.com/products/transaction-signing/cronto

Post reply on HN