Live data from Hacker News

Android Developer Verification: Threat masquerading as protection

f-droid.org

771–780 of 793 posts

Re: Android Developer Verification: Threat masquerading as protection

#771
post #69

Earlier quoted context omitted.

I'd usually say it'd be far fetched but I can totally see Google banning developers and removing their apps for political reasons, where some lobbying group bombs them with emails because with this they're explicitly saying they're now choosing who gets to be in or out, there's no way for them to say we can't do anything about it I do think this would improve security, but I also think it's sort of a Trojan horse to…

Banning it from the app store is different from banning from distributing their app on any surface. It's closer to Walmart choosing to not carry a product vs the government saying no one may carry that product. Of course both can happen for political reasons but generally the latter is a bigger hammer applied less often.

my point still stands, the problem is, now instead of Google saying "we can't do anything about it" any lobbying/political group can go and say "well you could just ban it, does this mean you approve of this app?"

it's like how credit card companies can shut down porn sites overnight by citing their terms of service

Re: Android Developer Verification: Threat masquerading as protection

#772

Earlier quoted context omitted.

I recently bought my first smartphone, just went for a refurbished Pixel 8 with GrapeheneOS. To be honest, life without a smartphone was increasingly becoming a PITA. For example, Ryanair doesn't accept printed tickets anymore. A few clubs in Berlin (Tresor, Ohm, Oxi) have recently replaced their cloakroom by automated lockers that require a smartphone to operate. I've encountered a few gyms (2 in Spain, 1 in USA) th…

https://dumbermini.com/ (LineageOS fork) https://commodore.net/callback/ (Sailfish OS) I too am a GrapheneOS Pixel 8 user. However, I am starting to realise even a screen this large is a huge source of distraction and dopamine fracking that I don't have the time or desire for in my life. So I'm looking at these even dumber options. I just want my calendar and email, and maybe Signal. No web browser or socials.

thank you! I'll definitely consider those.

one thing that helps me is using OLauncher as replacement from the system "shell" UI. it's on f-droid.

and the News Feed Eradicator browser extension. God's send.

and of course don't install Insta, X, Reddit, etc.

Re: Android Developer Verification: Threat masquerading as protection

#773

Earlier quoted context omitted.

If I hand my windows laptop to someone, they can also install a keylogger. But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes. It's ridiculous that changing the settings on my device is protected 10× more than transferring all my money to a random person.

> But no one said we have to copy that flawed concept. macOS and Linux already have a good solution, requiring your full unlock password in a privileged dialog to authorize changes. You use operating systems that have significantly worse security than GOS, iOS and even stock Android as your examples? Also you literally are the owner with GrapheneOS, lacking security is not "full ownership." You can create your own bu…

> lacking security is not "full ownership"

It kind of is. A locked box with no key, is a very secure device with no utility. If I can't unlock the box ever, just because someone could steal my key and unlock it as well, doesn't make the box an example of a perfect security model.

The issue with taking away root access, and providing no alternative for modifying installed apps, it's just taking away rights from user. An app can modify its own data (which is fine), but a user modifying the data of an app is somehow a big no no. GOS also provides no proper firewall solution, other than the stupid VPN-based solutions available on Android.

If the intention of GrapheneOS is to serve the app developers and not the owner of the device, it should just say so.

Re: Android Developer Verification: Threat masquerading as protection

#774

Earlier quoted context omitted.

Oh? I'm not familiar with any fines or ongoing cases against Apple in the EU over their implementation of alternative app store support.

Why would they get a fine for complying? You can install alternative app stores on iPhone perfectly well.

Apple also still requires all apps that go through their app store to be signed through their mechanism and retains the same ability to banish them.

Re: Android Developer Verification: Threat masquerading as protection

#775

Earlier quoted context omitted.

Why would they get a fine for complying? You can install alternative app stores on iPhone perfectly well.

Apple also still requires all apps that go through their app store to be signed through their mechanism and retains the same ability to banish them.

Presumably not for apps in alternative stores.

Re: Android Developer Verification: Threat masquerading as protection

#776

Earlier quoted context omitted.

Not useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google servic…

There are plenty of banks in Germany which offer over-the-counter services, if you prefer to do banking as if it's 1999. Most of the time, when people say it's impossible to live without a smartphone, it's actually only impossible to enjoy the conveniences of the internet without a smartphone (at least in Germany). Besides these rentable scooters, I can't think of anything that actually requires a smartphone. Sure, y…

I have a German bank sccount that can be used with a standalone code generator, that uses the chip on your bank card.

I have a Finnish bank account that use a completely standalone, purely time-based code generator.

Alternatives exist. But with current know your customer requirements it's increasingly difficult to open new ones if you are a foreigner and/or non-resident.

Re: Android Developer Verification: Threat masquerading as protection

#777
post #656

Earlier quoted context omitted.

Probably not the case for most people. I'm living abroad and had to do something on the Brazilian e-gov platform. To log in I had to confirm my ID with an Android app. Not only is it exclusively on Play store, but it also refuses to install on any rooted device, so I had to boot an old non-rooted Android I had stored somewhere. I'm confident this is a very common experience worldwide, be it with gov IDs or banks.

Are you saying the e-gov platform cannot be accessed using their website on a computer? So people without smartphones are excluded?

Recent headlines in Finland say that about 10% of the population are basically excluded from society with no access to important services.

Re: Android Developer Verification: Threat masquerading as protection

#778

Earlier quoted context omitted.

And all are useless because you can't use your mandatory bank or gov id app.

We're moving to a world where it makes sense to have one cheap locked down phone with the society mandated garbage apps on it, and another device that you use for real computing.

I actually agree that the "two-phone future" makes sense, but I still wouldn't bet on it actually taking off on a large scale, because 95% (maybe even 99%) of people won't carry a second device just to preserve a freedom they don't really feel they're losing in their daily lives. Large corporations are able to make such radical decisions with ease precisely because of this inertia of the masses.

Re: Android Developer Verification: Threat masquerading as protection

#779

Earlier quoted context omitted.

Apple also still requires all apps that go through their app store to be signed through their mechanism and retains the same ability to banish them.

Presumably not for apps in alternative stores.

It applies equally to all apps regardless of what app store they are delivered through.

Re: Android Developer Verification: Threat masquerading as protection

#780
post #419

Earlier quoted context omitted.

Thanks, I appreciate the elaborate response. If you can just disable it with the activity manager or similar, I don't think Google would provide another workaround with a wait time and everything - and that only after a lot of public pressure. It's claimed to be a security feature against scams, and scammers can theoretically let you open up an adb shell and run an am command, so that would negate the safety. (That t…

>and scammers can theoretically let you open up an adb shell and run an am command It requires a lot more steps to do this. Finding another computer, installing Android dev tools, finding a cable to connect them. In reality this adds a lot of friction. >How do you know nothing will happen to already-installed apps and their data, when the user hasn't had time yet to go through the annoyance unlock procedure? Extrapol…

> It requires a lot more steps to do this. Finding another computer, installing Android dev tools, finding a cable to connect them. In reality this adds a lot of friction.

That's exactly the point. I think it's fair to require people to use a command line (and go through the steps that we already need to get there) to do advanced things. My grandma is an excellent comprehenseless button presser but, when faced with an "MS DOS" window, even she would be stumped at how to fuck up her system :-). Yet that's not what Google is doing and thus I concluded in that paragraph:

> > it's just about ecosystem control and not actually for user safety.

Regarding destruction of data, Android does actively remove people's data unasked. Just today I got another one of these notifications "you haven't used these apps in the last 3 months, we've removed the permissions you've set", and I previously made the mistake of ignoring that annoyance but now I know it'll move to stage 2 "we've removed your user data, enjoy!" after something like half a year. One of those apps is one of the 2FA apps I have and need less than once a year for e.g. an insolvency I'm involved in (a slow process). They'd remove the hard-to-recover 2FA secrets if I don't actively move to prevent that. (Having root for making backups makes this a bit less impactful thankfully, but the average person doesn't know how to make full-system backups.)

Post reply on HN