Live data from Hacker News

Your phone is about to stop being yours

keepandroidopen.org

871–880 of 927 posts

Re: Your phone is about to stop being yours

#871
post #32

Earlier quoted context omitted.

Google could lock out Graphene too, whenever they like, with no warning. I hope Graphene has a plan.

They could conceivably lock the bootloader, but Graphene now has a partnership with Motorola.

There are many ways Google could prevent third parties from using Android code, and the code of Android components (e.g., Google Play), to make varient OSes. Without Android support and compatibility, it would be very tough going for GrapheneOS.

They already are slowing the publishing of AOSP (or something like that).

Re: Your phone is about to stop being yours

#872

Earlier quoted context omitted.

IDK, not really a fan of redefining computer to make a rhetorical point. It seems counter-productive to tell people the computing device they think as a computer isn’t really a computer. It’s like saying my car isn’t really a car because I can’t adjust spark timing. Someone could make that semantic argument but it’s hard to imagine anyone would care.

>It’s like saying my car isn’t really a car because I can’t adjust spark timing. What if it only drives along select predetermined monetised routes?

Then it's a streetcar

Re: Your phone is about to stop being yours

#873
post #851
post #846

Earlier quoted context omitted.

I'd be happy with either approach, frankly. I just think yours is slightly less realistic. > Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes! The bank isn't banning graphene os. They're banning anything Google labels as untrusted. I think that's an important distinction. This is Goo…

> The bank isn't banning graphene os. They're banning anything Google labels as untrusted. I don't agree here :-). AOSP provides an attestation mechanism that totally works with GrapheneOS [1]. Google provides Play Integrity on top of that, as an easy way to check that the phone is signed by Google. It doesn't say "it's unsafe if it is not signed by us", it just says "here is a way to verify that it is signed by us".…

I feel like this is semantics. I don't know all what they say, but I'd eat my breakfast cold if the word "safety" didn't come up in the PowerPoint deck. We may have to agree to disagree on this.

My point was that this is the direction the world is moving to. Maybe it's not total coverage yet, but every year more and more of our stuff only operates with verified trust through the entire process. Everything from video games to movies to programs. We're already sitting here complaining about Google enforcing developer verification, how long until Google turns on play integrity by default? And then how long until it's the only option? It'll come if something doesn't change.

And I still agree with the post way up above that these devices are too important now. I don't care about Google's interests here.

Re: Your phone is about to stop being yours

#874
post #863

Earlier quoted context omitted.

"But this is not all Google's doing there: all the Android manufacturers are actively preventing users from doing it." Google is (a) restricting "Android" functionality through trademark and software licenses with manufacturers and (b) paying the manufacturers, e.g., through placement agreements and revenue sharing agreements Given Google's actions in this regard, why would a manufacturer want to allow hardware purch…

I feel like you haven't read enough HN reply but I've said the exact thing about Apple OS they can have it and have HW but they should be seperate companies and the OS regulated like the monopoly service it is. OSs are few in number and are special pieces of software supported by extreme network effects and locking in effects. Its virtually impossible to abandon mainstream OSs even in the desktop world which is much…

Ironically, I think regulation is what keeps them in power. They are major companies that comply with government regulations. Why would the government regulate to allow people to have devices that forgo government regulations?

If you want a successful mainstream operating system. It needs to work within the rules of society. It needs to comply with regulations. It needs to cooperate with mobile device manufacturers and network operators.

These small grassroots operating systems fail because, to do all those things, you need to be pragmatic.

The next major operating system will be backed by a business or government.

Re: Your phone is about to stop being yours

#875

Earlier quoted context omitted.

I agree. I don't like the idea of Android being locked down, but the conversations around this topic are tipping into disingenuous. Your phone is still yours, you can still install third party apps, and you can still develop apps without a verification. But now there's a one-off hurdle to install them. Not ideal, but when we think of the people that it's trying to protect, this feels like a reasonable middle ground.

Exactly. Nuance and good faith is in desperate need here. Google hasn't been perfect here by any stretch, but they are clearly responding to feedback. This side however seems to stick its head in the sand over security, "I wouldn't fall for it therefore it's not a problem" sort of stance, which is just talking cross-purposes. By all means push back on security being a concern, but the numbers don't support this.

You mention nuance and good faith, but on your profile, and on your website, you claim to work on Android at Google. Previously on Google Play. I don't see that mentioned in your comments about this issue, I do think it matters a lot.

> This side however seems to stick its head in the sand over security, "I wouldn't fall for it therefore it's not a problem"

Which is also a total misrepresentation of the arguments made on the website, and made by many people opposing these changes. Again, since you mention good faith and nuance.

> By all means push back on security being a concern,

The website does not seem to push back on security being a concern in general, if I'm reading it right. It does however push back on the idea that changes made by Google will actually increase security of the users.

> but the numbers don't support this.

Can I see these numbers? I would seriously love to.

Re: Your phone is about to stop being yours

#876
post #859

Earlier quoted context omitted.

I think it’s because the Microsoft Store barely has any apps that users use. The Microsoft Store didn't support the Win32 API, so developers had to rewrite their apps. iOS was a new SDK from the start.

Wait, you lost me somewhere. The MS store didn't support the old way of doing things, people had to rewrite their software; yet iOS was... new as well? People had to start from scratch and so that worked?

Sorry, the statements were a bit disjointed.

iOS existed before the Microsoft Store. The apps developed were brand new. No backlash from a new SDK and platform.

Windows RT is closer to iPadOS though. For iPadOS, apps just worked since it’s based off of iOS.

The Microsoft Store only supported a new half-baked SDK that limited what applications were capable of. Developers already had Win32 apps and rewriting them with the new SDK seemed pointless just to support what seemed like a needless limitation.

Re: Your phone is about to stop being yours

#877

Android's original openness did attract users, but the flood of poorly-made apps also created real fraud and crime risks. Those of us on HN have high security standards, but for older users, that old policy created genuine security vulnerabilities. Just observing my own family members.

But how does this help? I guess most of the apps used for fraud were installed through the play store anyway

That's not accurate. Most fraud apps targeting elderly users are distributed via APK links in phishing messages, not through Play Store. They impersonate banks, government apps, etc. The ability to sideload APKs is exactly what makes these attacks possible on Android but not on iOS.

Re: Your phone is about to stop being yours

#878

Earlier quoted context omitted.

Because it's true, and I know what he said, I am not confused at all. Did you not read anything at all? On the Librem laptop, the tampering is done by PureBoot and inject into /run/firmware. The other user was linking the stuff with the laptop. *On a Librem 5, it is stored on a separate chip, then they read it with the initramfs, then mount it on top of the regular filesystem at /lib/firmware*. Like I said, it's just…

I'm tired of arguing with you. I see no effort from your side to come to some understanding or to clarify anything. Here's why. > On the Librem laptop, the tampering is done by PureBoot What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say. > If…

> I see no effort from your side to come to some understanding or to clarify anything.

Accusing me of your own sins.

> What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say.

On the laptop, messing with the system memory (/run) and dumping firmware packages in there instead of just shipping it with the OS using a sensible approach like the linux-firmware package is a hack-job and nasty practice. And since it's messing with system memory, that's your "tampering" right there.

On the phone, once again, instead of using a normal, sensible approach like the linux-firmware package on desktop Linux or the vendor partition on Android, they just store the firmware in some chip, then have the OS (or more accurately, the initramfs) mount the content of the chip using overlayfs in /lib/firmware anyways. It's another implementation of the same hackjob. That, and they combine it with using peripherals whose firmware are stored inside of internal flash chips so the OS doesn't have to be shipped with firmware packages that it then needs to load into the peripherals.

What does this entire exercise do for freedom or openness? *Asbolutely nothing*. It's called shuffling the firmware storage around so you can market the OS as "blob free" when it's literally meaningless. If anything, it makes it harder to audit and figure out which firmware version is being run than if the firmware were to be shipped along with the OS.

---

To dumb it down a notch if you really do not understand what I am trying to say:

This makes about as much sense as if I were to take the SSD out of my laptop, destroy the M.2 socket, then advertise it as a "storage free and OS free laptop". To use the laptop, you must plug in external storage through the USB port and load up an OS. But hey, since there is no SSD or OS on the "main" part of the laptop, I am now qualified for some made up certification and can advertise my stuff as "freeing" the user from the shackles of the evil storage system and nastiness of having an OS. Definitely more "open" than other laptops.

Re: Your phone is about to stop being yours

#879
post #596

Earlier quoted context omitted.

Imagine Windows limited you to three apps. How is this acceptable?

Imagine Windows was free.

Wait, I can download and run iOS on my own hardware? Not that I have tried, but I always thought Apples whole schtick was you were only allowed to run their software on their latest X revisions of their hardware?

Re: Your phone is about to stop being yours

#880
post #863

Earlier quoted context omitted.

I feel like you haven't read enough HN reply but I've said the exact thing about Apple OS they can have it and have HW but they should be seperate companies and the OS regulated like the monopoly service it is. OSs are few in number and are special pieces of software supported by extreme network effects and locking in effects. Its virtually impossible to abandon mainstream OSs even in the desktop world which is much…

"I feel like you haven't read enough HN reply but I've said the exact thing about Apple OS they can have it and have HW but they should seperate[sic] companies and the OS regulated like the monopoly service it is." Was this under a different HN account I went through all replies by xphos and found nothing that discussed removing IOs and running some other OS on an iPhone What I want is for Apple to sell hardware that…

s/IOs/iOS/
Post reply on HN