A theoretical way to circumvent Android developer verification
91–100 of 185 posts
Re: A theoretical way to circumvent Android developer verification
#92Earlier quoted context omitted.
That very much depends on the country, many require ID.
The ID presented at time of purchase does not have to be the ID of the actual user of the card. Your local drunkard will be happy to get $10 to buy a SIM card for you. Or you could visit eBay (or local equivalent) and get a valid SIM card without leaving your house.
As a result, sites where I could rent a number for verification, now don't offer local numbers anymore.
Re: A theoretical way to circumvent Android developer verification
#93While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…
> hope we can get the EU to fund a truly open Android Fork The same EU that keeps pushing for breaking encryption and chatcontrol? No thank you
The two are not equivalent issues; the first one is ill-formed as stated.
Cryptography is a tool of control. It's "dual-use", in the same sense like a knife or nuclear fission is - its moral valence depends on who is wielding it, and to what end.
In the context we're discussing, encryption is being used against the people. Working encryption is in fact needed to make chat control work - it's fundamental to it, the same way it is to Developer Verification and Safetynet/Remote Attestation. It would be great if EU decided to break that set of encryption applications. Alas, chat control only wants to break E2EE on messages, and uses encryption elsewhere to guarantee E2EE stays broken.
A more general comment about this thread, and related ones in the past: people really need to stop thinking about "encryption" and "security" as inherently good. They're not. Most of the social problems with computing, the attempts at user disempowerment and disenfranchisement, persist because they apply cybersecurity solutions.
The core question of security is always: who exactly is being secured, and from who.
Re: A theoretical way to circumvent Android developer verification
#94Earlier quoted context omitted.
That looks like someone made a list of mostly features specific to GrapheneOS so they could make a chart where all of the other alternatives (including stock Android) are full of red boxes. Several of those are the opposite of security features, like SafetyNet support, which might be a convenience in some cases but it mostly makes it so you can't upgrade certain parts of the system to newer versions even when the old…
>That looks like someone made a list of mostly features specific to GrapheneOS so they could make a chart where all of the other alternatives (including stock Android) are full of red boxes. No one else even bothered to make a list. >Several of those are the opposite of security features, like SafetyNet support, which might be a convenience in some cases but it mostly makes it so you can't upgrade certain parts of th…
That doesn't make the biased list good.
> Citation needed
Are you not aware of what SafetyNet is? It's the thing where Google certifies that the phone is running the software produced for it by the OEM. The problem, of course, being that the OEM stops issuing updates and then the certified version has known vulnerabilities. Which is a lot of the point of wanting to install a newer ROM on such a device, except that then it won't pass SafetyNet because you replaced the vulnerable but certified code with third party code that has the patch but not the certification.
Re: A theoretical way to circumvent Android developer verification
#95I think this means we need to rely on web technologies more. PWAs are looking pretty good on mobile devices these days and you can publish any web app you want with no reviewing authority. The web has a bunch of crazy APIs now that let you build crazy things and for everything else you're a hosted server away somewhere that can run more complex jobs. I believe devices I own should let me do whatever I want with them…
Bad news for you, Google happens to have a tight grip on the entire web ecosystem -- browser, search, ads etc.
Re: A theoretical way to circumvent Android developer verification
#96Earlier quoted context omitted.
Then Apple should get sued for bundling Safari, and also for forcing all browser engines on iOS to use Safari - which is way worse than anything Microsoft ever did with IE.
Apple does not have a platform monopoly on smartphones the way Microsoft did on PCs.
Which makes a lot of sense, because you couldn't run Windows on a Mac nor MacOS on PCs from the likes of Dell or IBM, and you couldn't run third party software for Macs on Windows or vice versa. By contrast, you could run various types of Unix on a Dell, and run Windows software on OS/2 or DOS software on DOS competitors other than MS-DOS.
That distinction seems like it might be relevant to the current situation.
Re: A theoretical way to circumvent Android developer verification
#97Re: A theoretical way to circumvent Android developer verification
#98Just use adb. You can do adb wifi on device. You don't have to distribute a signed apk just sign it fresh on device.
This is the way. You can also do adb-over-webusb with a second device.
Re: A theoretical way to circumvent Android developer verification
#99Earlier quoted context omitted.
> I hope we can get the EU to fund a truly open Android Fork. How are things in the EU on whether it's legal to buy a SIM card without showing ID?
A secure OS is a prerequisite for secure digital services. We can agree on that, right? The task, therefore, is to convince enough politicians to establish an independent unit that can address this issue without direct political influence. Fund the unit with enough money so that it can take care of the cybersecurity and sovereignty of all citizens. A side effect of this would hopefully be that these politicians would…
Secure for who, and from whom?
Remote Attestation and Developer Verification both make Android OS and platform more secure against malicious actors that would want to defeat the guarantees the platform gives, guarantees that enable secure digital services.
Yes, this includes protecting the banking services and DRM media services and advertising platforms from malicious actors like you and me, who pose a real threat to the revenues of the aforementioned players, by:
- Expecting banking to do security right on their own side, instead of outsourcing it to mobile platform and society at large (like with "identity theft" trick);
- Enjoying entertainment and education in ways the vendor or IP owner does not like or can't be arsed to support, and thus not spending extra on the inferior ways that are supported;
- Not looking at the ads.
Same is with Chat Control. Chat Control improves security of the society against threats such as sexual predators who want to hurt children, or citizens who disapprove of how the current ruling class is governing the people. To effectively provide that security, Chat Control in turn relies on a secure OS and platform providing secure digital services - in particular, secure against those malicious actors that would want to circumvent Chat Control protections.
Is the larger picture clear now? Security technologies are not inherently good, they're morally ambivalent. They're "dual-use". It's important to consider their deployment on a case-by-case basis, always asking who is being secured, and what are the actual threats they're being secured from.
Re: A theoretical way to circumvent Android developer verification
#100Earlier quoted context omitted.
There's eu(maybe even EEA?) wide free roaming legally mandated since I think 2017 or so? But it's not a permanent solution, your second paragraph still holds true.
I know of some UK SIMs that do not roam.