11 ms·
F-Droid version of KDEConnect uninstalled by PlayProtect
- hardcopy 3y agoIt looks like KDE Connect doesn't have reproducible builds set up for F-droid. I wonder if this problem could be avoided with reproducible builds?
- RGBCube 3y agoMm, resisting the urge to mention NixOS.
- neilv 3y agoOne way to be a little less constantly violated by your phone is to run GrapheneOS, instead of iOS or ordinary Android: https://grapheneos.org/ https://grapheneos.org/
- blameitonme 3y agoThey only seem to support pixel, although pixels can be bought for cheap when compared to iphones, they're still expensive for countries which are still developing. For example Im using a device which is 1/4th the price of cheapest first hand pixel that I can get :(
- notpushkin 3y agoLineageOS is supported on a bit more devices, and works with microG if you're willing to sacrifice Google Pay for better battery life and less privacy violations: https://lineage.microg.org/ https://lineage.microg.org/
- snapplebobapple 3y agoThis worked ok, but wasn't as nice as grapheneos' solution so I ended up upgrading to a pixel once my cheap chinesium phone was sufficiently old and haven't looked back since. If you do the microg route you should be using a throw away gmail account you don't care about losing with the aurora store (if you need access to the google play store) because there is a non zero chance they ban your account.
- notpushkin 3y ago> a throw away gmail account you don't care about losing with the aurora store They also have a pool of accounts you can use by clicking “anonymous”. They do get banned frequently, and you have to re-login once in a while (for me it's almost every time I want to download something new again), but it is definitely usable.
- wkat4242 3y agoIt's a lot less usable lately because of the "Oops this account is rate limited" error unfortunately. Sometimes it takes me 10 tries. Updates are fine though, it's just searching for new apps that trigger it.
- notpushkin 3y agoYeah, I thought search was completely broken tbh. Usually I search in browser then use “Open in app” to open in Aurora and download. Maybe they can add some web scraping thing to sidestep this issue completely?
- sspiff 3y agoInteresting, can I still use the Play Store with mircoG? I already run LineageOS, but with Play services. I would like to be able to ditch Play services, but still need the Play store for things like my banking app, and an app to log in to government services.
- mindslight 3y agoYou can install apps from Play Store with Aurora Store, which is in F-Droid. I'd say it's a toss up whether specific apps will definitely work. But if they don't I'd recommending segmenting between different physical devices, and making the one that lives in your pocket as secure as possible. It's likely that you don't need to run banking and government apps on the same device that's privy to your movement.
- sspiff 3y agoIn my country (Belgium), mobile payments are a big thing using the national payment network (Bancontact). Lots of small shops don't accept cards and only do mobile payments because of the lower transaction fees. These mobile payments only work with your banks app or a dedicated app (Payconiq). My current approach is to put all these apps in my work profile which I can turn off (using Insular from F-Droid). Only apps for which I need background activity or instant notifications (Signal, an open source podcast app, and sadly WhatsApp) are installed in the main profile. Sadly, this approach still requires me to have Google services always running in the background for a functioning Play store in my work profile.
- notpushkin 3y agoI've heard something about using Play Store proper with microG, but obviously that's very flaky. Aurora Store is the way to go. And banking / government apps tend to work in Europe (at least the ones I have tried). Notable exceptions for me are Revolut (shame!) and McDonalds (who knew microG is the healthier option haha). Of course, in the US things might be vastly different.
- HansHamster 3y agoLineageOS unfortunately dropped support for my Moto G4 relatively quickly after I installed it and it only was supported up to Android 7.1. I have been running an unofficial build of 8.1 ever since, but that is also horribly outdated by now.
- tortoise_in 3y agoDude buy something new
- HansHamster 3y agoBut why waste the money? I intend to use this thing until it breaks...
- slikrick 3y agoit's not a waste of money, that android version is a security mess
- HansHamster 3y agoIt is for me. And there is nothing important on my phone so it is not a huge concern. And why do we have to accept that phones just turn into garbage after a few years? Even my old 2009 laptop* still runs an up-to-date OS but my 2016 phone is obsolete after 2-3 years? * but I have to admit that the hardware is quite slow
- eks391 3y ago> And why do we have to accept that phones just turn into garbage after a few years? Even my old 2009 laptop* still runs an up-to-date OS but my 2016 phone is obsolete after 2-3 years? It is because computers run one of a few available OS's. The OS is being maintained by the distributer (MS, Apple, Google) and your hardware is good as long as the drivers are still receiving updates. Phones are different because even though everyone only uses iOS or Android, every Android manufacturer puts their own layer onto Android, so Google can continusously update it but the manufacturer might not. Most companies only maintain their phones for about 3 years, giving a significantly reduced lifetime than computers. It still works fine, from from a security perspective, keeping the phone without patch support is a bad idea.
- wkat4242 3y agoYeah I love MicroG. But I really wish there was a big-tech-free payment solution :(
- notpushkin 3y agoYeah. It's either that or state-supported systems (UPS in India, SBP and MirPay in Russia). Cryptocurrencies could be the answer but governments would never let that happen I think.
- neilv 3y agoEven in the US, the limited hardware support is a barrier right now, especially with having to find a unit that has an unblockable bootloader. But it's still doable for many people. I most recently bought a second-hand Pixel 6a for GrapheneOS, and BYOD it to an inexpensive no-contract plan. Pixel 6a units with unlockable bootloaders are currently $235+ on US eBay, which is less than new current Pixels and iPhones bought outright, but more than many lower-end devices, and more upfront than people pay for contract plans that toss in a phone.
- milosmns 3y agoCan you share some examples? It's very interesting because 1/4 of Pixel 6a would be around 80 EUR... so I wonder about your environment and what workarounds you have for these problems.
- blameitonme 3y agoSo I'm in India, and pixel 6a seems to be of 30999 Rupees on Flipkart (amazon like online store) The device I use regularly is moto g14 which is at about 8500 online, with discounts can go for 8000. Honestly there is no work around as the moto g14 comes with a 4gb ram and 128 GB internal storage, 6.5 inch screen and 5k mah battery, it can do pretty much anything. I've just started working full-time after college and now I earn more than enough to buy pixels or iphones but currently the money is going on other important things that were pending
- callalex 3y agoAren’t those kind of phones typically infested with malware from the manufacturer to begin with, making Google’s stalking the least of your worries?
- diego_sandoval 3y agoI got lucky and bought a barely used Pixel 3a for ~ $130 USD. But yes, it was hard to find. It was much easier to find a Pixel 4 or a 4a, but those were too expensive for me.
- gjsman-1000 3y ago… as long as you trust the developers, and their ability to secure themselves, of course. I mean, if I was a three letter agency, sneaking into some GrapheneOS developer’s basement to add a camera to record his keystrokes would be the easiest trade ever for all the paranoid people using it. It’d be way easier than sneaking into Apple or Google. Might even be worth violating internal law to do it; because getting caught is extremely unlikely, and forgiveness is easy. Edit: Also, don’t forget that, if you should get arrested, “he used GrapheneOS” is 100% going to be used against you in court. You might use technical arguments or principled reasoning, but that doesn’t resonate with juries. Unfortunately, using extra-strong privacy tools is perfect for framing you as a criminal.
- tomrod 3y agoYou make a convincing argument. I'm switching to GrapheneOS for my next phone upgrade. Here is the source code: https://grapheneos.org/source https://grapheneos.org/source > “he used GrapheneOS” is 100% going to be used against you in court. I look forward to using this as a litmus test for legal representation.
- gjsman-1000 3y agoAre you personally capable of ensuring: A. The builds match the code? B. The NSA hasn’t stolen the signing key and isn’t feeding you customized images? True, you can’t verify that with iOS or Android either. I am saying though that trusting my security because it’s safer… by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least.
- stavros 3y agoNo I'm not. Does that mean I might as well cc the NSA to all my emails? Your comment is basically "is it perfect? No? Then it's not better".
- gjsman-1000 3y agoI’m saying that, if people who use it aren’t careful, they could end up like the university kid. There was a university that received a bomb threat over Tor. They found one student who used Tor on the network at around the right time, and because he was the only Tor user, he’s in jail for a very, very long time. That kid was at Harvard, his persuer the FBI. If you are going to use GrapheneOS, don’t be naive and think it will make you agency-proof. If anything it probably flags you to their attention.
- lawn 3y agoThere are other alternatives as well; LineageOS, /e/OS and CalyxOS that might be more your taste.
- fodmap 3y agoAlso Volla OS.
- BlueTemplar 3y agoIt's still based on Android though - so isn't it building on sand ? Isn't it better to focus our efforts on projects unrelated to Android, especially since some viable ones have appeared recently : Librem 5 and especially PinePhone.
- jacooper 3y agoNo it isn't, as unlike the others, grapheneOS is actually usable and dailyable.
- fsflover 3y agoI doubt grapheneOS requires much less effort to daily drive than others. Sent from my Librem 5.
- eks391 3y agoThere's some hiccups when you first set GrapheneOS up, but after that it is as smooth as, and blends in with, any other Android device. I've never used Librem or PinePhone to comment on them
- ryukafalz 3y agoAs an owner of both a Librem 5 and a Pixel 6a running GrapheneOS I can confirm that the latter has been much more reliable and has taken substantially less work to get to the point where I can daily drive it. The Librem 5 is not there yet, and while I would like it if it were I'm not currently very optimistic about that.
- bkallus 3y agoIn the past year, I have used a pinephone+keyboard with Arch, a oneplus 6t with postmarketOS, and a pixel 7a with GrapheneOS. In my opinion, Graphene is significantly easier to daily drive because the applications are designed for a phone's form factor.
- fsflover 3y ago
- WD40forRust 3y agoBased fellow GrapheneOS enjoyer!
- drowsspa 3y agoSadly device attestation has all but destroyed installing other OS. I couldn't use government or banking apps back in my old phone with LineageOS.
- nfriedly 3y agoI'm running lineageOS, and I had to root the phone to make one banking app work (and Netflix and some games.) It actually passes SafetyNet out of the box, but there's a CTS profile check that some apps do in addition to SafetyNet, and I had to root the phone to make it provide a profile that those apps are happy with. And then I had to install a SafetyNet bypass, because fixing the CTS profile broke SafetyNet. It un-roots itself every time I install an update, which is kind of a pain in the ass, but someone wrote a script to re-root lineageOS (from a desktop computer), so it's not too bad these days.
- azalemeth 3y agoWould you mind saying what phone you have, and which script? I'm using a (by now rather old) OnePlus 5 and potentially in the market for an upgrade -- and easy rootability is more my key feature than bling or a 50 megapixel camera....
- 0xDEADFED5 3y agoWhat I would do is make a short list of phones that interest you and go check the XDA developers forum for each model
- computerfriend 3y agoI'm also hanging on to my OP5 on Lineage. Always keeping an eye out for a replacement: * runs Lineage, * dual SIM, * not enormous, * headphone jack (nice to have). There's nothing out there.
- morrbo 3y agoLineage on a Xiaomi redmi 10 pro, everything working perfectly (also dual SIM and SD card + headphone jack) get about 2 days battery life. Though it's quite old now so I've no idea if it is as good as a OP5 or not lol Running https://github.com/kdrag0n/safetynet-fix/releases https://github.com/kdrag0n/safetynet-fix/releases on magisk to allow for things like NFC payments using Google wallet etc. The way you have to hide from apps is a bit weird these days using magisk filters, but other than that the entire thing has been set and forget, and I've not had any issues
- haunter 3y agohttps://news.ycombinator.com/item?id=37861467 https://news.ycombinator.com/item?id=37861467
- zvmaz 3y agoIs it ill-intentioned? If so, why? Has anyone any idea?
- prirai 3y agoI can't really comment on that but what I know is that play store also has KDE connect available and this issue is not happening for the people who got it from there. Perhaps it's someone who has some sort of play signing enabled with uploading unknown apps and the signature difference between play and fdroid versions might have created a false positive.
- jeroenhd 3y agoThat's my bet as well, the signature difference probably makes it look like one of the many fake APKs people often download from piracy sites and malware infested file sharing sites. Unfortunately, Google doesn't let you upload an APK with your own signature to Google Play anymore, so the devs can't really offer any solution. Best I can come up with is downloading the signed version from Google Play and uploading that, but that'd make updating the app wirhout uninstalling impossible for most of their users. Same with offering the free version as a different package name as the proprietary version, existing users would lose updates. Google needs to fix this because they're basically killing every alternative app store this way, which probably violates the DMA/DSA law (whichever applies here) in quite a major way.
- aib 3y agoI think that line has been blurry (blurred?) for a long time. Is it ill-intentioned when Apple slows down charging with non-authenticated cables because "they might be shitty and high currents can cause a fire"? If companies can hide behind good intentions, they will. And I'm not even sure such intentions originate from human beings, anymore. Not from individuals, at any rate.
- flyinghamster 3y agoI don't use KDEConnect, but quite a while ago I got FUD about battery life from Play Protect concerning F-Droid itself. Never mind that F-Droid has never used more than trivial amounts of battery.
- raybb 3y agoToday I learned KDEConnect has a MacOS app. Unfortunately, it doesn't seem to be actively developed. https://kdeconnect.kde.org/download.html https://kdeconnect.kde.org/download.html
- drampelt 3y agoI've been using Soduto, a 3rd party KDE Connect client, on the Mac for a few years now and it works quite well for my needs https://soduto.com/ https://soduto.com/
- ognarb 3y agoA lot more similar reports can be found here: https://old.reddit.com/r/kde/comments/175upzi/has_play_protect_removed_kde_connect_from_your/ https://old.reddit.com/r/kde/comments/175upzi/has_play_prote...
- Arnt 3y ago[flagged]
- nolok 3y agoI don't understand what you mean ? F-droid doesn't ship a keyboard app.
- nani8ot 3y agoIf they installed a keyboard with the same app id (e.g. com.google.[...]) F-Droid would try to update it and ask the user to confirm the update since F-Droid can't update an app that was installed by another app store. I'd be curious which keyboard this is. Maybe Gboard took over the app id of the previously foss android keyboard. PS: I recommend F-Droid Basic which supports silent background updates on any Android 12 without root.
- Arnt 3y agoThe app it wanted to install was its AOSP, it's likely that I was using another AOSP build at the time but I'm not sure. I've used either AOSP or gboard almost all of the time, so it's 99% likely to have been one of those two.
- Arnt 3y agoThe AOSP keyboard was available on f-droid when I installed f-droid, and the f-droid app kept nagging me to replace the keyboard app on my phone with the debloated AOSP version from f-droid. Debloated, in this case, meaning without support for minority languages such as mine.
- boudin 3y agoThere's nothing intentional there. If the keyboard you had installed was also distributed via F-Droid using the same APK identifier, then F-Droid just detects an update since it's the same app. To prevent this (it can happen with most apps distributed both on the play store and F-Droid) you can tell F-Droid to ignore updates for a specific app.
- albertvaka 3y ago[dead]
- 38 3y agoNon crap link http://farside.link/twitter.com/albertvaka/status/1712954968477401478 http://farside.link/twitter.com/albertvaka/status/1712954968...
- lucb1e 3y agoTakes about 9 seconds to load, then redirects to a nitter instance. Does it benchmark all the nitter options out there and then redirect you to the best result? The farside.link homepage doesn't really say
- grishka 3y agoRelated to this, I really dislike how Google Play acts like it owns your device. Installing an apk? Hey, I'm Google Play, I exist, how about turning Play Protect on?
- garciansmith 3y agoThose messages are very annoying. Play Protect periodically tries to get you to turn it back on, once every few weeks or so. I really wish there was a way to turn that annoying nag off. Glad I have it off though: KDEConnect is great, I use it all the time to transfer files and send text messages from my computer.
- wkat4242 3y agoI agree but millions of users are ok with Tim Cook deciding what they may use on their own phone. We're so screwed.
- chenxiaolong 3y agoLooking at AOSP, the logic that allows something like Play Protect to work is at [1]. It looks for system apps that can handle the ACTION_PACKAGE_NEEDS_VERIFICATION intent, which is the Play Store app in this case. Looking at the Play Store's AndroidManifest.xml, the PackageVerificationReceiver component is what listens for that intent. With root access, it should be possible to disable just that component without breaking other functionality by running: pm disable com.android.vending/com.google.android.finsky.verifier.impl.PackageVerificationReceiver To reenable: pm default-state com.android.vending/com.google.android.finsky.verifier.impl.PackageVerificationReceiver Without root access, disabling the Play Store completely (if you don't need it) via the normal Android settings should also do the trick. [1] https://android.googlesource.com/platform/frameworks/base/+/refs/tags/android-14.0.0_r11/services/core/java/com/android/server/pm/PackageManagerService.java#2450 https://android.googlesource.com/platform/frameworks/base/+/...
- gbil 3y agoIs this proven? Some days ago I saw the reddit thread which is actually the first and only reply in the link and in that reddit thread there is no conclusion yet on who is actually affected why this conclusive title then?
- boomboomsubban 3y agoThe reddit thread makes it pretty clear that KDE Connect installed through third party sources are what's getting uninstalled. Nobody with it installed from the play store mention it being removed, and though some users that got it from F-Droud mention it still being installed, there are several possible explanations for that. Like me, it wasn't removed on my phone but it turns out I disabled PlayProtect at some point.
- gbil 3y agoEven if it is like you state, link directly there, to the exact posts that prove this and not in an intermediate site. HN is supposed to keep a higher post standard
- neurostimulant 3y agoI have kde connect installed from google play for months now and never got flagged by playprotect, so that's one data point.
- heavyset_go 3y agoI can speak from experience that I woke up yesterday with KDE Connect missing from my device.
- ensignavenger 3y agoHappened to me, I had to disable Play Protect scanning... interestingly, in ghe deacription in Android settings, it claims Play Protect will scan and WARN, not remove, apps. That is clearly a lie.
- Zambyte 3y agoMy phone forces me to reject "Play Protect" every single time I want to install an app. If I have to explicitly reject it more than once, it is obviously malware. Once is already arguable.
- throwaway914 3y agoThe only acceptable phone for me has been a Pixel phone, with GrapheneOS installed. I do wish the permission to install/uninstall were separated for something like this (I may be naive). I have everything installed to a work profile in Android (using the Shelter app). I can globally pause all work-profile apps. It's not the best, because when unpaused I'm not getting some notifications. I need to figure that out.
- fsflover 3y agohttps://news.ycombinator.com/item?id=37880628 https://news.ycombinator.com/item?id=37880628
- TimeBearingDown 3y agoIt’s still the best of all worlds for many people, a great intersection of privacy tool availability and general app usability.
- fsflover 3y agoI do not dispute that. If you have to run random untrusted apps, grapheneOS is more suitable. But it's not a long-term solution.
- stderrout 3y agoGoogle wants more control by projecting itself as infallible trust authority on device. Its standards are so high that if you are ever on other side of its automated tools first response usually is blame user rather than hire any human support team to investigate issues even if they may be coming from its programs. And then the reports keep coming on how it was error or mistake due to scale of operations its just rounding error. Next time it will be different. Trust us we are the only ones who knows this or able to do it right even if we sometimes do make mistakes you should only let us do it. No one is better than us.
- ekvintroj 3y agoWe should be able to install any OS that we want on our phones.
- eks391 3y agoThis is precisely one of the perks of rooting. Unless you mean as a right, without needing to root? I'd disagree (from a corporate/warranty perspective), but I'll bite
- BHSPitMonkey 3y agoDo you think the ability for the owner to root is not worthy of protections? It seems odd to draw that distinction when they are two sides of the same coin
- yjftsjthsd-h 3y ago> This is precisely one of the perks of rooting. Rather, it's a benefit of an unlocked bootloader; you can root a device with a locked bootloader, and you can use an unlocked bootloader to install an unrooted OS (or, for that matter, you can unlock the bootloader without rooting, depending on the device). > Unless you mean as a right, without needing to root? I'd disagree (from a corporate/warranty perspective), but I'll bite Why? I mean, sure, if the manufacturer can show that damage resulted from the user modifying the device then fine, but otherwise there's no reason for modifying software to affect a warranty on hardware.
- eks391 3y ago> otherwise there's no reason for modifying software to affect a warranty on hardware. I think you bring up a really good point. Except for extreme cases, such as a software that is designed to be self destructive on the physical components in which it resides, the hardware should mostly be unaffected by the software. Mostly that some components get used more or less than they were before, changing efficiency of some functions. Then we get into the grey area of whether or not the unorthodox use of components caused damage. > if the manufacturer can show that damage resulted from the user modifying the device then fine Here you are putting the burden of proof on the manufacturer, which seems a little unfair. If anyone can make a complaint (make use of warranty), and you the manufacturer are guilty as charged automatically unless you can prove the software caused the damage, then there will be an insurmountable amount of work to thoroughly review all software not sourced from one of your already-vetted approved sources. Then again, if burden of proof falls on the accuser (warranty holder), it is a catch-22 because you can't prove that a software is without any issues. Companies are constantly creating patches not because they intentionally want to have a fault until x day, but because they genuinely thought the software was good until y vulnerability was found/exploited. I think this is why companies take the 'any usage outside these specific approved usages voids the warranty' approach. In application to this conversation, this means while you may change your OS, it doesn't shock me that a manufacturer wants to keep their hands away from those consumers
- awinter-py 3y agosolution: need f-droid version of play protect they could raise so much money for lawsuit to force G to allow it to be swapped in
- its-summertime 3y agohttps://f-droid.org/en/packages/us.spotco.malwarescanner/ https://f-droid.org/en/packages/us.spotco.malwarescanner/
- shmde 3y agoI swear on God. Just 2 days back playstore decided to auto update my installed apps. The thing is I have them disabled by default. I cancelled the update, switched off the wifi. But once I turned it back on, it started auto updating again.
- jenadine 3y agoHapenned to me a couple of days ago. I then just re-installed it from the f-droid and it worked.
- npteljes 3y agoShows who's boss on the phone. It's practically a remotely managed corporate environment.
- eddythompson80 3y agoBut you can turn it off. It’s basically AV for Android.
- deleted 3y ago[deleted]