20 ms·
Android Developer Verification: Threat masquerading as protection
- mghackerlady 3mo agoI've just stopped using smart phones. If they aren't going to give me more freedom than a dumb phone, I have no reason not to use one
- TheRealPomax 3mo agoIt's nice that you have that luxury, but that makes you an anecdote in a world where folks need a smartphone just to access banking or government services.
- slowmovintarget 3mo ago> Disguising itself as the innocuously-titled “Android Developer Verifier” (ADV) process, this trojan horse runs surreptitiously in the background as a system service with full root privileges, quietly awaiting an activation signal. The service cannot be blocked, disabled, or removed. Unlike a commonplace bit of malware, this extraordinary strain won’t be detected and neutralized by Play Protect (the malware scanning and remediation service that is installed on all Android Certified devices). In fact, Play Protect is itself the vector through which this virus is transmitted and installed. > That is because it is Google themselves who is propagating ADV. And once activated, this malevolent process has exactly one goal: to block you from running software by developers who haven’t been approved centrally by Google. The rest of the article is a claim that Google's new terms of service amount to "malware is any software we [Google] don't like." It seems like Google is aiming for its own walled garden.
- ranger_danger 3mo ago> How long before they designate all ad-blocking software as malware, block installation on all Android certified devices worldwide, and permanently designate all developers of this class of software as malware creators? Classic slippery slope fallacy. https://en.wikipedia.org/wiki/Slippery_slope https://en.wikipedia.org/wiki/Slippery_slope History shows that when a "slope" appears... regulation steps in, technology evolves to solve the problem, or the culture shifts to reinterpret the thing. In almost every case, the feared "bottom" of the slope was never reached because humans constantly built ramps or bridges along the way.
- dminik 3mo agoIs it a fallacy if you've said before that Google is aiming to create a walled garden, Google itself has already started saying it wants a walled garden and they've already implemented several such steps?
- weikju 3mo ago> In almost every case, the feared "bottom" of the slope was never reached because humans constantly built ramps or bridges along the way. Perhaps it happens because the slope is called out...
- Terr_ 3mo agoMuch like the fallacy behind: "The Y2K bug was was a total hoax, you can tell because nothing much happened on 2000-01-01."
- acters 3mo agoPlus, it is not the bottom I fear, it's the precedent from letting companies slide down the slope. Regulation may try to stop it but history has shown some have slid to the point of no return or past a point where people can care enough to build out of. Prevention is better than retroactively fixing stuff.
- thinking_cactus 3mo agoI alternate my thoughts frequently (which I believe is healthy), and sometimes I think we should let things take their course a bit more before reacting. It's certainly tiresome and can be pointless (some people claim 'hysterical') to fight lots of changes, not necessarily this one but some like it. But I've come to realize there are serious downsides to letting things run their course too. Some changes are very hard to roll back (famous 'cat's out of the bag') just taking a lot of time to reverse if ever. For example, once there is a long term contractual agreement, if one parties decides to roll back they may just not be able to until the contract expires (like renting land; or worse, selling). A change in software systems for example that need backward compatibility can be quite difficult in technical and nontechnical ways. I think people need to also keep some sympathy for the protests and let people protest more. I'm leaning more toward: if in doubt, provide visibility to a cause (even if not full support). It's okay to save yourself some energy (in particular for the most important causes). Some things might have to run their course for people to understand they were valuable, and we will probably have to eat some frogs as a consequence. Don't lose you sanity ;) (As the saying goes, "Don't you dare go hollow.")
- Rekindle8090 3mo ago[dead]
- 3r7j6qzi9jvnve 3mo agorelated: https://keepandroidopen.org/ https://keepandroidopen.org/ previously on hn - https://news.ycombinator.com/item?id=47935853 https://news.ycombinator.com/item?id=47935853 (2 months ago, 889 comments) - https://news.ycombinator.com/item?id=47139765 https://news.ycombinator.com/item?id=47139765 (4 months ago, 378 comments) - https://news.ycombinator.com/item?id=47778274 https://news.ycombinator.com/item?id=47778274 (3 months ago, 68 comments)
- deleted 3mo ago[deleted]
- WarOnPrivacy 3mo agoMy Android 15 handset doesn't have com.google.android.verifier process. It could be a Ulefone thing. They're especially pro-user (ex:root friendly).
- EspadaV9 3mo agoChecked my Pixel 7 XL Pro and the app is installed and running (Version 1.0.866414232 com.google.android.verifier). I was able to force stop it, and disable it. Will check later to see if reenables itself.
- Aachen 3mo agoEx means "example" here right? Or do you mean ex as in the dictionary meaning of ex, as in, "formerly"?
- WarOnPrivacy 3mo ago> Ex means "example" here right? Yes. eg would have worked too. ie didn't seem like a good fit.
- anilgulecha 3mo agoI understand the frustration (I'm an avid fdroid user across many many devices). But this article comes off as childish with the virus/trojan/"malware vendor". With such an article, many (including perhaps google) get the ammo to disregard what fdroid says, by branding them as childish/not to be taken seriously. for eg: no reputable news org is going to post this. PS: https://keepandroidopen.org/ https://keepandroidopen.org/ is better done.
- econ 3mo agoI thought the same thing but he apparently has a point. The stated purpose covers only a tiny sliver of the capabilities. The agreement points to the TOS where it (last time I looked) says service may be terminated at any time without stating a reason. Nothing guarantees it won't be used for things other than security. And finally he has a point where it also doesn't really do much for security. If we ask their fine search engine, the AI helpfully explains malware to be software designed to gain unauthorized access to disrupt, extort payments and/or hijack devices. If you still think the shoe doesn't fit, imagine what would happen if one managed to create an app with the same capabilities. Google would remove it immediately for being malware. Obvious malware.
- stingraycharles 3mo agoIsn’t Google going to do what Apple has been doing since forever? Or is Google somehow doing something worse?
- jb282 3mo agoApple's policies were established when you purchased the phone. Apps come through registered developers and their vetting. Google has changed the game on something you already own. I'm sure their lawyers have done their homework, but in some jurisdictions this is certainly actionable.
- someonebaggy 3mo agoThey already lost a lawsuit and were fined a hundred billion dollars in the EU for locking down Android. Maybe they think since they already lost once, they can't lose again.
- stavros 3mo agoI don't understand how this is legal in the EU under the DMA, does anyone know?
- pimeys 3mo agoI already contacted the DMA authorities and complained how this has an effect on German diabetes communities and they replied that I am not the first one who approaches them on this and they are already investigating it. Google is just trying how far they can push this.
- stavros 3mo agoExcellent, I emailed them too but no reply yet. Yeah, given that we should be able to choose what app store to install, this seems wildly illegal.
- sebastiennight 3mo agoDo you have any pointers on how to find the correct authority and reach out? I'd like to inform my EU audience.
- pimeys 3mo agoYes. From here: https://digital-markets-act.ec.europa.eu/contact-dma-team_en https://digital-markets-act.ec.europa.eu/contact-dma-team_en
- kodebach 3mo agoSince Apples App Store is DMA compliant, the EU won't do anything against this far less restrictive change from Google.
- hurfdurf 3mo agohttps://www.eu-digital-markets-act.com/Digital_Markets_Act_Article_6.html https://www.eu-digital-markets-act.com/Digital_Markets_Act_A... Art 6 (4). Read it to the end. That's how.
- nusuth31416 3mo agoI use Android because it lets me install whatever I want on my phone, which it does not seem to me, controversial. The phone is either mine or it is not. I don't want Google's protection. Particularly, if I can't refuse it.
- kalx 3mo agoWell… you can run android without google? The problem is that essential security services require apple or google devices and you as a member of society need the security services.
- realusername 3mo agoLet's call them anti-competition services since there's nothing in these increasing security.
- karteum 3mo ago> Well… you can run android without google? You can only run LineageOS on smartphones that allow unlocking the bootloader (which is more and more rare), and properly release the kernel source-code (many still don't, especially low-end MTK-based phones...)
- palata 3mo agoYou can run GrapheneOS on Pixel phones, and soon Motorola :-).
- Aachen 3mo agoYet on LineageOS you're not affected. It seems you can build Android that isn't affected by Google, at least if you're willing to personally adjust the code to do what you want. You'd have to get exceptionally busy before it's not recognisable as an Android distribution anymore
- alfiedotwtf 3mo agoHow’s LineageOS compatibility these days? And besides F-droid, is there a place where mobile apps are plentiful without being full of malware? Also, how’s isolation on LineageOS for mobile apps? I think I’m getting to the point where I’m thinking of ditching Apple again
- khurs 3mo agoAndroid users need to switch to Graphene. Someone needs to create a Linux based mobile OS foundation - Google's domination is contrary to many large companies interests, and if Meta and many other such companies were approached, they may well donate large sums of money in their own strategic interests.
- preisschild 3mo agoI wonder if it makes sense to create an independent hard-fork of AOSP in the future. But probably the only option to keep this somehow maintainable is to replace many android-specific components with other userspace linux components that are already well maintained (systemd, networkmanager, wayland)
- kalx 3mo agoWould this not require some control over the hardware? Which would be difficult for the FOSS community?
- preisschild 3mo agomaybe not, heck people reverse engineered apple hardware and implemented it in various FOSS driver stacks But yeah, vendors maintaining their drivers upstream in FOSS projects would obviously make it easer
- darig 3mo ago[dead]
- kalx 3mo agoI tried. But then I didnt get access to essential services like banking and national resources.
- kalx 3mo agoCorrection: i did get bank access. I just couldnt log into the bank without a google or apple controlled device.
- foxrider 3mo agoThis would be the line for me. If at some point I'm unable to build an .apk and install it on my phone without Google letting me, I'm moving to Huawei.
- aerzen 3mo agoDoes Huawei not use android or Google play services?
- foxrider 3mo agoNo, they use AppGallery and HMS.
- animuchan 3mo agoIt's Android but without Google's services, there's an alternative app store. The irony of Chinese vendors providing a breath of fresh low-DRM air.
- pjmlp 3mo agoPartially true, HarmonyOS NEXT is its own thing, with a Typescript based language ArkTS. https://developer.huawei.com/consumer/en/arkts/ https://developer.huawei.com/consumer/en/arkts/ And now they are adding yet another one, AOT compiled, Cangjie https://cangjie-lang.cn/en https://cangjie-lang.cn/en Using Android fork has been a transition step.
- skybrian 3mo agoI understand not being happy about what Google is doing, but it seems like F-droid can’t be trusted not to heavily spin things.
- echelon 3mo agoThere is no spin here. Google is pulling up the ladder. There won't be an open web, there won't be user installs, there won't be anonymity. Everything will be identified, attested, and allowed only when Google permits it. Nevermind them choking startups and small biz out of the oxygen they need to survive.
- skybrian 3mo agoWhat are talking about? Android Device Verification has nothing to do with what websites browsers can access.
- Timshel 3mo agoIt does with reCaptcha: https://www.androidauthority.com/grapheneos-google-apple-approved-devices-web-warning-3665319/ https://www.androidauthority.com/grapheneos-google-apple-app...
- skybrian 3mo agoYes, Google could do a lot of things, in theory. Doesn’t mean they’re doing it.
- notrealyme123 3mo agoAs android shows: they are doing it
- 0x_rs 3mo agoThey are doing it now. You can already see that captcha around online, and cannot get past it without surrendering your identity to them.
- transcriptase 3mo agoI think the most fun part with Google is that if some wayward algorithm decides it doesn’t like you, along with nuking your app and developer account it will probably nuke your 20 year old gmail, your kids Google Drive accounts, your wife’s YouTube premium, the Adsense account of some company you worked for in 2008, and disable your Nest cameras. And you’ll never reach a human to sort it out.
- ferfumarma 3mo agoThe vulnerability of your Google identity is terrifying.
- m00dy 3mo agoit's a nightmare.
- techpression 3mo agoWe experienced this with Anthropic, not the same blast radius obviously, but out of nowhere account was terminated. No support available. It was via someone’s 30+ year old classmate via LinkedIn the account got reinstated. As a counterpoint to the right to the repair there should be a right to recover.
- Gigachad 3mo agoThere was a more direct case where someone’s child had been interacting with Gemini inappropriately resulting in Google nuking the entire families Google accounts.
- techpression 3mo agoThat’s quite insane, especially considering how Google is pushing Gemini into every single product.
- bayindirh 3mo agoI still remember how uploading photos of man's own child created the catastrophic chain of events. Kicker? The photos were requested by a doctor. Ref: https://www.koffellaw.com/blog/google-ai-technology-flags-dad-who-took-photos-o/ https://www.koffellaw.com/blog/google-ai-technology-flags-da...
- wolfi1 3mo agoI'm still a little bit confused why the EU does not take action in this. This is definitely a monopolist overreach which has to be shutdown from the beginning
- hurfdurf 3mo agoBut they did. EU formally allows all these measures by Google in the name of "security" as described in Digital Markets Act Art. 6 (4) fourth paragraph. https://www.eu-digital-markets-act.com/Digital_Markets_Act_Article_6.html https://www.eu-digital-markets-act.com/Digital_Markets_Act_A...
- IshKebab 3mo agoThey're allowed to do it "to the extent that they are strictly necessary and proportionate ... provided that such measures are duly justified". It remains to be seen whether the EU decides that this measure is strictly necessary, proportionate and duly justified. They sometimes do the right thing but I'm not getting my hopes up.
- int_19h 3mo agoEU will likely want something like this for ChatControl (or whatever it's called in its current draft iteration) enforcement anyway. And Google will no doubt be happy to have its highly paid lobbyists testify on how it will help catch child predators and terrorists.
- ajb 3mo agoIndeed. I wonder if it falls foul of labour law. Blacklisting is illegal and whitelisting (certification) is normally done with multiple competing third party certifiers.
- r_lee 3mo agothis is something the EU would love, it's part of the whole Transparency thing where you dox yourself to everyone HNers (especially Americans) are super naive and think the EU is some bastion of freedom. no. it just wants to be a huge nanny state but in a wholesome way, where you can do whatever you want as long as it's approved
- linuxhansl 3mo agoWhat Google is doing is shameful. One of the promises of Android was being more open than the restrictive Apple ecosystem. Now that they reached penetration they do the switch - under the guise of security. Just let me do with my hardware what I want to do it. Let it be my responsibility to install whatever I want (and stop calling it "side-loading", as if I am doing something shady from the "side"). We need to resist this! Alas, from the broader response it seems that most people just do not care.
- altairprime 3mo agoShame isn’t an applicable concept for a corporation.
- nehal3m 3mo agoMaybe we need an economic system where it is. Shame should come packaged with legal personhood.
- altairprime 3mo agoBetter to pass state bills modifying all of that state’s articles of incorporation to compel adherence to B-corp standards.
- stymaar 3mo agoShame has ceased to be an applicable concept for anyone “important” enough to get free media attention.
- sscaryterry 3mo agoThis is worse than Apple. With Apple you knew where you stood day 1.
- Grombobulous 3mo agoIf you go back far enough, the original iPhone didn’t even promise to give you the ability to install apps.
- charcircuit 3mo agoThis is not malware. It's an official part of Google Play Services.
- vrighter 3mo agoit is malware when everyone is explicitly asking to not have it.
- RobotToaster 3mo agoThose are not mutually exclusive.
- ale42 3mo agoIt all depends on how you define malware. If malware is software doing something that is contrary to the user's interests, then for many users it is indeed malware.
- someonebaggy 3mo agoToo much hedging in this comment. Malware is something that maliciously breaks your computer. This maliciously breaks my computer so it's malware. There's no difference between this and the ILOVEYOU virus, except the delivery mechanism.
- spaqin 3mo agoCan I install some software on your computer to send me over your bank details? It won't break your computer, I promise, it's not malware.
- charcircuit 3mo ago>this malevolent process has exactly one goal: to block you from running software by developers who haven’t been approved centrally by Google. This claim is made by FDroid with no evidence. They make this scary claim which goes against everything Google has claimed so far. They are a biased party, and I can't trust their opinion. I would appreciate if they shared a more in depth investigation or a way to verify there big claim.
- deleted 3mo ago[deleted]
- p0w3n3d 3mo ago[flagged]
- Rekindle8090 3mo ago[dead]
- gadders 3mo agoI just launched an app in the Google Play Store. I did find it a bit weird that I had to provide my physical home address to get my app listed. Not sure what I would do if someone turned up to complain. Make them a cup of tea?
- r_lee 3mo agowell they can swat you, order pizza, send you packages (who knows with what inside), spread false info about you if you've given out more info etc... all it takes is one guy who gets too mad for some reason and it's gonna be a lot more costly for you to do anything about it vs. that guy who gets to be completely anonymous about it
- Arnt 3mo agoHow? I don't see the address published. They can sue you and Google will give your address to the court, clearly. But swat? Send packages? How?
- wiseowise 3mo agoDon’t know about US, but in EU you legally have to publish your address and it will be shown on the store page if your app has ads or in-app purchases.
- Arnt 3mo agoI see. I looked at https://play.google.com/store/apps/details?id=eu.faircode.email https://play.google.com/store/apps/details?id=eu.faircode.em... and saw nothing. I can see why your address is shown if you offer something for sale. Ads, that puzzles me.
- nicce 3mo ago> I see. I looked at https://play.google.com/store/apps/details?id=eu.faircode.em https://play.google.com/store/apps/details?id=eu.faircode.em... and saw nothing. I can see? FairCode B.V. marcel+play@faircode.eu <redacted> Anyway, ads are just a sidechannel for purchase. There is a product advertised, someone buys it and developer gets the cut from the seller of the product. This is how ads work.
- bouncycastle 3mo agoDoes this mean that apks that i've built and installed through adb will stop working? That would be a real damn shame.
- willtemperley 3mo ago> In computing, a trojan horse or trojan is a kind of malware that misleads users as to its true intent by disguising itself as a normal program. [1] Google is Trojans all the way down. What is the true intent of almost every Google product? Data harvesting. Every single product is spyware of some kind. They've even managed trojanize TVs by subsidising manufactuers to ship their spyware. [1] https://en.wikipedia.org/wiki/Trojan_horse_(computing) https://en.wikipedia.org/wiki/Trojan_horse_(computing)
- wazoox 3mo agoI've already disabled Play Protect ages ago because it kept removing apps I had installed through F-Droid. Actually, I almost only install apps via F-Droid. I wonder if the ADV will install with Play protect disabled ?
- johnathan101 3mo ago[flagged]
- selectively 3mo ago[dead]
- pjmlp 3mo agoThis kind of speech will only go with fellow technical users, most folks buying phones at the usual phone operators won't care less.
- dwoldrich 3mo agoThis is more than enshittification, it feels like purposeful brand destruction. Are governments going to institute more lockdowns? Is this some topdown control thing? I will root this POS android phone I have and forego any Google Play services and just use it as web browser and a phone. Fuck these guys!
- StingyJelly 3mo agoWe finally live in an age when I can tell a clanker that I want an app that does something that I need, connect the phone with adb and in half an hour have a working solution for my tiny problem while knowing little about android development. This is something google should embrace, not kneecap.
- cryptonym 3mo agoWhat's their interest in you building side-loaded apps instead of using their data hungry services?
- zeumo 3mo agoThey do also sell the data-hungry side-loaded app builder.
- int_19h 3mo agoSure, but the real profits to be had there, if any, are package deals with other megacorps, not hobbyists.
- titzer 3mo agoOr buying some crappy app off the app store, from which they take a cut.
- thewebguyd 3mo agoTheir interests shouldn't matter. If they matter that much to restrict, then they are abusing monopoly power and need broken up.
- hurfdurf 3mo agoInstalling via adb is not affected.
- StingyJelly 3mo agoThat's great but I want to be able to share such app with my family members coleagues
- sambuccid 3mo agoIt doesn't solve the current issue, but in case we don't manage to push back on this, some people might not know that there are various actual linux OSes for mobile: - SailfishOS: still linux based and seems fairly community inclusive, but the UI part of the stack is closed source. Is the only one officially allowed to run android apps, via emulation. Has existed for a very long time, it's lightweight and I think the most stable/bug-free in this list. - Ubuntu Touch: fully open source and community driven, it uses snap packages for security, you might be able to run android apps. Last time I run it also seemed fairly stable/bug-free. - PureOS: fully open source and privacy focused. I think it's the only one that, released with the Librem 5, can avoid using proprietary blobs for interfacing with the hardware. Seems less stable than SailfishOS and Ubuntu Touch. You would need to buy a fairly expensive-but-old phone(librem 5) to run it. - PostmarketOS: fully open source, focused on being lightweight and revive old phones, has a huge amount of phones it has been tested on, is based on Alpine. - Mobian: mobile version of Debian, it's fairly new on this list. There are many more linux mobile OSes, but as far as I know these are the main ones. There might also be some inaccuracies on this post, I tested some of these a long time ago, and I never actually run the last 2.
- hollow-moe 3mo agoAnd all are useless because you can't use your mandatory bank or gov id app.
- throwburn202605 3mo agoMight be worth trying to get your gov to pin down the number of users or process to get gov id supported on any new platform. They likely wont specify 100k people or 10% of population or whatever email/petition but it at least records the requirement that other OSes exist and requires a process to support
- karussell 3mo agoNot useless. It is like the missing printer driver for Linux Desktop. It makes the experience ugly, but this is not the fault of the Linux OSes. Also the bank should not require apps (instead they can offer hardware key support or desktop apps) and in fact some - at least in Germany - offer a different authentication possibility. Also the app for the German ID is published on fdroid and does not rely on Google services.
- nsim 3mo agoSo, what's a good Linux tablet? I was thinking of trying an old Surface Pro.
- spwa4 3mo agoSo wait ... Google intends to enforce this on old versions of android?
- prmoustache 3mo agoI guess it becomes a part of Play Services.
- modzu 3mo agohow is graphene these days, or is there a better alternative that can run map apps that depend on google play services (like waze)?
- notpushkin 3mo agoAnything with microG should do the trick.
- Cider9986 3mo agoAll my apps work.
- HybridStatAnim8 3mo agoGrapheneOS is great, and easy to use. Sandboxed google play can run your maps apps that depend on google play without issue.
- RIshabh235 3mo agowe need to create a new os
- prmoustache 3mo agoWe already have the OS, what we need is a company that is willing to take a bet on it, support it and convince hardware vendors to provide upstreamed drivers for their stuff. PostmarketOS may not be perfect as of now, but it would advance and progress so much if people were hired to work on it and if people could buy a smartphone with it preinstalled. Bug reports and corrections would come much quicker as well as supported apps. Right now it is just a confidencial toy OS because of the lack of hardware support really, only a small number of smartphones are supported, only 2 of them are still sold and available as new (pinephone and pinephone pro), their specs are nowhere close to what you would expect for the price and they are only sold through a rather confidential online store.
- mpfect 3mo agoThis is exactly why I use Android over iOS, for software freedom. If Google forces ADV and locks out F-Droid, they remove the single biggest differentiator between the two platforms. Making Play Protect into a forced gatekeeper instead of an opt-in security scanner is a massive bait-and-switch for users who care about digital sovereignty.
- geokon 3mo ago> looming requirement that all Android developers register themselves centrally Does this somehow also apply to developers in China? Are Chinese OSs (Vivo/Honor/Oppo/etc.) entirely forked off of Google's Android? Is the solution to just a Chinese phone without the Play Store?
- Timwi 3mo agoHow does this affect the Fairphone? If I buy a Fairphone now (which I've been considering for months now) will I continue to be able to run F-Droid and load arbitrary apps, or does it come with “official” Android that will contain the restrictions?
- boudin 3mo agoIt depends of the operating system you install. Fairphone by default comes with a pretty standard Android version with Google Play serices, so it will be impacted. If you either buy a Fairphone from Murena (with /e/ OS) or from Iode (with Iode OS) or if you buy a standard one and install a version of Android without Google Play Services (like /e/ os or Iode), then you can still use FDroid.
- microtonal 3mo agoI would in general recommend against getting a Fairphone. They traditionally have a lot of hardware issues. Some of the early issues on the FP6 (fried logic board while charging and broken volume button) are not user replaceable. Many people have had to wait a month before they get a reply from customer support and even longer to get their hardware fixed. They also completely fail to communicate about issues. They also have a bad reputation when it comes to updating their software. E.g. their initial Android 15 builds for FP4 had bad memory management issues, with a result that many people could only have one app in memory at the time, which made it impossible to switch between e.g. an app/browser and a password manager/payment app. Some of their updates would cause boot loops when there were fingerprint reader issues, etc. Currently a lot of users are dealing with an issue where apps hang when used over WiFi because IPv6 gets misconfigured when a router sends an IPv6 router advertisement with lifetime 0 (which e.g. Fritz!Boxes that are popular in Europe do). The issue has been there for over three months without any acknowledgement or fix from Fairphone. Also, even though they do Android Security Bulletins and major releases (though very late), their phones often run ancient kernels and firmware with many known vulnerabilities. This is also the case if you run an alternative OS, because pretty much all of them use upstream trees. Also their firmware has Chinese TCL image processing blobs (might be a security/privacy issue for some people). I think many of these issues stem from the fact that the development of both the hardware and the software is largely outsourced to a Chinese ODM (T2Mobile), who maintain everything, so there is a lot of delay in everything. My guess is that Fairphone as a company is mostly a PR/support/supply chain auditing (as in minerals/labor, not software supply chain) company, with all the development outsourced.
- nirui 3mo agoEmotional talk aside, there's not many good solution to this problem, unless of course F-Droid starts to make their own phones. But then, Librem 5 Phone was just failed few years ago, telling the story that people who care about their rights are still sensitive to how much they would pay (which is a form of rights too). Also but, there is the thing, making a phone is not easy. If you reach deep enough, you'll eventually reach the layer where you realize how solid the monopolization has become. The global telecom standards if you read them is in the hands of few companies, Boardcom, Motorola, Huawei, Nokia and such. They'll control whether or not your phone can access the network. Then there's telecom companies who runs the network, and they might have to approve your device/modem as well since they got their channel allocation from the government. It's not easy, and it's not just the software problem. Oh and yes, we also have the software problem. Linux, if you want to go that route, cannot be used as a mobile OS, as least not for the public, because the average people don't know how to properly secure their system, and Linux is not a restrictive-by-default system. It will be a malware nightmare if you ship Linux on a phone as is. The best hope for now I think is for geek vendors to make more mobile/4/5G enabled Fairphone or uConsole-like product to the enthusiast market, and then you can load whatever OS on it as you want.
- m4rtink 3mo agoThe Librem phones do exist and people use them. Did it take the world by storm ? No. But it exists, has users & is building the case (together with Sailfish OS and others) that having an abusive mobile OS duopoly is not the desirable state of matters.
- KJs6ZxELzQM37O 3mo agoThere is a good solution. A big disclaimer and the user accepting the risk of running the software they want. The same solution they've been doing for years that did not need change. The new developer program is only here because it is more convenient to Google and governments.
- IshKebab 3mo agoWe've known for literally decades that that doesn't actually work, for several reasons: 1. People are conditioned to ignore warnings. There are way too many benign warnings in the world; you can't read them all. 2. Even when people wouldn't ignore them, in cases where they are being tricked by scammers it's easy for the scammer to talk people into accepting them. 3. Those sorts of warnings aren't actionable. You're installing a new app. It appears legit. You want to use it. You get a warning like "this app hasn't been verified; it might be malware!". What can you do with the information? Absolutely nothing. 99.9999% of users have zero way of doing any deeper check to see whether it actually is malware. Their only options are to give up and go home, or just hope that the warning is wrong. Even I - a highly technical user - get zero value from things like Windows' smart screen. "The app you're running hasn't been signed! It might be malware!". Err yeah sure. I'm not going to reverse engineer it to check am I? I think their solution of allowing you to disable the restriction with a one-time one-day delay is actually a really reasonable solution. As long as they don't go further than that - the risk is that it is just a temporary placation and they'll ditch that option in a few years.
- vrighter 3mo agoisn't this like the ps3's otheros thingie? Where the advertised functionality of the device was crippled after the customers bought them?
- charcircuit 3mo agoIn the PS3 case the feature was removed fully where in this case you just have to go through a new flow with warnings to reenable sideloading unverified developer's app.
- RandyOrion 3mo agoAndroid developer verification program, together with recent reCAPTCHA push [1], and Manifest v2 force depreciation on chrome [2], make one thing crystal clear. When companies like GOOGLE talks about things in the name of "your security", it's a sign that they want you to sacrifice your own things, e.g., privacy, freedom, etc., for their own security. And if you trust them and show your consent by doing nothing, you pay the price. [1] https://news.ycombinator.com/item?id=48067119 https://news.ycombinator.com/item?id=48067119 [2] https://news.ycombinator.com/item?id=48555244 https://news.ycombinator.com/item?id=48555244
- geocar 3mo agoGoogle has been attempting to license the right to write. There are a lot of poor people, mostly brown people, who do not have the ability to get one of these licenses. Some of them are feeding themselves with their ability to write, and Google is literally stealing that food from their mouths.
- birdsongs 3mo agoCan I ask what you mean when you say "write"? Are you talking about literature / articles, or software? This is new to me, want to stay on top of it.
- MSFT_Edging 3mo agoI think the commenter is alluding to writing software, as software is considered speech in some places.
- geocar 3mo ago> Can I ask what you mean when you say "write"? To "write", I mean the precursor to "read". https://www.gnu.org/philosophy/right-to-read.en.html https://www.gnu.org/philosophy/right-to-read.en.html > Are you talking about literature / articles, or software? All of the above. > This is new to me, want to stay on top of it. I am sorry to tell you it is not too new. Google tried this before recently with something called WEI (which you might be able to find on ddg or other search engines): It failed for reasons few people know for sure[1], but the initiative had the same basic bullshit about security, and the same outcomes. [1]: The story I heard was a couple South-American countries noticed that this would prevent their people from being able to work on software that runs in the Google ecosystem and threatened to block Google en masse. Since then, one of the countries that Google has a lot of offices in invaded one of those South American Countries for conveniently unrelated reasons.
- jzer0cool 3mo agoAs user wouldn't you like knowing there is a non-verified app? Is it restricting And still providing way to override if you choose?
- terminalbraid 3mo agoIs that not already the case today? Everything on the play store is verified. Anything outside of that is not by google and you are shown something. The whole point out of this outrage is alternative stores (like f-droid) can wholly and entirely be shut down on a whim without recourse.
- kodebach 3mo agoGoogle already announced the "Advanced Flow" that lets users override the verification. Yes, it's quite complicated, but it shows Google isn't trying to completely close down Android (yet). All this outcry is just lead to a boy who cried wolf situation. ADV is gonna become active, 90% people won't notice the rest will (begrudgingly) use the Advanced Flow. If Google then changes their mind actually does what F-Droid claims right now, nobody's gonna listen. IMHO F-Droid is just mad because their store model of "developer publishes source code, F-Droid builds and signs the APK" would put immense liability on F-Droid. After all with that model F-Droid owns the private signing keys and now has to register them with Google. If they let a single malware app slide through, Google might designate F-Droid as a malware provider and block everything ever published on F-Droid. (Sidenote: Last I checked F-Droid had nothing in their policies that forbids publishing malware, just that it has to be open source) If you ask me this store model was always stupid and completely missed the point of having signed APKs. I think they also have a newer model where they don't own the private keys anymore, but there's still tons of legacy apps. Of course Google might have been open to talks about some kind of verified app store program allowing F-Droid to operate under different terms. But that's certainly out the window after all the fear mongering, hyperbole and straight up propaganda F-Droid has put out in recent months.
- pimeys 3mo agoBtw. This whole debacle made me to stop installing any Android updates. I've done my best to avoid installing even the security updates, so my diabetes apps continue working in the future. I really need to take the time and go with Graphene OS in this device. My bank N26 kind of still allows it, but they made it harder and harder to use with certain custom checks. Looks like in the future I need a separate banking phone and my daily driver. The device works right now how I want it. I don't want anything to change.
- 0x000xca0xfe 3mo agoI have an old $70 test device with stock Android/Google that hasn't seen security updates in half a decade yet all banking apps, electric car charging, Google services, you name it, work absolutely fine. Meanwhile the daily driver phones of my privacy-aware family members running up-to-date Lineage or Graphene OS with recent kernels and frequent updates constantly run into apps refusing to work for "security" reasons. It's a complete joke.
- Gander5739 3mo agoTo pass MEETS_STRONG_INTEGRITY a device needs to have a security patch within the last year. Most apps don't check for storng integrity, though.
- patcat007 3mo ago[dead]
- Gander5739 3mo agoGoogle Play Services is independent of Android releases and will update itself automatically, though I believe you can disable this by uninstalling a specific system app with adb.
- yunohn 3mo agoWhile I sympathize with the general negative outrage towards this change, I truly believe that people here fail to empathize with the mainstream users of Android phones. I personally have seen every single older relative and non-tech friend, end up installing bloateare, spyware, and malware inadvertently - because they have no idea how anything in the tech domain works. And given the widespread popularity of Android (globally 70% vs iOS at 30% market share) and even moreso in lower income demographics, it also leads to rampant piracy of obviously non-essential apps like games and streaming (eg Spotify). In fact, even here on HN, almost everyone who has given their parents an iPhone has extolled the virtues of a secured AppStore/device and the peace of mind it brings. While there may someday be a way to support both the average user and the HN power user, we are not there yet. It’s hard for me to outright reject Google/Android attempts to secure people’s devices.
- rtsil 3mo agoThey can lock down the Play store completely, that's what 99% of people and the people most vulnerable to malware are using. The problem is extending that to F-Droid and other alternative services.
- Zak 3mo agoThe only time I've actually seen Android malware in the wild, it was because my mother installed a homescreen flashlight toggle widget from the Play Store that also displayed ads on the lockscreen. That was forbidden under Play Store rules, but there it was. I replaced it with something from F-Droid. The Play Store still has a problem with shady apps years later. If Google wants to be more like Apple, they should start with better curation in their own store.
- chrismorgan 3mo agoI’ve seen a fair bit of bloatware, spyware and what I’d count as malware on people’s Android phones. Every last piece of it has come with the OS or from the Play Store.
- deleted 3mo ago[deleted]
- shevy-java 3mo agoIt is time to dismantle - and subsequently forbid - Google. Too much Evil is now concentrated in this greedy adCompany. Mass-infecting so many devices on purpose is beyond compare now.
- sinuhe69 3mo agoWhile attribution is a strong weapon in fighting malicious software, persevering the ability to install and run anonymous software is essential to fight authoritarian regimes and corrupt systems. If we accept that only signed, permitted software can be installed and run on users’ phones, democracy and our freedom are doomed. Regardless if it is in the West or the East, or it’s against an AI overlord.
- einpoklum 3mo agoThe temerity of Alphabet to claim to protect users from malware/spyware, when they are known to share all of your personal information and communications with the US government (Snowden revelations), is the epitome of hubris. And, also, in the world we live in, just another Thursday. But even ignoring this - it is not for Alphabet/Google to decide whether, and how, I want protections. I want to be able to pick a sequence of bytes and install that as an application on my phone, without Alphabet having any say in whether that happens or not, and in fact without them knowing about it. It's my phone, not theirs, and the software should help me do what I need/want, not help them provide me their often-questionable services.
- titzer 3mo agoIt's even worse when Google believes they have a legally defensible justification that your data has been "anonymized". E.g. "anonymized" location data directly from your phone that just so happens to be accurate to the meter. Such data just cannot be anonymized.
- scotty79 3mo agoAs a user how do I opt out? Can I root my phone and excise this crap with some tool? If this is disseminated through Play Protect, does disabling Play Protect prevent triggering this?
- schnatterer 3mo agoMeanwhile in Luxembourg: Google loses fight against EU’s $4.7 billion Android fine https://www.msn.com/en-us/money/other/google-loses-fight-against-eu-s-47-billion-android-fine/ar-AA272fSq https://www.msn.com/en-us/money/other/google-loses-fight-aga...
- 1970-01-01 3mo agoAll talk, no solutions from F-droid. What are they actually doing to solve it? Why not stand up their own vetting system? I'd love some technical solutions, instead this is just childish.
- titzer 3mo agoBy analogy, would complaining about any organization ridiculously more powerful than you (e.g. a government) without having a complete alternative ready to go also be "childish"?
- 1970-01-01 3mo agoIf the underdog is directly involved in the -alt business, yes, it is very childish!
- terminalbraid 3mo agoBecause as designed they have to live under whatever google puts into Android because they have inordinate control over the whole ecosystem? I'm not sure why or how you would possibly describe that as "childish".
- LoganDark 3mo agoSolutions from F-Droid? There are none. Like they said, it's an unremovable system service.
- dingaling 3mo agoThey could register as a corporate developer, but they decline to do so because _"that would effectively seize exclusive distribution rights to those applications."_ But it wouldn't - the course code is still available for anyone who wants to build and distribute the apps themselves.
- Zopieux 3mo agoAt this point, the only "solution" is anti-compete legislation.
- ciefa 3mo ago[dead]
- krunck 3mo agoWould this also be a strategy to get all Android users to have a Google account? Once you are locked in to using Google's Play Store then can then require login to even install apps. I don't have a Google account. I never will. If I am required to get one to use my phone(Fairphone4, eOS) then I will cease using the phone. There is nothing in my life that requires me to have an Android phone.
- renegat0x0 3mo agoGovernments plan to use google play for government services. It is just a matter of time before it is required for you to use it. https://news.ycombinator.com/item?id=48730729 https://news.ycombinator.com/item?id=48730729 More and more sites require you to use it be it github, or even fdroid (via gitlab).
- terminalbraid 3mo agoBanking has slowly been transitioning in this direction as they close brick and mortar places. I'd have to drive 20 minutes to cash a check (which is still sadly common in the US in certain industries).
- scotty79 3mo agoMy iOS using friend told me that he can't even use the iOS software that he has written on his own phone. He can run the software but it expires in a week so he'd have to redeploy every few days to keep it running. Is that right? Is that the future of Android as well?
- economistbob 3mo agoIt would seem to me that the best hse of resources here would be ensuring LineageOS ports to more devices than Pixels ASAP. Yet no one works on that angle.
- xylon 3mo agoWhy not replace F-Droid with a catalogue of links to open-source apps hosted in play store?
- stankondrat 3mo agoMost F-Droid apps are built from source. A link to Google Play may point to a newer version that has changed and could contain undesirable behavior.
- m_m_carvalho 3mo ago[dead]
- dmos62 3mo agoWe can't make arbitrary changes to much of hardware and software we rely on. We can't inspect their designs, we can't reproduce them, sometimes we can't repair them. Sometimes we can't even tell that they're designed to act against our interests, and, if we do, sometimes we can't do anything about it. We are forced to choose between price and privacy, between interoperability with proprietary (or official) systems and liberty. Android making another step in this direction is bad. But, let's not kid ourselves: we are neck deep in this cyberpunk serfdom, and have been for decades. If we were to get this Android win, it would be only a small win. I'm saying this not to be defeatist, but to remind us of the bigger fight. How does this feudal goliath meet its end? When is enough enough?
- t1234s 3mo agoThis is just getting us ready for the coming police state in the US. Choose your ankle monitor: apple or google.
- TZubiri 3mo ago>Should a developer — contrary to our recommendation — elect to register themself with Google as a “verified” developer, they should expect to sign up for an account and pay a fee, surrender detailed personal information and upload government-issued identification Again, there is a tradeoff between protecting consumers and protecting vendors. If you protect the privacy of vendors, you do so at the expense of increasing risk to the consumers. I don't want to be polarizing, but narcissistic is the best word to describe the position of this article. I'm assuming that when they are consumers, they would find it reasonable that their vendors provide due diligence and be held to higher standards. When they go to the pharmacy, and they buy aspirins, would they choose a tablet of aspirins from a pharmacy that doesn't ask where the aspirins came from or who the distributor or producer is? If such privacy of the producer were respected then the market would open up to actors that provide low quality, counterfeit, or malicious product. You can't have it both ways. If you are a vendor, you are no longer an anonymous consumer. Installing a VPN, paying with cryptocurrency, using firefox and duckduckgo to avoid tracking, that's not on the table for you once you decide to be on the other side of the production market. If you want to make software and distribute it anonymously, go ahead and submit it to one of the many malware riddled distributors that don't do any due diligence like npm, github, AUR, why must you insist on being let in a club that doesn't want you? Is it perhaps because the reputation of such club is higher because it doesn't have malware because it performs such due diligence? At least if you are going to complain about this, do it with standard language don't co-opt cybersecurity terms, adding noise to whoever cares about actual security. If this is really a problem you wouldn't need to exaggerate or plain lie about it.
- notpushkin 3mo ago> If you want to make software and distribute it anonymously, go ahead and submit it to one of the many malware riddled distributors that don't do any due diligence Like F-Droid, one of the most famous malware dens in the Android ecosystem.
- LoganDark 3mo agoI think it's funny that they look at the phrase "malware or other harmful applications" and then only have an issue with the definition of "malware" rather than "harmful". Like, wouldn't "harmful" be FAR easier to apply in literally any case you feel like? "malware" sounds like it'd need some proof of malicious intent but "harmful" needs no such thing and is much looser.
- mindaslab 3mo agoIt's high time we ditch evil Android and switch to something libre.
- noisy_boy 3mo agoI have already migrated my government and banking stuff off Gmail. I'm fine losing my access to HN but Google can't be trusted with serious shit.
- codedokode 3mo agoI wanted to use an alternative mobile OS, but they only support expensive devices like Pixels or outdated models. So I am planning to port some open Android variant. Obviously, all Google Services will be removed and most proprietary apps too. I also want to be able to manually edit permissions and remove Internet access from most of the apps, even open source. It is inconvenient that Android actually has "Internet" permission but doesn't allow the user to revoke it. I do not need Google Play (a collection of spyware, covertly collecting Wifi points and cell towers location in my country and sending them abroad), I do not need bank apps (I have a laptop for that) so I guess I will be fine. Obviously there will be no developer verification on my device as well, and I mostly use apps from F-Droid anyway. Good thing about F-Droid is that they build apps themselves and you can always get the sources - unlike Google Play and Apple Store that provide no sources and unlike PyPi/NPM which allows sources to not match the binary distribution.
- sneak 3mo agoYou do need Google Play, or a suitable replacement, because most android apps won't work without it.
- codedokode 3mo agoF-Droid apps do not need Google Play Services. OSMand (offline maps) and other apps works without it. Telegram probably should work too, but I did not test. AI also says that it is possible to have push notifications without Google.
- BatteryMountain 3mo agoIf they go through with this, I will make it my life's mission for the coming months to de-google my personal life and break any dependencies on google at work. Done with this nonsense. Shouldn't take more than a month to remove the tumor. On my android phone: My own launcher My own keyboard My own sync tool for local net My own net tools to WoL some devices on my lan. My own tool to control 3 proxmox servers My own tool that parses groceries slips My own tool that keep tracks of my vehicles events/lifecycle/purchases etc. If they break my launcher/keyboard and my ability to use my phone in my customized way, they will NEVER see me as a client again. None of these apps are in the Play Store, they are signed with my own signing keys, which have never been uploaded to google, in fact, no google account is linked to these apps. These apps are also privacy-oriented (even the keyboard, I ship a 1mb dictionary with and it learns my own words, never transmits anything). I will not give google my ID , neither Persona or anyone else. I'm very happy to go back to using bank card + chip + pin than use google wallet. Trust me I will walk away. I already move 4 family members off of Windows in the last 2 years, I will get them off google too.
- bobbean 3mo agoI started de-googling a few weeks ago. I don't really know what I'm doing but it's kind of enjoyable to learn. Graphene OS with F-Droid and I'm most of the way there. I still use the play store for some apps unfortunately. Also google maps, gmail, google messages (for rcs) and google fi. I'm not sure if theres anything close to the quality of traffic reporting as google maps, so it's hard to give up. The rest I will eventually move away from... Hopefully. I have a home server with a reverse wireguard proxy for self hosting photos, calendars, etc. I also have firefox with noscript blocking everything by default, but that's a big pain for an average person. Also it doesn't seem like firefox does a good job of anti-fingerprinting, but I haven't looked too deeply into that. I even bought a tv that has adb access, and I removed a bunch of bloat, but it doesn't seem possible to remove the google launcher without causing huge system instability. I might just firewall it off. There are a ton of open source alternatives to google products now, way more than the last time I tried moving away. It's time to leave.
- BatteryMountain 3mo ago
- zb3 3mo agoWhile I hate how user-hostile stock Android is (and it's getting worse, all because of Google's ad business model), these reactions are so blown out of proportion they might only teach Google to do it the subtle way, or use such changes as a smokescreen.. 24 hour waiting time? Big outcry.. Anticompetitive permission system where apps can do not that much more than websites? Nah, it's fine.. Unless you unlocked the bootloader, you were NEVER able to install apps you want, as Google had the final say what those apps could do (the anticompetitive permission system where user is the third class citizen, vendors are second-class citizen and there's only one first class citizen - Google). We need to fight for the right to unlock the bootloader and then not be restricted by the actual malware that is Play Integrity.
- Pxtl 3mo agoMaybe I've too much faith in Google, but a part of me wonders if Google doesn't want to get sued for this change. After all, their competitors have similar systems. While Microsoft's is circumventable with a few click-throughs, it's particularly nasty in that their code-signing certs are comparatively brutally expensive, too much so for hobbyist projects generally. If Google is looking at a world where all of their competitors are using first-party-controlled signing, it makes sense for them to wonder "why not us". And if they get sued for this, that would set the precedent for all of their competitors too. At that point the playing field would be level and platforms would be properly open.
- huxflux 3mo agoWe can't let this shit roll boys.
- deleted 3mo ago[deleted]
- slayernominee 3mo agoImo the best way to act against this is promoting custom ROMs like Graphene OS in your circle
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- binarysneaker 3mo agoAfter many years of Android freedom and choice, this'll likely be the reason I switch back to iOS/Apple. If I'm forced into a walled garden, it may as well be the best one.
- matejzvikl 3mo agoghhj
- matejzvikl 3mo agoghuu
- paulnpace 3mo agoA threat being masqueraded as protection is a deception. I now think this has been Google's modus operandi the entire time.
- pliuchkin 3mo agoGoogle won't ever take a break until we all pay for YouTube Premium. I think this trojan horse is mostly because of apps like New Pipe, Vanced, SmartTube and ad blockers in general.
- alok-g 3mo agoThis change is so significant that it feels like they are changing the product after it is sold. Could one stop this by disabling OS updates?
- tsoukase 3mo agoLet's see some points: 1) side loading, or however it's called, is used by less than 1-2% of global Android users (we can't be more than 50 million). Google made us a favor leaving it open after an only 24h delay. It could be much worse but now it's nothing in our eternal tinkering with developer options. Thank you from me Google. 2) GMS is a huge convenience for any app developer that needs tight control, including governments. They can secure their apps against users of any hat color. Add to that the possibility of hidden backdoors to support surveillance and Google's direct lobbying in EU. This makes it very difficult to go without it, even under the current anti-US EU direction and it will be the last that will be replaced in Europe. 3) There are various levels of "degoogling". From installing a totally open OS without or with microG, to just don't login to a Google account in stock Android. It's a spectrum but someone at the free edge will never have the same rights with one in the jailed edge. 4) Developer verif is NOT to prevent ad blocking. There is a simple and free method to block anything you like at DNS level: just select Private DNS and insert an appropriate URL for ads/trackers/porn etc, eg from controld.com. Find some other justification, like tight user control to continue sleeping with the governments or reach ultimate user surveillance with the upcoming children ident.
- unknownfuture 3mo ago> 1) side loading or however it's called is used less than 1-2% of global Android users (they can't be more than 50million). Google made us a favor leaving it open after an only 24h delay. It could be much worsa and is nothing in our eternal tinkering with developer options. Thank you from me Google It's wild how far we've come, from IBM trying to lock down the PC to truly open hardware, to you now thanking Google for only mostly restricting what you can do with a device that you bought and own... The rest of your content is just other forms of Google apologia. This is honestly deeply disheartening... And on "hacker" news of all places...
- tsoukase 3mo agoI don't distinguish a phone from other electronic home devices I also happen to buy. I don't change their firmware for various reasons, like not worth it (eg fridge, washing machine), illegal (eg set top box or car) or impossible. Being able to even enable developer mode in Android and do anything more than designed for a regular user goes already too far in relation to the other devices. Is there any car that you can boost with tapping seven times its gas tank cap? And I am afraid it will be removed someday in the future like the bootloaders became locked one after another. PCs are another story, an open remnant from the past, that the hard and soft tech companies sweared not to leave happen the same mistake again with phones. The term "buy" and it's rights are not inherited from a PC to a phone. I am not an advocate for the greedy tech companies but I am trying to give some rational perspective of the balance of power between them and us. If we want openness we cannot reach it with wishful saying.
- fithisux 3mo agoVote more carefully.
- tomdow 3mo ago[flagged]
- tomiow 3mo ago[flagged]
- tomkow 3mo ago[flagged]
- tomjow 3mo ago[flagged]
- tom1ow 3mo ago[flagged]
- br0ceph 2mo ago@grapheneos Can the upcoming motorola phone have a microsd or somekind of removeable/expandeable mass storage? One of the most annoying things on modern phones, and all the pixels, is the lack of storage expansion. Its a constant battle to maintain free space on the device. Remote storage is largely useless to me due to datacaps and slow service. MicroSD slot and some kind of automatic but secure removeable disk encryption would be very desireable to me. Obv theres a threat vector here, so id appreciate a hardware/software solution that mitigates this. Maybe requiring user confirmation before any hardware pins are active, and some kind of removal/tamper/evilmaid detection. Also easy servicing hardware issues like a bad battery