Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
NotPractical
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
121.
▲
by
NotPractical
2y ago
> you're allowed access to full Linux-land Yes, but there are strict SELinux policies forbidding you from accessing certain "dangerous" stuff like execve(), which may end up killing native terminal emulators like Termux (d
122.
▲
by
NotPractical
2y ago
FWIW GrapheneOS is rolling it out as well: https://grapheneos.social/@GrapheneOS/114132940314692519 Looks like the GrapheneOS implementation will be less restricted and will let you run operating systems other than Deb
123.
▲
by
NotPractical
2y ago
> If Apple let you run macOS from a tethered iPhone, it just might! Maybe that's why? It seems that people just aren't currently capable of fathoming the concept of "one device for everything". If Apple did it though,
124.
▲
by
NotPractical
2y ago
You might be able to turn off developer mode once it's enabled, maybe? Anyway, apps have literally no reason to query the status of developer mode and should not be allowed to do so. I don't think apps should be able to query the
125.
▲
by
NotPractical
2y ago
> despite app authors worst intentions All app authors must comply with the rigorous App Store guidelines so the technical limitations on what they can do don't really matter anyway. Add sideloading as an option and we'll get t
126.
▲
by
NotPractical
2y ago
One important thing to note that isn't mentioned in the article: you have to manually add the porn app's source URL to the AltStore before it'll show up there. Because you have to browse to the (adult) porn app website in Saf
127.
▲
by
NotPractical
2y ago
They had a much more convincing argument before the Play Store started forcing the same exact thing that they said was one of the main problems with F-Droid, and F-Droid started providing reproducible builds.
128.
▲
by
NotPractical
2y ago
> The whole “choice” process is a farce in the EU. What do you suggest? Forcing people to use DuckDuckGo against their will?
129.
▲
by
NotPractical
2y ago
Apple donated $1 million to Trump. So did all the other big tech CEOs, who were also invited as distinguished guests to his inauguration. Conservatives like Trump generally favor big business and deregulation. Your faith in Trump doing anyt
130.
▲
by
NotPractical
2y ago
I should clarify that it isn't my area of expertise either; if you already found something in the kernel, by all means, keep looking there! I was more trying to suggest a starting place but it seems you're past that point already,
131.
▲
by
NotPractical
2y ago
I don't imagine something like this would be implemented in the kernel? Might help to search system apps/binaries for the string displayed in the notification alert: https://raw.githubusercontent.com/nathan-contino
132.
▲
by
NotPractical
2y ago
If you're reversing this: I was curious if Google determines if your device is "affected" using the phone's serial, or the battery's serial. I've seen reports that people who replace the battery manually outsid
133.
▲
by
NotPractical
2y ago
If you prefer reading over watching (thanks @MaximilianEmel): https://wiki.rossmanngroup.com/wiki/Pixel_4a_Battery_Perform...
134.
▲
by
NotPractical
2y ago
xattrs are great, and would the obvious solution for tags/metadata on Linux too, if the syscall API didn't delete them at every opportunity; programs must be explicitly told not to do that. https://wiki.archlinux.org&#x
135.
▲
by
NotPractical
2y ago
Android will block any update to an existing app that wasn't signed with the same signature. The benefit of using the developer's signature (even if the app is built by F-Droid) is that the F-Droid release of the app is not treate
136.
▲
by
NotPractical
2y ago
From what I can understand the attack scenario is as follows: 1. User downloads an app from F-Droid that supports reproducible builds. 2. The developer's account is compromised and submits an app with a different-than-expected signing
137.
▲
by
NotPractical
2y ago
Thanks for clearing that up. I should've read your post more closely. To be honest I never checked the second link because I follow the Android privacy/security scene pretty closely and I was already pretty confident that if Dives
138.
▲
by
NotPractical
2y ago
> to provide a trusted boot chain the way Apple does Your flaw is assuming that Apple's only doing that for your security and has no ulterior motives. But iOS apps are disabled and Netflix reduces to a lower resolution when you disa
139.
▲
by
NotPractical
2y ago
I probably wouldn't use an alternative launcher with those caveats attached. It seems the awkward animation thing may be a consequence of an Android security feature: > Why is the recent screen buggy? > Unfortunately, it is becau
140.
▲
by
NotPractical
2y ago
They didn't have a microG implementation from what I can tell. From your first link: > DivestOS will not include microG or the GrapheneOS' Play Services sandbox.
141.
▲
by
NotPractical
2y ago
The main advantages these days are reducing reliance on Google [1], supporting open-source software, and extra security/privacy protections. Probably true that the average poweruser perceives less value from them than before. Some of t
142.
▲
by
NotPractical
2y ago
Is there still the issue of third party Android launchers being treated as second-class, not allowed access to features like gesture navigation? I haven't used one in a while.
143.
▲
by
NotPractical
2y ago
The App Store forbids any app that violates the terms of service of any company [1], regardless of the legality [2]. Since YouTube forbids alternative clients in their terms of service, Apple will not allow Grayjay onto the App Store. Even
144.
▲
by
NotPractical
2y ago
The best feature of alternative YT clients IMO is "multiple subscription lists". I have so many subscriptions, when using the official YouTube app or site the "subscriptions" feed is overwhelming, and I prefer not to use
145.
▲
by
NotPractical
2y ago
Microsoft actually reversed course on this. You can make a one-time purchase to access "developer mode" and then run whatever you want. It's been suggested that this is the reason there's been less interest in hacking
146.
▲
by
NotPractical
2y ago
> shall make available to a consumer, upon request Do those requests have to be submitted via a Google Android or Apple iOS app with remote attestation, or can we use a web browser?
147.
▲
by
NotPractical
2y ago
See also: EU Digital Markets Act: Litigation Against Apple https://news.ycombinator.com/item?id=41970854
148.
▲
by
NotPractical
2y ago
> Our dear friends at Free Software Foundation Europe (FSFE) have filed an important brief with the European Commission I think they used the wrong link here. They linked to a document submitted to the CJEU defending the European Commiss
149.
▲
by
NotPractical
2y ago
Is this legal case still ongoing? At first I was under the impression that this was about Apple's lackluster compliance with the DMA, but it looks like it might be about whether the DMA applies to Apple at all . [Edit] They submitted
150.
▲
by
NotPractical
2y ago
Those apps are deactivated after 7 days unless you pay for an Apple Developer subscription. There's the non-EU version of the AltStore which attempts to circumvent this restriction, but it's a dirty hack and I expect Apple to patc
More ›