Google promises verification will make Android safer, but at what cost?
mesa
link
fedilink
English
9610d

Why cant we be trusted with installing apps on our phones? Its my device, ill do what I want!

Its so dumb.

@[email protected]
link
fedilink
English
5210d

Just wait until they start pushing this with computers too. We have continually coddled normies by dumbing shit down instead of pushing them to be smarter. No doubt they’ll look at this as a good thing too.

Meh, Linux. There’s an alternative for those who want it, not a big deal. Smartphones, and most ARM devices are just weird to me. Device specific images, flashing, crap. Why can’t they just be PC-like?

@[email protected]
link
fedilink
English
610d

Arm is slowly advancing on pcs… We’ll have bootlocked pcs in no time

@[email protected]
link
fedilink
English
2110d

Once ARM on PC takes off it’s over.

@[email protected]
link
fedilink
English
8
edit-2
9d

There are plenty of ARM on PC examples and there will always be an alternative option that is open there. It’s too entrenched.

We need to free mobile devices with functional distros like mobian/postmarketos that are fully functional.

@[email protected]
link
fedilink
English
29d

Yes there are, 90% can’t run Linux. And PCs built to specificly run Linux will only be available to Western markets, everyone else will be stuck with whatever corpos put out because they will be excluded by the weak currencies they use and in some cases also by prohibitive import taxes.

Pycorax
link
fedilink
English
1310d

x86 is far too ingrained for that to happen. Even if it takes over on the consumer side of things, enterprise will still be stuck on x86 and you know how difficult it is to get them to change. The odds of it dying is exceedingly low.

@[email protected]
link
fedilink
English
89d

This is one reason why the changes to the boot process on X86 were a major concern, if machines only boot an an OS with a “trusted” signing keys then it is a pretty straight path to MS-only. Lack of published architecture assist gets here and there are X86 machines that will fail spectacularly on Linux due to this (weird EFI boot stuff, certain chipsets for such drivers can’t be had or made, etc). Hardware-level DRM is a major threat.

Then add in stuff like browser-based DRM. Oh cool, you can install whatever you want but this differently stuff will only play on Chrome with the DRM extension enabled, maybe sending CPUID info, and doing a bunch of other stuff for lock-in that makes the IE6+ActiveX/MS-JS pale in comparison

@[email protected]
link
fedilink
English
19d

Fuck those people we will just keep our own stuff and use it. This is one reason I have been hanging on to old hardware. I can still play games 20 years from now on my old PCs.

@[email protected]
link
fedilink
English
39d

I setup a mini PC that runs as a PXE server. Pretty much anything with an Ethernet port can boot from it and play a bunch of of classic games I’ve got on disc, plus some GoG titles etc. It’s awesome.

Projects like OpenSpy also make some of the old dead titles playable again

Pycorax
link
fedilink
English
19d

I’m assuming this is referring to prebuilts? I can’t imagine this to be the case for DIY set ups.

@[email protected]
link
fedilink
English
19d

It was everything for awhile, but the end architecture design did allow people to choose to not use secure-boot or to load their own keys on some boards. It did make some devices - mainly tabletized laptops - pretty much unusable for anything but the installed OS though.

Browser DRM though… That’s just getting started

This is why we still have 2G I heard. Telling regular customers to upgrade from 3G was easy. Like, what are they gonna do about it. But 2G is used by a lot of IoT devices, including gas and electric companies, and they’re not upgrading that easily while I assume generating a significant revenue.

Snot Flickerman
link
fedilink
English
3
edit-2
9d

What?

In the US at least, AT&T shut down 2G in 2017, Verizon in 2019, and T-Mobile started shutdown of 2G in 2022 but has it still hanging on but on it’s final way out by the end of this year likely.

Even for Europe, a lot of 2G shutdowns started in 2022, and most places in Europe will have 2G phased out by the end of this year.

I am talking about Slovakia. That’s just what I remember seeing. Currently only Orange plans 2G shutdown, and that is for 2028.

From the public documents I could find, it seems 2G is going to be mandatory until 31.12.2028, however only Orange has said something about its shutdown publicly so far.

@[email protected]
link
fedilink
English
510d

We then have RISC-V computer by Pine64 running Libre-ICEBlock

@[email protected]
link
fedilink
English
29d

I don’t believe those will be accessible for people outside of Western markets.

@[email protected]
link
fedilink
English
1
edit-2
9d

Unless the arriving country’s customs decide to inspect it and seize it. You should be able to buy it anywhere.

@[email protected]
link
fedilink
English
1
edit-2
9d

In theory yes, in practice there is also the matter of your currency’s buying power and import taxes. I would know, when PinePhone was first coming out I looked into it to see if I could get one. And yes I could, except it would come at the price of an iPhone. The tax and IMEI unlocking fee quadrupled the price.

It would be less bad with laptop or desktop since there is no IMEI fee, and there are some workarounds you can employ but it’s still a pain.

MoreZombies
link
fedilink
English
27d

From what I understand that is why Valve started working on their own operating system and hardware.

@[email protected]
link
fedilink
English
39d

Thank god we have Linux. Let’s just hope Linux becomes viable for phone as well

sunzu2
link
fedilink
3910d

Its so dumb.

It is not dumb, it is a smart business move that can only be made by a monopoly.

They literally just settled with FTC and now they got blank check to fuck the plebs.

It will get so much worse.

BurgerBaron
link
fedilink
English
27
edit-2
10d

All the “Western” Empires are in decline. A lot of Europe, Australia, Canada, USA are all doing this shit at the same time clearly in cooperation with one another for anti privacy.

The corporations meanwhile want their increasingly walled in gardens and diseased governments won’t stop them as long as they get their back doors and data mines.

edit:

Reminded me of something. I was watching one of the few FuriOS reviews on YouTube, and the guy happened to be Australian. He took a moment to mention that he couldn’t use the phone at all on specific mobile service providers because they only allowed white-listed pre-approved hardware.

That’s pretty sickening.

@[email protected]
link
fedilink
English
510d

All the “Western” Empires are in decline.

Its why I’m slowly losing my will to live.

@[email protected]
link
fedilink
English
210d

and one country stands to benefit from this, and likely is behind the sudden all these countries doing it.

@[email protected]
link
fedilink
English
310d

Not only that, I got the newest android update yesterday and it automatically, without my consent, took my fingerprint and face

@[email protected]
link
fedilink
English
410d

What the fuck?

@[email protected]
link
fedilink
English
410d

Right? I put in a complaint from the system feedback tool, but I don’t expect a response. Between the way Google is roping off Android and killing dependent open source OS’s, and my relative lack of money, I’m only seeing privacy options dwindle

katy ✨
link
fedilink
English
23
edit-2
10d

i hope this shit gets hacked and cracked to allow the install of any apk so quickly.

guess i aint upgrading anymore. congrats google you made your own os less safe

@[email protected]
link
fedilink
English
810d

also remove com.wssyncmldm to forcibly prevent your phone from updating

CAREFUL: when you reset, android updates itself to the newest version.

guess i aint upgrading anymore.

Oh, no, this will be pushed to devices. Ever seen the “your device has new features”?

@[email protected]
link
fedilink
English
1010d

😁

masterofn001
link
fedilink
English
49d

This won’t stop anything

I still use a phone that hasn’t received ota security or play security updates in 4 years.

Yet, they still installed - without notice or consent - safety core (to rescue me from naughty text messages) to scan my images.

Funny how they can rapeload apps onto my devices without my consent that work on 3 generations old hardware/os but they can’t update the security and they want everyone else to register to be able to provide foss apps to people for free.

RVGamer06
link
fedilink
English
3
edit-2
9d

rapeload c/brandnewsentence

Eager Eagle
link
fedilink
English
35
edit-2
10d

if only…

As part of this so-called improved verification, Google should also be held liable for any damages caused by malicious applications.

but no, regulators won’t do shit and they’ll have the cake and eat it too

governments are becoming the puppets of big tech, in 50 years we’ll have night city IRL

@[email protected]
link
fedilink
English
210d

Snow Crash’s world is here…

🔰Hurling⚜️Durling🔱
link
fedilink
English
26
edit-2
9d

Fuck off Google, now we need degoogled phones more than ever.

*Sent from my cheap as fuck pixel 8a running graphene os

Edit: ducking autocorrect you ducking duck

Mike D
link
fedilink
English
6110d

When it announced developer verification, it said the process would not evaluate the content of an app.

Ok, sure. The ICE Block app Google just pulled from Play Store will not be evaluated.

sunzu2
link
fedilink
1910d

This is a great example why google control is a bad idea… you can’t trust these bootlickers with anything, they are an extension of the ruling oligarchy which controls the corporation directly and the government organs via corruption.

This is a class war, and plebs are way behind.

@[email protected]
link
fedilink
English
310d

you mean Apple? the app was exclusively on iOS. it was a doxxing target from the get-go ran by an amateur that ran his database with unfixed vulnerabilities

@[email protected]
link
fedilink
English
-210d

sounds like it was garbage. IRL ice watch volunteers use Signal or Whatsapp

@[email protected]
link
fedilink
English
1010d

I’m sure that’s another well researched comment.

@[email protected]
link
fedilink
English
-410d

these apps are slop generating machines. the equivalent of relying on Nextdoor to keep your community safe. I’m waiting for any journalism or research papers to come out proving they didn’t just make the situation worse

@[email protected]
link
fedilink
English
2910d

$25? lol no, my next phone fill be either Linux or a flip phone.

@[email protected]
link
fedilink
English
4
edit-2
10d

I have 2 cheap options I could recommend for Custom ROMS:

  1. Moto G 5G 2024 $140 runs Lineage OS (I have this)
  2. CMF Phone 1 $290 runs e/OS, has OLED display, overall a better phone than the cheap moto.

I’m not sure about “Linux” atm, there are still more apps for Custom Roms than you’d find for Linux that’s optimized for mobile use.

@[email protected]
link
fedilink
English
4610d

Paid or free, All I know is that I won’t be buying any device i can’t install my own apps on.

Max-P
link
fedilink
English
5610d

That also means they now will know about every app installs, worldwide. So when the government comes in and ask who have installed this app they decided is bad, they can come get you.

Signal, VPNs, they’ll have a list of everyone opting out of government-mandated backdoors.

LineageOS so worth losing Play Integrity.

@[email protected]
link
fedilink
English
19d

Is there a guide to get lineage on my galaxy s24? Or something else?

Stez
link
fedilink
English
39d

Yeah download.lineageos.org but I don’t think the s24 is supported.

@[email protected]
link
fedilink
English
49d

Lame. Thanks for the guide though!

Stez
link
fedilink
English
19d

Yeah generally Samsung devices are not very well supported by the custom rom community since they are extremely locked down and are hard to get drivers for and soon with one ui 8 won’t even be able to unlock their bootloaders

@[email protected]
link
fedilink
English
6
edit-2
9d

That also means they now will know about every app installs, worldwide.

Wait, how? Also, don’t they already?

Max-P
link
fedilink
English
49d

Apps from outside the Play Store? No, because previously your phone had no reason to ask Google anything. You could always not sign in to Google and disable Play Protect and use F-Droid and Obtainium.

But now, it needs to check developer signatures to know if it’s a verified developer, and it obviously can’t cache all of them as the size would be insane.

And that in turn implies that your phone needs to reach out to Google and be like yo, is this app banned?

That query gives them at minimum the IP of the user, the package name, and the time at which it happened.

And thus they can effectively track anyone using say, privacy apps, making it that much riskier to use them in places where they’re not allowed.

For your “safety”.

@[email protected]
link
fedilink
English
5
edit-2
9d

Apps from outside the Play Store? No, because previously your phone had no reason to ask Google anything.

Play store seems to be sending list of all applications to ask for available updates. This is observable because play store offers me updates for apps I installed via f-droid and obtanium.

But now, it needs to check developer signatures to know if it’s a verified developer, and it obviously can’t cache all of them as the size would be insane.

Not how signatures usually work. You check the signing key (certificate) is signed by google key and you fetch a revocation list (banned developers). Of course, google could implement it in the way you suggest in theory, but I find it unlikely, since it would block offline installation for no reason.

Max-P
link
fedilink
English
49d

They said it would require network access and that they would have a handful of popular apps preloaded to avoid too much disruption so those can be installed offline. In practice that probably means Google apps, Meta apps and other big corp apps.

They also have you register package names with them, not just a certificate.

I was hoping it would be a certificate situation but we’re kind of past Google using the least intrusive and privacy preserving options.

@[email protected]
link
fedilink
English
2
edit-2
9d

I must have missed that. Well, there goes any possible excuse about security, since they are going out of their way to make it less privacy preserving…

HexesofVexes
link
fedilink
English
9610d

"Google, however, has decided anonymity is too risky. "

The rest of the sane universe appear to be deciding Google is too risky.

Kairos
link
fedilink
English
4410d

The cognitive dissonance with saying that the current state of Android is “too risky” without giving a single example of why it supposedly is.

@[email protected]
link
fedilink
English
410d

Sorry for knitpicking, but saying “the rest of the sane world” implies Google is also sane.

HexesofVexes
link
fedilink
English
410d

Sane => Worry Google is a threat

Worry Google is a threat =/> Sane

@[email protected]
link
fedilink
English
2410d

Can’t install apps offline on my own phone 🤯

NeilBrü
link
fedilink
English
1610d

Linux Phone it is.

Einar
link
fedilink
English
410d

If truly wish that were the way forward.

As it stands, name a good one that works with current apps and isn’t a battery hog. 🤷‍♂️

@[email protected]
link
fedilink
English
29d

This seems to be the closest

https://furilabs.com/

Einar
link
fedilink
English
17d

Thanks. It looks like a start, an enthusiast’s phone.

For now. Here is a review.

It clearly needs development. But it has the potential for greatness. Banking apps really need to work, for example (as much as I hate banks relying on phone 2FA or some banks only having an app apart from a feeble website).

@[email protected]
link
fedilink
English
17d

Amost all banking apps are moving towards using the secure android layer which means they will never work on something that can’t fully emulate that. Even in things like grapheneos with gapps installed in a profile they sometimes don’t work. If banking apps are what you are waiting for that is already very hard and will only become less likely to work over time.

Einar
link
fedilink
English
1
edit-2
7d

Pretty much everyone, or at least many people, will need this eventually (although it is likely shortsighted of banks to lock into a system provided by one or two companies HQ’d in the same country).

So I hope a solution will be found. But this is just one of the issues why a Linux phone isn’t quite there yet. At least not for me. Wish it were.

@[email protected]
link
fedilink
English
3110d

They should rebrand it to aOS since it’s quickly becoming just as shit trash as iOS. I wonder how many people will jump ship to iOS where they still get a shitty OS but with some modicum of privacy OOTB as an added bonus

My next phone is going to be as basic as possible and I’ll have to start carrying a laptop with me everywhere again.

@[email protected]
link
fedilink
English
1110d

A lot already have actually, writing was on the wall back when they dropped the version names which was also around the time a lot of the original Android hardware OEMs gave in which left us with carriers giving you the option between Samsung, Google, and Motorola.

Then they abused Trump’s first term to ban Huawei for spyware since it was competing too well.

The frontend UI sucks, the backend ART sucks, the process pausing system can’t hold most of your app views because reasons, Samsung removed OEM unlocking, Google has a stranglehold on decade old RCS with only google messages supporting such a protocol (wtf???), AOSP is functionally dead, Gapps has been eating the left side of your homepage for years, etc etc.

I’m thinking about getting some handheld and making it into a PDA, like those upcoming DS-like consoles, and then maybe just get a pocket modem for phone/internet.

Avid Amoeba
link
fedilink
English
2410d

This is so fucking bad.

@[email protected]
link
fedilink
English
31
edit-2
9d

The point of this is to break Fdroid, as the point of removing device tree publishing from their phones was to remove third party ROMs that would ignore the requirement for verification, as well as the changes to AOSP updates. This is a war on users that want to keep control of their phones and when it’s done, you will not be able to escape the enshittification and surveillance. And I’m convinced that was the price they paid to get out of the FTC lawsuit.

Einar
link
fedilink
English
2510d

Just when I thought that I cannot possibly hate Google even more, I see D. Veloper.

Create a post

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It’s fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

[email protected]


  • 1 user online
  • 15 users / day
  • 102 users / week
  • 370 users / month
  • 1.5K users / 6 months
  • 1 subscriber
  • 2.12K Posts
  • 38K Comments
  • Modlog