16 ms·
Google I/O 2021 and Uncomfortable Questions
- williesleg 5y agoGoogle has achieved their goal, world domination
- kwyjobojoe 5y agoGiven that Google has a history of accidentally breaking things in YouTube that only impacts Firefox, I'm 100% certain they can be trusted to muck around in apps written by others. Think of the opportunities. Next time Google releases a new social media system they can automatically add it into every existing Android app as a login option! Google dropping their payment system again? Not a problem, they can just change everyone's billing code. Or when they do the monthly random feature deprecation on Google cloud they can just modify any code that accessed it, across all apps! Why bother testing when your app code could be changed at any time by Google. The time and cost savings will be massive.
- square_usual 5y ago> Given that Google has a history of accidentally breaking things in YouTube that only impacts Firefox For those not in the loop about this: https://archive.is/ODWrQ https://archive.is/ODWrQ
- loosetypes 5y agoIdk sometimes seems like YouTube’s just been breaking YouTube lately, even outside of Firefox. I think they must have recently changed playback sync to be cloud-first, as jumping back 10s in a video has recently been badly glitching for me both in Chrome and on the iPad app. Often jumps back 20 mins to the start of a video, or where a prior session’s playback had been saved, thereby losing progress you’d made. Not the end of the world but frustrating when you’re watching a lecture and want to catch a detail you just missed. Really breaks continuity. I’m sure maybe it consolidates implementation making each client simpler and probably satisfies a couple buzzword checkboxes from the business side but why would I possibly trust picking up playback across devices when I can’t trust it on one?
- jrockway 5y agoWhy do I care? Google can already modify the behavior of an app without the developer's permission; they can just push an update to Android that changes the behavior of that app. It's "reflections on trusting trust" all over again.
- Aeolun 5y agoMy android updates do not come directly from Google, but instead my mobile provider. Google has no control over them, but they have direct control over the play store.
- pas 5y agoGoogle controls the "Google Play Services" app. It's privileged, it can do anything.
- fragileone 5y agoAn OTA Android update which modifies your apps would make it incompatible when those apps try to update themselves at a later point and find different signed apps. This would out Google as hostile immediately since there would be no other party who could feasibly swap out your apps. Whilst not preventative, even one attack would likely get enough media coverage it'd destroy Android by Google trust irreversibly.
- corty 5y agoGoogle Playstore is a walled garden, like Apple's. The walls are only growing higher and higher. Once Apple adds a layer of bricks, Google follows and vice versa.
- encryptluks2 5y agoThey are very different. Google provides open source alternatives. On Linux I can use Chromium. On my Android I can install F-Droid, or just install APKs manually.
- tehlike 5y agoBut you cannot do unattended updates through fdroid.
- enriquto 5y agosounds like a good feature to me
- Krssst 5y agoIf you want to update all your F-Droid apps at once on a non-rooted Android, you need to go through all of them one by one. Basically: click upgrade, click "Install", wait for Android to do its stuff, do the same for the next app. It is extremely impractical and most of the apps I installed from F-Droid are severely out of date because of this Android restriction. Fortunately F-Droid has an "Upgrade all" button which will download all the APKs in the background, but the click&wait loop sequence cannot be avoided.
- encryptluks2 5y agoNot that this is perfect either but if you know how to grab the APKs and developer mode is enabled, you can script the installs using adb from a computer. I agree there is room for improvement to help make this process more seamless, but it still much more flexible than what is being offered by Apple.
- _hyn3 5y agotldr: Google's new app bundle signing might be a precursor (well, almost certainly is) to Google's being able to replace parts of and modify your app on the fly when installed by certain targeted users or within certain targeted countries at Google's whim, with users being none the wiser. Google might do this for a lot of reasons, and none of them seem to be good. FWIW, Google promises not to change the functionality of your apps. Finally, it appears to be the intention that this will justify setting a new norm and become mandatory for all apps.
- jayd16 5y agoThey probably just want to be able to patch in OS api compatibility shims so they can make faster changes. For app bundles they want to be able to remove unneeded assets and make device specific builds. Think high dpi only. I think ios has a similar feature called app thinning.
- pmoriarty 5y agoWouldn't a simple solution to this be a double signing of one and the same app by both Google and the app's author? That way, if Google changes the app and signs it, while the author only signed the unchanged app, then the author's signature would no longer validate on the new, changed app. Or am I missing something?
- jayd16 5y agoWhat would be the point if Google's signature would still validate. If an author wants to share an app with a different signature outside the appstore they can.
- Godel_unicode 5y agoYou're not, this is absolutely the correct solution. There's no reason it needs to be either/or.
- teraflop 5y agoThe whole point of this feature is to allow Google to modify the APK by stripping out unneeded resources to reduce file size. If you require both a signature from Google and a signature from the developer, the modified versions would not pass validation. The issue is that this inherently requires users and developers to trust Google to only make innocuous changes.
- est31 5y agoApp bundles allow smaller apk sizes [0]: > Google Play uses your app bundle to generate and serve optimized APKs for each device configuration, so only the code and resources that are needed for a specific device are downloaded to run your app. You no longer have to build, sign, and manage multiple APKs to optimize support for different devices, and users get smaller, more-optimized downloads. But as all this logic sits on Google servers and might involve lots of signing of apks for a single app and version, Google has decided it needs your signing keys for that feature. Which is weird already because you could also think of a model where you provide Google not with the keys but a service where Google presents you an apk, and you sign it. Then you can inspect it retroactively and run scanners on it, if you want to. The keys stay yours and you would know what Google is up to with your application. If you have problems with giving Google your signing keys, you can just avoid this feature. But apparently there is the fear that Google wants to make the feature required. Which would give them ability to alter basically any app on the play store as they deem fit. Or they might in fact be forced by governments. Already now many providers like facebook take down public posts because a local government disliked a post. What if a govt told Google "please install this altered Signal app on this person's device"? And yes, Google apps already run as system app so they could already do something like that, but an implementation of that is way harder to make consistent among different vendors. [0]: https://developer.android.com/guide/app-bundle https://developer.android.com/guide/app-bundle
- nodamage 5y ago> Which would give them ability to alter basically any app on the play store as they deem fit. Google already controls the operating system, the Play Store, and the SDKs you used to develop your app in the first place. If they wanted to alter your app there is already ample opportunity to do so, what additional trust do you gain by managing your own signing key here?
- prepend 5y agoIsn’t it simply that any changes by Google would clearly not match the developer’s signature so are evident when they are different?
- JollyMerchant 5y agoApple and Google, the Rockefeller and Standard Oil of our era.
- HDMI_Cable 5y agoI don’t want to be pedantic, but it would be more apt to say: “Apple and Google, the US Steel and Standard Oil of our era” since Apple doesn’t own Google.
- kjeetgill 5y agoIn response to a now deleted comment about if they constitute monopolies: Hm, I'm sympathetic to where people are coming from. Treating Apple Apps as a distinct market from Android Apps doesn't feel technically true, but I think it's more then true enough. More generally I think people have a sense of what fair play is and how large companies shouldn't be as free to throw their weight around, laws be dammed. And that whole feeling gets lumped under monopoly.
- andrekandre 5y agoi think the word people are maybe looking for is oligopoly...
- colineartheta 5y agoCarnegie and Rockefeller might be more apt.
- holoduke 5y agoEvery small step Google takes is a good thing for the mass consumer 99% of the people, but much worse for the content creator. Google is slowly destroying itself.
- chiefalchemist 5y agoI recently finished the book "The Age of Surveillance Capitalism." If you *really* want to understand Google - the real Google, not the PR spun version - then this book is a must read. https://www.wnycstudios.org/podcasts/otm/segments/living-under-surveillance-capitalism-on-the-media https://www.wnycstudios.org/podcasts/otm/segments/living-und...
- rektide 5y agofour days ago I commented on a thread about Google & Apple app store domineering by saying that Google seemed at least to be building an alternative-ok os, where players like f-droid could work on almost all devices[1]. really really hoping we are not entering some new capitalist platform control hell, like this article seems to be indicating. [1] https://news.ycombinator.com/item?id=26965298 https://news.ycombinator.com/item?id=26965298
- SimeVidas 5y agoWeb apps have become so powerful on Android lately. What good reasons are there to still go native today?
- EvilEy3 5y ago> What good reasons are there to still go native today? Providing native experience instead of wrapped website.
- SimeVidas 5y agoYou’re an idiot.
- dang 5y agoWhoa, you can't do this here and we ban accounts that do. No more of this, please. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- SimeVidas 5y ago> Don't be snarky. > Eschew flamebait. > don't post shallow dismissals Will you also ban the other person for being snarky and all the other things I quoted? If yes, then I’m fine with a dual ban.
- dang 5y agoFirst, I'm not banning anyone, I'm saying that we ban accounts that do this kind of thing repeatedly, so please don't. Second, I don't see that https://news.ycombinator.com/item?id=27013656 https://news.ycombinator.com/item?id=27013656 was snarky or did those other things. Third, it's distasteful to point the finger at the other person instead of simply taking responsibility for your actions. Why not just use HN as intended? If another commenter is wrong or you feel they are, the way to respond is with correct information, neutrally and respectfully. If you don't want to do that, not responding at all is the other good option. To a first approximation, the internet is wrong about everything anyhow, so for sanity's sake we all need to learn how to let go. Believe me, I know that's not easy, but it's what we all have to do if we want a forum that doesn't suck.
- bsaul 5y agocould anyone explain if this is different from what apple is already doing on the app store ?
- mcintyre1994 5y agoThe article linked from this one is worth a read: https://commonsware.com/blog/2020/09/23/uncomfortable-questions-app-signing.html https://commonsware.com/blog/2020/09/23/uncomfortable-questi... They claim that because Google strips the developer signature and signs it themselves, they can modify the app and re-sign it. They suggest that an authoritarian regime could coerce Google into serving modified versions of eg. E2E encrypted messaging apps to people of that regime’s choice as a condition of doing business there. Does anyone know if the iOS App Store has the same vulnerability? I know that they do clever things like universal apps and App Clips, but I’m not sure if they achieve it by stripping developer signatures and re-signing. Alternatively, since all signing certificates must be issued by Apple could they technically re-sign any app anyway if they’re coerced into holding onto the private keys they issue? I’ve never written an app in their ecosystem so I’m not sure exactly how it works or if they have an opportunity to do that.
- iudqnolq 5y agoIt's silly, because if you control the OS you control the app. They can push an OS or trusted app update that reads/writes the app's private data, or changes the shared libraries the app depends on, or with a little more work reads/writes the app's memory. Anyone claiming to provide protection from Google on a phone Google has remote root access to is selling a theatrical experience.
- thu2111 5y agoGoogle do not control the signing keys for Android for any phones other than their own Pixel line. So whilst true in theory, in practice the open source nature of Android with OEMs in the middle distributes the power around.
- iudqnolq 5y agoMy impression is to implement things like the Play Store, Google Play Services has effective root access. I can't find any great sources for that though.
- 2ion 5y agoIs it possible for the developer to just make detached signatures of compiled/assembled pieces of the app bundle, include it in the bundle, and then at runtime self-check and tell the user if the app is unmodified?