11 ms·
My Android phone prevents me from taking screenshots if an app author doesn't want me to. My Android phone prevents me from recording phone calls at the reques
by jeffparsons 1y ago
My Android phone prevents me from taking screenshots if an app author doesn't want me to.
My Android phone prevents me from recording phone calls at the request of my carrier, even though it's totally legal for me to do so in my jurisdiction.
I'm not loving where this is all going.
- craftkiller 1y ago< recording phone calls FWIW the default phone app on GrapheneOS supports recording phone calls.
- 7e 1y agoDid a nation state ask GrapheneOS to add that feature?
- zamadatix 1y agoWhy is it always "nation state" when this is brought up, do states and nations that aren't congruous not represent a perceived threat?
- floren 1y ago"nation state" has a particular meaning and it's not just "a smart-sounding way to say country" but it tends to get used that way.
- tsimionescu 1y agoIt does have a particular meaning, but it is one that's not relevant in this context, and it's probably narrower than what the poster intended. For example, Belgium is not a nation state, but I'm sure the GGP would be surprised by an answer like "no, it wasn't a nation state, Belgium asked them to do it".
- metabagel 1y agoTIL
- meiuqer 1y agoWhat do you mean by 'Belgium is not a nation state', if i may ask?
- tmtvl 1y agoBelgium may be used as a stand-in for Brussels, i.e. the European Union.
- e-v 1y agoI think the author of the post was referring to the fact that Belgium is a multinational state, comprised of Dutch-speaking Flanders and French-speaking Wallonia.
- stonogo 1y agoBut it isn't, here. The state of Belgium created itself by secession from the United Kingdom of the Netherlands, and its populace generally comprises two nations, Flanders (Flemish) and Wallonia (French), neither of which are continguous with the state, nor particularly interested in sharing a national identity with each other. In short, a state is about turf, and a nation is a people, and you need them both to look similar on a map to make a nation-state.
- rkomorn 1y agoI've heard Brussels as a stand-in for the EU. I've never heard Belgium as a stand-in-for-Brussels-as-a-stand-in for EU.
- bonoboTP 1y agoThey probably mean that Belgium consists of French-speaking and Dutch-speaking (and German-speaking) groups, which the person counts as separate nations, hence Belgium not being one nation. This is mostly a language confusion for non-native English speakers. Nation, country, state, a people, nationality, ethnicity, citizenship etc. are used in confusing ways for speakers of other languages. For many, "nation state" just means an independent state (roughly speaking, a UN member, note also that the UN is called United Nations), because just saying "state" could mean a subdivision, such as a US state. And "country" can be confused with the subdivision of the UK (they call, e.g. Scotland a "country"). In more precise contexts of political history, "nation state" mostly refers to modern (post-World War I) countries that more or less correspond to a people speaking the same language and having the same ethnic identity. It delineates nation states from the previously more common multi-ethnic empires and kingdoms, such as Austria-Hungary or the Holy Roman Empire etc. Similarly, in English, nationality is often an exact synonym for citizenship, while speakers of other languages expect it to mean ethnicity, e.g. an ethnic Hungarian in Romania with Romanian citizenship would be considered a "Romanian national" in English-language news. This often makes people confused/angry. Also, in some contexts in English, "ethnicity" is more like a euphemism for something like "race", but not quite (e.g. in the US "Latino" is considered an "ethnicity" but not a race). In that sense "Hungarian" would not count as an "ethnicity" at all, but still phrases like "ethnic Slovak" refer to a minority group in a different country than Slovakia. But also "ethnic" can also just mean with "exotic foreign origin", e.g. "ethnic food" or "an ethnic woman" (this was really weird when I first read it). But I digress.
- pasc1878 1y agoWhy? I would very much like to record phone calls made by me. When the company on the other end denies what we agreed a recording would be useful.
- _heimdall 1y agoOnly your carrier is supposed to record the calls. Edit: apparently the /s is obligatory on this one
- Maskawanian 1y agoAbsolute lies, where I live it is one party consent. I can still record with another device on speakerphone.
- jeffparsons 1y agoI think the person you were replying to might have intended sarcasm.
- _heimdall 1y agoYes this was sarcastic, I should have put a /s I also live in a one party consent state.
- m463 1y agoiphone now allows phone call recording. I don't know if it is geolocked somehow, I wouldn't be surprised if it was. for example, Japanese iphones always make a shutter sound in japan or in airplane mode There is a waveform thing in the corner you can press during a call. It will say "this call is being recorded" and waits 5 seconds, then records the call. strangely... the recording doesn't end up in voice memos, it ends up in notes.
- hypeatei 1y ago> prevents me from taking screenshots if an app author doesn't want me to The most frustrating part about this "feature" is that you don't know it's enabled until the screenshot is taken and you're left with a picture of nothing. That and some app authors thinking they're protecting you with this (referring to banking apps in particular)
- nerdponx 1y agoPretty sure Twitch on iOS does this now. Screen recording still works though.
- nine_k 1y agoNow consider the fact that an arbitrary other app can take a screenshot clandestinely, via API. Would you like it to happen when you're looking at the summary of your accounts? your list of credit card numbers? The problem is that certain actions should only be acceptable if initiated by the user, physically. Think of the way Ctrl+Alt+Del works in Windows. This, of course, is not possible if you don't have enough fingers for the action, or something; here comes the loophole of assistive technologies, widely (ab)used for that on most platforms.
- wiseowise 1y agoThat’s why taking screenshots should be a runtime permission thing.
- Foobar8568 1y agoI want to send my new IBAN to my company, I can, no screenshot allowed on the screen with banking information. So I need to log on their website to do it. At least my new bank allows such screenshot and to copy account information directly from the app.
- akomtu 1y agoTwo mirrors will make it allowed.
- 1y ago
- dsp_person 1y agoI think this might be a longstanding "bug", but I have also not had any luck on my android using the screen recorder to record device audio from a browser (either chromium or firefox). It used to partially work using the mic to record the speakers, but currently it sounds like it does processing to subtract away the original signal; I hear mostly silence with occasional garbled artifacts resembling the original audio.
- tsimionescu 1y agoMaybe this depends on the site? I have definitely recorded video with audio off YouTube and other popular video sites, on a stock Samsung phone, even yesterday.
- emporas 1y agoThe issue is bigger than that. Why not two people share a device, and when passed from one person to another, delete applications and install all apps and profiles from scratch using verified checksums saved on a blockchain. An OS which could do that is something like Nix. When passed to the previous person same thing, delete and install everything from scratch. Using smartphones in a smart way, not a dumb way, like timesharing mainframes of the past. Same procedure could be applied to cars and other devices.
- nine_k 1y agoThis assumes that these two persons will never need to use a smartphone at the same moment, which is a bit of a logistical puzzle. Installing apps is the trivial part; isolating, or removing / reinstalling user data is much harder. Especially a few gigabytes of it. An SD card could work maybe. This all goes against the grain of the smarthpone UX, the idea of a highly personal device that you can use for anything, and might need (or benefit from) at an arbitrary moment. If the point is reducing e-waste, the solution would rather be opening up the hardware enough to provide long-term software support, LineageOS-style.
- emporas 1y ago> This assumes that these two persons will never need to use a smartphone at the same moment, which is a bit of a logistical puzzle. In general no one wants to share anything with anyone, but when two people cannot afford a device individually, but it is within reach when they buy it together, time-sharing becomes a totally acceptable solution. > Installing apps is the trivial part; isolating, or removing / reinstalling user data is much harder. An SD card could work maybe. Checksums might overlap by quite a bit. No need to remove programs installed by both users. If the total installation of each user is 10 GB, but the installation diverges 300MB only, not a big deal in most cases.
- ohdeargodno 1y ago[dead]
- rerdavies 1y ago
- ulrikrasmussen 1y agoMy government (Denmark) refusing to let me use their digital identity app because I don't want to accept Google's or Apple's TOS, and Google helping them enforce that via remote attestation services. Luckily there are alternatives in the form of code displays and NFC chips. However, next year I won't be able to watch porn unless I verify my age using a smartphone, no alternatives are planned. Or rather, I have the "free choice" to choose between a privacy preserving ZKP solution operating in the kingdom of Google or uploading my face to a porn site. Dark times.
- throw83834948 1y agoDuring covid I was not allowed to leave house. Permits were only issued to local SIMs, which I did not had! If I respected the rules, I would starve to death!
- EEBio 1y agoI assume you’re talking about another country, because in Denmark there was no general curfew under Covid (attendance to events might have required proof of negative COVID test or vaccination, but shops never did).
- dennis_jeeves2 1y ago>If I respected the rules, I would starve to death! respecting rules is more important that saving your life. /s
- nicman23 1y agoroute everything through a vps?
- Aerroon 1y agoIt's a temporary solution though. It's only going to get more draconian. Next thing you know the talk is about punishing VPN users, because now they can be painted as evading the law.
- socalgal2 1y agoIt's not just phones. Try asking ChatGPT/Gemini anything the hive mind in SV doesn't want you to ask. Try asking it anything the hive mind as decided has only one possible answer. It's only going to get worse
- jbstack 1y agoAt least with LLMs you have more options (Deepseek, Grok, offline models, etc.). It's still far from perfect, but it's not as bad as phones where you basically only have a choice of Android or iPhone if you don't want to have to live with major inconvenience (such as being unable to do online banking or pay for parking). It's also a lot easier to launch a competitor in the AI market: you just need capital. With phone OS's it's essentially impossible. The barriers to entry are too high.
- fragmede 1y ago> you just need capital The capital itself isn't going to do anything sitting in the bank. It's used to procure a team of PhDs, an team of SWEs, DevOps, business people, HR, marketing, access to a GPU supercomputer (renting a couple of 5090s off Vast.ai ain't gonna cut it). For, say, $50 million, you could get the blueprints to an Android phone and port your choice of Linux userland and get drivers working, and then do a run of 20,000, sell them for $1100. Compared to training GPT5, $50 million is cheap. If we use an estimate of $1 billion for the whole thing, making a Linux phone running a hypervisor with an Android VM to run banking apps seems not-impossible. (Based on AVF.)
- jbstack 1y agoThat's not the point I was making. Both operations need capital. But capital isn't the only barrier to entry. With a LLM, you can spend the money to develop the model, then spend some money marketing it, and if you get enough paying customers to cover your costs and a bit more then you're done. Done in the sense that you're now competing on the same level (roughly) as other LLM providers. Even if it's at a smaller scale, you can offer a similar product with similar features. With a phone OS, that isn't enough. You need to become big enough that significant numbers of app developers are willing to publish apps on your store, including most major ones (Netflix, Spotify, WhatsApp, social media, banks, government agencies, etc.). Running a VM isn't a full solution: banking apps are already actively blocking usage just based on phone settings that they don't like; unlses your OS does a very convincing job of masquerading as a genuine Android/Apple device you're likely to run into problems (and if you do the latter you might hit legal problems). You also need to convince major manufacturers that it's worth bundling your OS with their phone. Without those, for a significant segment of the population your phone OS will always be seen as an inferior product to Android / iOS.
- nicman23 1y agorun a custom rom. Infinity X (the gsi one) does both
- microtonal 1y agoCustom ROMs do not work with remote attestation (typically), so that means saying bye bye to a lot of apps, including some banking apps.
- nicman23 1y agoplease research before spreading missinformation. the specific gsi rom passes strong out of the box
- 63stack 1y agoSaying that custom roms typically fail attestation is not spreading misinformation, it is very correct, and google is closing the door on it fast. It's possible that this one random rom that you mentioned passes it today, but it might not pass tomorrow.
- nicman23 1y agolol that is not how that works. it is client side. they cannot do anything to block it.
- microtonal 1y agoThey certainly can. Since Android 8.0, apps can check if a key is stored in a hardware-backed store: https://developer.android.com/privacy-and-security/security-key-attestation https://developer.android.com/privacy-and-security/security-... This works by signing an attestation using a hardware-backed key (which is in turn signed by Google). So, there is no way to emulate this in software, because your ROM simply does not have the private key to do so. Part of the attestation is information on whether the booted operating system was signed: https://source.android.com/docs/security/features/keystore/attestation#rootoftrust-fields https://source.android.com/docs/security/features/keystore/a... Again, since this is all hardware-signed, you could only fake this information if you were somehow able to extract the private key from the secure element. The primary weakness is that you could try to patch out the part of the application that asks for this attestation. But they found a solution to that, remote attestation. Instead of the app asking for the attestation, e.g. Google's servers or your bankcan ask for the attestation and for the reasons outlined above, your custom firmware is not able to fake this. If your bank, etc. implemented remote attestation, you can simply do not do banking on your phone anymore.
- liendolucas 1y agoIs not your phone and it probably never will be.
- szszrk 1y agoI tried to debug a google pay issue with a Bank once: - Bank told me to go to Google. - Google support told me to go to the Bank. - (... few emails later...) - Google support told me to make screenshots of the banking app and google pay. So have a second phone ready, or stop complaining :) A few years later and 3 phones later... it works again!
- preisschild 1y agoGoogle Pay requires SafetyNet verification, which means it only works with a Google-approved hard & software combination, so not with GrapheneOS for example... I hate that banks use this proprietary "standard" for NFC payments
- mschuster91 1y agoI get where that one is coming from though - tap-to-pay is considered second-factor-authenticated, aka no PIN entry is necessary at the PoS terminal because the user already entered their PIN or presented biometric credentials to the smartphone. If a malware were able to snatch the key material that represents the credit card outright or it could (by running as root) act to the TEE like it were Google Pay's NFC controller app, it would enable the actor controlling the malware to spoof the credit card on their own phone... and since tap-to-pay is considered authenticated, chances are next to zero you can dispute the payment.
- 63stack 1y ago>If a malware were able to snatch the key material that represents the credit card I'm pretty sure that data is stored in the secure enclave, which is impossible to access by design, root, no root, bootloader unlocked, google approved or not.
- nani8ot 1y agoThere's already a better way to check whether an Android phone is secure enough and it is independent of any proprietary OS certification: basicIntegrity [1]. Most banking apps in Germany use this API and thus work on GrapheneOS and other non-Google controlled ROMs with a locked bootloader. PlayIntegrity is unnecessary and mostly offers vendor lock in to Google's ecosystem. [1] https://grapheneos.org/usage#banking-apps https://grapheneos.org/usage#banking-apps
- mihaaly 1y agoThese petty measures are as self damaging to reputation as futile: one can easily make screenshot or do recording with an other device, which is soooo commonplace nowadays. It is just ruining user experience with small-minded measures, driving people away.
- motbus3 1y agoMy friend, your phone might snitch on you depending what pictures or files you save. Your messages and calls can be saved at will without your knowledge. Even your notifications are being watched. Your apps have backdoors to spy on you. It is already here.
- benterix 1y agoFortunately we still have the analog loophole.
- jeroenhd 1y agoThe first part also happens on desktop thanks to DRM, unfortunately. Like on Android, it can be worked around, but it's a massive pain to do so. I'm curious about the second part, though. How do carriers influence the call recording feature on your phone? Is it because you run a carrier ROM or is there some kind of integration with the mobile network/SIM card that I'm not aware of?
- layer8 1y agoSee https://source.android.com/docs/core/connect/uicc https://source.android.com/docs/core/connect/uicc. UICC is the software component of a SIM card.
- amelius 1y ago> My Android phone prevents me from taking screenshots if an app author doesn't want me to. It's worse. An app author can even be notified if a screenshot was taken.
- croon 1y agoThe Amazon app does this: "Amazon Shopping detected this screenshot." I'm assuming (hoping) it's Android letting me know and not the app passive aggressively side eyeing me.
- BrandoElFollito 1y agoThis reminds me of a story of my bank that at some point told me to send them a screenshot. I told them that their app prevents this. To their surprise. I told them that I would use the web site and they were happy that there is a workaround for their own limitation. I had other wild stories with this otherwise good bank.
- sterlind 1y ago> My Android phone prevents me from recording phone calls at the request of my carrier, even though it's totally legal for me to do so in my jurisdiction. my GrapheneOS phone has the record button. :) though I have to obtain all-party consent to do so legally in my jurisdiction (but that's my responsibility.)
- aerique 1y agoThat's what I love running Android apps in Sailfish OS. I can just take these screenshots. Then again, this is also what makes me almost throw my Android phone against the wall when I try to do the same on that phone.