6 ms·
I like the android way of security, where "rooting" your device to install updates is insecure, but using a horrifyingly out-of-date android (because your manuf
by Elfener 9mo ago
I like the android way of security, where "rooting" your device to install updates is insecure, but using a horrifyingly out-of-date android (because your manufacturer, the only one who can update your device, didn't bother) is secure.
- zx8080 9mo agoIt's because "security" is not a user one, but a security of Google Play Services. As rooting may tamper the google's telemetry (can we already call it "spying" please).
- goodpoint 9mo agoIt's about keeping google's device secure *from* the user.
- 3abiton 9mo agoNot to mention, play integrity is being used a some sort of "anti cheats" by bank apps and other essential services. Even some government apps in the EU, essentially forcing you to be spied on by google. The worse part is that, you can do all of those functionality with a browser on linux (or Android), yet to use them as Android apps on a device without gapps (even if jt's not rooted and with locked bootloader) is not allowed. Make this make sense.
- goku12 9mo ago> Even some government apps in the EU, essentially forcing you to be spied on by google. The same in India. I can't use even the government weather app and the disaster alerts app without signing in to google play. Seeing that this malpractice (of forcing the users into Google's surveillance net) is widespread among seemingly unrelated agencies like banks and government agencies of several nations, I would really like to know who is peddling this draconian scheme among them. I want to send some angry rants to the app owners/developers and ask for those malicious peddlers to be permanently banned from further interference in cyber security matters of these institutions.
- 3abiton 9mo agoI would not be surprised if Google is sponsoring a lot of this efffort targeting young devs, and "teaching about security". They basically positioning their services as "authenticators" of truth, despite it 100% being cat and mouse game still.
- _heimdall 9mo agoThat really makes sense though if you think about it. When a company has an annual revenue that would put them around the 43rd largest country by GDP, they could very well begin acting more like a state. States spy and states claim to be the arbiters of truth.
- metalman 9mo agomoto g15 in hand, deguggled as much as possible right out of the box, no guggle accounts or big tech apps, bank through a browser, but there is defintly a lot of outright fraud as to bieng able to turn off google apps, it is an arcane procedure to turn off notifications, insisting that nothing will work without "play store" installed, though it is clear that going to a linux phone will become the only way to avoid adversurvielance security and tracking from taking over my device completly. keep in mind that our techno facist elite did provide the "intel" that led to ICE bieng sent to a particular area code in minaipolis, where they executed a mild mannered chearfull poet, who's last words, somehow knowing, were, "i dont hate you". "tech" is central to whatever comes next https://calebhearth.com/dont-get-distracted https://calebhearth.com/dont-get-distracted
- microtonal 9mo agoGet a phone that runs GrapheneOS (second-hand Pixel 7 or 8 will do fine). Run apps that do not require it without Google Play Services and run apps that do require Google Play Services with the sandboxed Google Play Services. That will constrain the data that can be collected a lot. (Yes, there will still be issues if you use apps that require Google's remote attestation, but at least in Europe, many banks etc. do not require it.)
- 9mo ago
- cromka 9mo ago> The worse part is that, you can do all of those functionality with a browser on linux This isn't true, actually. Banks and gov entities use those mobile apps as authenticators. They do have a distinct purpose.
- lrvick 9mo agoI do not have a smartphone and have had no problem being a customer of multiple top banks. They strongly _encourage_ you to use apps, but if smartphones are against your unspecified religion, alternative paths always appear.
- cromka 9mo agoIn EU? For internet banking you need a mobile phone or a dedicated hardware token (thing you own), as part of the Strong Customer Authentication (SCA) requirement under the PSD2 regulation: https://ec.europa.eu/newsroom/fisma/items/658958 https://ec.europa.eu/newsroom/fisma/items/658958 I know in some countries (UK, Germany, Switzerland, Austria) they're used to hardware tokens already since they were in use long before PSD2. But I seriously, seriously doubt banks in e.g. Poland specifically implement support for hardware tokens issued to very few annoying customers who refuse to use an app but otherwise want internet banking.
- bluebarbet 9mo agoBetween what the law says and what actually happens there's sometimes a gap. I'm in the EU and currently I do online banking with 3 banks without using any app, i.e. thru a laptop browser. The 1st literally lets me stay logged in with a simple cookie, with an SMS 2FA requirement every 90 days. The 2nd additionally asks for a PIN to be entered at each session. The 3rd is a neobank and is tougher, requiring a TOTP (which I generate on the same machine, needless to say). A 4th does require an app, and in fact can hardly even be used with a desktop OS. That bank is Revolut and I therefore don't use it and I recommend others avoid it too.
- 3abiton 9mo agoThis is untrue in reality. Literally I used more than 5 banking apps, and few investement ones (including 1 in the US). I could log in to all of them through a browser, using a phone number 2FA, or a proprietary authenticator of the bank (a physcial device). Never a bank forced me to use their app to login. It's an option though (and a convenient one). If that end up ever to be the case, I am for sure not using a google phone to do so. iPhone it is. And here is the funny part. On my A13 Android (fully rooted, BL UL, custom ROM) I can totally bypass play integrity, using the keybox method. There is literally no way for google to patch this. I am yet to get it working on A16, mainly for lack of time to tinker, also because OP15 has no sources released yet to build ROMs for it, which is the main motivator for me to use an Android phone. The takeaway is this: Google promotes "Play Integrity" (PI) as a working solution against "tempered devices" (ie. because god forbid you have sudo access on your device). Yet, it's easy (albeit a bit complex as you have to know the right telegram groups) to bypass it. PI gives the illusion of security, yet in reality it counter-solution exists. Real bad actors would have 0 issues doing what they want to do, the real impact is deterring users from open source roms like Lineage, simply because their bank app wouldn't work, which imo is Google plan all along masquerading as security feature. Google's main business is ads, and hosts based ad blocking is extremely easy once rooted. Their recent moves align well with this (slow rollout of open sourcing, QPR2 is still not out yet, antagonizibg 3rd party stores like f-droid), all in the "name" of security.
- brnt 9mo ago> Even some government apps in the EU The Dutch ID app got rid of all trackers and such requirements last year, but they didn't go the full length and made an F-droid repo (or a government store or sth). Google actively guiding developers to APIs like the Play Integrity API (which requires not only you register the phone with Google on a Google account, but also an untampered device, outdated or not. I don't even root my devices, just using something like Lineage already gets you the basic-integrity Max. Not enough for many banking apps.
- interpol_p 9mo agoThe reason this happens is because big companies get their software pen tested. Part of the pen test report will include something like “accessible from jailbroken devices.” The pen test results get put into the ticket system as immovable entries. Engineers will question them, only to be shot down by the cyber security department who organized the pen test. The engineers will eventually accept that they cannot convince cyber to drop the issue, and implement the jail break detection. Why does cyber mandate it? Because no one in a large company wants to accept the risk, even imaginary risk. They want to be able to say, when security is breached, “we did our due diligence. Look at the report, we implemented everything in it” Why do firms offering penetration testing keep putting junk like this into their reports? Because their automated tools list them out and they’re getting paid to find issues. The more the better. It’s insane and entirely about passing off risk.
- Sophira 9mo agoThere was a time when we did call it spying. Programs that had what we would now call telemetry used to be called spyware. The term has fallen by the wayside and hardly ever gets used nowadays.
- atanasi 9mo agoIt's the security of the ecosystem, where the interests of app vendors are fundamental: content distributors can count on enforcing DRM, and banks are relying on the camera used for KYC actually being a camera and not a virtual device.
- youhatetheleft 9mo agoJust accept being spied on, it’s not as if there are genocidal billionaires out there.
- plagiarist 9mo agoAndroid devices are enraging. ARM in general, why is there never a boot loader? I have a little Android handheld game device that will allow me to dual boot a Linux from SD quite easily... but why can't I overwrite the existing install? I thought Android was more open and hackable than that.
- opan 9mo agoI've got an Anbernic RG353M, came with a dual boot as you've described. I completely wiped it and only have ROCKNIX on there, a minimal distro based on LibreELEC, I believe. I actually maintained an Android + ROCKNIX dualboot at first, but it breaks the sleep function for some reason, and the ROCKNIX docs for this device say to remove Android, so eventually I did. I didn't actually use the Android side but had kept it around just in case before. Not all these devices have the same level of support, so do your research on your model before trying to overwrite the install.
- plagiarist 9mo agoI went with a Retroid after seeing articles about people booting ROCKNIX on it. And one can, from SD. But I did not do enough research to see there was no documentation on writing Linux to the internal storage. I'm so tired of doing research. I'd just like it to be a functioning BIOS. I at least learned my lesson and have stayed clear of other Android devices.
- bpye 9mo agoWell there is a bootloader - on Qualcomm its even UEFI, but you don't have access to it. https://worthdoingbadly.com/qcomxbl/ https://worthdoingbadly.com/qcomxbl/
- plagiarist 9mo agoThat's somehow worse. Good for them that they made it convenient to launch their software on the device I paid for.
- bfrog 9mo agoI think you had the wrong idea on security here, the security is for the device manufacturers benefit to obsolete the hardware and force you to buy a new one not for your benefit. All the data is already being shipped off to where the hell ever for building models of you for advertising and more.
- digiown 9mo agoAndroid does have a meaningfully improved security over typical Linux desktop: the segmentation of data between apps. Imagine what would happen if people run all the proprietary crap they do on a typical Linux box. That's multiple spyware apps with full filesystem access. Unfortunately, Google also uses it to abuse the user by also segmenting the user's access as well, "protecting" apps from the user, which is an abomination.
- zozbot234 9mo agoWe have Flatpak/bubblewrap that can accomplish the same sandboxing on the Linux desktop, with no need for clumsy hacks like app-specific user ID's.
- realusername 9mo agoAnd yet, I keep all my important stuff on my Linux laptop and not on my phone. There's maybe a lesson here that security is also about trust.
- digiown 9mo agoMe too. But you have to be a lot more careful about not running proprietary crap on the desktop, which is easier to do than on phone. Ever been forced to install some crap for some event/business/etc?
- realusername 9mo agoI have the somewhat controversial opinion that most Android apps are pretty much useless as native and they would be okay as a webapp if it would be more seamless. Exceptions would maybe be games.
- digiown 9mo agoI wouldn't disagree at all. But you often have to waste a lot of time to avoid them, if at all possible. It's a good thing that Android at least offers some protection against them exfiltrating your filesystem.
- mrweasel 9mo agoThe whole security of both Android and iOS is a joke at this point. We know now that plenty of apps/games have proxy services built in, allowing the publisher to monetize their users, by selling proxy services to AI companies. If that can happen, with all the "security" those platforms and store supposedly offer, then I fail to see the point. We're being prevented from installing and updating software on the devices we own, but Google and Apple will happily approve and sign malware in their stores?
- kube-system 9mo agoThey’re one in the same. You can’t exploit privilege escalation vulnerabilities unless you are vulnerable to them!