23 ms·
The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a
by dfabulich 8mo ago
The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient."
In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-developer-verification-early.html https://android-developers.googleblog.com/2025/11/android-de...
> For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses fear and urgency to direct them to sideload a "verification app" to secure their funds, often coaching them to ignore standard security warnings. Once installed, this app — actually malware — intercepts the victim's notifications. When the user logs into their real banking app, the malware captures their two-factor authentication codes, giving the scammer everything they need to drain the account.
> While we have advanced safeguards and protections to detect and take down bad apps, without verification, bad actors can spin up new harmful apps instantly. It becomes an endless game of whack-a-mole. Verification changes the math by forcing them to use a real identity to distribute malware, making attacks significantly harder and more costly to scale.
I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is."
A related approach might be mandatory developer registration for certain extremely sensitive permissions, like intercepting notifications/SMSes...? Or requiring an expensive "extended validation" certificate for developers who choose not to register...?
- verdverm 8mo agoAgree with this middle path you point out. On one hand, I do not want some apps to be distributed anonymously, I need to know who is behind it in order to trust the app. On the other hand, many apps are benign. Permissions are a great way to distinguish.
- amiga386 8mo agoDo you need Google to compel the author to start a business relationship with them, which they can cut off at any time? Or would you be OK knowing that Thunderbird you downloaded from https://thunderbird.net/ https://thunderbird.net/ is signed by the thunderbird.net certificate owner?
- verdverm 8mo agoSomething like Thunderbird might be an exception, but also domain confusion exists, so in the general case, most likely not because most users are susceptible to this.
- jyoung8607 8mo agoTypo squatting is a thing, and so are Unicode homographs. The permissions approach isn't bad. I may trust Thunderbird for some things, but permission to read SMS and notifications is permission to bypass SMS 2FA for every other account using that phone number. It deserves a special gate that's very hard for a scammer to pass. The exact nature of the gate can be reasonably debated.
- amiga386 8mo agoThey are, but this the next-layer-up problem. Most people don't type memorise and type URLs into their browser bar, they use a search engine result, browser history or browser bookmark. It's therefore on their choice of search engine, or choice of app store, to lead them from "thunderbird" to "The app downloadable from https://thunderbird.net/ https://thunderbird.net/", which can then be validated as signed by the verified owner of the same domain. I'm not proposing changing the permissions system.
- joshuamorton 8mo agoshould I be confident that thunderbird.net is the real one, or could it be hosted at thunderbird.org, thunderbird.com, or thunderbird.mozilla.org?
- amiga386 8mo agoThat's a search engine / reputation problem and it's also present even in Daddy Google's and Daddy Apple's walled gardens. If you search any web search engine for "thunderbird", https://thunderbird.net/ https://thunderbird.net/ is the top result. You can choose your preferred search engine, you should be able to choose your own app store, and your level of confidence stems from your own estimation of that entity's past competence. If you do search Google Play for "thunderbird", you'll find it lists an app with internal name "net.thunderbird.android" as the top result (along with lots of other mail clients). What I'm proposing is that if your choice of search engine or app store shows you https://thunderbird.net/ https://thunderbird.net/ as the place to download Thunderbird, and you do, PKI can then verify that the app was independently signed by the owner of the matching domain, and that the certificate was issued to them by a CA who regularly validates they control that domain.
- JoshTriplett 8mo agoIf you can "coach someone to ignore standard security warnings", you can coach them to give you the two-factor authentication codes, or any number of other approaches to phishing.
- harikb 8mo agoInstalling an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. In contrast, convincing someone to read an OTP over the phone is a one-time manual bypass. To use your logic.. A insalled app - Like a hidden camera in a room. Social engineering over phone - Like convincing someone to leave the door unlocked once.
- JoshTriplett 8mo ago> Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. The motivating example as described involves "giving the scammer everything they need to drain the account". Once they've drained the account, they don't need ongoing access.
- jyoung8607 8mo agoPersistence allows the scammer free license to attempt password recoveries for every account the victim could possibly have. Other banks, retirement accounts, the victim's email account.
- TeMPOraL 8mo agoScammer that thrive are greedy, but not too greedy. Easier to break into one type of account for 10 victims, than to break into 10 different account of one victim. Persistence is risk.
- sdenton4 8mo agoWhen the victim's relatives send them money because they need to eat and pay rent after handing everything over to the scammer, the persistent backdoor lets that money be drained as well... You're underestimating the persistence and ruthlessness of the scammers.
- darkwater 8mo ago> In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de https://android-developers.googleblog.com/2025/11/android-de... This reeks of "think of the children^Wscammed". I mean, following this principle the only solution is to completely remove any form of sideloading and have just one single Google approved store because security. > A related approach might be mandatory developer registration for certain extremely sensitive permissions, like intercepting notifications/SMSes...? O It doesn't work like that. What they mean with "mandatory developer registration" is what Google already does if you want to start as a developer in Play Store. Pay 25$ one-time fee with a credit card and upload your passport copy to some (3rd-party?) ID verification service. [1] In contrast with F-Droid where you just need a GitLab user to open a merge request in the fdroid-data repository and submit your app, which they scan for malware and compile from source in their build server. [1] but I guess there are plenty of ways to fool Google anyway even with that, if you are a real scammer.
- kotaKat 8mo agoYou can’t even win with adding more scare screens because as soon as Epic isn’t allowed to bypass the scare screens, they’ll sue you. Just like they went after Samsung for adding friction to the sideload workflow to warn people against scams. https://www.macrumors.com/2024/09/30/epic-games-sues-samsung-google/ https://www.macrumors.com/2024/09/30/epic-games-sues-samsung...
- daveidol 8mo agoI agree with Epic. It should be like on windows or macOS where you can register, get notarized, and then distribute without scare screens. I don’t see why phones are inherently different than computers.
- cherryteastain 8mo ago> community needs a better response to this problem than "nuh uh, everything's fine as it is." You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. Google and the state are not your nannies.
- john_strinlai 8mo ago>You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. oh nice, i love this game. you cant carry a kitchen knife that is too long, you cant carry your kitchen knife into a school, you cant brandish your kitchen knife at police, you cant let a small child run around with a kitchen knife... literally most of what "the state" does is be a "nanny" (not agreeing or disagreeing with google here, i have no horse in this particular race. but this little knife quip is silly when you think about it for more than 5 seconds)
- CamperBob2 8mo agoyou cant buy a kitchen knife that is too long What?
- john_strinlai 8mo agosorry, should say "carry", not "buy". most states have a maximum length you can carry (4-5.5 inches is common). although, i would imagine at some length, it becomes a "sword" (even if marketed as a knife) and falls under some other "nanny"-ing. i have not googled that.
- mikestew 8mo agoYou still have an hour or two to edit your comment. Look in that line of text where you see your user name, click “Edit”.
- CamperBob2 8mo agoAs kevin_thibedeau points out elsewhere in the thread, he's not necessarily wrong. In many states and foreign countries it's illegal to carry a large knife in public without a reason and I'm sure purchases are restricted in some places as well. Most people are more or less OK with that, it seems, so there historically hasn't been a lot of pushback. So, having been given the proverbial inch (or centimeter), those obsessed with banning potentially-dangerous tools are trying to take the next mile (or kilometer): https://theconversation.com/why-stopping-knife-crime-needs-to-start-in-the-kitchen-246258 https://theconversation.com/why-stopping-knife-crime-needs-t...
- daveidol 8mo agoI don’t want to be too flippant, but I think there is a real trade off across many aspects of life between “freedom” and “safety”. There is a point at which people have to think critically about what they are doing. We, as a society, should do our best to protect the vulnerable (elderly, mentally disabled, etc) but we must draw the line somewhere. It’s the same thing in the outside world too - otherwise we could make compelling arguments about removing the right to drive cars, for example, due to all the traffic accidents (instead we add measures like seatbelts as a compromise, knowing it will never totally solve the issue).
- bonoboTP 8mo ago> protect the vulnerable (elderly, mentally disabled, etc) Yes, one could imagine some kind of mental test and if you fail you don't get to use your bank online, you have to walk to the physical location to make transactions. But this can obviously be abused to shut out people from banking based on political and other aspects. Generally democracies are wary of declaring too broad sets of people as incapable of acting independently without some guardian. Obviously beyond a certain threshold of mental incapacitation, dementia etc. it kicks in, but just imagine declaring that you're too easy to influence and scam and we can't let you handle your money,... But somehow we can rely on you using sane judgment when voting in elections. Or should we strip election rights too? We rely on polite fictions around the abilities of the average person. The contradictions sometimes surface but there is no simple way to resolve it without revising some assumptions.
- MSFT_Edging 8mo agoI think there's room to raise the bar of required tech competency without registration. Manually installing an app might be close to the limit of what grandma can be coached through by an impatient scammer. Multiple steps over adb, challenges that can't be copy and pasted in a script, etc. It can be done but it won't provide as much control over end user devices.
- snowhale 8mo ago[dead]
- Cyph0n 8mo agoDoes your logic extend to PCs? If not, why? Because I hope you realize that clamping down on “sideloading” (read: installing unsigned software) on PCs is the next logical step. TPMs are already present on a large chunk of consumer PCs - they just need to be used.
- bitwize 8mo agoOf course it extends to PCs. It'd suck for us, but end users, software vendors, content providers, and service providers all benefit from a more restricted platform that can provide certain guarantees against malware, fraud, piracy, and so forth. It's pathologically programmer-brained to assume that the good old days of being able to run arbitrary code on a networked computing device would last forever. That freedom must be balanced against the interests of the rest of society to avoid risk from certain kinds of harm which can easily proliferate in an environment where any program can run with the full authority of the owner and malware spreads willy-nilly.
- Cyph0n 8mo agoObviously I disagree completely. But it is still sad to see this kind of reasoning on HN of all places :(
- eikenberry 8mo agoThe "programmer-brained" assumption is that I will be able to write any program and run it on my machine and that this ability isn't reserved for only me or some limited class of people and that I can share what I write with others. One big plus of the current stye of AI will be that "end users" will be able to write simple programs and will value this ability. Thus helping protect general purpose computing from this bit of evil for a while longer.
- jeroenhd 8mo agoDeveloper registration doesn't prevent this problem. Stolen ID can be found for a lot less money than what a day in a scam farm's operation will bring in. A criminal with access to Google can sign and deploy a new version of their scam app every hour of the day if they wish. The problem lies in (technical) literacy, to some extent people's natural tendency to trust what others are telling them, the incompetence of investigative powers, and the unwillingness of certain countries to shut down scam farms and human trafficking. My bank's app refuses to operate when I'm on the phone. It also refuses to operate when anything is remotely controlling the phone. There's nothing a banking app can do against vulnerable phones rooted by malware (other than force to operate when phones are too vulnerable according to whatever threshold you decide on so there's nothing to root) but I feel like the countries where banks and police are putting the blame on Google are taking the easy way out. Scammers will find a way around these restrictions in days and everyone else is left worse off.
- gjsman-1000 8mo ago> Stolen ID can be found for a lot less money than what a day in a scam farm's operation will bring in. Well, in that case, Google has an easy escalation path that they already use for Google Business Listings: They send you a physical card, in the mail, with a code, to the address listed. If this turns out to be a real problem at scale, the patch is barely an inconvenience.
- jeroenhd 8mo agoSo they'll have a lead time building up a set of verified developers. These scams are pulled by organized crime syndicates, using human trafficking and beatings to keep their call centers manned with complicit workers. Now they'll need to pay off a local mailman to give them all of Google's letters with an address in an area they control so they can register a town's worth of addresses, big whoop. It'll cost them a bit more than the registration fee, but I doubt it'll be enough to solve the problem.
- joshuamorton 8mo ago
- Tharre 8mo agoThere simply isn't a known solution to this problem. If you give users the ability to install unverified apps, then bad actors can trick them into installing bad ones that steal their auth codes and whatnot. If you want to disallow certain apps then you have to make decisions about what apps (stores) are "blessed" and what criteria are used to make those distinctions, necessarily restricting what users can do with their own devices. You can go a softer route of requiring some complicated mechanism of "unlocking" your phone before you can install unverified apps - but by definition that mechanism needs to be more complicated then even a guided (by a scammer) normal non-technical user can manage. So you've essentially made it impossible for normies to install non-playstore apps and thus also made all other app stores irrelevant for the most part. The scamming issue is real, but the proposed solutions seem worse then the disease, at least to me.
- Retr0id 8mo agoWe know how to do hardware-bound phishing-resistant credentials now, it is a solved problem.
- Tharre 8mo agoI'm going to assume you're referring to auth codes, especially the ones sent via SMS? In which case yes, banks should definitely stop using those but that alone doesn't solve the overarching issue. The next step is simply that the scammer modifies the official bank app, adds a backdoor to it, and convinces the victim to install that app and login with it. No hardware-bound credentials are going to help you with that, the only fix is attestation, which brings you back to the aformentioned issue of blessed apps.
- jcynix 8mo ago>I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." OK, so instead of educating stupid (or overly naive) people, we implement "protections" to limit any and all people to do useful things with their devices? And as a "side effect" force them to use "our" app store only? Something doesn't smell that good here … How about a less drastic measure, like imposing a serious delay for "side loading" … let's say I'd to tell my phone that I want to install F-Droid and then would have to wait for some hours before the installation is possible? While using the device as usual, of course. The count down could be combined with optional tutorials to teach people to contact their bank by phone meanwhile. Or whatever small printed tips might appear suitable.
- warkdarrior 8mo agoHow would that solve scammer-driven installs? The scammer is not in a rush, they already have the victim listening and following their instructions.
- deleted 8mo ago[deleted]
- bigstrat2003 8mo ago> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adults, which includes letting them make very bad decisions if they insist on doing so. Someone being gullible and willing to do things that a scammer tells them to do over the phone is not an "attack vector". It is people making a bad decision with their freedom. And that is not sufficient reason to disallow installing applications on the devices they own, any more than it would be acceptable for a bank to tell an alcoholic "we aren't going to let you withdraw your money because we know you're just spending it at the liquor store".
- gretch 8mo ago> At some point you need to treat people as adults, which includes letting them make very bad decisions if they insist on doing so. That's right, it's your decision to use Android. If you choose to do so, that's on you.
- zarzavat 8mo agoYou're right, all Android users who are upset about this change are free to switch to iOS.
- raw_anon_1111 8mo agoRight like someone who can only afford a $100 phone can buy the cheapest iPhone which is 5x more expensive. This is about like the geeks who hate the idea of ad supported services and think that everyone should just pay for every service they use. FWIW: I do exclusively buy Apple devices, pay for streaming services ad free tier, the Stratechery podcast bundle, ATP and the Downstream podcasts and Slate. I also pay for ChatGPT and refuse to use any ad supported app or game.
- 8mo ago
- hypeatei 8mo ago> but I think the community needs a better response The community does not need to do that. Installing software on my device should not require identification to be uploaded to a third party beforehand. We're getting into dystopian levels of compliance here because grandma and grandpa are incapable of detecting a scam. I sympathize, not everyone is in their peak mental state at all times, but this seems like a problem for the bank to solve, not Android.
- iamnothere 8mo agoThese people would try to ban talking if the scams moved to in-person conversations. At some point individual responsibility has to come into play.
- 999900000999 8mo agoHow about. "I am responsible for my own actions" mode. You click that, the phone switches into a separate user space. Securenet is disabled, which is what most financial apps rely on. Then you can install all the fun stuff you want. This is really a matter of Google not sandboxing stuff right. Why the hell does App A need access to data or notifications from App B.
- AAAAaccountAAAA 8mo agoThe new "Terminal" app might eventually evolve into something like that.
- thewebguyd 8mo ago> Why the hell does App A need access to data or notifications from App B. Advertising networks. Just like how you see crap like a metronome app have a laundry list of permissions that it doesn’t need. Some cases they are just scammy data harvesters, but in other cases it’s the ad networks that are actually demanding those permissions. Google won’t sandbox properly because it’s against their direct business interest for them to do so. Google’s Android is adware, and that is the fundamental problem.
- renewiltord 8mo agoThis mode already exists. It's called "Install LineageOS".
- Retr0id 8mo ago> the malware captures their two-factor authentication codes Aren't we supposed to have sandboxing to prevent this kind of thing? If the malware relies on exploiting n-days on unpatched OSes, they could bypass the sideloading restrictions too.
- UncleMeat 8mo agoCodes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app. On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible.
- Retr0id 8mo agoIf they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.
- warkdarrior 8mo agoSo no access to SMS for apps distributed on F-Droid?
- Retr0id 8mo agoFine by me, what are people using SMS for in 2026 except for spam and sending 2FA codes insecurely? (I'm being facetious here but this is massively preferable to disabling sideloading altogether)
- deaux 8mo ago> sideloading If you care about the topic, which you seemingly do, stop using this doubleplusgood term.
- UncleMeat 8mo ago
- hahn-kev 8mo agoI like the idea of requiring extra work to get notification access. But really what all these scams pray on are time sensitivity, take that away and you solve the problem in many ways. For example, your bank shouldn't let you drain your account without either being in person or having a mandatory 24hr waiting period. Same could be done with side loaded apps getting notifications, if it's side loaded and wants to read notifications, then it needs to wait 24 hrs. Mostly it won't ever matter. Alternatively reading notifications could be opt in per app, so the reading app needs to have permission to read your SMS message app notifications, or your bank notifications, that would not be as full proof as that requires some tech literacy to understand.
- marcprux 8mo agoI am the author of the letter and the coordinator of the signatories. We aren't saying "nuh uh, everything's fine as it is." Rather, we are pointing out that Android has progressively been enhanced over the years to make it more secure and to address emerging new threat models. For example, the "Restricted Settings"¹ feature (introduced in Android 13 and expanded in Android 14) addresses the specific scam technique of coaching someone over the phone to allow the installation of a downloaded APK. "Enhanced Confirmation Mode"², introduced in Android 15, adds furthers protection against potentially malicious apps modifying system settings. These were all designed and rolled out with specified threat models in mind, and all evidence points to them working fairly well. For Google to suddenly abandon these iterative security improvements and unilaterally decide to lock-down Android wholesale is a jarring disconnect from their work to date. Malware has always been with us, and always will be: both inside the Play Store and outside it. Google has presented no evidence to indicate that something has suddenly changed to justify this extreme measure. That's what we mean by "Existing Measures Are Sufficient". [^1]: https://support.google.com/android/answer/12623953 https://support.google.com/android/answer/12623953 [^2]: https://android.googlesource.com/platform/prebuilts/fullsdk/sources/+/refs/heads/androidx-xr-arcore-release/android-35/android/app/ecm/EnhancedConfirmationManager.java https://android.googlesource.com/platform/prebuilts/fullsdk/...
- mirekrusin 8mo agoWould you say that iOS ecosystem suffers the same rate of malware as Android?
- tadfisher 8mo agoOf course not. In other news, a new study shows that cutting off your feet is 100% effective against athlete's foot.
- mirekrusin 8mo agoHaven't seen that one but I've seen working medication, it does exist on the market and does work, why not switching to use it?
- realusername 8mo agoGoogle's announcement is just trolling, there's an order of magnitude more scams on the Play store and they don't call for its closure. Right now when I search for "ChatGPT", the top app is a counterfeit app with a fake logo, is it really this store which is supposed to help us fight scams?
- warkdarrior 8mo ago> Right now when I search for "ChatGPT", the top app is a counterfeit app with a fake logo, is it really this store which is supposed to help us fight scams? Just did Play search for "ChatGPT" and the top-2 results were for OpenAI's app (one result was sponsored by OpenAI one result was from Google's search). So anecdotally your results may vary.
- realusername 8mo agoSee what I'm seeing on my device : https://ibb.co/DJKGM8d https://ibb.co/DJKGM8d So maybe before talking about anything about direct installs, they could fix the big scams on the Play Store.
- raincole 8mo ago> standard security warnings Make the warning a full screen overlay with a button to call local police then. (Seriously) "but local police won't treat that seriously..." "the victim will be coached to ignore even that..." well no shit then you have a bigger problem which isn't for google to fix.
- a456463 8mo agoMaybe we should take away peoples' phone calls, ability to use knives, walking on the street, swimming in water, drinking liquids of any kinds, alcohol, trains, while we are at it.
- GeekyBear 8mo ago> I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." People choosing between the smartphone ecosystems already have a choice between the safety of a walled garden and the freedom to do anything you like, including shooting yourself in the foot. You don't spend a decade driving other "user freedom" focused ecosystems out of the marketplace, only to yank those supposed freedoms away from the userbase that intentionally chose freedom over safety.
- chopin 8mo agoThe main problem here is the banks relying on an untrusted device as second factor. Only immutable devices should be allowed as second factor.
- shaky-carrousel 8mo agoThat attack vector is just a symptom. It’s unfathomably foolish to use two-factor authentication via something as easy to intercept as SMS. Two-factor authentication should be done using a separate hardware token that generates time-based one-time codes. Anything else is basically security theater.
- microtonal 8mo agoOne time codes are still vulnerable to phishing by a site that proxies the bank's authentication challenge. You need something like FIDO2 where a challenge-response only works when the relying party ID is correct.
- RHSeeger 8mo agoThere will _always_ be a need to balance between safety and the cost of adding more safety. There is no point at which safety is complete; there is always more that can be done, but the cost gets higher and higher. So yes, "its fine the way it is" _is_ valid; but the meaning it "we're at a good point in the balance, any more cost is too much given the gains it generates"
- glenstein 8mo ago>A related approach might be mandatory developer registration for certain extremely sensitive permissions, like intercepting notifications/SMSes...? Or requiring an expensive "extended validation" certificate for developers who choose not to register...? I think my overriding concern is not nuking F-Droid. I actually think that's a great solution and, interestingly, F-Droid apps already don't use significant permissions (or often use any permissions!) so that might work. Also it would be good if perhaps F-Droid itself could earn a trusted distributor status if there's a way to do that. Or a marriage of the two, F-Droid can jump through some hoops to be a trusted distributor of apps that don't use certain critical permissions. I think there have to be ways of creatively addressing the issue that don't involve nuking a non-evil app distribution option.
- pessimizer 8mo ago> In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. If you can be convinced by this, you can be convinced by anything. What if the scammer uses "fear and urgency" to make the person log onto their bank account and transfer the funds to the scammer? If you can convince people to install new apps through "fear and urgency," especially with how annoying it often is to do outside of the blessed google-owned flow (and they're free to make it more annoying without taking this step), that person can be convinced of anything. > I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." There's no other "solution" other than control by an authority that you totally trust if your "threat" is that a user will be able to install arbitrary apps. The manufacturer, service provider, and google, of course, won't be held to any standard or regulations; they just get trusted because they own your device and its OS and you're already getting covertly screwed and surveilled by them. Google is a scammer constantly trying to exfiltrate information from my phone and my life in order to make money. The funny thing is that they are only pretending to defend me from their competition - they're not threatened by those small-timers - they're actually "defending" me from apps that I can use to replace their own backdoors. Their threat is that they might not know my location at all times, or all of my contacts, or be able to tax anyone who wants access to me.
- rogerallen 8mo agoI wonder if putting this choice on the user would be most appropriate? People fearful about being scammed should buy a phone with a hardware lock to prevent it from ever accepting sideloads--no option to go to dev mode, ever. You could even charge more for the extra security. People who want the freedom to sideload can choose to buy a phone without the extra hardware security feature.
- miloignis 8mo agoI have a radical solution - it should not be possible to contact someone unsolicited. All phone calls, SMS, emails, and instant messages should be blocked unless the other party is in my contacts or I have reached out to them first (plus opt-in contact from contacts of contacts, etc). Ideally, cryptographically verified. I would argue this is the real solution to spam and scamming - why on earth are random people allowed to contact me without my consent? Phone numbers or email addresses being all you need to contact me should be an artifact of an earlier time, just like treating social security numbers as secret. I realize this isn't super practical to transition existing systems to (though spam warnings on email and calls helps, I suppose, and maybe it could be made opt-in). I dearly hope the next major form of communication works this way, and we eventually leave behind the old methods. Also, SMS shouldn't be used for 2FA anyway.
- wilsonnb3 8mo agoHow are you going to reach out to someone first if all communication is blocked because they don't already know you?
- miloignis 8mo agoAh, I should have elaborated a bit more - the strict solution is out-of-band only, namely in person or allowing contacts-of-contacts to reach out. I think practically you'd want to be able to create time-limited, otherwise uncorrelated invite tokens/addresses that you could freely give out and deactivate later.
- cjmoran 8mo agoI have an even more radical solution. The real root of the problem is that we use this "money" concept to represent value. If money didn't exist there wouldn't be any reason to steal, hack, or scam. What do we replace it with? Haha, idk man. How about water? More difficult to hoard in ridiculous quantities, better spend it before it evaporates, and it occasionally falls from the sky (UBI). That's what I call a liquid asset!
- 8mo ago
- cyberrock 8mo agoAh this explains why so many banks are making their own 2FA apps with warnings to never share the codes. Well a lot of people are very annoyed to install them because they perceive it as a technological downgrade when it's the opposite. I can only imagine asking them to use passkeys or hardware keys would be difficult, especially if there is some FUD (or truth?!) about how $boogeyman has your keys if you use them.
- eviks 8mo agoAre you not aware of cases where marks physically went to the bank, withdrew all cash and dropped it off to the criminals, also taking out loans and yelling at bank employees when they were trying to stop them? No app involved. You'll always find individual cases where people do extremely dumb stuff, but using that as a justification is also dumb. If you want to significantly curtail that freedoms of a large group, it's on you to come up with a good evaluation of tradeoffs, so > the community needs a better response to this problem than "nuh uh, everything's fine as it is." They already have, but you choose to use a fake simplification as a representative