7 ms·
Will F-droid continue when Google bring in their changes, soon?
by scrollop 7mo ago
Will F-droid continue when Google bring in their changes, soon?
- microtonal 7mo agoEven with Google's changes, F-Droid will continue to work with Android phones that do not use Google GMS. If you care about your actually owning your device, install something else than stock OS. I would recommend GrapheneOS, since the security of some/most other alternatives is pretty bad.
- scrollop 7mo agoWould love to ditch google and use grapheneOS, however have so many banking and (stupid) outlook for work.
- sheiyei 7mo agoApparently a lot of banking apps work with the sandboxed Google malwares. Not sure though, I'm not a user (wrong hardware)
- wafflemaker 7mo agocan confirm. And there are even some pages that list banking and other apps working on GrapheneOS. It's actually very few that don't work with sandboxed Google Play API. edit: https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- microtonal 7mo agoCorrect. I am using my Dutch bank and credit card apps without any issues. Someone linked the curated GrapheneOS banking list already. If your bank does not support it, you could either contact them. If they require remote attestation, this can be implemented for GrapheneOS as well: https://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu... If the bank is very hard-nosed about it, you could consider keeping an old iPhone or Pixel (because long security updates) for banking if it is practical to do for you. 95% without big tech is also a big win. Of course, if you need to have it with you at all times, that might not be a worthwhile option.
- TobTobXX 7mo agoThe outlook webapp is quite decent. I've never used their native app, but I've manahed to get by fine with their webapp, even though notifications don't work (I just check it regularily). IIRC K9/Thunderbird also has support for exchange now.
- amelius 7mo agoYou can check banking app compatibility here: https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/ https://privsec.dev/posts/android/banking-applications-compa...
- CorrectHorseBat 7mo agoEven if it works now, how can you be sure the next app update doesn't break it in the name of security?
- amelius 7mo agoBecause it would cause public uproar.
- CorrectHorseBat 7mo agoI very much doubt that
- ninjasmosa 7mo agoThe outlook app works for me on GrapheneOS, is there something about it that doesn't work for you? Many banking apps do work on GrapheneOS, the list had already been linked to by others
- kgwxd 7mo agoCan you not setup your work email through a regular email client? I thought the days of being locked into Outlook specifically went away with Exchange. Everywhere I've worked since has been able to. Also, what kind of banking are people doing that requires an app? I genuinely don't know what it could be.
- wafflemaker 7mo agoIt's way more comfortable to login with fingerprint and not going through a longer login to the website. Especially since in many countries it requires a national e-ID that is an app on your phone.
- duozerk 7mo ago> Also, what kind of banking are people doing that requires an app? I genuinely don't know what it could be. Close to every bank in the EU requires their user to have an app, for MFA (both for logging in and for validating transactions - transfers, payments). They use the smartphone's TPM. I have yet to see one that allows you to use your own MFA app. The few I've seen that don't require it will validate the same through text messages (not everyone has a smartphone); though if you associate their app even once, you're screwed - the app it is from now on.
- bluebarbet 7mo ago>Close to every bank in the EU requires their user to have an app Possibly this was hyperbole but in any case it's not correct at all. Anecdotally, of my two EU (massive legacy French) banks, neither requires a mobile app. SMS all the way. Even Wise, a cutting-edge neobank, does not require you to use its app. And its website accepts standard TOTP authenticator for 2FA. Revolut is app-only, which is why I never use it.
- microtonal 7mo agoHere in The Netherlands banks used to offer authenticator devices, which they are phasing out (you can still use them, but they wont replace them once they run out of battery). Pretty much all banks switched to app-only. No SMS at all (which is not surprising, because SMS is not secure). Also, IMO fingerprint/face-based authentication is much nicer/quicker, especially for online payment flows like iDEAL (Dutch predecessor to Wero). And banks here work on GrapheneOS, so not much is lost.
- rkagerer 7mo agoI don't much like the official Outlook app. Been using Nine for ages, it does everything I've needed.
- ekjhgkejhgk 7mo ago> Would love to ditch google and use grapheneOS grapheneOS only works with google phones.
- 4gotunameagain 7mo agoI would rather pay a one off ransom to google, than have them harvest all my data and profit from them in perpetuity. Better yet, you can buy a used pixel phone.
- burningChrome 7mo agoPixel 9 Pro handsets are going for around $500 on the secondary markets like ebay. That's a only a single generation off from their current Pixel 10 models and you still get OS and security updates until 2031. Not a bad deal and pretty crazy how fast smartphones depreciate now.
- microtonal 7mo agoIndeed and Pixel 10 was 549 Euro here just a few weeks ago and Pixel 9a as low as 338 Euro.
- kruffalon 7mo agoFor now[0]. And I don't really think that people mean using google hardware but rather being mined by google software. May I ask, if you (a) just want to be technically correct, (b) don't see the difference or (c) are trying to make a point I don't understand and if so would be willing to explain? --- [0] https://piunikaweb.com/2026/02/02/grapheneos-non-pixel-hardware-announcement/ https://piunikaweb.com/2026/02/02/grapheneos-non-pixel-hardw...
- ekjhgkejhgk 7mo agoWhy do people need banking on their phones though? Banks have websites too.
- gyulai 7mo ago> Why do people need banking on their phones though? Banks have websites too. 2FA. I was a smartphone hold-out for longer than anyone I know, but banks mandating 2FA with no options for doing it in a standards-compliant way or any way that doesn't involve the app stores was what finally broke my resistance.
- pmontra 7mo agoThis is asked again and again. Apparently you guys in the USA or in other parts of the world are still lucky, but in Europe banks must be compliant with regulation that more or less force them to do 2FA through their app with the biometric authentication of either an Android or an iOS phone. There are other ways (eg giving a hardware OTP generator to customers,) but apps are the cheapest solution.
- fsflover 7mo agoYou can still find banks in Europe that do not force Google and Apple on you. They may ask you to use their own security devices for instance.
- kruffalon 7mo agoDo you have a link with information about this? I'm just wondering since I'm currently using 3 different European banks without any biometric authentication to unlock my phone, password manager or provide a 2FA. I'm asking so that I can adjust in time to any new regulations I'm not aware of.
- pmontra 7mo agoThis https://en.wikipedia.org/wiki/Strong_customer_authentication https://en.wikipedia.org/wiki/Strong_customer_authentication
- zwarag 7mo agoTheres e/OS where you can have a locked bootloader with some phones
- echelon 7mo agoThis piddly open source effort pales in comparison to what we should really be doing: Horizontally splitting Google into multiple companies. Not division via department splits, but equal partitioning across the company into multiple horizontal businesses that compete on the same offerings. The EU and next DOJ/FTC need to force this.
- microtonal 7mo agoI agree, but the probability that this is going to happen anytime soon is near-0. The current US administration is not going to rein in the tech broligarchy and if they did, it would be done out of spite and the pieces wold sold to administration-aligned oligarchs (e.g. Ellison), which might end up being worse. The EU is not going to force this, because it has enough fights to pick with the US, and this is not the hill that they are willing to die on. It would be far more likely for them to financially support an AOSP-based OS.
- lukan 7mo agoThe EU simply is not (and should not) be able to split up google who operate international. But they can regulate the EU market and declare that a monopolist cannot operate there as a monopolist and introduce any arbitary rule achieving it.
- microtonal 7mo agoYes, though I think that is what echelon was aiming at - the EU saying either you break up or you cannot do business here.
- burningChrome 7mo agoNot sure if you know this, but both Biden and Trump (in his previous admin) had their DOJ file lawsuits against Google. "United States v. Google LLC," which was filed in 2020 and focused on Google's dominance in search and advertising markets. A separate case was filed in 2023 targeted Google's monopolization of digital advertising technologies. The State of Texas also sued them in 2020. Google lost all three cases. The DOJ in all three recommended the company be broken up, but the judges disagreed. If you want to blame someone, then blame the judges, not the current admin or Bidens DOJ - both of whom said Google should be broken up.
- miroljub 7mo agoGrapheneOS works only with Pixel devices, which doesn't make it much useful for the vast majority of Android users.
- microtonal 7mo agoIndeed. Sadly the reality is that most other Android devices are simply not secure enough. Many Android phones do not have a separate secure enclave (outside Pixel and IISC Samsung flagship and A5x range), so they are vulnerable to breaking PIN-based unlocking, side channel attacks, etc. Besides that they often only provide old vendor kernel trees, old firmware blobs, etc. So, you have to wonder whether you want such a phone anyway if you care about security and privacy. If you don't care about security anyway, you could as well run /e/OS, etc. Above-mentioned Samsung phones could perhaps make the cut, but don't support unlocking anymore (and when they still did, would blow a Knox eFuse).
- RealStickman_ 7mo agoPerfect really is the enemy of good when it comes to GrapheneOS
- handedness 7mo agoIt really isn't; the project acknowledges numerous existing compromises. Take a look at their roadmap or any number of threads if you think they only ever implement perfect features. That's also an unfair take when one considers how many improvements they've upstreamed to AOSP and how many quality of life features they've implemented.
- bwoah 7mo agoWhen feasible, they also provide harm reduction updates for legacy hardware.
- saintfire 7mo agoReduced security has always annoyed me a bit as an argument. Sort of in the same way as signal deprecating SMS because it's insecure. I get all or nothing when your threat model is state actors. However, for most people, the benefit is just freedom from corporate agendas. Not everyone needs kernel hardening, or always E2EE (as with signal). Personally I just like the features it provides (e.g. scoped storage, disabling any app including Google play services, profiles etc etc Its also an easier sell to people who are apathetic to security when the product is just better and more secure, the same way apple does (for whatever their reasons may be). All that said, I get they're limited in funds and manpower, plus the things mentioned at the end there, so I can only be so peeved they chose a target and stuck with it. They typically cite security as the reason, not those other ones, however.
- jona-f 7mo agoAFAIK every popular Android phone uses a qualcomm modem chip with a separate OS that has complete access to ram. NSA most certainly has a backdoor there and such complete access to any Android phone. This was common knowledge after the Snowden stuff. I don't think this has changed at all since. Only few niche phones (pinephone) separate these systems or have a hardware switch to disable the cellular system.
- roblabla 7mo ago> NSA most certainly has a backdoor there and such complete access to any Android phone. Citation needed? > This was common knowledge after the Snowden stuff. Not to me, it isn't? As far as I'm aware, most of the Snowden stuff were centered around PRISM, which allowed widescale wiretapping of internet backbone, as well as agreements with big cloud providers to allow tapping into their data. I haven't seen anything indicating that there was widespread compromise of personal computing devices at such a deep level of the root of trust. I haven't seen any indication that the NSA has a backdoor in the earlyboot CPU of any device, whether that is the Qualcomm boot processor, the Intel Management Engine or the AMD Platform Security Processor (which all have similar capabilities and hidden firmware). If I missed anything/have links to research into these backdoors, I'd like to see them!
- jona-f 7mo agoThe backdoor is that those are all US companies and the NSA can force them to comply.
- ysnp 7mo ago>I don't think this has changed at all since. There is common knowledge to suggest that it is not the case (or maybe is no longer the case): >Mainstream smartphones do not provide DMA access from the baseband to the application processor's memory... Yes, getting baseband access then lets you monitor regular voice and SMS comms. But no, it does not instantly compromise the AP so using the Signal app would still be secure. https://news.ycombinator.com/item?id=10906488 https://news.ycombinator.com/item?id=10906488 >Apple mitigates baseband processor vulnerabilities by putting it behind what's essentially an IOMMU. https://news.ycombinator.com/item?id=29440154 https://news.ycombinator.com/item?id=29440154 >This is false FUD that keeps being repeated. It's not true. No iPhone ever has had a baseband with DMA access to my knowledge, and modern Qualcomm devices have advanced IOMMU systems to firewall away the baseband from the rest of system memory. I'm sure some phones somewhere existed where the baseband was privileged, but it's not the norm. https://news.ycombinator.com/item?id=30393283 https://news.ycombinator.com/item?id=30393283 >Connecting a cellular radio via USB provides far less isolation than the approach of a tiny kernel driver connected to an IOMMU isolated cellular radio on mainstream devices. USB has immense complexity and attack surface, especially with a standard Linux kernel configuration. Forensic data extraction companies mostly haven't bothered using attack vectors other than USB due to it being such a weak point. Many of the things people claim about cellular radios in mainstream smartphones are largely not true and they're missing that other radios are implemented in a very comparable way. https://news.ycombinator.com/item?id=46841004 https://news.ycombinator.com/item?id=46841004
- duskdozer 7mo agoAs of now, Google isn't destroying non-Google android installs, so F-droid will still work there (correct me if wrong). So until Google takes android fully closed or succeeds in getting popular/necessary apps to blacklist non-Google-verified devices, F-droid still has a role
- asacrowflies 7mo agohttps://keepandroidopen.org/ https://keepandroidopen.org/
- asacrowflies 7mo agoI still think they are planning on coming down side loading and app dev registration with newer phones
- deleted 7mo ago[deleted]
- riedel 7mo agoI hope so. The changes can mean two things: people can only use it easily in custom roms (I guess there is an overlap there) or they actually would play with Google: i guess technically they could as well register and sign the stuff with a Google key as the software is all FOSS and would allow defining another responsible developer (otherwise Google would have to through out all FOSS without CLA from their playstore). I guess quitting would be an option, but IMHO the outrage outside the bubble would probably be hardly noticable, so what would be the point?
- izacus 7mo agoIs there a KDE/GNOME/kernel-like group forming to take over Android AOSP development and provide free alternative yet?
- deleted 7mo ago[deleted]