4 ms·
That's why you should be downloading from F-Droid anonymously.
by codedokode 5mo ago
That's why you should be downloading from F-Droid anonymously.
- EvanAnderson 5mo agoFor sure. Another demonstration of why "side loading" software is better.
- logicchains 5mo agoThat's why F-Droid eventually won't work on new Android phones.
- bigyabai 5mo agoIt works right now, though.
- nathanmills 5mo agoNo, it will continue to work just fine. The restrictions are being added to Google Play Services, not Android itself. I and many others do not run closed source software like Google Play Services on our devices.
- xp84 5mo agoAnd how long do you think that window will remain open? I expect anyone not running a closed system (hardware attestation) is going to not only be locked out of things like banking apps, government apps, etc., but also if Google has its way, you’ll be prevented from accessing those things on the web as well, maybe even from your desktop. We just saw that story a few days ago with them replacing CAPTCHA tech with “prove you have an unmodified locked-down Google or Apple phone.” Clearly there is a single driving agenda, which Google and the government are largely in harmony on, to try to approach 100% real-identity-tying to every activity done online. Where once, “online” meant generally greater anonymity than “IRL” activities, since most things could be signed up for with an arbitrary throwaway email address and no proof of identity. It is now or shortly will be the opposite.
- nathanmills 5mo agoForever, honestly. I don't see things actually becoming as closed as you predict. I will avoid banks that require me to do any of that (I already don't use any that report to credit agencies, avoiding ones that don't work on the web browser is much easier). There is about 1 site I use that uses the google captcha and that is archive.today, I will swiftly stop using it if I can't use it with open software, and I doubt they would keep it around in that case anyway.
- JacobKfromIRC 5mo agoWhat software do you use for the reCAPTCHA on archive.today? I use a fork of hacktcha [1] but I had to modify the software myself to get it to work conveniently [2], so I'm curious how other people do it. [1] https://git.koszko.org/haketilo-packages/hacktcha/ https://git.koszko.org/haketilo-packages/hacktcha/ [2] https://codeberg.org/JacobK/unfinished-site-fixes/src/branch/main/archive.today https://codeberg.org/JacobK/unfinished-site-fixes/src/branch...
- behaviors 5mo agoThis is very SaaS optimal. I never use these types of services on a "smartphone" device. I honestly think my OS (derived from AOSP) is more secure than googles "trust." Every android device is not an identity tied to a account. Many phones exist with no accounts whatsoever.
- VLM 5mo agoWe're going to have two phones, the big brother phone you usually leave at home for banking apps and tax filing and boring stuff like that, locked down and nanny up, and the "real phone" from aliexpress or whatever that is purchased rooted and you actually live your real life upon. I would not be surprised to see double sided phone cases so we can carry our big brother phone with our real phone. There is some prior art in people being forced to carry a "work phone" and a "personal phone" at the same time. There will be strange product marketing effects. If you only carry one phone, you can currently talk people into spending over $1K on a high tier big brother phone. But if you only use a big brother phone for bank apps and only at home, a $1K phone from Apple or Samsung is a hard sell, I'd be more likely to spend $1K on a really nice anti big brother phone on ali express or whatever.
- gruez 5mo ago>and the "real phone" from aliexpress or whatever that is purchased rooted and you actually live your real life upon. Ironically the phones with best third party rom support are google pixels. Good luck getting lineageos support or even unlocked bootloader on a random aliexpress phone. You might be able to sideload without restriction, but the ROM is probably gimped, won't receive updates, and has random privileged apps possibly spying on you.
- Denatonium 5mo agoSome of us are already doing this. My main phone is a Google Pixel 8 running LineageOS 23.2 with F-Droid, microG, and Aurora Store installed. For things requiring Play Integrity, I picked up a $20 burner carrier-locked Motorola phone at Walmart for $30. It's WiFi-only, given that I'm never going to pay for service on it, but I can also tether it to my main phone. It's also useful for writing one-star reviews on apps that require Play Integrity to function, which is something everyone should be doing.
- ashirviskas 5mo ago>For things requiring Play Integrity, I picked up a $20 burner carrier-locked Motorola phone at Walmart for $30.` So it's a $30 burner phone, not $20?
- password4321 5mo ago99% sure Google would still know the app was run associated with other identifiers, but probably won't be turned over with the list of users downloading from the Play Store.
- tencentshill 5mo agoAny device with Google services installed has all apps scanned at least once per day. >Real-time protections for non-Play installs Google Play Protect offers protection for apps that are installed from sources outside of Google Play. When a user tries to install an app, Play Protect conducts a real-time check of the app against known harmful or malicious samples that Google Play Protect has cataloged. https://developers.google.com/android/play-protect/client-protections https://developers.google.com/android/play-protect/client-pr... They will also go further for apks with novel signatures - take a copy, upload it to google to decompile and scan, and then if you have their express permission, allow you to install it.
- gruez 5mo ago>Any device with Google services installed has all apps scanned at least once per day. You can turn it off, so it's not "any". At best it's "most".
- tylerchilds 5mo agoAlso I daily drive graphene and that has no Google play services
- bornfreddy 5mo agoUnless you want push notifications.
- nabakin 5mo agoThen you can sandbox
- bornfreddy 5mo agoTheir app is still running all the time. I do not know what exactly it is collecting, but I'm sure it sends a lot of information to Google. Even just the fact that Google knows my IP (which is otherwise dynamically assigned) at any time is too much. On the other hand, if you try selectively enabling and disabling the service, the push notifications stop working. LineageOS + MicroG is a much better solution if you only need them occasionally and if you prefer an app which does not actively (try to) spy on you.