cross-posted from: https://jlai.lu/post/24787719

Starting next year, Google will begin to verify the identities of developers distributing their apps on Android devices, not just those who distribute via the Play Store.

  • Wrrzag@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    9 hours ago

    Is this just a signature check when installing? Could it be bypassed by getting your dev cert and just signing everything you want to install? Things like obtainium and fdroid could even have a “load your own cert” option and automate this.

  • Zerush@lemmy.ml
    link
    fedilink
    arrow-up
    34
    ·
    2 days ago

    The terrible risk that you install apps which don’t use google-tagmanager, googleanalytics and don’t send logging and user data to Alphabet.

  • toneburst@lemmy.4d2.org
    link
    fedilink
    arrow-up
    26
    ·
    2 days ago

    It seems Google has been tightening control over Android in recent years and this looks like the next major step. Most people probably won’t care and the only realistic option for users who value software freedom and privacy is to wait until Linux or another free and open-source OS becomes a viable alternative. Overall a disappointing turn of events for the mobile computing space

    • LiveLM@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      19 hours ago

      mobile computing space

      I’m starting to feel like the Mobile Computing space died somewhere around when the Subnotebooks and the PDAs died and we’ve been living illusions ever since.
      It’s the Mobile Appliance™ space now.

      • mapu@slrpnk.net
        link
        fedilink
        arrow-up
        8
        ·
        2 days ago

        They’re closing in on alternative ROMs with their fucking shitty device integrity checks, I’m afraid it’s only getting worse. I literally had to switch back to stock Android because none of the e-government apps of the country I live in NOR two out of my three banks work on /e/. Literally impossible to participate in society unless I sell my soul to Google, sadly.

        I really hope we’re able to fight back and win the war.

        • Ferk@lemmy.ml
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          1 day ago

          That’s sad, and so backwards…

          If they really wanted to make sure the data on the phone is safe, the integrity checks should be about making sure the phone is built from FOSS with available source code, that can be publicly audited and even the banks themselves could check it for security… which should actually rule Google services out, not the other way around!

        • Zerush@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          2 days ago

          Well, it’s not a cheap phone, but it’s a phone for the rest of your life, it’s full modular, that means, you can fix and change everything by yourself any component of the phone, no need to pay money to an technic workshop. Apart it offers also sys specs which fits the price.

            • Zerush@lemmy.ml
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              2 days ago

              Well, even if you can’t afford the price for an FairPhone, you can use /e/OS or also LinageOS in your Phone instead of Android, they are free and full based on the Android code, so all your apps will work in these without problems, but without Google breathing in your neck, dictating which app you can use and which not. You can also use some Linux distros made for Mobile, like Ubuntu Mobile and others, but these are not so compatible with Android apps, despite that Android is also an modified Linux, so it’s better to use the mencioned de-googled forks.

              • Echedelle (she/her)@lemmy.blahaj.zone
                link
                fedilink
                arrow-up
                1
                ·
                2 days ago

                I use LineageOS4microG but as far as I can read, this will apply to Android itself and I am yet to see if LineageOS devs will avoid implementing the measure or what.

  • ScoffingLizard@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    51
    ·
    3 days ago

    My personal favorite is how they are doing it to prevent data theft and malware. All they have ever done is trick people out of data. All of their shitty apps that I can not remove from my Samsung phone ARE the malware I do not want. Fuck Google and every person that works there!

  • Hellfire103@lemmy.ca
    link
    fedilink
    English
    arrow-up
    77
    ·
    3 days ago

    Whoa, whoa, whoa! What the actual fuck, Google‽

    I swear to Hephaestus, at this point I’m considering switching to UBPorts or Sailfish OS or something…

        • ScoffingLizard@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          19 hours ago

          I swear I just saw something the other day that said it was unauthorized outside the region. I remember thinking it was strange. I swear I remember seeing it.

            • tomenzgg@midwest.social
              link
              fedilink
              English
              arrow-up
              2
              ·
              17 hours ago

              If it helps, my comment was more riffing off of noodlejetski’s phrasing than what you’d originally said. “pulling things straight outta your ass” felt like some off-brand magician so I wanted to make a joke about that.

      • HappyFrog@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        11
        ·
        2 days ago

        This is from their site:

        We currently sell in European Union, UK, Norway and Switzerland.
        Please be welcome to use our products anywhere in the world, however due to our limited resources we can only support the noted regions.

  • doctortofu@piefed.social
    link
    fedilink
    English
    arrow-up
    69
    arrow-down
    2
    ·
    3 days ago

    And, just like that, no more modded apps, no more custom stores, everything is tightly under control unless you install a custom ROM (and then it’s no more banking apps,etc.). And it’s all for our own good, after all, big brother Google knows what’s best for us!

    • utopiah@lemmy.ml
      link
      fedilink
      arrow-up
      24
      ·
      2 days ago

      Some banking apps do work so it would be helpful not to spread that misconception.

    • apfelwoiSchoppen@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      edit-2
      2 days ago

      Requirement of authentication apps is making it trickier too. If you want to go to a concert or sporting event vended by ticketmaster, you’re fucked outside of Android and iOS.

      Clocking into jobs increasingly requires Android or iOS.

      • Ferk@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        1 day ago

        Yes, there used to be papers for “coordinate systems” you could use as 2FA, and SMS one-time-passwords… but they are slowly being rolled out in the EU due to security concerns and the “Strong Customer Authentication (SCA)” standards mandated by PSD2. EU banks are transitioning to app-based and biometric authentication now… here you literally need a phone if you want any form of online banking.

      • zod000@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        5
        arrow-down
        1
        ·
        2 days ago

        yeah, I had to resurrect an old phone to go to a concert last week. It’s possible I’ll never go to one again. I wouldn’t have bought the tickets had I known about that bullshit.

  • StarlightDust@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    64
    ·
    3 days ago

    While I won’t tell people exactly what to search, I can guarantee that I can find malware first try on Google Play. Google Play Integrity is just as dodgy.

    • floofloof@lemmy.ca
      link
      fedilink
      arrow-up
      26
      ·
      edit-2
      3 days ago

      When a preventative measure very obviously won’t solve the stated problem, that may not be what it’s really there to solve. This is another of Google’s anti-open-source moves designed to bring all Android devices entirely under their control and surveillance. It goes along with their bringinh all Android development in house and making it harder for third parties to make their own custom versions of Android (Graphene OS etc.). It also seems a little odd that this happens right when several countries are introducing requirements that users supply ID to visit websites.

    • Grazed@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      2 days ago

      What would you get instead? I think if Google actually follows through with this, I’ll switch to LineageOS, which is still Android. Obviously, iOS is much worse on this front.

        • COASTER1921@lemmy.ml
          link
          fedilink
          arrow-up
          7
          ·
          2 days ago

          There’s no alternative that won’t have major limitations. I predict it’ll just be more like going back to the days of jailbreaking to install unsigned apps. Unfortunately AOSP is already pretty much unusable without Google services installed for the vast majority of apps.

          • thedruid@lemmy.world
            link
            fedilink
            arrow-up
            7
            arrow-down
            1
            ·
            2 days ago

            I’ll thank you to not rain and piss facts on my moody parade. Just leave an irrationally cranky old man his delusions. Lol

  • tomenzgg@midwest.social
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    2 days ago

    I’m probably going to spam this around a bit, since most people don’t seem to know about it, but a reminder that FuriLabs has a (GNU+)Linux phone with decent spec.s and the ability to run Android app.s (from what I’ve heard) pretty decently: https://furilabs.com/

    Biggest drawback is it’s based on Halium. Usual growing pains of a new product/company apply but apparently the company is pretty responsive and their dev.s have worked with customers to get things like calling working with the carrier and bands of their country where it hasn’t worked before so improvements move pretty quickly.

    Collection of different experiences I’ve variously seen online over the last year or so:

    I don’t own one, myself, so I can’t give any personal experience but I’ve seen it around for a few years now but most people don’t seem to even know about it. Maybe there’s a reason for that? But none I’ve ever seen anyone say.

  • apfelwoiSchoppen@lemmy.world
    link
    fedilink
    arrow-up
    33
    ·
    3 days ago

    Wish we lived in a world where open source was funded even at a single percentage of what this oligopoly pulls in each year. We’d have a viable alternative to the duopoly by now.

    • smiletolerantly@awful.systems
      link
      fedilink
      arrow-up
      5
      ·
      2 days ago

      Baby steps: I wish it was mandated that any software receiving even a penny in public funding must be open source down to the last byte.

  • utopiah@lemmy.ml
    link
    fedilink
    arrow-up
    20
    ·
    2 days ago

    Time to fund /e/OS GraoheneOS etc but also bridges like Waydroid until we can use e.g. PmOS and avoid Android altogether.

    • rezad@lemmy.world
      link
      fedilink
      arrow-up
      9
      arrow-down
      1
      ·
      edit-2
      2 days ago

      Time to fund /e/OS GraoheneOS

      no.

      those are just android with some modification. two years from now google can easily disrupt them too.

      phones need a copyleft new OS. not a foss one, an actual copyleft one. with an independent group managing it.

      an OS that a company can decide what app I can run on it is just a surveillance apparatus gadget.

      google never wanted user to have control of their phone even 10 years ago.

      the easiest way to check this is to see if you can stop an installed app to ever do stuff without you explicitly opening it. they are so many “triggers” that apps can register and run based on them that user cant do anything about them. “wifi connected” “wifi disconnected” and so on.

      if an app can “listen” to these triggers and I cant disable it from listening to them (even for non-system apps) them I don’t really own my phone. then android is just a attention stealing spam machine at best and spying and terror gadget for world’s supremacist regimes too.

      I think even apple iOS has that option (disabling backgournd refresh per app ) and in that regard is better than android. If I wasn’t against non-foss software and I didn’t live in Iran, at this point apple iOS is not that different fro google and is more polished too.

      • utopiah@lemmy.ml
        link
        fedilink
        arrow-up
        4
        ·
        2 days ago

        Sure I’d support that, is there such a project or starting one? If not what’s the closest?

  • ☂️-@lemmy.ml
    link
    fedilink
    arrow-up
    24
    arrow-down
    2
    ·
    edit-2
    2 days ago

    yup, they are closing in. i wonder why the surveillance wing of the fascist regime wants to control everyone’s digital life that more tightly.

    you guys may have the power to protest this before it goes worldwide. i wonder if there will be real pushback.

    • SugarCatDestroyer@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      2 days ago

      It is unlikely that there will be a real resistance, the majority will resign themselves like submissive cattle and only a few will try to fight to the end, I have already seen this in history.

    • Echedelle (she/her)@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      5
      arrow-down
      2
      ·
      edit-2
      2 days ago

      I mean, some of us did when GrapheneOS and folks started to bootlick goolag for their walled garden in pro of security as well as the economical breach they did not cover (Pixels are not available to everynyan) and even incentivated.

      Yet here we are again.