Android 6.0 Marshmallow Reviewed
arstechnica.com
arstechnica.com
google still does not get the fact that some apps do not need, and should not be able to transmit or receive data from the network. We still need root and install AFWall+ to secure our phones.
PfSense is a free gateway firewall but the UI left much to be desired last I checked. Another option is the Sophos UTM, which has a firewall, web filter, and VPN server built into one.
Gateway protections are your last resort when it comes to protecting yourself from shady behavior like this.
I won't buy a phone that doesn't have that feature.
i still have one question in a forum about why Android browser's ignore etc/hosts, and every now and then (question is 6 years old) people comment how shocked they are to discover that is the case (still!)
Or feature? I'd love a firewall rule that could block any traffic that contains my contact list. Wouldn't be possible even if the traffic wasn't encrypted...
Maybe scatter a few of these contacts through the alphabet to catch apps sending in batches.
As responsible developers they wouldn't want to send your entire address book across the wire in the clear, would they? Why, someone could easily listen in and then you would have no privacy! /sarcasm.
To make it harder to write an ad blocker
Of course its ideal to not send the packets and waste the battery at all but when that's not an option, I'd rather use a firewall to block the traffic rather then just let it through, regardless of the hit to the battery due to it constantly retrying the blocked connection.
Compared to my experiences with the Sophos UTM, it's downright painful. With the UTM the UI elements of every part of a service are grouped together, and are duplicated in sections where it's intuitive to do so. Eg Certificate Management can be found in multiple places in the UTM but all things related to the web filter are in one place, all things related to routing are in one place, et al.
Luckily they are redesigning the GUI for the next version, I'm hopeful that they will rearrange it as well (even though that will obviously be awkward for everyone already familiar with it) but I don't know, haven't paid attention to the development.
Case in point: Reboot, shutdown and Backup/Restore ought to be under the "System" menu, right? Nope. It's under Diagnostics, which is a large alphabetically sorted list (not by functionality or anything else, so if you are unsure of which term was used, well, you're better off consulting google).
I much prefer to support PFSense because they seem more supportive of their community, I will be looking forward to trying out their new UI when its out!
The first 3 words are still "Don't be evil"
You're confused about the news that Alphabet now has a parent Code of Conduct that is "Do the right thing". But Google retains "Don't be evil".
I recall that "Don't be evil" was criticized for being passive and morally neutral; Alphabet's new motto addresses that.
I. Avoid Conflicts of Interest
II. Ensure Financial Integrity and Responsibility
III. Obey the Law
https://investor.google.com/corporate/code-of-conduct.htmlThe internet permission was never accurate. Malicious apps had plenty of ways to get data off of the phone. The INTERNET permission was promising something that was not enforced. Something about it had to change, and seeing as connectivity is heavily assumed and ingrained into everything it makes sense to just nuke the false permission.
Practically speaking the main users that want INTERNET to be a permission and to revoke it are people that want to block ads. That's a moral grey area at best, so making that harder is far from "evil".
I'm not sure where the grey area is here. I am not under any moral compulsion to make requests on a network just because an app developer wants me to. Building structures to force me to make those requests is definitely leaning into evil.
In fact, it's the last straw for me, personally. I'm back to iOS and the "evil" walled garden that respects my rights as a network user.
bad news: iOS has always granted network access by default.
It's not the frequency or importance of popups. Users simply don't read them. From watching users, the users who don't read them usually have an image in their minds of what they're trying to accomplish and an image of the screens they need to go through to get there. Any popup or notification screen is instantly dismissed so that they can see the screen behind and try work out if it's where they expect to be. It's maybe 25% of users who do this, but they do it constantly regardless of what the popup is.
This alone is the reason I will not use Android 6 before they either change this or there is a good firewall available (and I am able to root my device)
I wrote a mental note that that when I have to start thinking in this manor and tread carefully in a minefield then the technology does not serve me any more and I don't want it.
Time up.
I think that Google is way aware of the situation. The problem is that most apps need internet access in order to work. A permission that most of the apps will have to ask for is useless because the casual user will just be trained to accept it in all cases. AFAIK, that's how iOS handles network access as well. Permissions are here to safeguard the access to your personal data, that's it.
No, it's not. Carriers and OEMs that have picked up AOSP and bloated it needlessly are the ones who are behind. You wouldn't blame Linus Torvalds for all the computers out there running outdated kernels, or for anybody still using git 1.x.
The difference is that downstream companies have decided that since the have the source, they might as well add a year of dev work on top of Android to "improve" it. If they had these options for Windows or iOS, I'm pretty sure they would do so (ever bought a new windows laptop with no crapware?) and bring security updates for those devices to a grinding halt.
I know it's not a straight comparison, but Apple managed to wrangle the carriers into not making this a problem. Why can't Google?
Just because Google and OEM X have some agreement doesn't mean that Carrier Y trusts OEM X not to muck up their network (or their bloatware). So carriers end up adding their own drawn-out testing process for their own reasons, probably including time to update their carrier bloatware.
I should point out as evidence that I use a major carrier and run a Nexus phone, and I have no issues whatsoever getting Google updates, security or otherwise. I expect to have Android Marshmallow on my handset by the end of the week.
As a platform vendor, IMO that's their job. At a bare minimum , to ensure their users get the security updates they need.
On Android, the vendor needs to build the OS for me. Even with AOSP that's true, the Android driver model basically means modifying Android. Vendors are generally doing a good job of upstreaming kernel drivers, but Android has this whole awful userspace driver stack as well. You'd think at least one benefit you'd get from the Android HAL is pluggable drivers, but sadly no.
What rot. Driver problems are not exclusive to phones, nor are custom terrible drivers. This is a problem that exists throughout the spectrum of products.
I can't wait for this one to be solved
A billion non-geek, non-HN, non-ArsTechnica device owners are not going to re-flash their phones with a custom ROM. Those consumers will have to get Android updates as a seamless upgrade from their phone carrier, or not at all.
In other words, the "I can't wait for this one to be solved" was not a personal plea for help but instead, a commentary on the old software the 1 billion consumers are stuck with.
This could provide us with:
No more (at least non-google) bloatware
No more needless recreated basic features (AT&T messaging, navigation, Samsung Messaging, etc.)
Can actually update the OS for security problems
The device manufacturers are able to embed their brand's identity into the device. They're members of OHA and they like "needless recreated basic features."
The networks have nothing to say in this in 90% of the world. They're not phone-vendor's customers. They merely want the latest data-gulping phones on their network so they can charge their real customers (people like you and me, which are also the phone-vendor's customers) money for consuming bandwidth.
I get that things are messed up in the US, but don't generalize this to the rest of the world.
Most networks and cellphone operators around the world sell generic phones, with unmodified software, unlockable bootloaders and carrier-provided SIM cards.
And for those phones, which you will find in big parts of the world, having Google responsible for software-updates would work just fine.
That means forcing the manufacturers to release the source of any component not behind a stable ABI, and release at least the binaries of any component behind them such as apps (with a suitable license).
They have two ways of doing this:
1. Make it a condition for bundling Google Apps
2. Relicense Android with GPLv3
The phone manufacturers aren't really in a position to negotiate (can't lose apps), so they should go along.
Once this is done, they can just have the Play Store offer or even require updates to the OS.
Not sure what Google gains from not doing this, it seems they are just gifting users to Apple.
In many countries the choice is between Android and Windows Phone, not iOS.
Specially in countries where people go with pre-paid and the average salary cannot afford the usual iOS contracts.
I do wish the vendors would keep up with security fixes, though. That's the real problem with Android updating, IMO.
^ That is the thread and it was closed, not deleted (a subtle but important distinction)
It's been a while since I've unlocked an HTC for someone else, but I've never had issues with mine.
Even though Verizon has blocked HTCdev access to unlock our bootloaders...
The only option to unlock on these carrier-locked devices is a software exploit that a group of hackers charge $25 to run on your phone.
This meets my expectations for what is reasonable, but I understand others will have a different opinion.
I sure hope you don't mind bringing what is essentially a vulnerability vector into whatever wifi networks you connect to...
Not changing my policy to deny wifi access to Android (or Win10) devices visiting my house.
But if all the other devices are secure, then what is the harm in allowing an insecure device onto the network?
I suppose they could become host an exit node or seed an illegal torrent or something, but you (personally) have indemnity as an impartial carrier in that case, right?
I'd also suggest looking into a segregated guest network.
I'm not expecting Marshmallow to roll out to my device at all, and nobody that I know who use cheap android device does.
Honestly, the features of the OS are not worth upgrading. The only thing that suffer is my gaming abilities. I can't play the most recent games on it... I guess. I don't game on my device.
Average Android user don't care if they are not cutting edge. They would be using Apple product if they cared about that at all. The only exception are those users that purchase the high-end products. Those will gladly trade their phones to stay up to date, they are the ones in the statistics that keep up with the latest versions. The average user are using Android because it's "the cheap smartphone".
I will move up the chain if main features start to break. So far, browsers, social media networks and all those things have been backward compatible. When they won't, I'll trade in my phone, pay $50 and get another low budget Android phone.
- if you have animations disabled in Developer Settings, re-enable them
- Reboot
- Pull down the quick settings toggles, long-press the gear/settings icon at top right. It should spin and then tell you UI Tuner is enabled
- You can then find it in Settings, and can re-disable animations
I had animations disabled and it took me forever to figure out why I couldn't get it to work.
Curious as to how they're getting away with it. Maybe because it's open-source, so someone could replace the default if they worked hard enough? On the other hand, in the MS anti trust days it wasn't hard to choose a different default browser--and it was certainly easier than changing source code.
I don't mind Google's bundling as much because you can still use Android without it. Old versions of Windows and current versions of iOS are irritating because can't remove those default apps. They're just always there, and sometimes you can't even replace them with alternatives.
In the MS anti trust days, you couldn't delete IE either. But you could use Firefox instead, and just pretend like IE wasn't there. Android seems like that kind of situation to me--you can't delete the Google defaults, but in a deep, dark advanced menu you can disable them at best, after a scary warning. In other words, you can use alternatives to Google apps, but you have to pretend like the defaults aren't there--but they always are.
AFAIK, All the Google branded apps & Services are part of Play Services. Nothing prevents you doing what Amazon is doing and create a device from AOSP, don't include AOSP and replace it with your own services.
IANAL, but it seems that the focus is on the fact that Play Services comes with a full suite of apps.
I would have taken a screenshot, but since the phone wasn't setup yet, I didn't think it would work.
I thought I should try landscape orientation to make it recalculate the layout, but I couldn't scroll at all in landscape. The screen reflowed correctly, but the page was unusable in that orientation.
I know that setting up a new device is not a common experience, but I'd hope Google would have better QA in place for a major release like this. Then again, having spent over a decade using Google products, I should know better than to presume anything about their QA process.
/facepalm
Who decided that the world shall enforce white backgrounds for everything, while eliminating user control? Even Windows 3.1 had themes.
I think that's because the fonts have become smaller and all the vector graphics now use a very thin stroke style, so there's less lighted pixels against the black background.
https://play.google.com/store/apps/details?id=pt.bbarao.nigh...
It's a limited, partial solution at best. If it reversed lightness instead of going negative it might be more helpful.
You can trivially root many Android devices and do whatever you want.
The amount of technical insight and accuracy in a this review does actually impress me.
I believe stuff like this not to be common knowledge even among a more technical crowd like HN, yet there it is in a geek/consumer-oriented OS review.
The number of settings in general seems much less (I'd kill for a setting to disable that immersion mode that hides my back/home button, personally, but no luck) so I think they are going full steam toward Apple style, they know what is best for you.
http://superpowered.com/androidaudiopathlatency/#axzz3nj4FLE...
Lean mean, fast and stable.
Just fix stagefright and stagefright 2.0 and it's a wrap.
you can rip out the "cloud services" if you have root
http://developer.android.com/reference/android/Manifest.perm...
If you were asking something else about SD cards, then you probably want to check this part of the review: http://arstechnica.com/gadgets/2015/10/android-6-0-marshmall... (which would have been found if you'd searched for "sd card", it's in the table of contents)
And no, I have not read article yet, will do later. Was expecting tl;dr ansver to my question.
> Was expecting tl;dr ansver to my question.
Seemed rather odd to spend the time writing out the question and reply compared to just doing a quick search.
You could have used the last three days to try downloading any one of many file managers on the play store and seeing if they did what you wanted.
Or you could have bothered to do a tiny bit of searching and found that the security restrictions changed when lollipop came out.
Personally that single feature makes this a worthwhile upgrade, it seems I'm endlessly managing storage on my 8GB of internal storage despite having a 64GB SD card which has barely been touched.
Gotta increase those ad impressions.
The who should not be enabled together. One is about giving your Google services' data to Google and the other is about giving all of your other data to Google as well.
I can't wait until real privacy laws arrive in the EU.
http://arstechnica.com/gadgets/2015/10/android-6-0-marshmall...
" The assistant app only gets data about the current view if the user long-presses on the home button—it's not a passive scanner.
If all of this sounds like a privacy nightmare, the assistant feature can be turned off in the settings. Head to Settings -> Apps -> Configure Apps (the gear button) -> Default Apps -> Assist and Voice Input and turn off everything. Here, users can also set which app has access to the Assist API (there can only be one) and pick between sending the app text-only or text and a screenshot."
To make this work, holding down the home button allows Google to "read" the screen by combing through the Android text fields and view hierarchy, sending Google that text plus a screenshot. This will work not only in Google apps and in the browser but in third-party apps too, as long as they use the standard Android framework bits. Apps can be data providers for the feature, too; for instance, in the famous actor example above, the IMDB app could provide a link into the app to display the actor's filmography.
I know, I'm old, but every time some "feature" like this pops up somewhere, I still can't believe that people don't mind using it.