F-Droid version of KDEConnect uninstalled by PlayProtect
discuss.kde.org
discuss.kde.org
If I have to explicitly reject it more than once, it is obviously malware. Once is already arguable.
Edit: apparently according to a post below he's still involved just not lead dev anymore. Sorry I missed that part.
No denying the guy isn't a no-joke developer, so, his code and work would be valuable, but only if the bigger picture didn't depend on his judgement.
It's not that I have a specic scenario of a particular bad thing he might do, like make a backdoor for the government or secretly collect & sell data, or even something like somehow ban you from using as an individual he didn't like because you criticized him or something. It's that once someone is shown to be that irrational, then all bets are off. You don't have to have a specific proposal of what they might do, because they might do anything.
Anyone might do anything, and the only way you can function is you just have to trust other people, and the only thing you have to go on is very little in most cases. So you have to give strangers the benefit of the doubt until there is some reason to doubt. And this guy acting this way is more than enough to avoid. It's not like there haven't been countless examples of people who seemed good at first going off the rails and taking a bunch of users down with them. It is entirely valid to see this guy and go "Nope. Avoid.", and that would not be a case of just ignorant discrimination against non-conformity, it would be using your nose for what it's for.
But if we don't actually have to trust him as much as before, that changes things.
I was following CalyxOS' progress at the time because they were working on enabling support for some OnePlus models but right around that moment OnePlus came out with an update that made it impossible to do change the bootloader signing keys and they abandoned the project (which I understand). I'm also a huge fan of MicroG and really prefer this open-source approach over the sandboxed google play approach. And I'm critical about some of Graphene's stances, around SafetyNet in particular ("We don't lie about security features" - I don't agree attestation is a security feature but in my opinion it's more about control/DRM). So yeah if I had a choice I probably would have gone for CalyxOS. But I'd never even heard of the guy before this happened. I had nothing to do with any hate campaign (which I doubt even exists).
But no, I don't want someone like that deciding what code goes on my phone.
It's a telephone, with a computer on it in your pocket with a shit load of sensors. The computer part involves components from many parts of the world, with many opaque subsystems. The OS is sort of Linux with knobs on and a lot of opaque parts - the first layer "belongs" to a prolific ad slinger hell bent on knowing everything about you. Then if it isn't a Google jobbie, it will have another layer of software, lots more shiny and a lot more data gathering (eg Xiomi/Samsung/whatevs). Then your "TSP" gets to put their spin on it. All three layers can sell out to eg MS for yet more data gathering and ads and profiling and so on.
Apple does the same but manages to be layers 1 and 2 and be a bit cooler about the whole thing.
You worry about Graphene?
I don't advocate for full Luddite (I run an IT company) but please get some perspective. If you are concerned about Graphene, I suggest a burner feature phone or smoke signals.
EDIT: I have F-Droid and KDE Connect wired up to both of my Arch (actually) boxes on my Samsung Invasive Intruder ... sorry Galaxy S23. I'll try switching out the Play version of Connect for the F-Droid one and see what happens.
I hit Uninstall and within a few seconds the button switches to Install.
I hit install and the app is installed from F-Droid. I open it and pair my phone to my laptop.
One data point. Perhaps a knob has been twiddled in the Chocolate Factory in response to this article. There are a lot of Googlers here.
(EDIT: formatting)
EDIT2:
I've gone into the Play app and got Play Protect to scan apps: "No harmful apps found". KDE Connect is still working
Someone else said that the head guy isn't the head guy any more so the biggest problem may not be a problem any more. The idea, stated ideal, design, & construction (as far as one can tell honestly) of the os are all fine.
But the point was, you don't need any more reason than his behavior to avoid granting him such a priviledged place in your phone, which holds such a priviledged place in your life. Just on basic principle. You don't need to justify that to anyone and he or the project does need to justify why one should trust them. The usual justification is merely the utterly flimsy weak one of benefit of the doubt. It's more or less impractical to actually vet strangers, and so you just grant benefit of the doubt until there is some reason to question. But that goes out the window the instant there IS any reason to question.
People have different tolerance for risk, and so, you might be fine with saying "that guy is acting a little weird in this way, but whatever, probably he can still be counted on in this other way.", but no one else is obligated to. And this example of "weird" was not just neutral irrelevant non-conformity.
There have been countless examples of people in positions of responsibility and trust going off the rails and taking a bunch of users down with them. There is no reason not to use your nose for what it's meant for in this way.
But like I said, maybe the problem is resolved now by the fact that we don't actually have to trust that guy any more. In which case, ok.
Don't trust. Verify.
Even if there were something special about graphene that made it more desirable, the real way to deal with an open source project with something unacceptable about it's production or management, is to fork it. But I already have something else to do all day, and am happy to run lineage or calyx or or others. If I did need a fork, I'd need someone else to do it, and I'd have to trust them.
Fork it or help someone else who is forking it or work towards changing the original (which is what seems to have happened actually, so this is all a bit academic now), or just use anything else, are all more reasonable responses than "the people producing this thing with access to all my communications have shown themselves to be off the rails, so what I'll do is keep using it, but personally read all the code in an entire android os."
It seems to me that it's no different than running a non-Microsoft/Apple operating system on desktop.
Dear Google UX designers, the way you present your little "decline" links is illegal in the EU. I'm sure you've got these design directives from a product manager, but you can still say "no" to breaking the law.
But I don't see the problem with the decline link and EU law?
AFAIK, most EU regulations are about tracking and consent in using your information...
In this case, you're already using a Google product (the Messages app), and Google is just (aggressively) nudging you to use extra features that they have shipped in their app. It doesn't follow that Google is definitely going to use more information to track you than it would've done before (though it could be possible, of course)
...of course, I fully agree that this doesn't embody their "respect the user" ethos, but frankly... If you worked on new features for your users, I think it's fair to nudge them to try to make sure that what you worked on will end up benefitting them (of course, a company behaves differently than an individual, and it's not guaranteed that the work done might actually have merit... But that's orthogonal to this discussion)
Here's the consent popup: https://imgur.com/a/PIqcDgR
The design of such consent popups has been deemed illegal in the EU, Google was also previously fined [1] for a similar consent popup. The "REJECT" button needs to be just as accessible and needs to have about the same visual weight as the "ACCEPT" button, dark patterns like the ones you see in the RCS consent popup above are illegal.
[1] https://www.theverge.com/2022/1/7/22871719/france-fines-goog...
"Honestly, the days of any third-party SMS app are numbered."[0]
[0] I asked Signal motivations for SMS removal: https://news.ycombinator.com/item?id=33258684
If there is one thing like about EU, is that it's the only one in the world standing for the user's rights keeping these companies with their antitrust pratices in check.
If it weren't for them @pple wouldn't have switched to USB-C
There's a timer that re-enables the Play Protect nag after a certain period of time. I can't remember how many days it is.
You can permanently disable it by running the following over ADB or a local shell. Works for me.
# This should disable Play Protect. Maybe.
# https://android.stackexchange.com/questions/187097/is-there-a-way-to-control-use-google-play-protect-together-with-microg-open-sou
settings put global package_verifier_enable 0
settings put global package_verifier_user_consent -1
settings put secure package_verifier_user_consent -1
settings put global upload_apk_enable 0
settings put global PACKAGE_VERIFIER_SETTING_VISIBLE 1
settings put global PACKAGE_VERIFIER_INCLUDE_ADB 0For example Im using a device which is 1/4th the price of cheapest first hand pixel that I can get
:(
They also have a pool of accounts you can use by clicking “anonymous”. They do get banned frequently, and you have to re-login once in a while (for me it's almost every time I want to download something new again), but it is definitely usable.
Maybe they can add some web scraping thing to sidestep this issue completely?
I already run LineageOS, but with Play services. I would like to be able to ditch Play services, but still need the Play store for things like my banking app, and an app to log in to government services.
I'd say it's a toss up whether specific apps will definitely work. But if they don't I'd recommending segmenting between different physical devices, and making the one that lives in your pocket as secure as possible. It's likely that you don't need to run banking and government apps on the same device that's privy to your movement.
And banking / government apps tend to work in Europe (at least the ones I have tried). Notable exceptions for me are Revolut (shame!) and McDonalds (who knew microG is the healthier option haha). Of course, in the US things might be vastly different.
These mobile payments only work with your banks app or a dedicated app (Payconiq).
My current approach is to put all these apps in my work profile which I can turn off (using Insular from F-Droid). Only apps for which I need background activity or instant notifications (Signal, an open source podcast app, and sadly WhatsApp) are installed in the main profile.
Sadly, this approach still requires me to have Google services always running in the background for a functioning Play store in my work profile.
* but I have to admit that the hardware is quite slow
It is because computers run one of a few available OS's. The OS is being maintained by the distributer (MS, Apple, Google) and your hardware is good as long as the drivers are still receiving updates.
Phones are different because even though everyone only uses iOS or Android, every Android manufacturer puts their own layer onto Android, so Google can continusously update it but the manufacturer might not. Most companies only maintain their phones for about 3 years, giving a significantly reduced lifetime than computers.
It still works fine, from from a security perspective, keeping the phone without patch support is a bad idea.
It is really annoying how every vendor cobbles together a Frankenstein abomination of a kernel with just the right drivers and patches and good luck trying to run anything else. But I also understand that they (except maybe for Google) have no interest or incentive to clean up this mess.
Fairphone 5 will receive security updates for 8 years
Pixel 8 will receive updates for 7 years
iPhone 15 will receive updates for 6+ years (apparently, Apple has a track record of between 6 and 8 years)
My laptop is also from more than a decade ago, and I'm happily running LMDE 6 on it.
Everyone doesn't have to live like this, but it's utterly valid, and no one has any right or justification to try to tell anyone else not to.
I can buy anything any time, but I miss swappable batteries, headphone jack, sd card. These were all basic utility features than made a device interoperable and more generally functional. Removing them only benefits the people selling new phones, wireless headphones, and cloud storage.
My old vaio 3 laptops ago is actually still perfectly fast enough at what I do today, it just only has usb2 ports, which eventually became too big of a pain point. But it also had a real docking station that you plop the machine into, not the stupid "docks" we have today that are not docks but just mega-dongle-hubs where you connect a usbc cable. I miss that dock every day since 5 years ago. I could easily still be using it today even though it must be 15 years old or more by now. And if I were, no one else would have any justification for trying to say that I shouldn't, and no software or service provider would have any justification for artificially creating some incompatibility that only serves their goals instead of mine.
But it's still doable for many people. I most recently bought a second-hand Pixel 6a for GrapheneOS, and BYOD it to an inexpensive no-contract plan.
Pixel 6a units with unlockable bootloaders are currently $235+ on US eBay, which is less than new current Pixels and iPhones bought outright, but more than many lower-end devices, and more upfront than people pay for contract plans that toss in a phone.
It's very interesting because 1/4 of Pixel 6a would be around 80 EUR... so I wonder about your environment and what workarounds you have for these problems.
The device I use regularly is moto g14 which is at about 8500 online, with discounts can go for 8000.
Honestly there is no work around as the moto g14 comes with a 4gb ram and 128 GB internal storage, 6.5 inch screen and 5k mah battery, it can do pretty much anything.
I've just started working full-time after college and now I earn more than enough to buy pixels or iphones but currently the money is going on other important things that were pending
It was much easier to find a Pixel 4 or a 4a, but those were too expensive for me.
I mean, if I was a three letter agency, sneaking into some GrapheneOS developer’s basement to add a camera to record his keystrokes would be the easiest trade ever for all the paranoid people using it. It’d be way easier than sneaking into Apple or Google. Might even be worth violating internal law to do it; because getting caught is extremely unlikely, and forgiveness is easy.
Edit: Also, don’t forget that, if you should get arrested, “he used GrapheneOS” is 100% going to be used against you in court. You might use technical arguments or principled reasoning, but that doesn’t resonate with juries. Unfortunately, using extra-strong privacy tools is perfect for framing you as a criminal.
> “he used GrapheneOS” is 100% going to be used against you in court.
I look forward to using this as a litmus test for legal representation.
A. The builds match the code?
B. The NSA hasn’t stolen the signing key and isn’t feeding you customized images?
True, you can’t verify that with iOS or Android either. I am saying though that trusting my security because it’s safer… by being in some guy’s garage feels like an odd trade. One that shouldn’t be casually ignored, at least.
Your comment is basically "is it perfect? No? Then it's not better".
There was a university that received a bomb threat over Tor. They found one student who used Tor on the network at around the right time, and because he was the only Tor user, he’s in jail for a very, very long time. That kid was at Harvard, his persuer the FBI.
If you are going to use GrapheneOS, don’t be naive and think it will make you agency-proof. If anything it probably flags you to their attention.
Please.
I do not condone or endorse illegal activity. That does not mean your use of GrapheneOS might not be used against you if you use it at an inopportune time. There is currently almost no discussion online about this, so it’s worth a mention.
Edit: I forgot to mention some obvious context in my head. Think journalist, in Russia, using GrapheneOS for “safety.” In such a situation, probably a terrible idea.
A mention, not a core argument against use.
In my reading, your core point is an old argument: https://en.wikipedia.org/wiki/Nothing_to_hide_argument
"You're painting your fence beige instead of white? Are you sure that's a good idea? What if there's a crime committed in the neighborhood - beige-fenced deviants are the first that the police will look at!"
GrapheneOS is likely not a secure system, but neither is any smartphone OS. I'll compliment anyone taking steps towards transparency that makes governments and global-scale corporations tremble at the knees.
It actually put a little fear in me because I look around and not a lot of internet users in my small hell hole of an open prison I call home and i was like "dude. You're like a alert beacon screaming here is a tor user, check him out".
I was using tor at the time and that is the last day I used it because this use case fit me somewhat. Not for sending bomb threats but because the nature of surveillance, I am a target of the government so any outlier gets flagged pretty hard.
Let's give some credit to Daniel Micay and assume he isn't coding this by himself, especially after the CopperheadOS debacle.[0]
Also Daniel Micay no longer works on the project.
This isn't true. He stepped down as lead dev. Still one of the main contributors
For the rest of us, who just want to be violated less, we have to choose our poison. The corporate options are shameless violators, and the alternatives are gambles.
Weakest link in the chain and all that. There are just a lot fewer links in the chain. More likely that a vuln is introduced as part of Android and makes its way into GrapheneOS than directly into a tiny project.
Has that ever happened?
I hadn't heard of that, and people have been running GrapheneOS (and Copperhead before it) for many years.
The first person I knew using it was a lawyer at Harvard Law School.
Isn't it better to focus our efforts on projects unrelated to Android, especially since some viable ones have appeared recently : Librem 5 and especially PinePhone.
When you get to the lowest level, technically, the banking apps want to store files on the phone that the user can't access.
This means that something like lineageos can run banking apps, if the phone tells the banking app what the app wants to hear. It's fiddly but can be done, and in fact it is what I do on my private phone. It also means that a platform that fundamentally gives users the right to read all the files on the phone (ie. to make a complete backup) will not be supported by banking apps, because such a platform will not let the banks do what they think they need to do.
I think this implies that such platforms can't grow beyond a niche within a niche.
In end effect, the banks treat a non-rootable device as suitable as a "something you have" factor, but will not treat a rootable device as that.
Oh, it’s fsflover, the poster with the Librem idée fixe. Haven’t noticed you here in couple of years. Your comment elsewhere here about GrapheneOS not requiring much less effort to daily drive is way off. GrapheneOS runs banking apps and, in countries that legally enforce use of certain apps for ID or payment, those apps, too. Zero hoops to jump through. Meanwhile, a Librem phone (or a PinePhone) will not work.
It's nice to know that I'm somewhat famous. I never suggested that running banking apps on GNU/Linux phones was as easy as on Android forks (however, reportedly it is possible for some banks). I meant other daily tasks of course.
My bank does not offer Western Union transfers, for example, because there's been too much fraud. And does not accept root-platform devices as 2FA "something you have" factors.
Liberty or consumer protection? Your choice, really.
Same eg. with app for a local 2nd hand site, which on startup complains that it needs the Google services... and then runs without issue (only appears to use those Google services to pinpoint the phone's location).
Imho this is 1 more reason to put alternatives like LineageOS on a phone: the more users on those, the harder it is for app developers to drop that usergroup for... well, reasons.
Banking and public services are too important to be restricted to people with smartphone ownership (even regardless of OS).
It's even more important to refuse to use them, publicly shame them, and complain about them failing at their duties.
So really, if anything, I'd like people to focus on regulation.
It actually passes SafetyNet out of the box, but there's a CTS profile check that some apps do in addition to SafetyNet, and I had to root the phone to make it provide a profile that those apps are happy with. And then I had to install a SafetyNet bypass, because fixing the CTS profile broke SafetyNet.
It un-roots itself every time I install an update, which is kind of a pain in the ass, but someone wrote a script to re-root lineageOS (from a desktop computer), so it's not too bad these days.
* runs Lineage,
* dual SIM,
* not enormous,
* headphone jack (nice to have).
There's nothing out there.
Running https://github.com/kdrag0n/safetynet-fix/releases on magisk to allow for things like NFC payments using Google wallet etc.
The way you have to hide from apps is a bit weird these days using magisk filters, but other than that the entire thing has been set and forget, and I've not had any issues
It is great, and the offical unlock tool works seamlessly.
But you have to wait a week before unlocking, which I guess is there for you to """try""" MIUI. Still not a problem, though.
And this is the script I'm using: https://github.com/NicolasWebDev/reinstall-magisk-on-lineage...
Overall I'm really happy with my g100. The bootloader was easy to unlock, it has a headphones jack, a microSD slot, the battery lasts 2-3 days, and the performance, screen, and cameras are all good enough that I don't think about it.
The only things that I don't like are that the physical size is a larger than I would prefer, and it's not waterproof. Additionally, the single down-firing speaker is kind of lame when compared to my previous phones stereo front-firing speakers above and below the screen. I'd much rather have a bit of bezel if it meant I could have stereo front-firing speakers (and no camera hole punches!)
Oh, and I had to use a different phone to activate the SIM card to make it work on Verizon, because even though the phone is actually compatible with their network, they don't like it for some reason.
Additionally, I've blocklisted certain apps so that they're not even allowed to request root access, because the banking app that forced me to root it in the first place would ask for root permission every time I launched it.
The only thing which doesn't work is google wallet because they explcitly expect a Google signed operating system.
Restricting things to only Google ROMs basically also means your banking app won't work on a bunch of non-google Android phones and even most banks don't want to go that far.
It's idiotic that they require hardware attestation, but let's not fall into the trap of "it worked for me".
Even with these limitations, I'm okay with continuing to run GrapheneOS.
Somehow it detects that it was not installed through Google play and refuses to work with an explicit message stating this reason. I really wonder why they care. The app doesn't even take payment, at least not in this country. You still have to pay at the order portal thing.
Today, I consider the inability to use government or banking apps on a device that travels in my pocket a feature, not a bug, but it was indeed a steep and sometimes unpleasant learning curve.
Glad I have it off though: KDEConnect is great, I use it all the time to transfer files and send text messages from my computer.
With root access, it should be possible to disable just that component without breaking other functionality by running:
pm disable com.android.vending/com.google.android.finsky.verifier.impl.PackageVerificationReceiver
To reenable: pm default-state com.android.vending/com.google.android.finsky.verifier.impl.PackageVerificationReceiver
Without root access, disabling the Play Store completely (if you don't need it) via the normal Android settings should also do the trick.[1] https://android.googlesource.com/platform/frameworks/base/+/...
Unless you mean as a right, without needing to root? I'd disagree (from a corporate/warranty perspective), but I'll bite
Rather, it's a benefit of an unlocked bootloader; you can root a device with a locked bootloader, and you can use an unlocked bootloader to install an unrooted OS (or, for that matter, you can unlock the bootloader without rooting, depending on the device).
> Unless you mean as a right, without needing to root? I'd disagree (from a corporate/warranty perspective), but I'll bite
Why? I mean, sure, if the manufacturer can show that damage resulted from the user modifying the device then fine, but otherwise there's no reason for modifying software to affect a warranty on hardware.
I think you bring up a really good point. Except for extreme cases, such as a software that is designed to be self destructive on the physical components in which it resides, the hardware should mostly be unaffected by the software. Mostly that some components get used more or less than they were before, changing efficiency of some functions. Then we get into the grey area of whether or not the unorthodox use of components caused damage.
> if the manufacturer can show that damage resulted from the user modifying the device then fine
Here you are putting the burden of proof on the manufacturer, which seems a little unfair. If anyone can make a complaint (make use of warranty), and you the manufacturer are guilty as charged automatically unless you can prove the software caused the damage, then there will be an insurmountable amount of work to thoroughly review all software not sourced from one of your already-vetted approved sources.
Then again, if burden of proof falls on the accuser (warranty holder), it is a catch-22 because you can't prove that a software is without any issues. Companies are constantly creating patches not because they intentionally want to have a fault until x day, but because they genuinely thought the software was good until y vulnerability was found/exploited.
I think this is why companies take the 'any usage outside these specific approved usages voids the warranty' approach. In application to this conversation, this means while you may change your OS, it doesn't shock me that a manufacturer wants to keep their hands away from those consumers
Unfortunately, Google doesn't let you upload an APK with your own signature to Google Play anymore, so the devs can't really offer any solution. Best I can come up with is downloading the signed version from Google Play and uploading that, but that'd make updating the app wirhout uninstalling impossible for most of their users. Same with offering the free version as a different package name as the proprietary version, existing users would lose updates.
Google needs to fix this because they're basically killing every alternative app store this way, which probably violates the DMA/DSA law (whichever applies here) in quite a major way.
they could raise so much money for lawsuit to force G to allow it to be swapped in
why this conclusive title then?
Nobody with it installed from the play store mention it being removed, and though some users that got it from F-Droud mention it still being installed, there are several possible explanations for that. Like me, it wasn't removed on my phone but it turns out I disabled PlayProtect at some point.