If I have to explicitly reject it more than once, it is obviously malware. Once is already arguable.
If I have to explicitly reject it more than once, it is obviously malware. Once is already arguable.
Dear Google UX designers, the way you present your little "decline" links is illegal in the EU. I'm sure you've got these design directives from a product manager, but you can still say "no" to breaking the law.
But I don't see the problem with the decline link and EU law?
AFAIK, most EU regulations are about tracking and consent in using your information...
In this case, you're already using a Google product (the Messages app), and Google is just (aggressively) nudging you to use extra features that they have shipped in their app. It doesn't follow that Google is definitely going to use more information to track you than it would've done before (though it could be possible, of course)
...of course, I fully agree that this doesn't embody their "respect the user" ethos, but frankly... If you worked on new features for your users, I think it's fair to nudge them to try to make sure that what you worked on will end up benefitting them (of course, a company behaves differently than an individual, and it's not guaranteed that the work done might actually have merit... But that's orthogonal to this discussion)
Here's the consent popup: https://imgur.com/a/PIqcDgR
The design of such consent popups has been deemed illegal in the EU, Google was also previously fined [1] for a similar consent popup. The "REJECT" button needs to be just as accessible and needs to have about the same visual weight as the "ACCEPT" button, dark patterns like the ones you see in the RCS consent popup above are illegal.
[1] https://www.theverge.com/2022/1/7/22871719/france-fines-goog...
"Honestly, the days of any third-party SMS app are numbered."[0]
[0] I asked Signal motivations for SMS removal: https://news.ycombinator.com/item?id=33258684
If there is one thing like about EU, is that it's the only one in the world standing for the user's rights keeping these companies with their antitrust pratices in check.
If it weren't for them @pple wouldn't have switched to USB-C
It's a telephone, with a computer on it in your pocket with a shit load of sensors. The computer part involves components from many parts of the world, with many opaque subsystems. The OS is sort of Linux with knobs on and a lot of opaque parts - the first layer "belongs" to a prolific ad slinger hell bent on knowing everything about you. Then if it isn't a Google jobbie, it will have another layer of software, lots more shiny and a lot more data gathering (eg Xiomi/Samsung/whatevs). Then your "TSP" gets to put their spin on it. All three layers can sell out to eg MS for yet more data gathering and ads and profiling and so on.
Apple does the same but manages to be layers 1 and 2 and be a bit cooler about the whole thing.
You worry about Graphene?
I don't advocate for full Luddite (I run an IT company) but please get some perspective. If you are concerned about Graphene, I suggest a burner feature phone or smoke signals.
EDIT: I have F-Droid and KDE Connect wired up to both of my Arch (actually) boxes on my Samsung Invasive Intruder ... sorry Galaxy S23. I'll try switching out the Play version of Connect for the F-Droid one and see what happens.
Someone else said that the head guy isn't the head guy any more so the biggest problem may not be a problem any more. The idea, stated ideal, design, & construction (as far as one can tell honestly) of the os are all fine.
But the point was, you don't need any more reason than his behavior to avoid granting him such a priviledged place in your phone, which holds such a priviledged place in your life. Just on basic principle. You don't need to justify that to anyone and he or the project does need to justify why one should trust them. The usual justification is merely the utterly flimsy weak one of benefit of the doubt. It's more or less impractical to actually vet strangers, and so you just grant benefit of the doubt until there is some reason to question. But that goes out the window the instant there IS any reason to question.
People have different tolerance for risk, and so, you might be fine with saying "that guy is acting a little weird in this way, but whatever, probably he can still be counted on in this other way.", but no one else is obligated to. And this example of "weird" was not just neutral irrelevant non-conformity.
There have been countless examples of people in positions of responsibility and trust going off the rails and taking a bunch of users down with them. There is no reason not to use your nose for what it's meant for in this way.
But like I said, maybe the problem is resolved now by the fact that we don't actually have to trust that guy any more. In which case, ok.
Don't trust. Verify.
Even if there were something special about graphene that made it more desirable, the real way to deal with an open source project with something unacceptable about it's production or management, is to fork it. But I already have something else to do all day, and am happy to run lineage or calyx or or others. If I did need a fork, I'd need someone else to do it, and I'd have to trust them.
Fork it or help someone else who is forking it or work towards changing the original (which is what seems to have happened actually, so this is all a bit academic now), or just use anything else, are all more reasonable responses than "the people producing this thing with access to all my communications have shown themselves to be off the rails, so what I'll do is keep using it, but personally read all the code in an entire android os."
I hit Uninstall and within a few seconds the button switches to Install.
I hit install and the app is installed from F-Droid. I open it and pair my phone to my laptop.
One data point. Perhaps a knob has been twiddled in the Chocolate Factory in response to this article. There are a lot of Googlers here.
(EDIT: formatting)
EDIT2:
I've gone into the Play app and got Play Protect to scan apps: "No harmful apps found". KDE Connect is still working
Edit: apparently according to a post below he's still involved just not lead dev anymore. Sorry I missed that part.
No denying the guy isn't a no-joke developer, so, his code and work would be valuable, but only if the bigger picture didn't depend on his judgement.
It's not that I have a specic scenario of a particular bad thing he might do, like make a backdoor for the government or secretly collect & sell data, or even something like somehow ban you from using as an individual he didn't like because you criticized him or something. It's that once someone is shown to be that irrational, then all bets are off. You don't have to have a specific proposal of what they might do, because they might do anything.
Anyone might do anything, and the only way you can function is you just have to trust other people, and the only thing you have to go on is very little in most cases. So you have to give strangers the benefit of the doubt until there is some reason to doubt. And this guy acting this way is more than enough to avoid. It's not like there haven't been countless examples of people who seemed good at first going off the rails and taking a bunch of users down with them. It is entirely valid to see this guy and go "Nope. Avoid.", and that would not be a case of just ignorant discrimination against non-conformity, it would be using your nose for what it's for.
But if we don't actually have to trust him as much as before, that changes things.
I was following CalyxOS' progress at the time because they were working on enabling support for some OnePlus models but right around that moment OnePlus came out with an update that made it impossible to do change the bootloader signing keys and they abandoned the project (which I understand). I'm also a huge fan of MicroG and really prefer this open-source approach over the sandboxed google play approach. And I'm critical about some of Graphene's stances, around SafetyNet in particular ("We don't lie about security features" - I don't agree attestation is a security feature but in my opinion it's more about control/DRM). So yeah if I had a choice I probably would have gone for CalyxOS. But I'd never even heard of the guy before this happened. I had nothing to do with any hate campaign (which I doubt even exists).
But no, I don't want someone like that deciding what code goes on my phone.
It seems to me that it's no different than running a non-Microsoft/Apple operating system on desktop.
There's a timer that re-enables the Play Protect nag after a certain period of time. I can't remember how many days it is.
You can permanently disable it by running the following over ADB or a local shell. Works for me.
# This should disable Play Protect. Maybe.
# https://android.stackexchange.com/questions/187097/is-there-a-way-to-control-use-google-play-protect-together-with-microg-open-sou
settings put global package_verifier_enable 0
settings put global package_verifier_user_consent -1
settings put secure package_verifier_user_consent -1
settings put global upload_apk_enable 0
settings put global PACKAGE_VERIFIER_SETTING_VISIBLE 1
settings put global PACKAGE_VERIFIER_INCLUDE_ADB 0