Keep Android Open
f-droid.org
f-droid.org
> We appreciate the community's engagement and have heard the early feedback – specifically from students and hobbyists who need an accessible path to learn, and from power users who are more comfortable with security risks. We are making changes to address the needs of both groups.
> We heard from developers who were concerned about the barrier to entry when building apps intended only for a small group, like family or friends. We are using your input to shape a dedicated account type for students and hobbyists. This will allow you to distribute your creations to a limited number of devices without going through the full verification requirements.
> Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. We are gathering early feedback on the design of this feature now and will share more details in the coming months.
It is also true that they have not updated their developer documentation site and still assert that developer verification will be "required" in September 2026 [1]. Which might be true by some nonsensical definition of "required" if installing unverified apps requires an "advanced flow", but let's not give too much benefit of the doubt here.
0: https://android-developers.googleblog.com/2025/11/android-de...
In classic Google fashion, they hear the complaint, pretend that it's about something else, and give a half baked solution to that different problem that was not the actual issue. Any solution that disadvantages F-Droid compared to the less trustworthy Google Play is a problem.
For it to be truly considered open source, you should be able to fork it and create your own edits to change the defaults however you wish. Whether that is still a possibility or not, is a completely separate issue from how they proceed with their own fork.
It's my phone.
You paid for it but Google still has the control. I understand that you prefers things to be different (as do I) but the reality is that we don’t have control over devices we paid for.
You answered the question here:
> You paid for it
If you paid for hardware, legally that makes it yours.
> Google still has the control
Therein lies the problem. Google should not exercise such control over devices which are yours, not theirs.
Perhaps this is why Google hardware doesn't have locked bootloaders; Samsung et al can get away with locked bootloaders since it's not Google forcing the consumer in that case.
Whether the bootloader is or isn't locked should be very conspicuous before purchase, for consumer protection.
The law. The contract. The money I paid.
> the reality is that we don’t have control over devices we paid for
So, the reality is that a company is exerting ownership rights on things they don't own. If that is exclusive, then that is called theft.
If you don't like their choices, you should be able to install other software you do like. There should be completely free options that people can choose if they desire. But the majority of people just want a working phone, that someone like Google is taking great pains to make work safely and reliably.
There are legitimate concerns being addressed by these feature restrictions.
IMO the way this should work is that Google can make their software however they want provided they don't do anything to stop me from changing it to work the way I want.
Unfortunately, they've already done a lot of things to stop me from changing it to work the way I want. SafetyNet, locked bootloaders, closed-source system apps, and now they're (maybe) trying to layer "you can't install apps we don't approve of" on top of that.
That's exactly how it is. You're free to get your soldering iron out, or your debugger and reverse engineer anything you want. I don't mean to argue unfairly, but all we're talking about here is the relative ease with which you can do what you want to do. How easy do they have to make it?
As for their software, as delivered, there are literally an infinite number of ways that it stops you from changing it. Maybe you want everything in Pig Latin, or a language you made up yourself. Do they have to design around this desire? Do they have to make this easy to do?
A couple decades ago it would have been impractical if not impossible to make a TV, sell it to a bunch of people, and then remotely update it a few years later to start showing unkippable manufacturer-installed video ads every time you power it on. Or create a car that requires you to pay money to the manufacturer every month in order to use the seat heaters. Or build a tractor that detects if you repair it using parts not made by a specific manufacturer and shuts itself off if you do.
But now, in the age of software, all of these abuses are not only feasible to implement, but easy. And it all comes down to the fact that the software that controls these devices cannot be easily modified by the user who purchased them, or by anyone other than the company that originally manufactured them. It's a local monopoly. Were software developers required to distribute the source and build tools along with the compiled code, I suspect a vibrant modding community would spring up around any product of sufficient popularity which would make such abuses much more difficult to get away with. (Why pay a monthly subscription for my seat heaters when I can just buy a $5 software mod that permanently enables them? And why bother developing such an anti-feature in the first place if you know users will easily bypass it?)
I don't think the distinction exists the way you're trying to describe. If I should be allowed to install any software I want, surely that includes any .apk I want? Conversely, someone could make the exact claim one step down the chain and argue that you don't get to tell them how their firmware should work and if you want to install your own OS you should just go buy a fab, make your own chips, write your own firmware, and make your own phone. And that's absurd, because users should be allowed to run their own software without being forced to ditch the rest of the stack for no reason.
And the argument is the same lower down the stack. You shouldn't be able to tell someone how to design their firmware.
The only problem is where the law prohibits us from trying to undo these restrictions, or make modifications ourselves. It's government that restricts us, and we should focus our efforts there.
> And the argument is the same lower down the stack. You shouldn't be able to tell someone how to design their firmware.
Earlier, you claimed,
> They should be able to install any software they want.
but it sounds like actually you only mean that users should be allowed to futilely attempt it, not that there should actually be allowed to run software at will. If the firmware only allows running a signed OS, and that OS only allows running approved apps, then the user is not able to install any software they want.
And as users we should be free to buy only devices that respect maximum capabilities and customization.
There is a tension between these goals, and it's difficult to resolve, so that everyone gets most of what they want. Google seems to be doing the right thing mostly though. Providing both the locked down device, and making provisions for people who want the non-standard option too.
Anyone who thinks they can do better, should enter the market and give us something better. I'd like more options for completely open and hackable phones.
So you draw the line between the bootloader and the OS. Other people draw the line between the OS and applications. Most (nearly all) people can't write either, so for them it is just part of the device.
> you don't get to tell them how theirs should operate.
I paid for it, and I allow it to be legal in the jurisdiction I (partly) control. So it is not only theirs anymore.
Just like they shouldn't be required to offer it in pink if that's your favorite color. It's up to you to paint it yourself. And if you want to load random apk's, you'll have to do whatever it takes to figure that out too, up to creating your own hardware and software.
If I tell someone to install a light switch in my living room and then it occasionally switches states when someone presses another switch at my outside wall and occasionally refuses working, I don't feel like they fulfilled their contractual obligation. Same with smartphones and software.
I would agree with you if I would want additional features, like if I want a filesystem, but there is no filesystem manager yet, or if I want to install a package, but there is no package manager, or the package manager uses another format. But here there is a package manager and the package has the right format, so I tell the device to install it and it just doesn't solely because I am called John Brown and not Alphabet Inc. . That is not right.
If the light switch you bought, has a little daylight sensor on it, and turns off when the sun is out, and that's what it does.. you may not like that light switch. You might want one that "does what you want, because you paid for it!" but then you should have purchased a different one, or made a light switch you actually liked. Of course you are free to get the soldering iron out, and try to change the light switch. But the manufacturer is under no obligation to make it easy for you to change the way it works.
That is fair, and right.
Not sure this analogy works as it gives prospective light switch buyers a choice of different light switch types. What google is doing seems more like forcing EVERY light switch to have daylight sensors, thus forcing you to save power (even if you're pro-global warming and just trying to do your part for the cause), then telling people with vision problems relating to suboptimal indoor illumination or suffer from sunlight frequency melting disorder or think they've got some other random "daylight makes life suck" bullshit to create a student/hobbyist account.
There is a difference between making a choice because there has to be something there (setting a default wallpaper, installing a default phone/sms app so your phone works as a phone) and actively choosing to act against the user (restricting what I can install on my own device, including via dark patterns, or telling me that I'm not allowed to grant apps additional permissions).
> For instance, should you be able to text message one million people at a time? You might want to, but Android doesn't offer that feature.
There's a difference between not implementing something, and actively blocking it. While we're at it, making it harder to programmatically send SMS is another regression that I dislike.
> Do you want to install spyware on your girlfriends phone? Maybe that's your idea of complete freedom, but the fact that Google makes it harder, is a good thing, not a bad thing.
Obviously someone else installing things on your phone is bad; you can't object to the owner controlling a device by talking about other people controlling it.
> If you don't like their choices, you should be able to install other software you do like. There should be completely free options that people can choose if they desire. But the majority of people just want a working phone, that someone like Google is taking great pains to make work safely and reliably.
Okay, then we agree, right? I should be able to install other software I like - eg. F-Droid - without Google getting in my way? No artificial hurdles, no dark patterns, no difficulty that they wouldn't impose on Google Play? After all, F-Droid has less malware, so in the name of safety the thing they should be putting warning labels on is the Google Play.
Google killed every other competition via dumping and shady business practices. Sure, you can go to iOS, but that is even more closed and restrictive, not to mention the devices are overpriced.
While we're talking about that, have you heard of Bright Data SDK? A lot of apps on the Play Store include it to monetize. What does it do? It uses your phone as a botnet node while the app is open, and pays the app developer. How is Google protecting you from spyware, again?
The problem is that this is decreasingly possible. If this was possible then people wouldn't be complaining much about Android being more opinionated than an ordinary operating system has any right to be.
So, yes, there is a lot of things stopping you from coding your own OS.
I've lived through them locking down a11y settings "to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer", and it's a nightmare. It's not just some scare text, it's a convoluted process that explicitly prevents you from just opening the settings and allowing access. I'm not giving them the benefit of the doubt; after they actually show what their supposed solution is we can discuss it, but precedent is against them.
> Seems reasonable?
No. As I said before, any solution that disadvantages F-Droid compared to the less trustworthy Google Play is a problem.
This was already the case for enabling sideloading at system level: it warned you. Nobody really says having this toggle is a bad thing, basically the user shouldn't get an ad network installing apk's just browsing around the web without their informed consent (and android has been found to be vulnerable to popunder style confirmations in the past).
They also already had the PlayProtect scanning thing that scans sideloaded APK's for known malware and removes it. People already found this problematic since what's to stop them pulling off apps they just don't like, and no idea what if any telemetry it sends back about what you have installed. There have been a handful of cases where it proved beneficial pulling off botnet stuff.
Finally, they also have an additional permission per-application that needs to be enabled to install APK's. This stops a sketchy app from installing an APK again without user consent to install APK's.
The question is: How many other hurdles are going to be put in place? Are you going to have to do a KYC with Google and ping them for every single thing you want to install? Do you see how this gets to be a problem?
That describes the current (and long-established) behavior. App installation is only from Google's store by default and the user has to manually enable each additional source on a screen with scare text.
Anything else won't do.
https://developer.android.com/sdk/api_diff/36.1/changes/andr...()
If they implement what they said they would implement after the uproar, users will be better off. Previously, if a company wanted to distribute their app on their website, any user who installed it would have to dismiss scare text. Now, they have a way to distribute apps on their website without the scare text, and people who want to distribute apps without any tracking can still do that with the scare text.
I remember when big sites started having to put big banners in your browser console warning you that if you weren't a dev and someone told you to paste something there, you had been scammed, and not to do it. They had to do that because the average Facebook user could be tricked very easily by promises of free FarmVille items or the opportunity to hack someone else's account, and those are fairly low stakes bait. Now people bank with real money on their phones.
We should be prioritizing securing our systems so that they run only what we want them to run, instead of putting all of that trust in gatekeepers who make money when they let you get scammed.
HN tends to forget that linux is not a target for general malware because nobody gives a single fuck about linux as a real malware target because they're smart, and therefore not the target of most scams. HN has the cute attitude that technology is king and that as long as you inspect it and open source it and care enough and have full control, then that's enough. Often the same people ignoring that AI has made it way easier to fuck stupid people over with no effort at all.
I don't not want unlimited control over the hardware that I buy from vendors like Google but I don't know yet of any better way to keep stupid people from kneecapping themselves other than introducing harder and harder quizzes. If you think it's an advantage that third party vendors like f-droid are absolved of responsibility then you deserve and own the fault when you get hacked and fucked over. Most people don't want that. They have real life to deal with. In real life you can kill people or sue them and it's harder to kill people over the internet.
How many people have successfully sued Google because of malware on the Play Store? Ever?
People can learn about links to payment websites, self-signed apps/updates and unlocked bootloaders, because anything less is restricting computers for idiotic reasons.
Maybe the real solution here is not to. Pay cash when you can (better privacy), else use a credit card. Other types of "banking" such as sending wires is best done on a big screen anyway. The idea that everything can and should be done on a phone is terribly misguided.
I should have the right to have parents, friends or anyone use a "free" store that is not under control of Google if the user and app developer wish so. But also, somehow there should be something done to avoid the monopoly forcing to use the Google services. Like major institutions like bank, gov and co being forced to provide alternatives like a webapp when they provide app tied to the Google play store.
The EU and every other nation with digital sovereignty concerns need to make this happen to both Apple and Google.
These are our devices. The giants are camping.
The guy's name? Google. ;-)
Well, unless you use one of the many crappy Android devices that never get security updates, are running old kernels, old vendor security patch levels, miss all Android security patches, except applying the backported security bulletins every three months (1-2 months late). Yet, Google is happy to certify them as Android devices.
It was never about security, it is about control. If it was about security, they would have revoked the GMS licenses of pretty much every vendor outside Google themselves and maaaaybe Samsung, until vendors actually started caring about security. If it was about security, there would not be as many scam apps in the Play Store itself.
Back to your sister, the proper solution is to educate her (and everyone else) not to give apps unfettered access when they ask you to, plus let Google implement more security measures that systems like GrapheneOS already have (contact scopes, sensor permissions, network access permissions, etc.).
It also doesn't help that mobile carriers can delay updates for months. Thanks T-Mobile.
People forget to ask the most important question: security for whom, and from what.
> Well, unless you use one of the many crappy Android devices that never get security updates
You mean those crappy devices that let me record my phone calls and let the voice recorder continue recording the lecture even when the screen is locked?The industry still doesn't understand the concept of delegation of authority and the fundamental role it plays in everyday life.
It also doesn't understand the idea of people making mistakes and the need to have robust recovery paths either.
It also doesn't understand the idea of people making mistakes and the need to have robust recovery paths either.
Thousands of people get scammed and have their lives ruined every year, so deprecating passwords is absolutely the right move
1. Stop requiring computers/phones for everything. Your 91 year old grandma isn't going to make her way through your super cool very intuitive 2FA magic link email confirmation system, and I don't WANT to make my way through your super cool very intuitive 2FA magic link email confirmation system.
2. teach the people who need to use computers, how to use them.
> Stop requiring computers/phones for everything.
Ah yes, that sounds straight forward. Let us know when you’ve deployed that to prod.
Is "that guy" in the room with us right now?
And that example isn't random, I just tried and the first result for me is a counterfeit app with the logo of chatgpt copied .
Android is massive and extremely popular and I know several people who have been scammed already. It is important that Google makes this harder for scammers.
Google is not doing this to harm developers but to protect their users.
Google shouldn't be able to hold a vertical monopoly, on what apps can run, what os's are allowed and what hardware can be used on devices that run Android, rest solely on this weak excuse that someone might harm grandma.
Oh, and of course, if grandma gets scammed by a app in the Google store, Google isn't in any way held responsible. Such garbage, two-faced bs.
Is it that people "somehow miss this simple logic", or is it that they weigh security and freedom differently than you?
Moreover, there are better ways to protect against malware: 1. educate people; 2. rather than using whitelisting, use blacklisting (similar to XProtect on macOS).
Finally, the argument is not very strong on Google's side, since the Play Store itself has had its history of scams. Which, again is easier to protect against by educating people. No, don't put your banking information in a random app you downloaded from the Play Store (use the app that your bank tells you to). Do not install random keyboards from the Play Store. Etc.
We live in a dark age where the majority of people would gladly give their freedom so the don't have to be responsible.
1. The ownership of security can be entrusted with the user. For example, if the user wants to install a 3rd party app store that doesn't use developer registration, they should be able to do so. The consequences of that decision should be on the owner. FDroid is one such app store. But I trust it over play store any day.
2. Careless users can be prevented from making such decisions, and capable users can be prevented from making mistakes, by careful UI designs that provide copious warnings and require deliberate actions. We have plenty of examples for both. An example for a system that prevents mistakes with warnings is the certificate trust override in browsers. They allow you to override rejection of untrustworthy certificates, but not before you read a lengthy warning message and click a couple of buttons. Similarly, an example of a deliberate action is when you want a repo to be deleted on github or gitlab. They force you to type in the repo name as confirmation. Not only does it take multiple key strokes, it forces you to review what you're actually deleting.
> Google is not doing this to harm developers but to protect their users.
No. Google is doing this to satisfy their insatiable appetite for profit growth by squeezing their current revenue streams. This protects no one, but their shareholders and top executives. I'm a bit ashamed to have to explain this on HN.
Don't be. Like it or not, this is a site run by venture capitalists and populated most heavily by software engineers, both of which have historically been treated well by capitalism.
Although it's improved in recent years, I've noticed there's still a lot of corporate bootlickers on this site.
Yes, it saddens me too.
But people need to realize that most of the population aren't treated well or paid well. Most of us don't have the luxury of being SWEs, or even white-collar workers for that matter. Most of us struggle to even put food on the table and have to scrounge week to week, let alone month to month.
So, I'm not bothered by the bootlickers downvoting me. At best, they're fooling themselves; at worst, they're class traitors.
If you ask me, the time for tactful language is long over.
+1
> If you ask me, the time for tactful language is long over.
Sadly, I reached the same conclusion a while ago. Subtlety seems to have lost all value and too much is at stake to keep on appealing to everyone's sensibility.
And also monopoly.
This is exactly the thing for which Apple gets bashing. Closed garden.
Does a business have right to pay literal pennies per hour if it manages to find people willing to work at that pay ?
Does a business have right to lace food products with addictive substances for repeat customers and profit ?
All these cases are already happening today at some level depending on who you ask. But they don’t tilt to extremes because we have laws in place to maintain balance between business needs and collective good.
This move by Google will tilt that balance forever towards absolute duopoly in mobile computing space. It is time for legislation to avoid that.
Not after creating de facto duopoly.
Yes, but we also need to stop thinking like we’re trying to please the ghost of Steve Jobs. There is no ”store”. There are installers. You distribute them how you see fit, probably through the web.
These ”alternative stores” angle is a controlled dissent corporate plan B, much like how recycling was propped up by the fossil fuel industry.
Even that is a step too far in the wrong direction. Doesn't matter if it's free, or whatever, simply requiring an account at all to create and run software on your own device (or make it available to others) is wrong.
There exists no freedom when you are required to verify your identity, or even just provide any personal information whatsoever, to a company to run software on your device that you own.
“Sideloading” is disabled by default on all new android devices. You have to go through deliberate steps to enable installation from outside sources.
End users are ultimately responsible or their own devices and choosing what software to run and not run. That some people can get scammed by someone on the phone walking them through how to enable sideloading, and telling them to ignore all the warnings that currently pop up, is not a problem that Google, Apple, etc. need to solve. It is already solved, via the disabled by default setting and all of the warnings.
We don’t need further restrictions on creation and distribution of software. We need end users to step up and educate themselves on how to use and operate technology safely.
Perhaps this, when shipped, will pave the way for sane regulation of Apple’s practices along these lines, too.
> We see a battle of PR campaigns and whomever has the last post out remains in the media memory as the truth, and having journalists just copy/paste Google posts serves no one.
> But Google said… Said what? That there’s a magical “advanced flow”? Did you see it? Did anyone experience it? When is it scheduled to be released? Was it part of Android 16 QPR2 in December? Of 16 QPR3 Beta 2.1 last week? Of Android 17 Beta 1? No? That’s the issue… As time marches on people were left with the impression that everything was done, fixed, Google “wasn’t evil” after all, this time, yay!
How can they count the number of devices you install the app on without being the ones to give a permission to install it?
They took nothing back, they are still putting in place the requirement that Google gives permission to install apps on your phone. They are misleading us about it too which is also terrible.
Google listened.
Blame the judge for one of the worst legal calls in recent history. Google is a monopoly and Apple is not. Simple fix for Google...
If Google had not done that, they wouldn't have lost.
It's been our choice to drink this glass of wishful thinking while giving that company a solid dominant position in the market.
We ("you") can only make choices that will overturn that trend.
Fully opensource hardware with fully opensource software? Maybe, but also this is wishful thinking.
MSFT Market cap: 2.951T AAPL Market cap: 3.883T
You're moving the goal post. Linix competed with the biggest software companies in the world in the server world and won. We can do it again in another market.
These are markets far bigger than the consumer desktop licensing market where Microsoft can't even make a dent into Linux's dominance, this represents >$100B in annual lost revenue for microsoft. So yes, Linux already won, and it won big time, despite going up against the MSFT behemoth as you say.
Global Linux desktop usage is at about ~5% and growing while Windows is bleeding out and dying. And Microsoft doesn't care, go read their earnings reports to see why, their consumer desktop business does not matter except for it's ability to generate leads and demand for their actual core products. And geopolitical levers are also in Linux's favor, e.g. EU's desires for tech independence: the moves European governments were already making away from global tech products while funding domestic (often open source) alternatives are going to continue to accelerate:
- https://cordis.europa.eu/project/id/101135795
- https://nlnet.nl/project/index.html
- https://www.linuxjournal.com/content/denmarks-strategic-leap...
- https://www.theregister.com/2025/10/15/schleswig_holstein_op...
And to answer your original question again, yes, open source software can compete, and it often can compete with a comical fraction of the resources of its closed source competitor. It's not a surprise: The open source model works extremely well and is the most efficient way to build software and technology that we know of; human beings have been sharing technology in this way for the duration of recorded history.
Literally everyone who uses Android or Chrome OS, for one.
I haven't heard about any other countries doing any better, either. Their systems were even cheaper to subvert.
My smartphone runs an FSF-endorsed OS, PureOS. This is reality. It's not open hardware, but it's a long way from Android in the right direction. You can also get a Precursor, which is open hardware.
To recap the storyline, as far as I understand it: last August, Google announced plans to heavily restrict sideloading. Following community pushback, they promised an "advanced flow" for power users. The media widely reported this as a walk-back, leading users to assume the open ecosystem was safe.
But this promised feature hasn't appeared in any Android 16 or 17 betas. Google is quietly proceeding with the original lockdown.
The impact is a direct threat to independent AOSP distributions like Murena's e/OS/ (which I'm personally using). If installing a basic APK eventually requires a Google-verified developer ID, maintaining a truly de-Googled mobile OS becomes nearly impossible.
I don't think this is true, right? An AOSP build can just decide to still allow installing arbitrary APKs. Also see this post from the GrapheneOS team:
https://mastodon.social/@GrapheneOS@grapheneos.social/116103...
So at the very least you’d have to keep patches up to date.
Long term divergence could be enough that’s it’s just a hard fork and/or Google changes so much that the maintainer can’t keep the patches working at the same pace
I couldn’t read your link as it asks to join mastodon.social
I know iPhones aren't affordable for the layman in many countries. But for anyone with an option, why would you buy an Android? All the "customization" things I cared about when I was on Android are either doable on an iPhone now with better implementation, or something I don't care about.
I was a die-hard until I went through enough cycles of Google deprecating and reinventing their apps and services every year, breaking my workflow/habits, that I got sick of them and moved to Apple everything. And all the changes I've seen since then are only making me happier I got out of the ecosystem when I did. Unlimited Google Photos backups with Pixels are gone, Google Play Music is gone, the free development/distribution environment is gone, etc.
If people can't even develop for the thing without going through the Google process, they're really just a shitty iOS knockoff.
These are all due to limitations imposed by Apple.
I know it's still better than not having a workaround at all like in iOS. But just pointing out that Google probably never meant to let others access notification mirroring.
How the heck this is true?!? iOS is just bad.
Its usability is bad, its interface is bad, its apps are just a ton of crap, and it _will_ keep getting worse.
I'm not even talking about its "walled concentration camp" app model.
wake me up when there's an adblocker on an iphone.
That said, I want off the iOS ecosystem, but Google has basically said guess what? We are going the way of Apple, so we don't care about you either.
So right now there isn't really anywhere else to go. I'm going to keep trucking in iOS for now, but I hope I find something better soon.
And you know very well, There are only meme adblockers for the browser on IOS.
uBlock Origin on Firefox Mobile is significantly better than any Safari adblocker I've been able to find. (1Blocker's the best I've found for Safari.)
When UBOL was released for Safari I switched to it from 1Blocker in hopes of getting a closer experience to the full uBlock Origin, but actually switched back after a few weeks - the filter lists in UBOL were letting through more ads than 1Blocker - and both of them are notably deficient compared to uBlock Origin in Firefox.
That's for me to decide, thank you very much.
In the past I was also on Windows Phone, again great .NET based userspace, with some limited C++, moving into the future, not legacy OS design.
I can afford iPhones, but won't buy them for private use, as I am not sponsoring Apple tax when I think about how many people on this world hardly can afford a feature phone in first place.
However I also support their Swift/Objective-C userspace, without being yet another UNIX clone.
If the Linux phones are to be yet another OpenMoko with Gtk+, or Qt, I don't see it moving the needle in mainstream adoption.
Tragically, Linux phones have languished and are in an absolute state these days, but a lot of the building blocks are in place if user adoption occurs en masse. (Shout out to the lunatics who have kept this dream alive during these dark years.)
If you can install a linux distro you can flash a custom rom on a well-supported phone.
If it were more mainstream I could see GUI apps to manage all this for people, if they don't already exist. Idk I just use adb.
Yes, that is generally the case. As a general rule with an Android phone reflashing the OS itself or the bootloader carries no risk of bricking the device (meaning making it impossible to recover without specialized hardware and/or opening up parts that were not intended to be opened).
There are plenty of ways to "soft-brick" a device such that you might need to plug it in to a computer, and adb/fastboot can definitely be a pain in the ass to use (especially on Windows), but if you have a device with an unlocked bootloader it's very rare to be able to actually brick the device while doing normal things.
Now, if you're doing abnormal things like reflashing the radio firmware you can absolutely brick some devices there, but you don't have to do that just to boot an alternative OS and generally shouldn't be doing it without very good reason and specific knowledge of exactly what you're doing.
I'm not going to say there are no devices where the standard process to flash an alternative OS is dangerous, but none of the relatively common ones I've ever owned or used have been built that way because OEMs don't want their own official firmware updates to be dangerous either.
tl;dr: It is sometimes possible to brick a device by flashing the wrong thing incorrectly, but the risk of doing that if you are just installing an alternative OS through a standard process is basically zero.
It really depends on the device. E.g. Pixel is quite hard to brick. Though they do sometimes increment the anti-rollback version:
https://developers.google.com/android/images
In that case you have to be careful to not flash an older version to both slots and lock the bootloader, which is possible, because many non-Google/GrapheneOS images are often behind on security updates.
But the Android SPL versions of OTA updates from Android vendors monotonically increase.
It might not boot to a working OS, but you can still get back to the bootloader to flash something newer. Unless you blindly lock the bootloader without testing if it boots first and the bootloader can't be unlocked again I guess,
This is false. As long as the boot loader is unlocked, many phones will boot the downgraded image fine. It stops booting it when you lock the boot loader and on many phones, you cannot unlock it again. You need to boot the OS to enable OEM unlocking again, but you cannot boot the OS because the bootloader refuses to.
The Fairphone community is full of people who though 'oh it boots, so I can lock', locked it and they were in a boot loop and had to send their phone to Fairphone to get it repaired for 60-70 Euro (I don't remember the exact price, but that is the ballpark).
There is an adb command that can fairly reliably detect whether the boot loader can be locked. But I'm not going to post it here, because people have to read the full flashing manual, plus in the past there was a bug where the anti-rollback would trigger even with a newer SPL.
At any rate, flashing is not for most people and it was much easier when there was no rollback protection. Of course, rollback protection does make phones much more secure.
---
I wonder if your experience is based on Pixel or older/other Android devices that do not have rollback protection.
I'm running custom ROMs for the last 15 years
Also, /e/OS has pretty bad security practices (shipping very old kernels, very old vendor firmware, and missing most AOSP security patches).
Also, be careful to follow the instructions really carefully. For some devices it's really easy to get the phone in a boot loop, where the only resort is to get your vendor to repair it. E.g. Fairphone 6 has downgrade protection and will become a brick if you relocked the phone when the old system's Android SPL is newer than the new system's.
What you're saying should happen, but it will only happen when the government legislates it happens; which frankly they should be doing (along with nationalizing a few other software projects to be fair).
A trillion dollar transnational corporation with massive monopolistic tendencies will never ever do the right thing. Expect to force feed it down their throats.
Even the EU??? Huh? Did you misspell 'especially' there? Because when your governments want to spy on your own citizens more than the big tech companies want to collect data for advertising, you probably have a problem.
It won't.
Of course, now Google is doing what Google was always going to do.
Sent from my Librem 5.
So practically I cannot use it as a daily driver.
Librem 5 does have enough GPU horsepower, a functioning camera, and good pmOS support. But $800 is a lot to ask to test out switching to linux with no guarantee that my workflow will work or I will have enough battery life. It looks like the librem 5 can't record videos or do GPS navigation yet.
I am looking at the librem 5 specs again. The EG25-G is probably a better starting point for the modem now that it has been better documented and reverse engineered as a result of the pinephone project. It is interesting that the L5 has a generic smartcard reader though.
Commercial phones' costs also include the data value they continuously steal.
> It looks like the librem 5 can't record videos
It can: https://social.librem.one/@dos/115893142828953827
> or do GPS navigation yet
Yes, it can: https://forums.puri.sm/t/is-gps-supposed-to-work/21147/76
> or I will have enough battery life
Fortunately, you can replace the battery on the go. But yes, if you make no compromises, you will never win a tiny bit of freedom.
Besides having terrible battery life and security, it's just a hobby thing. Android has had millions of dev hours poured into it to be what it is.
Free software ultimately has time on its side. As long as a project has enough mindshare to keep its momentum, it really is unstoppable in the long run.
Where Linux shines is the absolute for-profit cloud/server world.
Open source has places where it works really nice, bazaar is better at "wider" stuff (having an active community, etc), while cathedral is more deeper/better at vertical integration, etc.
There's a whole lot of shady crap underlying the infrastructure and the hardware that consumers cannot touch, pinephone / librephone or otherwise. It's not designed for consent. At best you can gain ephemeral relief, but even that is illusory, because by simple process of elimination, differential analysis allows fine grained ID and tracking of people even if they don't have accounts, phones, interact with websites, etc.
It's not a shady cabal of lizard people, it's just the grubby natural alignment of interests by a wide ranging set of companies and regulators and groups who allow it to happen without imposing any accountability, and ensuring that the system remains structured such that no effective accountability can be imposed.
Extorting constant streams of data for adtech is too valuable and the entire thing is too complex for silly things like ethics to interfere.
Only when the kill switch is on. I control it.
Also, it's possible to get AweSIM service hiding your data from the mobile operators.
We should be enforcing informed consent regulation of network infrastructure, treating privacy and anonymity as synonymous with liberty and freedom. Allowing the system to operate as it does is a choice; those with lots of money get to make it grow by exploiting a constant invasion of privacy with no concurrent return to the society being exploited.
Phones aren't built to be privacy respecting, and kill switches are a mitigation of a symptom, they don't do anything to address the disease.
I know banking apps are the typical example, but I've always wondered why. I use my bank's app maybe once or twice a year when I need to Zelle someone, which I only need to do when they don't have Venmo. (Unless we consider Venmo a banking app.)
I only have one bank's app installed, the rest of my banks I only interact with over their website, on desktop.
As for insurance, I've never had an insurance company's app installed.
Am I just an outlier here? Honestly, if I switched to a non standard OS, I'd be more annoyed about losing, say, Google Maps, Uber/Lyft, or various chat apps. Banking and insurance just don't come to mind at all as something I need my phone for.
I haven't seen a cheque my entire life, and I'm born in the last century
I get an alert when a payment comes it - handy for knowing if a client has paid.
I can quickly check my balance - handy for knowing if I can afford another round of drinks.
I can repay a friend in two taps - handy if they've paid for dinner.
Is anything essential? No. Is it something people use multiple times per day? Yes!
We are so boned
What do you suggest? Everyone carry around their desktop computers and our CRT monitors like we did when we wanted to play Quake with friends?
The exercise would do people good. Jokes aside though, there is a nuance between completely inconvenient and designed for the marching morons.
https://www.demandsage.com/smartphone-usage-statistics/
I am sure you are thinking I’m a “moron” because I didn’t drive to the library and use microfiche to find the information…
Or maybe you would have been okay if I used Veronica and searched Gopher sites like I did pre Web in the 90s?
Get real, dawg
Email is for old people has been a meme for two decades
https://www.techdirt.com/2007/11/15/email-is-for-old-people/
Heck even when we first start a project we either federate (or whatever you call it) the client’s Slack workgroup with ours or we ask to be on their Teams channel.
Before working where I worked now, I worked for the 2nd largest employer in the US, even there most communication happened over Chime or Slack.
On a personal level you actually email personal contacts - in 2026?
She is a retired high school math teacher - been retired for 30 years - and she has used every popular word processor/suite from the original AppleWorks for the Apple //e and she was tutoring friends kids and helping them use GSuite and PowerPoint until 5 years ago.
She uses her phone for everything and she has up to date computers a couple of printers on her network and two ISPs just in case one goes out. She kept the legacy DSL account that’s not available to new subscribers and she has cable internet.
No, it's cool tho, worry about being "hip" and enjoy the authoritarian surveillance state that you are enabling because you've been indoctrinated to want "new thing" and to reject "old thing".
You realize how ridiculous this sounds, right?
Which is a pretty funny illustration of the gist of what he was saying… it’s easier to make mistakes on phones.
I'm not doing autocorrect typos when I type on computer keyboard, also banking on no gapps rooted phone would be kinda PITA
For Bank Of America it’s:
1. Click on “pay & transfer”
2. Click on “transfer”
3. Click on “From” and choose account
4. click on “to” and choose account
Then type in the amount and and click on the date?
Is it really that much easier on a computer?
yes, especially the 4th point, the entering all the recipient's banking details on real keyboard is much more convenient than switching the windows and checking some microscopic numbers in PDF document on smartphone same copypasting them one by one between different fields (and yes, there are many companies which still don't provide QR code in their invoice)
It's surprising how we still see posts like these in 2026 on what should be a "future-friendly" forum.
No. The "banking app doesn't work" argument against non-corporate mobile OS, raised incessantly is HN comments, is bogus
I want a "phone", i.e., small form factor computer, that can run something like NetBSD, or Linux. But I have no intention of using it for commercial transactions. Mobile banking is not why I want to run a non-corporate OS
I want to use it for recreation, research and experimentation
NB. I have more than one "phone". The choice is not corporate mobile OS versus non-corporate mobile OS, i.e., "either-or". I can use both, each for specific purposes
> I want to use it for recreation, research and experimentation
I am a firm believer that phones are personal computers and should have all the end user freedom we have come to expect from personal computers. I am totally behind what your saying. (The amount of irrational anger that wells up in me when I hear someone make the argument that phones are somehow not general purpose personal computers and shouldn't provider their owners software freedom would astound you.)
Personally, I opt out of services that require the use of phone "apps" and any potential attestation they provide. Unfortunately, I just offload those needs onto my wife and her iPhone.
Want to go to a concert in a TicketMaster venue? You have to have a phone. Pay to park in some places requires a phone. Mobile ordering for some restaurants requires a phone.
I don't think it should be this way, but it is. I think we need consumer regulation to insure software freedom on phones and curtail awful user hostile "features" like remote attestation.
Until that happens (if it ever does) there is a realpolitik with needing corporate phones for some activities that can't be denied.
Before you say “what about the poor people” in the US at least, even poor people can get a subsidized free phone through the UCF (?) government fund
Also see: no I’m not going to waste development time di you can get to a website I develop with JS disabled or so you can use lynx
And everybody should have the option of open computer systems
The assumption that everyone has a "smart phone" running locked-down Android or iOS is unreasonable. Just as race, sex, religion, national origin, etc, are protected classes, the "phoneless" should be a protected class. Denying people who choose not to use a locked down phone basic interaction with your business should be legally equivalent to posting a "No blacks allowed" sign on your door, and the consequences should be the same.
> Also see: no I’m not going to waste development time di you can get to a website I develop with JS disabled or so you can use lynx
I don't see what this non-sequitur has to do with the exchange. I didn't bring anything up about Javascript.
This conversation is officially done.
No, unfortunately some things can't be. There are venues that provide tickets exclusively via mobile applications, for instance.
So you only get 98% of the world instead of 100%. That 98% is far more than the the 100% of 10 years ago. Everyone wants perfection when they've already got abundance.
Ticketmaster is bullshit, for sure, but they're just one example of the problem of being forced to use proprietary user-hostile software.
So much self victimization to avoid using open alternatives.
So much confidence for an incorrect answer. As cited elsewhere in the thread, some venues are "no app, no entry", and do not have paper tickets.
Can you cite a venue that won't take printed tickets?
Edit: it looks like NFL doesn't take them, BUT you can go to the box office with an order number and still get in, so same thing.
Turns out Ticketmaster still has ticket printing machines at such venues
Was at a game at one of them, claimed I had a problem with the app and after some negotiation at the ticket window a millennial printed me a ticket
Why do they still have the printers
The "I'm having a problem with the app" strategy can work in other contexts too. The phone can be configured so that a young person trying to help gives up
"Modern" software is highly fallible and everyone knows it
I have recent (October and November, 2025-- venues in Indianapolis, IN and Cincinnati, OH) personal experience with this. With one venue I was able to play the "confused old man" card (via phone) and get the box office to print my tickets and hold them at will call.
At another venue I called prior to my show and tried the same tactic. They told me flat out "no phone, no admittance, tough luck for you" and cited the warnings and terms on the Ticketmaster website that I'd already agreed-to. I didn't want to chance losing out on $300 of tickets I bought so I knuckled under and loaded the Ticketmaster app on my wife's iPhone.
I don't think it's as cut-and-dried as you say it is, and I don't have the stomach to risk being denied access to events I bought tickets for-- particularly at the pricing levels of today's shows.
Perhaps this is why, e.g., venues that "require" apps still have ticket printing machines and still print tickets when there are problems with using the apps
The situation is not so "cut and dried" that no one ever attends an event at these venues using printed tickets instead of displaying the ticket on the phones they bring to the event
There are alternatives to apps that are sometimes used, e.g., when customers have problems, even when businesses try to "require" apps
As such, businesses do not always succeed in collecting the same amount of data from every customer
This is not to say customers who try to avoid unnecessary data collection always succeed, either
Generally, trying is a prequisite to succeeding
If most customers do not try it does not mean no customer succeeds. There are some who do, at least some of the time
Ditch your bank if they have issues. If their retention department asks why you're leaving, tell them their app doesn't work.
This is what I was thinking as well, TBH. I'm not particularly tied to any of my banks, I already did mostly switch off of BoA because their website was so bad.
Good to hear everyone's responses in the thread though, some stuff I definitely didn't consider.
Then, a while later, CBA pretty much phased out SMS-based 2FA (or they said that if you had the mobile app installed then you can no longer use it?). Only other supported option is in-app 2FA (no support for third-party TOTP apps). So I had to start opening the mobile app every time I needed a 2FA code. Then, within the last year or so, they made a new rule, that in order to log in to the web UI at all (just initial login, I'm not talking about sending money or any other high-risk action), you had to receive a push notification via the mobile app and tap "allow". So now I literally can't log in to the web UI without also logging in to the mobile app!
So, unfortunately, "just keep using the bank's website on desktop" is increasingly and deliberately becoming not an option. I assume there are many similar stories with other banks around the world.
I've made a lot of noise about it so maybe they've "unblocked" me to shut me up. Email the CEO so it registers a complaint. Make some noise. Definitely have another bank though as you can't just depend on one.
I hope, now that the debate about our excessive reliance on American tech is on the table, that we also put limits on those essential services, like banks, imposing the usage of products from only two companies (Google or Apple) in order to operate. I think that goes at least against the spirit of the European Union.
LOL, you couldn't even place a phone call in Australia without some US technology connecting the call. I should know, we setup the app that calculates your bill. That's from the US too.
Another commenter mentioned needing to get alerts for fraud, but none of the financial institutions i'm currently doing business with have any trouble sending me text messages. In fact I have the opposite problem, I can't get them to stop using text for 2FA codes...
Many other countries simply rely on banking apps for these things, and don’t have a separate service for this kind of transaction.
Here in NL many banks (not all) require their iOS or Google app to log into their home banking on a PC/browser.
It's because Google created this thing during backroom conversations with bank associations from a handful of countries.
And this tendency will prevail as bank can collect way more data this way. Just a month ago one of banks that is often praised here sent me a letter saying “your IP activity doesn’t match your residence” (and i am not even installed their app, they pulled data from web ui usage. Imagine what happens when they get access to data mobile app can supply
Take Denmark, for example: most banking apps use eID for login, so that problem translates 1:1. But other apps who do the same include the national school communications platform (which is pretty much mandatory for a huge chunk of the adult population, who need to look at it almost daily). Also: social security card (including health portal/doctor booking/comms), driver's license, bus pass, parking app, used-stuff-marketplace, ... eID is _everywhere_ because it's a good idea.
Sure, all of this can be done on a computer. If you're near one. Or you can have separate and physical cards, like we used to have. That still works, mostly: more and more services (eg. bus pass) are going digital-only.
Really, what we need is a top-down embrace of open-source-based platforms as being _as_ (or more) secure than the established tech giants. From governments down, organisations _should_ move away from locked-down (foreign) commercial interests.
I'm not holding my breath though.
My bank uses the app for 2FA, and that became a sort of a standard in Brazil, AFAIK. Mine at least gave me the option of using an RSA SecurID or sth alike when I asked, but I don't know how much it would cost me.
My stock broker on the other hand does 2FA exclusively on mobile (and only Android and iOS). The same for the health insurer.
My car insurer didn't force me to so far, which I find strange, given their interest in tracking my location and speed.
These were some of the major factors leading me to give up on using a feature phone when I tried, a few years ago. It was a good experience, especially at those times of pandemics and political instability, but the inconveniences were many.
Make sure to leave one star reviews on all such apps that you run into.
Reddit is the epitome of enshittification.
One without, does not exist, or is in violation of their national obligations and likely to be cut off by the RBA.
The only "effective" complaint here, would be the gigantic effort to lobby for a change in laws entirely.
[0] https://www.apra.gov.au/use-of-multi-factor-authentication-m...
The best Linux for phones, SailfishOS, has a fairly good Android compatibility layer that runs many bank apps well. But despite that, it's an uphill battle. The network effect of the duopoly is gigantic.
Decentralized banking is the future!
INB4 someone mentions some edge case like 'grandma got scammed' or refunds.
Soon we Europians will only be able to pay using either an iphone or an Android device.
Hilarious
You can have a separate core and kernel to run such code. They don't have to be powerful, but they'll need to be small enough to be verified by the said provider. For most of the code that doesn't need attestation, they can be executed on normal hardware.
The provider also has to convince the regulator or banks to trust them. However, if that's solved, the user should feel no difference between pure Android and alternative platform plus attestation.
https://grapheneos.org/articles/attestation-compatibility-gu...
Some banks even do.
https://news.ycombinator.com/item?id=46723594 from Emre @emrekosmaz
It is a smartphone that runs Android, launches Debian, and dual-boots Windows 11
Actual link https://nexphone.com/blog/the-tale-of-nexphone-one-phone-eve...
There is no reason whatsoever for a major corporation to not use remote attestation technology. Banks will use it because fraud. Streaming services will use it because piracy. Messaging services will use it because spam, bots. If you're the corporation, the user is your enemy and you want to protect yourself from him.
Governments want this too. Encryption. Anonymity. They need to control it all. Free computers are too subversive for them. They cannot tolerate it.
[Citation Needed]
I see this kind of claim made often, but never backed up with evidence that remote attestation of consumer devices has any real-world impact on fraud. It sounds like it could be true because it would detect compromised devices, but it could just as easily be false because people with devices that don't pass are usually technically sophisticated.
https://grapheneos.org/articles/attestation-compatibility-gu...
Some banks have added their verified boot keys. I think it helps that GrapheneOS is well-known by now for great security practices (most likely more secure than all vendor phones out there).
Seriously?? That was very unexpected... Here's to hoping this becomes standard practice!!
Hopefully 2026 or 2027 will be the year of the Linux Phone
- AI boom or bust will affect hardware availability - there is a push on its way to revamp phones into 'what comes next' -- see various versions of the same product that listens to you ( earing, ring, necklace ) - small LLMs allow for minimal hardware requirements for some tasks - anti-institutional sentiment seems to be driving some of the adoption
Gaming on Linux took off with Proton. Linux on phones might go the same path.
I understand some amount of reticence with commercial OSes, but there’s no justification for being against it on open Linux based desktops and mobile OSes. We really need to get past the 90s-minded paradigm of everything having access to everything else all the time with the only (scantly) meaningful safeguards coming in the form of *nix user permissions.
I do agree with that, and I strongly believe that the iOS and Android security model is way ahead of Desktop Linux. But what I observe is that nobody seems to care about the security model. A recurrent complaint I see against anything AOSP-based (including Android) is that people "want to be root".
The fact that Android complains and tells any app that asks whether the owner actually, you know, owns the device they paid for is an implementation detail.
A Linux distribution that adopts an Android style security model could easily still provide the owner root access while locking down less trusted apps in such a way that the apps can't know or care whether the device is rooted.
But that does not mean that all OSes should be open source. I think it's fine for iOS to be proprietary, but there should be enough information for someone to write an entire alternative OS that runs on iPhone. I think it should be illegal to prevent that (is it called tivoisation?).
All that to say, I don't believe that having root on my Android system is a right. But being able to install a system that gives me root should be one. If that system exists, that is.
But both Flatpak and Snap offer this new model from the two biggest desktop players in the Linux world: Red Hat and Canonical.
As the sibling comment said though, being an administrator for your own computer (including a phone) does not mean that you will be running untrusted applications as one: on the contrary, if you assume an administrator role and run an untrusted application, naturally, all bets are off. But even as a power user, I'd love to be able to safely run programs I do not necessarily trust, feeding it only data it needs and no more.
Again, Snap/Flatpak provide this model, but we need to see more application authors take them up to ship their software.
What most of these people do not seem to get is that proper sandboxing does not only protect against attacks from the inside (rogue developer, supply chain attack), but also from the outside. Most desktop apps probably have a good number of security vulnerabilities that can be exploited when they parse untrusted data. On the Linux desktop, most apps still use decades-old C libraries for parsing XML, images, JSON, etc.
Sandboxing also protects against external attacks.
Again, Snap/Flatpak provide this model, but we need to see more application authors take them up to ship their software.
Agreed, though for a lot of technical and social reasons, most apps still need privileges that allow trivial sandbox escapes on Flatpak (I don't know or care about Snap). Strengthening app sandboxing should be a top-priority for the Linux desktop, but only a few people seem to care. The same for fully verified boot, etc. Even things like UKIs only go so far, yet almost no distribution has adopted them.
The general security mindset of the Linux desktop community seems to be stuck in the 90ies, levitating between hahah, they cannot get root (as if that matters on desktop Linux) and secure boot and sandboxing is here to take my rights (on open source desktop Linux, seriously?).
On my Desktop I love Linux. But on my smartphone, I want AOSP.
But then on desktop/laptop-class hardware, since the thermal constraints are different and it’s nice to have extensible storage and RAM. Of course, all this on the phone is also nice for when you only have your phone with you.
Then one could use fully sandboxed apps for banks, instant messaging, etc. and the VM for development.
AOSP is getting pretty close to this ideal.
Yes I can totally imagine that in a few years, most people will only need a smartphone and a dock station. At home, they will plug their phone (iOS, Android, whatever) to their dock station and it will behave as a Desktop. And it will be good enough for everything they do.
The problem is that strict file system sandboxing in particular also breaks a substantial number of workflows that can't be modelled as 'only ever open the exact file the user explicitly' picked. (Any multi-file file formats are particularly affected, as well as any UI workflows that don't integrate well with strictly having to use the OS file picker.)
So you need some escape hatch for optionally allowing access to larger swathes of the file system, or even really everything as before, but that in turn then risks being abused again by malicious actors. And then…?
Plus things like Android's implementation initially using an API completely incompatible with classical file APIs, as well as causing some noticeable performance overhead even today if you need more than simply accessing the occasional single file here and there.
For example, it’s useful for a music player with metadata editing features to have read/write access to the whole filesystem, but that constitutes a significant risk since all we can do is wholesale allow or prevent access to the whole filesystem. What if the system could allow it to access only music files, though? That’d scope the risk back down to almost nothing while also allowing the music player to do its job.
This is the kind of thing I’ve been getting at in the other replies. Nobody has really sat down and given system level security controls a deep rethink.
(Some sort of way to store permission references with relatives paths in a file, but which most probably wouldn't work with files being exchanged cross-platform, and other than that mainly being able to get automatic access to 'related' files, i.e. same file name, but a differing extension – that solves some sidecar files, like video subtitles, or certain kinds of georeferenced images, but large capability gaps still remain – even the video subtitle example stops working if the file name is no longer 100 % the same, like if you have multiple subtitle files for differing languages, where VLC for example supports prefix-matching the video file name with the subtitle files.)
And while your idea does have its merits, I fear that pretty soon you still hit a point where you can't sensibly and succinctly display those more complex types of permissions in the UI.
I could very well be wrong, but my inclination is that it's possible, but it's going to take the sort of fundamentals R&D that desktop operating systems haven't seen in decades. It can't just be tacked on, everything to be designed with this new system in mind.
Because, as I said in a sibling comment and cosmic_cheese notes further below, this requires rethinking the usage model altogether: files and folders, and even file types, don't work anymore.
If an app needs to access any related files, it basically needs access to my entire $HOME, and once that is granted, well, any sandboxing is out the window.
I think Linux community is well aware of that, and basically what we get from sandboxing of desktop apps is all the nuisance with no benefit.
Android model is also broken from a usage perspective: having files "owned" by an app is just as wrong, and precludes there being multiple apps operating on the same file. Example of VLC with subtitles is a common one, but if you've never used multiple apps on the same file, this is the challenge that is unsolved by any sandboxing approach today, because it is more of a UX problem, than a sandboxing technical problem.
All these things make security substantially better than the Linux model of every app gets access to your full home directory.
Sure, a capabilities-based OS or whatnot would work better, but would even be harder to implement in the current desktop Linux. Instead of gradually improving security, you are basically throwing away the baby with the bathwater.
But even with your example, you might need access to cover art from your graphics editing app, and very quickly you get to the same state. How about lyrics file from your text editor or a dedicated one? And wait, I'd like to mix in some music into Audacity too. File portals are actually a decent solution there, but they only work for files with supported software.
Yes, you can adapt your workflow, but it's going to be adapting and you will lose some things you might love in your workflow.
And that's the part that I believe should be a right: if you buy a smartphone, you own that piece of hardware, and you should be able to install the system you want. But if you are not the one developing that system, you don't get to decide what this system does. Just like you don't get to decide whether Microsoft Word can export to PDF or not.
I'm saying that despite all they get right, the Android and Apple security models, when foisted on the mass market, are socially and ethically flawed. I'm saying that the end user has a fundamental right to tamper with the software on his own system. Those designing an OS that intentionally thwarts the user's will are in the wrong.
Just because something is legal that doesn't mean doing it is a good thing.
For "normies", it feels like the existing security model is actually not that bad. I can't imagine what would happen if everybody was running something without any sandboxing.
> I can't imagine what would happen if everybody was running something without any sandboxing.
I don't think anyone implied that? Having root or signature spoofing or even the ability to install kernel modules doesn't imply anything about the rest of the security model.
Second thing is: if you have root and change something on the system, you break the secure boot. So you fundamentally cannot have full access, can you?
That's why my opinion is that it's not Google's role to make everyone happy. They should just not be allowed to prevent alternatives. So that the rounding error minority can install the system they want and be happy with it.
I want to be able to do what I want with my PC or phone. I don't want every app on my PC or phone to be able to do whatever they want, without me agreeing first.
But that does not mean that I should be able to do whatever I want with any OS I install. If I am not happy with Android, I can install LineageOS and modify it the way I want.
I am obviously not a big fan of Google, but I do believe that AOSP is actually a good deal (a lot better than iOS which is proprietary). Google is doing a lot of work on AOSP. That I cannot unlock/relock the bootloader on some devices is not Google's fault.
This is not surprising. The desktop Linux community reacted with hostility to the well funded security efforts (selinux, apparmor, grsecurity, etc)
It's the same reason I choose to keep my front door unlocked basically all the time - I know my neighborhood, the risk is really low and the convenience is high.
Further... practically everyone agrees that they don't need bank vaults as front doors. It makes zero practical sense: The cost is incredibly high, and the convenience is very low.
There are ALL sorts of wonderfully cool things you can do on a system where applications are allowed to trust each other, and the system is permissive by default.
You can customize behavior more easily, you can extend software more easily, you can add incredibly detailed & functional accessibility support, you can create incredibly powerful macros and commands.
This is so important that fundamental OS design from the early 90s actually prioritized and catered to exactly this style of open, trusted, platform (ex - all of COM in windows...). This is what made personal computing a reality...
All of those fall flat when you try to impose "well funded" security efforts.
Those efforts have a place, in the same way that bank vaults have a place. Whether that place is a personal computer is a different question.
Implying those folks are hostile for no reason is... at best a woeful misunderstanding of the situation, and at worst a malicious mischaracterization.
As a datapoint, everything in /dev/input/* is owned by root:input on my Debian Bookworm install, and my main user is not a member of the "input" group either.
Biggest problem with most security hardening for Linux desktop is that it breaks the natural usage pattern: I store my files by their content, not by their format (eg. I might have a folder for my project containing image files, spreadsheets, FreeCAD files, maybe even some code or TeX/ODF files). If programs are restricted to access the entirety of my $HOME though, there is not much benefit to that protection since that's where my most valuable data is. If they are restricted to per-program folder, I need to start organizing my data differently and unnaturally.
Android mostly does not use the "files" metaphor and basically does exactly that (per-app data): coming up with a security model and file management UX that does both is where the challenge is.
They've for sure had more than their fair share of security issues, but those are bugs, not fundamental design problems as far as I understand?
A solution that's integral to the system and not just loosely taped on is required.
The hard bit is the desktop experience which is not fully there yet, but the technology is.
It would be much more nice if e.g. daemons could have their privileges pared down to only exactly what they need to function and nothing more with a config file somewhere. This can somewhat be achieved with the user system, but that really doesn’t scale well and doesn’t suit the purpose all that well in some ways.
Most apps not using tight hardening are for different reasons though (files/folders org).
The isolation is nice but not so important once you stop running malware constantly.
However, I have 2 Linux phones and Linux on phones is just not there. Massive vendors (Samsung, Huawei, etc) would need to get behind it to make it go anywhere. Also so banking etc apps remain available also on those phones. We can already run android apps on Linux, Windows apps, so it would be a bright future but really it needs injections and support for large phone makers.
I hope the EU/US mess will give it somewhat of a push but I doubt it.
Similarly, Palm Pre, and especially HP Pre 3 was a wonderful WebOS incarnation.
Ubuntu Touch did seem like it had a future, but it was a massive sink for Canonical so it was defunded as well.
The user experience was there on all of these: the apps, not so much.
death of personal computing freedom, sovereign compute, and probably soon our ability to meaningfully contribute to the field as ICs?
A lot of really bad things are happening to our field, and Google is one of the agents responsible for much of it.
I mean, breaking news from 2010, but of course never assume things are so bad that they can’t get worse.
The reality is that we're lucky to have mostly-good things at all that align with most of our interests.
Yet people get so comfortable that they start to think mostly-good things are some sort of guarantee or natural order of the world.
Such that if only they could just kill off the thing that's mostly-good, they'll finally get something that's even better (or rather, more aligned with their interests rather than anyone else's).
In reality, mostly-good things that align with most of our interests is mostly a fluke of history, not something that was guaranteed to unfold.
Other common examples: capitalism, the internet, html/css, their favorite part of society (but they have ideas of how it could be a little better), some open-source project they actually use daily, etc.
If only there weren't Android, surely your set of ideals would win and nobody else's.
Also, the open nature of AOSP gave Google its advantage during the early days. Since then, Google has morphed into a company that would likely not make the same decision to create an open-source OS free for others to use and contribute to.
So in the end, what we as consumers actually get, in 2026:
- Google encourages application developers to use hardware attestation to prevent themselves from running on non-blessed, third-party AOSP distributions.
- Google builds basic functionality people care about (including passkeys!) into Play Services, a closed mega-application that happens to require a Google account for most features, and is a moving target for open distributions to mimic.
- Google has closed AOSP contributions to themselves and OEM partners only. AOSP releases are now quarterly source dumps.
- OEMs which traditionally allowed bootloader unlocking (and thus actual ownership of the hardware) have removed it as a matter of policy.
So what exactly is open about Android anymore? Does "source-available OS you can see and not touch" align with your interests? Because it's increasingly not aligned with mine.
So I'm leaning more towards Apple is in compliance and the common perception is incorrect. Which is fairly common when it comes to laws and regulations of any country.
Not even playing devil's advocate, just wondering how many loopholes actually exist.
While MS code signing certs are more circumventable for power-users than Android's new approved developer program, their pricing is far more prohibitive for independent OSS developers and hobbyists, costing hundreds of USD per year.
I developed my own Android ROMs from 2009-2011, complete with my own tuned kernel. I ran the local Android developers MeetUp group and evangelised Android development. When Honeycomb launched I helped OEMs test their beta firmware. For free.
But as Google has become certified Evil, the direction of Android has been very clear. In practice I honestly can’t say it’s now any more open than iOS. Except it has a lot more avenues for Google to mine your data to sell ads. And the quality of third party apps on it is decidedly worse.
I thought long and hard about getting a Linux phone. But I need a good camera on my phone to take random snaps of kids/pets/etc. And the Linux phones just aren’t there.
I hate the shitty duopoly we have ended up with. But I now realise that the openness of x86 and pc as platform really was an accident of history.
I have trouble understanding why this is a threat to AOSP distribution. I would have said quite the opposite actually, I don't see why they would not remove the verification and that's an incentive for people to use their project instead of Google Android.
It's really a shame that you always wait until you really get forced. Particularly in situations when every individual's inability has consequences for the others as well. I really gave up all ideas of a better world. With this community, the best you can hope is that the decay will be slow.
So everyone who would describe himself/herself as a FOSS enthusiast, or at least a friend of a somewhat open system where the user has some actual rights beyond sole consumption, put some pressure towards having actually de-Googled systems. A system that mostly comes from Google, would not fit my definition of that term at all! Even if they removed some parts of it. It's an euphemism. And it's dangerous because you constantly get trapped by these euphemisms. Ever. Single. F'ing. Time.
Nothing about Android is open except the absolutely minimum amount of linux kernel that's required to boot the thing. Then it's blobs and restrictions all the way to the screen.
I honestly can’t imagine a good solution here. A move back to the early 2000s internet would be the ideal middle ground, which requires separating social stuff from informational stuff, and both from engagement algorithms. I have no idea how we’re supposed to put that genie back in the bottle.
And to be clear I’m not saying this as vouching for the current push, I hate it as well.
"just stop" is a good solution. Stop asking for ID, stop pushing for apps, just stop the general trend towards https://en.wikipedia.org/wiki/Enshittification .
Yes, misinformation is a problem. Deanonymization is a bigger problem. If you can't say anything anonymously, it becomes much more difficult to fight entities bigger and more powerful than you.
Governments and companies feel a pressing threat of a trump-like populist overtake in each country. They need the bots, fake socials and slop stopped yesterday. An abstract degradation of freedom of speech isn’t going to cause pause.
There is a national security argument that I think is more likely to help, at least for non Americans. Do you want a foreign power to have control over your citizens phones being functional?
Right-wing populism isn't what's being banned here, it's dissent. Platforms are happy to take domestic and foreign fascists' money and push their agendas no matter where they are globally because it benefits them, too. Those paid placements aren't being banned, your ability to disagree with them and not be identified is.
This “fix” just routes people through official channels but those channels aren’t exactly proving to be worth the term walled garden. My YouTube adverts lately border the quality of early 2000s piracy sites, it’s honestly baffling how little they value their own product in their willingness to take anyone’s money.
Later we got a new one: to reveal Russian shills/propaganda bots
Now we also have: to filter out AI slop
Any problem the internet experiences will eventually become an excuse to eliminate online anonymity.
Then, at least I control my hardware and my OS.
It's just nasty to have your device and OS controlled by an antagonistic entity.
I see this in people why have used antagonistic software for decades and have become zombified and shellshocked; the idea that software could be on your side is to alien to them. They hate software and technology and just want to get some work done. They tolerate the abuse because they can't fight Google alone; it's pointless to resist.
(And install GrapheneOS, the more successful open Android becomes, the better.)
- A refurbished Pixel works (except some weird Verizon locking that I heard about the other day).
- Pixels get really heavily discounted near the end of the cycle (e.g. 9a currently). Google probably doesn't make much on it if you are opting out of your ecosystem.
Remember that on every certified Google Android phone, Google Play Services runs with system-level privileges. On GrapheneOS, it is sandboxed like pretty much any other app (if you choose to install Play Services) and you can make it 'blind' by revoking most privileges.
Same for Pixel Camera, etc., I just block network access.
Supporting free competition with and within the Android market is in theory what these teams are all about so hopefully with enough voices they'll push harder on it. I'd love to see a shift here that makes non-Google/Apple-controlled mobile a possible option (even if it's a Linux-on-desktop-style niche for the foreseeable future)
If I understood correctly, to "protect" users, Google wants to control what is installed on Android phones. I guess it means the Play store will be the only way to install an app, which in turn means: - That users won't be able to install what they want and that they would need a google account to install apps - That app developers have to go through google to distribute their apps, with identity verification etc. Obviously this is awful and would mean the end of F-droid and Aurora store etc. However, I'm also reading here and there that it is a threat to alternative ROMs. To me it sounds at the contrary as an amazing opportunity, as they can strip this verification and be the only truly open Android, or am I missing something? Why do people link this app verification thing with a possible closing of AOSP?
Also, Mozilla was already saying it 10years ago with Firefox OS but... The web is the platform. 90% of the apps out there could be websites. We have all technologies needed for this including offline with service workers. And it works on every damn platform, even the most obscure OS has a web browser. Don't want to be locked to an ecosystem? Just target the web!
> I guess it means the Play store will be the only way to install an app
No, non-Play stores will still work, but developers will need to register a developer account with Google that is tied to some real identity. They already need to do this to distribute through the Play store, but now it'll apply regardless.
This is to make it harder for scam apps to churn app signatures. Kind of like requiring code-signing, but with only one CA.
> That users won't be able to install what they want
No, sideloading will still work, but it won't work if the APK isn't signed by someone in the Google developer registry.
> and that they would need a google account to install apps
Nope.
> That app developers have to go through google to distribute their apps, with identity verification etc.
They don't need to distribute through Google, but they will need to be involved with Google and do identity verification.
> However, I'm also reading here and there that it is a threat to alternative ROMs. To me it sounds at the contrary as an amazing opportunity, as they can strip this verification and be the only truly open Android, or am I missing something?
You're being misinformed. They won't even need to strip the verification. The verification is only for certified Android -- OEMs that partner with Google. Custom ROMs and the OEMs that aren't certified (Amazon, some Chinese manufacturers) won't have verification.
The target audience for verification and who would ever use a custom ROM has basically zero overlap.
> > That users won't be able to install what they want
> No, sideloading will still work, but it won't work if the APK isn't signed by someone in the Google developer registry.
So the user can't install what they want. They can only install stuff signed by developers Google has "approved".
Yes, in the happy situation this is everything except for developers that Google has revoked. But technically it is only approved developers.
> That users won't be able to install what they want and that they would need a google account to install apps
It was split up because "need a Google account to install apps" is strictly untrue, but "won't be able to install what they want" is more nuanced.
I did clearly say, "it won't work if the APK isn't signed by someone in the Google developer registry".
So, it depends on what the user wants.
If they're running certified Android; otherwise it doesn't matter.
It is only for registered developers, so of course that very much depends on the registration system.
I donated a few $100's to the petition.
With 23,623 (as of today) signatures I doubt anybody really cares, and we'd all rather be cheeple doing the tech companies' bidding as long as we can flop on our couches and consume.
Clearly Google wants to make money off their monopoly (created in part from initial openness) and they are disguising it as some security/safety enhancement bullsh*t. Shameful!
My main question: I chose Android over Apple because of the extra freedoms it affords me. When that goes away, what reason do I have continuing with Android?
Remember how hard Amazon had it to attempt an Android fork?
I was due to OEM SOC access being locked out due to those contracts....
Any open source mobile OS attempting to complete with AOSP needs access to mobile OEM soc providers not touched by AOSP contracts and currently that is somewhat hard.
I don't see a real future for Andrioid as an open platform unless the community comes together and does a hard fork. Google can continue to develop their version and go the Apple way (which, funny enough, no one has a problem with). Development of AOSP can be controlled by a software foundation, like tons of other successful projects.
It's the same as the situation with Chrome/Chromium. There are a million "de-Googled"/"privacy focused" alternatives to Chrome all using the same engine, and when Google pushed manifest v3 changes to block ad-blockers every single one of them was affected.
You are making an orthogonal point. Yes, Google maintains AOSP. No, that does not mean that AOSP OSes that are not in Google's Android program (calling it that to avoid semantics games) have to adopt this change. If you want to hear it from the experts: https://grapheneos.social/@GrapheneOS/116103732687045013
At any rate, this particular Google anti-feature does not require a large patch (or maybe none at all).
That's just objectively wrong, both Brave and Opera still support manifest v2 and are committed to continue doing so for the foreseeable future. Even Edge apparently still has it, funnily enough.
Brave does NOT support manifest v2. They have instead hand picked exactly 4 manifest v2 extensions (AdGuard, NoScript, uBlock Origin, and uMatrix) and have hard-coded special support for them. They quite literally say in https://brave.com/blog/brave-shields-manifest-v3/ that all other v2 extensions will go away from Brave once Google fully removes support for them (which may have happened already, since it was posted a while ago).
As for Opera (https://blogs.opera.com/news/2025/09/mv2-extensions-opera/):
> MV3 extensions are the new standard and will offer a more stable and secure experience. Opera itself will shift to an MV3-only extension store.
You're misreading that page, they have special cased the hosting of those 4 extensions, because they do not have their own addon web store and are relying on Chrome's instead. You can still install any manifest v2 addon manually, not that there are going to be many outside of those 4 that care about v2.
As for Opera:
"Today, we reiterate what we said back in October 2024: MV2 extensions are still available to use on Opera, and we are actively working to keep it that way for as long as it’s technically reasonable."
Read: for as long as Chromium allows this via a flag.
addons for firefox were at first a way to test features. we only have devtookls because one person wrote an addon copying ie6 dev tool. next Firefox release it was part of the core browser.
The only other options would be convincing users to pay 5 bucks a month for their software, or have some Government fork over the tens of millions required to pay open source developers. And good luck with that.
Every single release is a step backwards.
Android 15 cannot hold a candle to what cynogenmod did on top of android 2.3. And that's objective.
For the features you can read here for example what Android 16 changed:
sadly, given that both manufacturers on this duopoly are highly incentivised to push malicious apps, everything must be throw out for a cat and mouse game of sand boxing
I don't think you understand what that word means.
Regardless, your opinion (and mine) is irrelevant. People want at least some of the features of modern android, and any alternative lacking those is not going to be adopted by most people. Just look at how many people try GrapheneOS and find the minor things to be dealbreakers for them.
And as long as that's the case you can't expect people to vote for a scenario where they'll end up with a, in their eyes, worse product.
Only things nobody wanted were missing then. Like fake AI photo enhancement.
But even your own example works, just because you dislike camera filters, doesn't mean everybody else agrees with that. There are probably more women with smartphones that use those, then there are that don't.
This is not happening in my lifetime, of course it isn't. But by god does it need to happen.
Parent-poster just referenced past/future legislation in general.
The reason GNU and Linux won was because they produced software that was sufficient for the market: servers.
The software is also sufficiently good for a PC for software development.
There's almost sufficient software for PC gaming (up against an absolutely insane monopoly that is Microsoft).
Phones are slightly different and for something more than a dumb phone you need great hardware; great software; and great integration.
Employee computers for companies and general home users or tablets? Still a ways to go.
I don't think wanting features and good UX is unreasonable from consumers.
The people who speak in forums are a minority.
> they actually value ease of use and shiny features over privacy and software freedom.
There's no actual competition so we don't know this on any level.
We need some pro-consumer regulations on hardware which mandate open platforms. Fat chance of that happening, though, as the likes of both the EU and US want these locked down systems so they put in mandatory backdoors.
[1] https://github.com/eu-digital-identity-wallet/eudi-app-andro...
[2] https://github.com/eu-digital-identity-wallet/eudi-doc-archi...
It will cost a lot of money and as long as Google is still doing regular AOSP code drops, what's the point?
[1]: https://android.googlesource.com/platform/sdk/+/refs/heads/m...
[2]: https://android.googlesource.com/platform/tools/base/+/studi...
And I didn't expect Android-Studio to be open source!
[1]: https://android.googlesource.com/platform/sdk/+/refs/heads/m...
For example, most repos in LineageOS's GitHub org lack a global LICENSE file. Instead, licensing is specified on a file-by-file basis within the comment headers.
This does lead to some ambiguity though. You can't put a license header into binary files like PNGs. In those cases, you can only trust that Google won't sue you for using them.
Android has been a bloated walled garden for years. It should have been like a PC w/Windows or Linux: anyone should be able to make an app (any way they want), publish it, let anyone who wants to download it & run it. But that was never the plan. The plan was to provide a moat to allow mobile telephone operators (& Google) to dictate what users were allowed to do with their phones. Imagine your ISP having total control over your desktop computer. Or killing a website, or program, because the ISP doesn't like it.
It is insane that we, the people giving them the money and agency to do this, that we've allowed this to be the status quo. We need to do something about it. We need to kill Android. And from the ashes, make a new platform that works for us, and not for a corporation's profits and anti-competition.
It's not very hard to imagine? Most people don't expect that level of control anymore; their desktop just updates with whatever corporate slopware is pushed out seasonally. Websites come-and-go. It's not a hugely motivating rally-cry for average person.
> We need to kill Android. And from the ashes, make a new platform that works for us, and not for a corporation's profits and anti-competition.
Android is the best-working part of that equation. Microsoft supported Android apps on Windows Phone. Jolla supports Android apps on Sailfish OS. Linux supports Android apps in Waydroid. You don't have to "kill" Android as a runtime or smartphone OS; just force Google to compete with 3rd party ROMs.
How exactly are you going to force Google to do something?
What is the US going to do, apply more tariffs?
-----
Luthen: Turning back will be impossible. You knew where this was going. You've always knew. Has anyone ever made a weapon that wasn't used? The network has been built. It's up. It grows or it dies. We've waited long enough.
Mon: Do you realise what you've set in motion?
Luthen: It was time for that as well.
Mon: Palpatine won't hestiate now.
Luthen: Exactly. We need it. We need the fear. We need them to over-react.
Mon: You can't be serious!
Luthen: The empire has been choking us so slowly we're starting not to notice. The time has come to force their hand.
Mon: People will suffer!
Luthen: That's the plan. You're not angry with me. I'm just saying out loud what you already know. There will be no rules going forward. If you're not willing to risk your conscious then surrender and be done with.
---
https://www.youtube.com/watch?v=ao9ARb6dEfc
edited: formatting
> I see this in people why have used antagonistic software for decades and have become zombified and shellshocked; the idea that software could be on your side is to alien to them. They['ve come to] hate software and technology and just want to get some work done. They tolerate the abuse because they can't fight Google alone; it's pointless to resist.
*minor edit in brackets
Let's focus on making it possible to use really open Linux systems on smartphones.
Regarding some concrete examples - Google can deeply integrate Gemini, but a competitor can't do this and users get no final say here either. Competitors are restricted by the permission system, Google is not restricted at all.
While rooting can alleviate this to some extent, Play Integrity is there to make sure the user regrets that decision to break free..
At the risk of posting memes to HN: https://imgflip.com/i/akp488
Unfortunately, this mostly means using the closed android ecosystem.
I run GrapheneOS and use several US-based banking apps. I'll not name them since I don't really want my HN account associated with my financials in any way, but I've got a mix of well-known national bank apps and smaller local credit union apps working.
I'll admit there is a single institution's app I've found that doesn't work, but that is just one of several that I use.
https://privsec.dev/posts/android/banking-applications-compa...
Google Pay does not work, but some other NFC payment apps do (e.g. Curve).
Laptops exist.
https://privsec.dev/posts/android/banking-applications-compa...
I'm using my GrapheneOS phone to log on to their web app without issues (though I typically only do banking on my phone, much more secure).
Edit: Someone also made a good point, one of my CC's I can barely even manage without the app since the website barely works.
I use NFC payments often, but I wouldn't say that amounts to more than a few percent of my total usage.
Everyone uses their phones differently, of course. I don't think your use is unbelievable or odd, but I do think your use patterns are not the common case.
whatsapp, phone, push authenticator, safari (having followed a link from a message), spotify, slack, mail, calandar, disney plus and camera
Do you not do any of that on a mobile device?
I find it hard to believe someone would spend 4 hours and 9 minutes _per day_ looking at their banking app or using NFC payments.
Maybe, but there's no technical reason for this. As I've mentioned before, I can do banking just fine on my Gentoo machine where the entire corpus of software on it, is FOSS and compiled by myself.
"Security."
As if I'm in the government or something. Why can't the people who need military level security get their own platform? Shouldn't they just have that already?
Edit: this will likely exist "uncensored" in other markets but conform to the PRCs standards and practices domestically, similarly to how tiktok operated prior to selling a version specifically taylored to US censorship and propaganda.
This is what lack of options does to a MF
Say it with me: “Living in a police state is bad no matter who’s running it”.
You may theoretically find it advantageous to use such a system anyhow. To a first-order approximation, the danger a government poses to you is proportional to its proximity to you. (In the interests of fairness, I will point out, so are the benefits a government may offer to you. In this case it just happens to be the dangers we are discussing.) Using the stack of a government based many thousands of miles/kilometers away from you may solve a problem for you, if you judge they are much less likely to use it against you than your local government.
But China certainly won't put out an "open" anything.
Maybe it's just my experience.
Not Google controlled for sure but also not open.
As far as HarmonyOS i dont see many uptakes outside strict US free requirements as the other OEMs are lazy and also dont want to be locked into a competitor.
SailfishOS looks like its your time to faceplant once more , by not having a proper stratergy on monetizing on the many missteps from the current monopoly.I thonk at this point they need a leadership/biz stratergy overhaul - the tech is nice and polished, user demand is off the charts for an alternative . And they are just .. missing. Not even in th e conversation.
Where you been? They already had Huawei get kickbanned by Google and made their own OS (it's not more open): https://en.wikipedia.org/wiki/HarmonyOS
The US system is dying from lack of competition.
Government bad. Big government worse.
People mentioning forking Android is hard, how easy do LLMs make this?
Do you ever feel like the same food item doesn't taste the same it did 10 years ago? Maybe it's your memory being faulty or maybe the company got new management which decided to cut costs while keeping prices, extract the differential value from customer inertia and move on when the product stops being profitable.
Android is the same. Certain freedoms were a part of the offering - a part of the brand name. They no longer are. Not only should lose their trademark[0], they should be legally forced to change the name.
[0]: The purpose of which is to identify genuine product from counterfeits - in this case, the counterfeit just happens to be by the same company which released the original product.
As long as everybody knows that you are just talking, but in the end you are basically fine with everything and declare "pragmatism" and all those lame excuses from the last ~20 years, there will never be any actual movement for the better. So why taking care and constantly having those lengthy debates?
Is it just your way to deal with frustration? Or what are these discussions actually for?
I'm really just asking, because I'm actually asking that myself since quite some time now. I just don't get it. The same for some other yet similar topics, e.g. having these dependencies to corporate social media, ..., ...
Additional thought: I also constantly find people somewhere, fighting some decades old fight, e.g. against Windows and Microsoft, and how bad it is in terms of privacy, sovereignty, freedom, ..., and Recall, etc.; but if you ask them "Do you use WhatsApp?", they don't even have a clue why you ask...
IMHO, if the community isn't able to recognize that entire mindset as problematic AND find some actual solutions for it, there is no value in all these discussions.
No, enshittification is not new. It was obvious from day 1 that it will eventually happen. To everybody who know basic mechanisms of how human beings interact with each other.
Sometimes people come to me and say "yeah, well, it's about technology, that's not my business, and I don't really care". This is stupid in various regards. At first, the same people shifted their entire life into that 'technology', and were constantly crying how everything is going to be digital in the future. Beyond that, the entire topic is not at all about tech. It's about how human beings interact. About markets, and all kinds of non-tech things.
"enshittification on modern computers is still relatively new" is like a chain smoker saying something like "lung cancer is still relatively new". Sure, in some way it might actually be new. But is it a good excuse for anything? No. That danger was crystal clear since the first cigarette. Right? Everything else is lame excuses and stupid babble.
I've used Linux for 25 years, and never have I thought it has enshittified. It's only Android in the last decade that has, much like the iPhone, Windows and the big social networks defending their monopolies in court and even losing in some cases, though maybe not enough yet.
https://f-droid.org/packages/dev.imranr.obtainium.fdroid/
This is sad as there’s been a real resurgence of gaming devices (Ayn Thor/Odin, Retroid pocket devices, Ayaneo, etc) moving to Android from Linux variants (Batocera, Arc, Garlic/OnionOS).
It’s sad but more of an incentive for folks to finally take Linux as a viable alternative, and build on efforts made by Valve with SteamOS.
A bit ironic to not believe Google is doing this. The same questions have same answers when asked about when Google is locking down side loading. A bit self-serving to pick and choose which things you want to believe are happening.
In contrast, Apple has a ~48 hour turnaround for reviews before you can upload to TestFlight and distribute a beta with a link
Not sure if I am in some "trusted developer" cohort on iOS but not Android - but the difference was enough for me to stop trying on Android
not happy about it, but i don't see a path forward that lets one participate in the wider ecosystem and maintain their own sovereignty and sanity.
Nothing lasts for ever. The sooner you make the switch, the better off you will be.
Personally, I am still on W10 and and delaying the move, so i'm not holier than thou. It's tough. But I also am a programmer/power user and am on my PC 24/7, sort of, so this disruption must be timed properly for me to make the move, which is not necessarily the case for most people/average users.
Phone on the other hand, as long as it works and does not limit me, I have no need to use different ROM, it's more of a want. But i do not see me doing anything until the system stops being supported or it breaks or something else. So it depends on how you use it.
With W11, that is not the case. Therefore, it becomes inevitable. Worth mentioning is that companies, governments and whole countries are ditching Microsoft altogether - for various reasons(some are geopolitical, due to sanctions and tariffs, others are technical).
Lenovo, Dell and HP are slowly ditching W11 as well in favour of linux. If you look up definitions of malware and spyware, windows 11 falls into both of them. It's that bad. So again, I'm not a linux fanboy by any stretch of imagination, but the writing is not just on the wall, we've passed the point of no return. Or rather, Microsoft has.
Now that linux supports 95% of games, there is little holding people back as gaming was always the biggest hurdle when it came to linux. And Adobe, too, is no longer what keeps people stuck on Windows - either because they ditched it due to their horrible pricing practices, or because there are now solid alternatives.
Of course many people will switch to mac as well. But windows in general, i think, is done. It had a good run for few decades, but they dropped the ball so hard that there is no going back or fixing it with w12.
Point is, we techies might chafe at and complain about all these anti-consumer shenanigans (Meta and privacy, anyone?) but it does not affect their business momentum, probably because the rest of the world just doesn't care.
Recently, I was thinking that AI might force Apple to open their devices, because if Apple’s competitor allows sideloading, then the creatives and builders most likely to build their own apps will migrate to the platform providing less friction to getting custom apps onto their device. But apparently THIS is the time that Google has chosen to start locking down their devices as well?!
The government supports this, and might have demanded it through backchannels.
The government loves the concentration of media, because it usually limits the people who can own information flows to a very few people who are already deeply connected to government, or at the very least it limits the number of people you have to threaten or bribe to get what you want.
> So the people need to make some kid if a mass movement to rebel.
The point of controlling media is that people are isolated and can't do anything like this. They have no idea what is going on other than what they are told by massive corporations, and have all interpersonal communication mediated and regulated. They're even convinced to demand this, or evil people from other countries might take over their minds and molest their children. If they advertise these beliefs as often as possible, they will see this reflected in better, easier jobs with far higher salaries.
People who ever publicly contradict these beliefs will be put on many, many lists and their friends, family, random strangers, current or potential employers, providers of credit or banking services, and people who rent housing will be encouraged to also mock, threaten and isolate the people on the lists, or be mocked, threatened and isolated themselves.
When you're isolated, it doesn't matter if you're right and if what has been done to you is obviously unfair. Nobody will notice.
Sure parts of it were, but Google has always remained in control of Android. Anyone who expected that to change (in favor of more openness) hasn't been paying attention to the actions of tech companies for the past several decades.
You must find truth. Lies will find you.
This view NEEDS to be central to the tech freedom rhetoric, else the whole movement is literally just begging politicians and hoping corporations do the right thing... useless.
If we force it upon them by begging politicians, corporations still have the incentive to find a way to remove it or circumvent it.
Youre playing the cat and mouse game because you've been taught that solving it is too extreme (thats not a coincidence).
We dont need to endlessly fight a whole class of people, capitalists, for them not to use the things we require against us. Only socialism can solve that.
(these are honest questions and not "gotcha")
Well that would be true under a capitalist government.
> Why would state control lead to less policing?
Its not just "the state runs it", its "we actively become the state".
Collective ownership through peoples councils, peoples courts with a world view that keeps it all open: socialism.
The world view of not allowing individual ownership over collective goods, the world view of socialism, is the life line of the movement. The actual practice of daily democracy, of running production and of deciding social functions is everyones responsibility and it should not be left to what has become a professional class of liars.
Public office members, which should only exist where absolutely necessary, should be locals and serve as messengers with 0 decision making power. All power should be in the local councils. We can mathematically implement this today (0 knowledge proofs).
Every single book on socialism is on theory and practices of acheiving this. Thats what the "dictatorship of the proletariat is", the dictatorship of working people, collectively.
> What incentive structure would lead to innovation without a profit motive, when even the modern communist world relies on capital markets?
We've been innovating for hundreds of thousands of years before capitalism. You dont need to generate money to innovate, the innovation itself is the driver, AKA a better life. No need to lock and limit production behind the attaining of profits of those who lead it.
A lot of people are allergic to this rhetoric and will just assume I have a deep irrational bias, but I was actually a staunch free market supporter before.
Once I decided to be more intellectually honest with myself and read more about what both sides meant historically and currently, it really just made sense.
I take honest conversation where I can get it, even when I don't agree. And to be clear I don't agree with most of your points and think it's idealistic and couldn't work in the real world. But I appreciate the spirit of what you're arguing for (in my interpretation) power with the people vs power with corporations and government and I think that's a very fundamental principle that is very important common ground.
edit: clarity
I own a Pixel and while the hardware seems decent, I've had a buggy and annoying experience with Android, and it's been getting worse lately.
Are Google so high on their own supply that they think people use their phones out of preference for the OS? Because frankly it's not very good. That's like Microsoft thinking people use Teams because of its merits.
People buy Android phones because they can be had cheaper than an equivalent iPhone and because in spite of the buggy and inconsistent mess of an OS, you aren't beholden to Apple's regimented UX. Locking down Android will not give it a "premium experience"... It'll always just be "Temu iOS" at best.
Honestly having gone back and forth between iOS and Android every three years or so, both OS are the same. It's not like the grass is really greener on the Apple side. The UX is virtually identical for anything that matters. Personally I put material Android above liquid glass iOS. The alleged polish of the Apple UX was lost on me when I had my last iphone.
The reason Google's moves are surprising has more to do with them embracing being a service player more and more with the arrival of Gemini and them having regulators breathing down their necks everywhere.
I guess they did it after the truly baffling US decision in the Epic trial but it's very likely to go against them in the EU.
Come on, that's absolutely laughable.
There are several topics where Android is significantly ahead to the point that iOS is just a toy, and there are areas where the reverse is true.
And I say that as a recent convert, so it's not like I have a decade out of date view of any of the OSs. In my experience I had more visual bugs in case of iOS than android (volume slider not displaying correctly in certain cases when the content was rotated as a very annoying example).
It's not, though. Google phones are not going to suddenly become luxury devices.
It's going to remain at the same level of polish (i.e. mediocre), except now without the major selling point of being able to run your own apps and have alternative app stores, etc. Back around Ice Cream Sandwich or thereabouts they got rid of "phone calls only mode" and forced us to rely on their half-baked "priority mode" that's an opaque shitshow.
When my wife is on call she gets random whatsapp notifications dinging all night, whereas when I had an iphone I could set Focus mode and achieve proper "phone calls only".
Android is not good. I use it despite its flaws, because of the trade-offs, not because it's better.
Pixel Fold disagrees.
> When my wife is on call she gets random whatsapp notifications dinging all night, whereas when I had an iphone I could set Focus mode and achieve proper "phone calls only".
You can do that with do not disturb.
> Android is not good. I use it despite its flaws, because of the trade-offs, not because it's better.
That is your opinion. My opinion is different.
Android is good, but Googled Android is not. You should check out GrapheneOS to see what Android done properly looks like.
And yes, I can also click one button and go into phone calls only mode. I can even set it on a schedule or based on my calendar. I don't know where you're getting your half-baked Android, mine Just Works.
You might not agree with every one of those points, but you can't seriously think everyone thinks like you. Go outside your bubble some time.
Where do you live? I've literally never seen anyone using a Fold or Flip device, ever. My kids are at the age where some of their peers are starting to get phones. All those kids have iPhones.
And I don't quite see your point about your kids' friends using iPhones. I sure as hell wouldn't give a kid a "luxury" phone. I'd take the cheapest thing that does the job and lasts a long time. An iPhone has a very long software support window so the cheaper models actually end up cost-competitive with budget Androids.
As for folds and flips, I've mostly seen people in suits using them, along with a few techy power users and some kids with rich parents. That's a luxury phone in my book.
I do think they should offer more pre-configured notification modes by default, if only to show people what they can do with the feature. Perhaps "phone calls only" should be one of those.
GrapheneOS is great!
It's time to say goodbye.
https://wiki.postmarketos.org/wiki/Devices
Fairphone 4 looks close, hopefully fairphone 4 support will continue to improve at this rate. Pinephone is another close one, but underpowered hardware and camera support kills it.
I am not even that intensive of a phone user. but there is no way I could daily drive pmOS.
Discussed it with the AI chatbot Claude.
And sort of ran two trials.
First, just discussed with Claude based on the read I got from KeepAndroidOpen.
For that first one, it was just kind of ad hoc, and just discussed it freely, asking questions, getting responses, etc.
But then I wanted to see if Claude might respond differently if different sources were provided.
So as each new conversation is different, could start a new conversation, and included three sources. One being what Google has at developer.android.com at developer-verification. Second being a MSN story titled "Google Claims Android App Sideloading Won't Die, But Change". Third being a story at The Register with the title "'Keep Android Open' movement fights back against Google sideloading restrictions".
Did the best I could to make the prompt balanced and informed, and basically just asked Claude what it thought of the overall situation.
In both cases though, it seems that Claude is raising the question of whether security is a bit of a cover story to the objective of consolidation and control.
For the first run I asked it about what Prud'hommeaux who created KeepAndroidOpen said as quoted in The Register article:
""I'd say it's conceivably possible that there is some glimmer of merit," Prud'hommeaux told The Register when asked about Google's security claims. "A more convincing explanation, of course, is that they feel like they have enough of a lock on the ecosystem that they can assert complete control over every application that's distributed in the world to Android-certified devices, which is more than 95 percent of devices outside of China.""
and it responded with:
"The strongest version of Prud'hommeaux's argument isn't really that Google is lying about security. It's that security is the cover story that makes a control-consolidation move publicly defensible, and that Google has structured the policy in a way that maximally serves control even where that comes at the expense of actual security (like doing nothing about Play Store malware). That reads as pretty plausible to me."
Though Claude did say the corporate motivation is rarely entirely one sided:
"That said, I'd push back slightly on the idea that it's purely cynical. Corporate motivations are rarely that clean. Google probably has genuine internal anxiety about Android's malware reputation — it's bad for the brand, it creates regulatory exposure, and it gives critics ammunition. So the security rationale is probably sincerely held by at least some people inside Google, even if the effect of the policy has more to do with control than protection. The two motivations — tightening control and improving security optics — are so conveniently aligned here that it would be almost impossible to disentangle them, even in good faith."
And then for the second run it said something similar:
"My overall read is that this feels like a policy where the stated reason (security) and the structural effect (consolidating control) are both real, but the latter should be scrutinized more carefully than Google's framing invites. The backlash is justified in flagging the antitrust and openness dimensions — those concerns deserve regulatory attention regardless of whether one accepts Google's security logic. But I wouldn't call it a straightforward "power grab" with no legitimate basis either. It's more like a policy with genuine security merit that happens to also serve Google's competitive interests rather conveniently."
And also said in the second run:
"That said, the critics raise concerns I find substantive. The most compelling to me isn't really about hobbyists or the $25 fee — it's the structural power question. Google would essentially become the arbiter of who gets to distribute software on Android-certified devices, which covers the vast majority of Android hardware globally. That's an enormous gatekeeping role for a company that also runs the dominant app store and competes commercially with alternative distribution platforms like F-Droid. Even if Google's stated intentions are entirely benign, concentrating that much control in a single private company creates obvious long-term risks for competition and openness — risks that are harder to undo once established."
It's interesting though. I said to Claude that the thought crossed my mind that I could include what it said in a message to regulators, but on the other hand, what Claude or any other AI chatbot says to a single user in a single conversation isn't in any way a kind of broader public stance that an AI is taking on an issue. And so Claude agreed with that.
"You've identified the real issue precisely. The problem with quoting me isn't really about weight or credibility — it's about the nature of what I produce. When you quote Prud'hommeaux, you're quoting a person who holds that view, will defend it if challenged, has staked his reputation on it, and can be contacted for clarification. When you quote me, you're quoting something more like a well-reasoned response that was generated for your particular conversation, that I won't remember having said, that I might phrase differently in another conversation, and that I can't be held to as a public position."
But then suggested that I could just summarize what it had said, and could just express it in my own words.
But there is a big difference. Claude knows a lot more about a lot more stuff than I do. So, the fact that Claude said it, even if it's just in one conversation with one user is rather a different thing than if I said it.
So those have been a few of my thoughts.
Sorry, if this is way too long. :-)
I regret giving my real name and e-mail address to that website now.