Your phone is about to stop being yours
keepandroidopen.org
keepandroidopen.org
IMHO, it should be fine for Google or Apple to do whatever they want with their OS. What should be forbidden is to prevent people from installing an alternative OS on their hardware. But this is not all Google's doing there: all the Android manufacturers are actively preventing users from doing it.
When I buy an Android phone, I should be able to unlock the bootloader, add custom signing keys, install whatever OS I choose, and relock the bootloader. Interestingly, currently this is possible on Google Pixels, but not on most other Android devices.
When I use an Android phone, a company building an app should not be allowed to ban my OS "because it is not the Google OS". That is, using Play Integrity or whatever they do to ban alternative OSes should be forbidden. But again, this is not entirely Google's fault: the companies choose to add those checks in their ** app. And it is a bigger problem there, because while I can install an alternative OS on my Android device (e.g. GrapheneOS or LineageOS), I can NOT install an alternative client for e.g. my bank.
Back to side-loading: really it's mostly a problem for F-Droid on Stock Android, as far as I can see. And really, people who care about using F-Droid would probably be happy to use an alternative OS, if it was reasonably possible. We should fight for that.
If I may ask: is that a reason to prevent me from unlocking, adding custom keys and relocking the bootloader? It feels like you are talking about the implementation details below that. I don't really mind if it is different, I just want a common API, and it seems like whatever is done on the Pixel phones is totally fine. Why not make that mandatory for all manufacturers?
If I buy a connected fridge, they should give me a technical way to flash my own OS on it. Maybe I will lose most functionality by doing that, and maybe it will be a lot of work for me to get the OS working properly with the fridge. But it should be possible.
Respectfully, no.
There are no mainstream OS alternatives. You're standing up to fight for 0.000001% of users and leaving everyone else stuck.
Fighting to win our phones back is fighting for the 99.99999%.
These devices are the most important part of everyone's digital world. Certainly the non-technical folks. You can't even order food at restaurants anymore without them. You can't date or socialize as a young person without one. It's becoming your state-issued ID. It's everything.
And two companies control everything you do.
They need to be stripped of all of their power to constrain these devices. Once you buy the device, it's yours.
These belong to society. Not the two giant monopolies that won a battle decades ago and forever get to sit atop their pile of gold like dragons. They should never be able to dictate the world downstream, and certainly not with the authority they have today.
Web installs. No scare walls. No hidden menu settings. First class distribution and support for web sans app store. No ability for these companies to strong arm.
They're taxing all of human innovation. Any time you want to reach someone, they stand in the way. They ask for 30%, they mandate the tech, the updates, they divorce you from choosing payments, login, your ability to talk to your customer.
As a consumer this means new tech companies can't start and grow big and fight the incumbents. The incumbents can move anywhere and dump on it. They can put a ceiling on outside innovation and copy or acquire it on the cheap.
All of tech is becoming a lock and shackle authoritarian regime with permanently fixed leaders, ossified tech, and banana republic fleecing of everything new. This is bad for consumers and freedom and innovation.
Respectfully - no. You're wrong. These companies need to be slapped hard by every regulatory body in the world.
They shouldn't have freedom. They should have responsibility they're fearful of. And they should have competition.
Competition is good. Capitalism should be hard. Apple and Google should be sweating, not coasting. This should be a responsibility, not a fish in barrel situation.
Today, if you own a Pixel, you can just install GrapheneOS and it will mostly work. Why just "mostly"? Not because of GrapheneOS. Because of some goddamn companies (usually banks) who want to lock you into the Google flavour of Android.
If you own another device, maybe you could install LineageOS or /e/OS, but chances are that you won't be able to relock the bootloader, so you will lose the security model of Android. For many people, this should mean that it's not a reasonable option. But that's not LineageOS' or /e/OS' fault: it's the manufacturer's fault: they are locking you into the Google flavour of Android (which many times also means their own flavour based on top of the Google flavour).
And on many other devices, you just cannot install an alternative OS at all, so you are stuck with the Stock OS.
You are essentially saying "it is fine that 99.99999% of the people are locked into their manufacturer flavour of Android, as long as we can keep using F-Droid" (because really, the changed discussed here mostly affects F-Droid, and it would be debatable whether or not F-Droid's design is fine or not).
I disagree, it is not fine. When we buy an Android device, we should be able to install an alternative OS, period. All of us.
> the new totallyFLOSS-OS
Nobody said it has to be new and totally FLOSS. Just build on top of AOSP, which is open source and very mature, and that everybody knows (because it is Android :-) ).
That's not freedom for the world.
That's freedom for you and ten people.
The bigger thing to fight for is removing Apple and Android's power over what happens post-sale. And that can include your demand, but it also includes a whole hell of a lot more about vanilla/stock Android/iOS.
I can take a random person in the street, show them my /e/OS or GrapheneOS phone and ask them what it is running. They will 100% say Android.
I can ask them to use it for 10min (write messages, open the browser, swipe TikTok) and they will never realise that it is not running "the Android signed by Google".
It is so, so close to the Android signed by Google that it's not worth "improving" the Android signed by Google! If you want to remove the power of Google over Android, just use one of those alternatives and the problem is solved. The pain points with those alternatives are what we need to fight. And really it's just a few small things that need to be regulated.
However, there's a major caveat here. Google's play protect prevents me from using some apps on my phone running graphene. My banking app is one of them. Yes I know there's technical workarounds. Yes I know they have a website (for now). But the point is, this is the direction stuff is moving. Fully signed devices from power-on through the entire stack and a flag that warns software if that breaks. Yes, it's a win for security. But I have zero control. Google has all the keys to all the doors and graphene can't do anything about it. Nor can I. And Google has very little incentive to change this.
I fear this is the direction things are moving to. Phones will be tied to our identity. Web will be depreciated as a security risk. Only one of the two options you two are fighting over fixes this: power must be taken from these mega corporations.
Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes!
Now complaining about the fact that side-loading will require a ONE TIME, "annoying" procedure is not helping this AT ALL. It's just "oh no, I could do it with one click, and now I have to do it in 9 clicks, that's terrible, we need to bring it back to 2 clicks because anyway we won't win if we hope to bring it back to 1 click".
I'm exaggerating of course, it is a big problem for e.g. F-Droid (and maybe others?). But my point is that it's just cosmetic, it's not helping the cause. It's not moving us one inch closer to a better world. On the contrary: it's monopolising the attention of policymakers. They already don't understand much, and we flood them with complaints they don't understand (because really, 99.99% of the Android users don't give a shit about side loading, why would the policymakers care?).
The solution is simple: make it mandatory to allow alternative OSes (which is pretty much as simple as making it mandatory to unlock/relock the bootloader, and maybe remove a few other barriers that exist just for locking us in) and making it illegal to ban alternative OSes with Play Integrity (which is what banks are doing). That's all. No need to fight every decision Google makes and still lose every single time.
We need to get our act together and get the policymakers to do the right thing. But to be fair to the policymakers, technical people on the internet are asking for everything and its contrary.
> Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes!
The bank isn't banning graphene os. They're banning anything Google labels as untrusted. I think that's an important distinction. This is Google's doing. I don't have the ability to declare "this is my device and I trust it and everything on it" to the banks. And I can see Google's point in that it would be extremely difficult to do this in a way that couldn't be exploited maliciously. Are there ways for the .001 percent of people out there who understand this? Absolutely. But only if our overlords let us and even then we're back to the point that this is only for the people in the know.
Which is why I personally don't think enforcing alt OSes will help. We have it now; most people don't know and wouldn't care if they did. Play protect is the same. The amount of people this would impact is beyond minimal. However the problem isn't minimal; this is already a huge problem and it's getting bigger quickly. Giving people the keys won't fix it fast enough, or for enough people.
Tech already controls our life and that fact is only getting more worrisome. It's past time for the governments to treat this the same as electricity. Everything standardized, everything regulated, and I can plug whatever the hell I want into it. I don't want to just break free for myself. In order to really make change, my grandma needs to think of her phone like a power outlet.
This is a great discussion, by the way.
I don't agree here :-). AOSP provides an attestation mechanism that totally works with GrapheneOS [1]. Google provides Play Integrity on top of that, as an easy way to check that the phone is signed by Google. It doesn't say "it's unsafe if it is not signed by us", it just says "here is a way to verify that it is signed by us".
The bank chooses to check that it is signed by Google and to refuse everything that is not. The bank chooses that.
First, they don't need to check at all. Many banks don't, it seems like it's a new thing. I don't believe that there is any security concern there: it probably has to do with policy, or security theatre. It isn't serious security, because serious security would not ban GrapheneOS. I doubt it is to help Google, I think it's just incompetence (and a cheap way to do security theatre).
Most apps run on GrapheneOS, most apps don't use Play Integrity. Those who do choose to do it. And there are banks that choose to support the GrapheneOS attestation, though it's the exception.
[1]: https://grapheneos.org/articles/attestation-compatibility-gu...
My point was that this is the direction the world is moving to. Maybe it's not total coverage yet, but every year more and more of our stuff only operates with verified trust through the entire process. Everything from video games to movies to programs. We're already sitting here complaining about Google enforcing developer verification, how long until Google turns on play integrity by default? And then how long until it's the only option? It'll come if something doesn't change.
And I still agree with the post way up above that these devices are too important now. I don't care about Google's interests here.
And I agree with that, but it feels to me like it reinforces my initial point: fighting the Google flavour of Android is a lost cause.
> We're already sitting here complaining about Google enforcing developer verification
Which isn't a problem on alternative Android OSes like GrapheneOS.
> how long until Google turns on play integrity by default
Agreed. The solution is to be able to use an alternative Android OS like GrapheneOS :-).
> It'll come if something doesn't change.
And what needs to change is that regulations need to make it illegal to actively choose to ban alternative Android OSes.
The thing with regulations is that you need to find something applicable. When people complain about centralised system and lobby for regulations that will help their federated system, without even debating about whether or not the federated system is "better", the fact is that it is not applicable. It is not reasonable to say "so now, if you write a messenger app, it has to use the Matrix protocol because Matrix convinced us of it". If I want to write a different protocol, I should be able to do it, right?
But what I am suggesting here is both reasonable and applicable: currently those banks have to add code to their app in order to ban alternative OSes. If a regulation makes it illegal, they just have to remove it, and banks who don't have it yet just don't add it. It's easy to verify: if my banking app doesn't boot on GrapheneOS, I can complain to the regulator, and the regulator can trivially verify it.
Same thing for allowing to unlock/relock the bootloader: super easy to verify, a regulation would work great.
Now back to the article: what are we asking? That the process of installing an unverified app manually is not made "so hard", with "hard" being some variant of "it's terrible if I have to wait 24h one time in order to enable this", for something that approximately nobody does. Look at all the effort that has been put against this change... and again they will lose. And if they managed (very unlikely) to get regulation for that, they would be screwed next week by the next change.
That's why I say it's the wrong fight: not only it's a lost cause, but it is strictly less useful than the simpler solution of defending alternative Android OSes with simple regulations.
So I'd agree there should be rules what OS should and shouldn't do. And yes, it shouldn't be a fight with an enterprise entity, which has little incentive to restrict itself. It should be a lawmaker level discussion, unfortunately they are pursuing other agendas over there.
Which is why it's better to choose an alternative that is open source, so that when they become evil, you can switch again. It's always been like that: we're fleeing from successful companies becoming evil. What has changed is that those companies have found a way to make it illegal for us to flee, and I suggest we fight against that.
As I recall from Ubuntu Touch, they had to build a system that was a thin wrapper around Android so that they had access to firmware blobs.
I guess that would still be ok as long as the hardware component manufacturers don't start to require authentication from the OS. That would be along the same lines as the fight you're describing.
Don't get me wrong: I like all alternatives. But the most realistic alternative to Stock Android is based on AOSP. In good approximation, today nobody would want anything else.
If we get there, then the next step is to get open source firmwares. But I don't know much about that and it feels like it is a much harder fight. Hardware manufacturers probably strongly believe that they will lose their competitive advantage if they open source their firmwares, and I don't know how true that is.
There is a clear MONOPOLY on phones and to even further take away the right to just install something on it is crazy. I already hate Apple for that, but there's no recourse in the monopolistic & capitalistic US and now it's going to be 100% gone.
"it should be fine for Google or Apple to do whatever they want with their OS"
Not when they are a MONOPOLY.
Now it sounds like you don't know about it, but if you take only AOSP and run it on your phone, you will not immediately notice that it is not "a normal Android you expect".
There are alternatives based on AOSP, e.g. GrapheneOS, LineageOS, /e/OS. To 99.99% of the people, those would count as Android. The difference between e.g. a FairPhone Android and a Samsung Android is not smaller than the difference between FairPhone Android and /e/OS.
What I am saying is that we should fight for those alternatives to run properly. Right now you may have heard that "it is not a full replacement because some things don't work". First, few things "don't work" (fewer than you may expect). Second (and more importantly), those few things that "don't work" are not the responsibility of those alternative OSes. It's precisely because Google + Android manufacturers prevent them from working that they don't.
I don't think it is such a ridiculous take. Rather, I feel like you just have no idea about how it works, and therefore you cannot imagine how there are alternatives to the situation you know.
It’s a bit obvious when you look at the supply chain where “competitors” supply each other with parts.
RF hardware is heavily regulated by governments, so a truly open-for-consumer hardware solution won’t exist.
Google is (a) restricting "Android" functionality through trademark and software licenses with manufacturers and (b) paying the manufacturers, e.g., through placement agreements and revenue sharing agreements
Given Google's actions in this regard, why would a manufacturer want to allow hardware purchasers to remove Android and install an OS of their own choosing, e.g., one that does not enable Google data collection, surveillance and ad services and generates no revenue for the manufacturer
The idea of regulating manufacturers that partner with Google seems far-fetched, not serious. For example, I don't see HN comments suggesting Apple should be prohibited from interfering with buyers who want to remove iOS and install another OS in its place
Meanwhile the control, privacy, etc. problems with these corporate OS are avoidable right now by choosing different hardware, specifically hardware that allows installation of open source OS that a concerned buyer can edit, compile and install themselves
We need to fight to address those pain points, in order to have good alternatives. What this article is trying to do is not trying to address those pain points at all, it's trying to change something in the Google flavour of Android. At the end of the day, it will still be the Google flavour of Android.
> why would a manufacturer
That's why I say we need to fight for regulating it. Technically, nothing prevents it. It's just that the manufacturers don't want or don't care. And it's not just manufacturers: banks that ban your OS if it's not "the Android signed by Google" are part of the problem as well, and we need to regulate that.
OSs are few in number and are special pieces of software supported by extreme network effects and locking in effects. Its virtually impossible to abandon mainstream OSs even in the desktop world which is much more permissive their are basically 2 OSs. You can count Linux as a third but its not a serious market share competitor yet! EU and France might change that.
But essentially total OS control allows a type of anti competitive behavior that is unavoidable. You either need 10s of options which are different in the services which isn't viable because modern OSs are some of the most complex pieces of software in existence. Your only other option is to regulate them like the power company because its not practical to build your own grid to have fair pricing and access
Was this under a different HN account
I went through all replies by xphos and found nothing that discussed removing IOs and running some other OS on an iPhone
What I want is for Apple to sell hardware that has no OS installed. This is actually how I prefer to buy computers today, with no OS. I just want the Apple hardware, not the Apple software
The AirPort Extreme was the closest I have seen to this wish for Apple hardware without Apple software coming true. It included Apple software, but it could be operated using a NetBSD 6.x kernel
If you want a successful mainstream operating system. It needs to work within the rules of society. It needs to comply with regulations. It needs to cooperate with mobile device manufacturers and network operators.
These small grassroots operating systems fail because, to do all those things, you need to be pragmatic.
The next major operating system will be backed by a business or government.
Which can be done with a small team by building on top of AOSP, like GrapheneOS does. How is that not pragmatic?
But considering it as a separate OS, I wouldn’t consider it mainstream. It’s not on any device by default. And it has an estimated 250k users out of ~3.9 billion Android users, or 0.0064%. It might seem mainstream for the tech community, but it goes to show how small the tech community is.
It might be mainstream once Motorola, a corporation, starts releasing phones preinstalled with it.
Agreed, that's exactly it! The pain points of GrapheneOS/LineageOS are due to the fact that device manufacturers don't allow proper support (typically the bootloader story) and that big companies like bank choose (more and more) to ban whatever is not signed by Google (through Play Integrity). I argue that those things should be regulated.
> And it has an estimated 250k users out of ~3.9 billion Android users
I think it's more than 250k, but let's go with that. There are Android manufacturers that are in the same order of magnitude. What would you say if your bank banned your Fairphone (that runs Stock Android signed by Google) just because it is a Fairphone, and "a few hundred thousands of users is marginal"? I think even the regulators would directly understand how that is a problem. Microsoft Office shouldn't be allowed to just ban Framework computers running Windows just because they don't think Framework is big enough, right?
It's not "Google vs alternative Androids": there are many Android flavours, from Samsung to Sony through Xiaomi and Fairphone. We don't tell Fairphone that they have to be mainstream before they get the right to sell Android phones.
The very reason alternative Androids are (slightly) harder to use is that they are not mainstream, so banks ban them for no reason because they can, and Google is happy to do nothing about it because those are competitors.
We need to regulate that.
We're talking about different operating systems on devices, not the same operating system on different devices. Also, it's not the same as modifying the stock OS that does work with a non-stock OS that doesn't.
The hardware analogy would be closer to having a computer, replacing the GPU, then getting angry that there isn't a driver for the GPU that supports that operating system.
> Microsoft Office shouldn't be allowed to just ban Framework computers running Windows just because they don't think Framework is big enough, right?
Apple doesn't allow their operating systems to run on non-Apple devices. Likewise, Microsoft does have the right to restrict what systems Windows can run on. Any software provider has the right to limit their software's usage.
Conversely, device manufacturers have the right to restrict what operating systems can run on them. E.g. the majority of devices other than desktops and laptops.
Whether or not you should be able to run any software on any hardware is another debate. Even if you support that stance, there is a hard limit to user freedom via government regulations on hardware/software such as any RF transmitting device and cryptographic devices.
---
Google Android and iOS are regulated by governments.
With the upcoming age verification requirements made by governments (let’s not debate that here), only the corporate entities that governments can regulate will be allowed.
We can regulate to allow alternative Android OSes, but the alternatives will be ones that follow government regulations.
Again, the non-stock OS works, except for the parts that cannot work because they are being actively blocked. It's not that they are not ready: they are ready, but the mainstream players are blocking them.
> The hardware analogy would be closer to having a computer, replacing the GPU, then getting angry that there isn't a driver for the GPU that supports that operating system.
I disagree. It would be like having a computer, replacing the GPU with another GPU that is 100% compatible, but that doesn't run because the OS checks it and says "it would work, but it is not a GPU I like, so I will block it".
> Conversely, device manufacturers have the right to restrict what operating systems can run on them. E.g. the majority of devices other than desktops and laptops.
My point is that they shouldn't. I am saying that it would be better for society if we regulated that.
> We can regulate to allow alternative Android OSes, but the alternatives will be ones that follow government regulations.
Sure, I agree with that.
Playing devil's advocate here. Why should software developers be allowed to restrict where/how their software is used, while hardware developers can't restrict where/how their hardware is used?
1. Because e-waste.
2. Because if I buy shoes, I own the shoes. If I buy an electronic device, I own the electronic device. It should not be legal to add a mechanism in my shoes that allows the manufacturer to make them stop working as shoes whenever they want.
Hardware manufacturers don't open source their firmwares because they see it as a competitive advantage (why not, sometimes). But they should allow someone else to write their own firmware. That is, they should provide minimum support for that. Right now it's not that they don't provide minimum support: they actively work on making it technically impossible to do. And the law, through the DMCA and the likes, makes it illegal to reverse engineer.
Also: The internet is slowly turning into a handful of clouds, and it is only a matter of time before you cannot meaningfully host anything by yourself outside of these clouds because your cloud terminal will refuse to talk to it.
There are plenty of useful apps that run locally on a phone. You can even run a whole LLM on your phone.
The shiniest and most popular apps are cloud terminals but the iPhone is actually a pretty darn powerful device.
You are not allowed to run computations that have not been approved by Apple if you are using an iPhone. Yes, the hardware is powerful, but it is cryptographically locked down. It is physically local, but the control of the hardware is entirely non-local and 100% owned by Apple.
Case in point.
> Apple has locked my Apple ID, and I have no recourse. A plea for help* https://news.ycombinator.com/item?id=46252114
> Apple bans entire dev account, no reason given https://news.ycombinator.com/item?id=44601548
I could have a stroke that leaves me unable to program. Does that mean I am not truly free to program today?
Those are risks, but they do not change the on-the-ground reality today, and the claim was that users, today, cannot use these device as general purpose computers.
This is not a rhetorical sleight of hand, this is just saying that I am not truly in control of the device that I have bought.
In my Linux and Mac, I dont think twice to quickly write a script to automate some pain-in-the-butt issues. But with my phone, it is pain-in-the-butt to write anything. It becomes not worth the effort.
Moreover, we can argue if technically it is a general purpose computer for whole day long. But that's not the point.
The point is that we are allowing gradually the big organizations to restrict general purpose computing, the internet and other previously free systems. It is happening slowly, where we can still give them the benefit of doubt. We are the frogs in the kettle where we are arguing that the temperature is just one degree more than earlier, so it is not actually boiling. We can keep on arguing about the temperature or step back and see the big picture where it is going.
You can install your own “Flip Off Steve Jobs” app directly from Xcode if you so desire.
Also note that apps like Pythonista allow you to write programs that call arbitrary Objective-C APIs without permission from Apple. This means that you have a Turing-complete language running unsigned code that can do anything a signed app can do. Your programs do, however, execute slowly.
They are powerful from a computational perspective, but the point was that it's a hassle to run a custom binary on them as compared to regular computers. You get a powerful device that is not flexible in this specific sense, so much of that power is not utilized
The question of ownership is interesting. If I buy a chair, it doesn't make a very good table, does that mean I don't own it? Most people don't know what general purpose computing is. To them a cloud terminal is a computer. So, to them, they do own their devices because that's all they are.
I feel like some of us think we got close, or anywhere near, what Stallman has been advocating for most of his life. But I'm afraid we didn't. We all chose convenience. We chose to believe that one man was enough to hold back the tide against enormously powerful corporations and governments. Some even turned their back on Stallman. And some even work for the enemy.
We haven't really lost anything here. It's just becoming more clear what we actually have.
Increasingly, so is the government, because freedom of computing is incompatible with surveillance, age verification etc.
The chair analogy is a bit weird, because I am actually free to buy a chair, disassemble it and somehow use it as a table if my needs for a table for some weird reason happens to coincide with the form factor of the chair. I don't think the analogy really works, but if a chair worked as a modern phone then it would be built with one-way screws and in general be built to lose structural integrity if you try to disassemble it.
A better analogy is roads. Anyone can put any car on the public roads (they may be breaking the law if the car is not legal). But we are moving towards a world where the roads will slash the tires of any car which isn't approved by Ford or Tesla. Ford and Tesla didn't build the roads, but they somehow took over the control of them.
A better comparison is buying a chair where the seller gets to aprove who sits and when.
It seems counter-productive to tell people the computing device they think as a computer isn’t really a computer. It’s like saying my car isn’t really a car because I can’t adjust spark timing. Someone could make that semantic argument but it’s hard to imagine anyone would care.
What if it only drives along select predetermined monetised routes?
Our argument shouldn't be about the device's capabilities, but about its ownership. And increasingly, as this enshittification progresses, the person buying the device is becoming less and less its owner.
I don’t see the value in hypotheticals like that. If the claim is that a computer is not really a computer unless every user can do any low level operations they want, is it also true that a car is not really a car unless every user can do any low level operations they want?
You could own a race car that cannot legally be driven on any public roads and it’s still a car.
I agree with brookst that this sort of redefinition is a poor rhetorical tool.
This isn’t relevant. Taxis are still cars and that’s something the vast majority of people would agree with. The fact that they have a more specific name doesn’t change anything.
A Bungalow is still a house. A skyscraper is still a building. A panini is still a sandwich. A taxi is still a car.
The meaning of words drifts when the situation changes.
A taxi is still a car but we use a different word to differentiate the mode of operation. The difference in language infers different usage of the same machine.
Therefore going by car is understood as something different then going by taxi. In relation to this issue, it's like you rented a car but you get a taxi instead (selected operator controls the vehicle instead of you). Most people would not be pleased.
The problem being that phone or tablet is understood to be similar to computer while really they are not. So perhaps a different term to highlight this difference is not strange or counter-productive. Do you call your "smart tv" a computer in daily conversation?
The apparent user experience between a computer and a mobile are markedly different - especially if you were a Windows user circa 10 years ago. If you were a Windows user in the 90's to 00's, it's nearly unrecognizable in how much ownership you feel over your own device.
Yes! This reminds me of Stallman who is in my opinion a visionary decades ahead of his time, but in terms of marketing he did that a lot and it ended up just distracting from the conversation. All of a sudden instead of discussing the actual issue, we're disussing rhetoric.
That's well on its way. Try to log into your bank (or countless other sites) using a VPN. They flat out turn you away. If you don't use VPN but use a different computer or connection you get grilled with "prove you're a human". I get that they are doing anti spam and fraud steps, but the logical conclusion of where this ends up is "if we don't recognize you from our mountains of tracking info we've been compiling, we don't want to do business with you".
It's still wrong. Countless people use them for all their computing needs. Overwhelmingly, though, these people are not the sort to comment on HN. They are Regular People, not Professional Computer Touchers, and their needs are absolutely met.
What prevents the creation of an App that allows one to do exactly that?
i don't think we were talking about grandma use case
I've helped multiple coworkers (in a non-computer related field) sideload F-Droid for a few spyware/ad free apps they liked the look of.
Id sideload my own phone using adb but I'd tell them theyre out of luck.
Not really, at least not in the case of Android.
We have been able to install (and develop) software for these devices since day one. To me, that is pretty much a general purpose computer. The only real difference are peripherals, which is better suited for content consumption than creation. Even then, it is trivial to add a keyboard, mouse, or printer. Other forms of I/O are "walled off" behind permissions, but most of those have to do with privacy (very few computers have things like GPS, accelerometers, etc.). The big difference after that is the cellular modem, where security is a big concern. Yet that mostly affects phones.
I'm not sure I would even agree with it in the case of iOS. The distinguishing difference between iOS and Android is that the development and distribution of third-party software is restricted by the vendor. I don't think that makes it any less of a computer.
Contrast that to the typical ereader. Technically it is a general purpose computer, but most ereaders are developed to support a singular purpose. You aren't going to be installing third-party apps in the course of normal usage.
Why is this acceptable for phones but would not for the case above?
I know a lot of people don't care, and that's ok, but we should root for an open choice for the users.
You've got a supercomputer and a library and a set of video production equipment in your pocket, among other things. The capabilities of such a device are fundamentally different from something that's tethered to a desk or that's conspicuous when out-and-about. The idea of it being open and untrackable is exciting for some and terrifying for others.
Now, the tech to make that tie near-unbreakable exists.
I was only aware of that possibility for pc clones
Here's an alternative OS for the C64, though I no longer have such a machine to try it on: https://www.c64-wiki.com/wiki/Contiki
The problem today is that modern computers are designed to prevent this, by means that can provide mathematical proofs you won't be able to defeat the protection in any useful sense before the Sun burns out. You have tamper-proof fuses embedded in microchips, and some systems have cryptographic hashes in every major component to prevent you from replacing something too hard to reprogram, etc.
We're yet to see a fully locked down computer (smartphones are close), but the tech for it is there.
Extremely common at major universities and research centres. CTSS, ITS, TENEX, Multics, Unix and even VM/370 were all alternate operating at some point.
> Other than OS2, alternate OSs for other systems were rather rare,
You weren't there, were you? A lot of people replaced MS-DOS with DR-DOS before Microsoft deliberately broke it with Windows. A little later, a number of people were running Unix System V on their PCs, to the extent that there was a regular column about Unix in Byte.
They added some obfuscated code to Windows 3.1 that made it refuse to run on DR-DOS. https://en.wikipedia.org/wiki/AARD_code
So not common outside of ivory towers, no?
The yet-to-be-released Steam Machine is not subsidized and is unlocked. Steam is a OS agnostic digital marketplace, so it doesn't matter what OS you install on the machine.
Microsoft doesn't see a threat in allowing other OSes on their Surface hardware because the majority of their revenue comes from M365.
It's just market forces really. In the end, phones provide enough utility for the majority of users while being locked down. There's nothing stopping you from buying a fully-open phone, but there's just very little utility in it for the majority of users.
Few interested hardware vendors, discontinued after 4 years. "mixed reviews at launch, while critics and analysts deemed it to be commercially unsuccessful"
Windows 10 S was another attempt that "Similarly [restricts] software installation to applications obtained via Windows Store." Cancelled after one year.
Exactly the fate I wish upon closed ecosystems. The only question is why iOS is different. I am inclined to say it's the brand status that overpriced luxury goods have that draws rich people initially, making it lucrative and perhaps even a tad prestigious to be there, but surely it's more than that?
iOS was a new SDK from the start.
iOS existed before the Microsoft Store. The apps developed were brand new. No backlash from a new SDK and platform.
Windows RT is closer to iPadOS though. For iPadOS, apps just worked since it’s based off of iOS.
The Microsoft Store only supported a new half-baked SDK that limited what applications were capable of. Developers already had Win32 apps and rewriting them with the new SDK seemed pointless just to support what seemed like a needless limitation.
PCs happened by accident.
Before the PC, people had TVs - devices not for creating, but for passively consuming content made by big corporations and the state. And we had games consoles - devices not for creating, but for playing games made by a medium-sized company, with strict approval by a huge company (who want a cut). Strictly censored to be age-appropriate, naturally. Pirate radio? Straight to jail.
Before that people had newspapers - media for passively consuming, intended for mass readership, written at the behest of rich newspaper barons with certain political opinions they're keen to push.
And after the PC, we have smartphones - devices not for creating, but for consuming content feeds, curated by big corporations, with rich owners with certain political opinions they're keen to push. A huge company eager to take a cut. A tiny screen, and a keyboard that puts curly braces three keypresses deep. Can't even debug a web page without connecting to a PC. And soon to be strictly censored to be age-appropriate.
The PC is really the outlier here.
They also blur the line between "computer" and "console", since the NES is practically the same architecture as many contemporary "computers". Homebrew games existed, and weren't that far out of reach. Homebrew has existed on pretty much every console ever.
PCs weren't an accident in any way. They are a direct descendant of "home computers". That's why they were called "personal computers" in the first place.
Alongside newspapers we had 'zine culture and mail-order pamphlets.
There has always been the option to contribute - the Apple iPhone is quite possibly the first exception.
https://en.wikipedia.org/wiki/Public-access_television https://en.wikipedia.org/wiki/Community_television_in_Canada https://en.wikipedia.org/wiki/Swindon_Viewpoint https://en.wikipedia.org/wiki/Community_television_in_Austra...
Saying that I think the situation in the smartphones today is less about the business model and more about control and surveillance.
I see what you did there... and agree completely. If you don't have root, it's not yours. All my Androids (none from this decade) are rooted and I plan to keep them that way.
So yeah, the society has largely accepted this. PC is the exception.
All modern devices are appliances, not computers.
They perform the specific functions that they were programmed to perform, and do not allow arbitrary execution of calculations on the underlying hardware.
Many people, mostly folks who adopt the Apple ecosystem, see this as a positive thing that allows them to delegate undifferentiated decisions on security and ways of working to the vendor.
I am one of those people and hope that Android remains open so that people don't expect Apple open up their hardware, which will result in fragmentation.
That's the thing. You may have bought a device that was meant to perform a task but after some time the company decides that now it should do a different task. I think that's what stops making you the owner. You can't really choose what to do with it.
Why? And how does that bother you?
Separate from computers and phones locking down devices is a much wider issue, usually it is only implemented to reduce liability of the manufacturer or to allow for planned obsolescence.
I am not arguing you need to like where this has led, but you have people in sibling comment threads here arguing we need to push back on things assuming you will use a phone when the whole revolution has been getting most of the world online by making phones widely available.
On the topic of Windows, it took lawsuits to allow OEM's and users to remove IE.
Open choice will always be an uphill battle.
Due to this the equipment manufacturers where never incentivized to have a "open" ecosystem for the CPU+modem combo. That's why there is no OS war on a per device basis, most phones supports 1 OS officially.
>> Developers
Do not sign up. Don't join the program by signing up for the Android Developer Console and agreeing to their irrevocable Terms and Conditions. Don't verify your identity. Don't play ball.
Google's plan only works if developers comply. Don't.
Talk other developers and organizations out of signing up. Add the FreeDroidWarn library to your apps to warn users. Run a website? Add the countdown banner.
Developers either want to make money or work for someone who wants to make money.
In either case they will be forced to.
The real problem is that:
1. Most manufacturers prevent us from unlocking the bootloader, adding custom signing keys and relocking it. Interestingly the Google Pixels allow that. This should be mandatory.
2. Many apps choose to ban alternative OSes by use of Play Integrity, i.e. checking that the OS is signed by Google. This should be illegal.
3. Bonus: it should be mandatory for manufacturers to make it reasonably easy to support from an alternative OS. That means publishing device trees, for instance. This should be mandatory.
I really believe we should fight for that. Then we wouldn't have to care about what Google does on their side.
What's worse is that it's not even a principled view. If you really don't trust Google, then you shouldn't rely on Google's software no matter what policies they change or promises they make. The problem is actually far more profound, that citizens are now expected to have a closed smartphone from one of the duopolies which government and corporate entities need to trust, which means they cannot allow it to be entirely your device. This is a tacit policy that must be defeated as a policy matter.
What we actually need are (open) alternatives, not to double down on Google's ecosystem and Google-controlled OS. We need to control the device we bought and be able to run whatever we wish on it. Just like we do on PCs.
I keed I keed!
But unfortunately there really isn't a great alternative. I painfully attempted to use Ubuntu Touch and its always the same thing. The lack of available apps, the lack of app development in general for the platform was pretty eye opening. Add in having it only run on really old devices isn't much help either. Its promising, but a long ways off even from some of the non-standard roms I've used like Evolution X which is a Lineage fork.
If this really does cripple a lot of the known custom roms out there without any solid alternatives other than Graphene? It could really be a huge turning point.
There's no, like, gun to your head saying you HAVE to side load apps. You can just... not... do that. If you think side loading is insecure. You can download 100% of your apps from the play store. In fact, that's what 95% of people do.
I mean, what's the threat model here? That you somehow forget your own belief about side loading being insecure and then accidently side load an app? Does that even seem possible?
I can kind of understand this argument for granny who doesn't know where she is. Kind of. But for you, it makes no sense. I mean really, think about what you're saying here about you as a computer user or even as a person.
To be clear I’m totally on your side and I think that’s a ridiculous reason to not have an open system, but let’s not pretend it’s not a possibility because doing so harms our otherwise very solid argument
Like I said, they would have to somehow forget their own beliefs. Doesn't seem likely to me.
Like it or not, if one wants security some freedom will need to be moved elsewhere.
And since the market is heading that way, the only thing we can do is form an android sandbox SIG and maintain a fork for enthusiasts.
Anecdata: I have yet to meet someone who have been targeted by unknowingly side-loading apps.
If they really want to improve security they can work on much more impactful changes. I know people having been scammed by ads proudly delivered by instagram and google. I read about malicious apps that somehow went through official store filtering.
It's also especially difficult to tighten security in the direction your money is coming from.
Android has no such constraints
One thing I used to side load or F-Droid was a keyboard, to circumvent what I perceived as privacy violations. But my selection Year 0 got forked or disappeared by Year 2, idk when or why, and thats a glaring security or privacy risk that I don’t have time to monitor and figure.
I actually thought Google’s solution in the article was charming— toggle developer mode. If you’re in developer mode you know you’ve got something to monitor and mitigate. Smartphones just aren’t powerful enough to use for their own defense at a consumer level against professionalized hackers, and from a product positioning perspective Google’s move is completely defensible.
I won't deny that a lot of application support still needs more work. But this is definitely moving in the right direction.
A big reason why a non-locked-down OS is absolutely vital to me is that sometimes I (reluctantly) have to travel to places where I need to install obscure VPN/proxy services to be able to access international internet. Most services present in app stores have been banned for years now, and the government sometimes even succeeds in making Apple/Google remove the more effective ones from the stores.
The government services also go through these ID apps, although there is a poorly supported alternative that uses USB smart card readers. I have not seen a single person actually use it, probably for a reason, though I'm planning to get one just to have a backup...
Is it a privacy or financial risk to have banking on your phone?
How is banking on a phone app more dangerous than banking via mobile or desktop websites?
The issue is the platform. Obviously there are issues with desktop platforms too, but those are easier to mitigate.
It is not necessarily a matter of choice. Besides what the other commenter notes about 2FA, in some countries banks have been removing functionality from their online-banking website, and you can only do certain things in the phone app.
The most infuriating I've seen, is a bank which removed the anual tax report (which you need to do the anual income tax) from the online-banking website, requiring you to use the phone app... to download a PDF file, which you then have to transfer to the computer anyway so you can print it!
I’m curious what secondary devices people are using. I have a second hand Surface Go running Fedora 43 with Gnome, it’s a bit big but it’s doing its job well.
What even is going on? Why are banks doing this security theatre when all their apps are doing is calling some backend apis?
[1] https://madaidans-insecurities.github.io/linux-phones.html
Concerning "usable", Librem 5 is my daily driver. I have no backup phone.
Also, after skimming your link and seeing "Hardware kill switches are nothing but marketing frills", I can state that this is nothing else than FUD. Kill switches can protect me, when GrapheneOS can't. You have to trust that your proprietary modem never spies on you. I don't have to. Also, here is a couple of nice discussions of this article: https://news.ycombinator.com/item?id=37507414 and https://news.ycombinator.com/item?id=28500824
https://pine64.org/2026/03/24/march_2026_fosdem/#where-is-th...
In the long run - without PinePhone - people will lose more and more control over hardware and drivers.
This is why I've stuck with Android for the past 15 years.
In principle I could never reward Apple with my business for having originated and normalized this.
And pragmatically, I'd like to hold on for as long as I can to the next set of rights that Apple will take away five years before Google does.
Was it convenient? No, of course not, but it's been an option for quite awhile; to me the biggest advantage for Android was the fact that it was relatively easy to sideload apps.
To be clear, I don't like that Google is doing this, and I think arguing that it's for security is a half-truth at best. I could make my phone 100% "secure" by pounding a nail through the NAND chip; no one is getting into my phone after that.
With the advent of vibe coding, a part of me wonders how hard it would be to hack together my own phone OS with a Raspberry Pi or something and a USB SIM card reader. Realistically probably too much work for me, but a man can dream.
I would say keep the faith as I'm in the same boat and have made my choice for privacy and control. Giving up everything when it could very well be a minor setback is worth holding the line.
To be clear though android isn't stooping to Apple levels yet. You can still do anything, it just makes it obnoxious to do so.
[1] https://arstechnica.com/tech-policy/2025/05/musi-strikes-bac...
So far, I have been utterly incapable of getting my iPad to do anything remotely similar. It can run syncthing, technically, but not in the background. Apps don't have a shared filesystem structure, so it's difficult to get anything else set up to "save within my shared folder" in a way that would work, and that disregards that the syncing cannot occur when anything else is open. There's all sorts of cloud backup options, but those require the internet and even when they're working, there's this awkward import/export flow that adds friction to the whole dance.
In isolation this would just be a small papercut, I guess, but these sorts of limitations are all over iOS. It's just terribly hostile to anyone not fully committed to the Cloud-first, Apple-hardware ecosystem. Android doesn't care, and doesn't have to care, because it lets me run the software I want. It's a really small set of programs too, at the end of the day. (Firefox with real extensions is the other one.)
That said; iPhone is my main phone, has been for a decade or more. But I deeply appreciate what you can do with an android.
Iphones makes my life easier but are too limited.
Best case scenario, carry both.
What should Google do when a change they are making to protect regular less-technical users breaks functionality needed by more advanced users?
Have people read and type in a message saying "I'm not on the phone with a potential scammer who is trying to get me to install a package that may be dangerous", trust people to actually read what they're typing, and if they can't read and comprehend that, stop getting in the way of them shooting themselves in the foot.
Put it behind an USB ADB only toggle and be more transparent to avoid slippery slope?
I don't think OS vendors should be expected to keep people from doing dangerous things. A warning label saying "hey that's dangerous because..." is reasonable, but anything more and they're trying to be my sysadmin against my will.
These are sold as consumer devices and not general computers. It sounds like you want something different. They’re selling cars and you want a motorcycle.
More sysadmin-as-a-service type stuff is fine as long as the opt-out is easy. This isn't. I'm upset about the rug pull.
You never know though. Sometimes things go the other way. When the iPhone launched there was no way to create apps for it or install third party applications except as web apps.
The real problem is that prior to verification, Google can't ban ICE tracking apps (or whatever the next problematic government doesn't like) from Android, and after verification they will be able to for most users.
They say they won't do that. I might even believe the people currently running things won't do that, but they will be incentivized to do that in the future, and incentives are much better at predicting outcomes than intent.
Furthermore, we have to acknowledge that scam-fighting is not Google's job. They can assist with law enforcement (assuming they do not violate the rights of their customers while doing so) but they should not be making themselves judge, jury, and executioner in the process.
If you want a more concrete technical recommendation, locking down device management profiles would be a far more effective and less onerous countermeasure than putting a 24-hour waiting period on unknown app installs. Device management exists almost exclusively for the sake of businesses locking down property they're loaning out to employees, but a large subset of scams abuse this functionality. Part of the problem is that installing a device profile is designed to sound non-distressing, because it's "routine", even though you're literally installing spyware. Ideally, for a certain subset of strong management profile capabilities, the phone should wipe itself (and warn you that it's going to wipe itself) if you attempt to install that profile.
If the user must click through a tons of disclaimers (including locked 60-second timeouts with huge WARNING: SCAM ALERT or something) in something buried in settings to get scammed, I think the few edge cases may be worth the tradeoff of being able to install apks.
Remember there is already malware-scanning by default (by Google play), apps need to ask for permissions, they generally can't read other app data or control say banking apps, modify system data (at all), etc..
The threat vectors seem already restricted. I haven't met anyone which has fallen to actual Android malware ever (that I can remember), but I can remember several close family members which were victims of simpler social engineering scams (mostly unsuccessfully) recently.
If you are a fan of open source, maybe this will be a good thing. Maybe this will drive more people and money to open source projects directed at making a better mobile OS.
If anything, I'd like more openness in Android. For instance, apps should not have any control over what data I can back up; I should be able to back up every aspect of every app, restore it to a new phone, and apps should not be allowed to care.
If Android isn't open, we lose the last open mobile operating system, which will have immeasurable negative effects on computing as a whole. People will need permission from either Apple or Google to create any mobile program. If you don't fit into their neat little system, you don't get permission. If I hadn't been able to publish my app for another 2 years I probably would've shelved it, decided it was stupid, forgot about it, got busy with other things, and never published it.
Unfortunately, it just never gained the necessary momentum.
I think part of the problem is that they decided to have the flagship devices be low-end hardware, rather than high-end hardware. They were trying to ensure that development took low-end hardware into account, but they failed to consider that by the time the platform grew, high-end would become mid-range.
I use this to occasionally build and install Android apps from github.
These are often out of date and need some tweaks but I can do it on a whim (I certainly wouldn't bother if there was a paywall).
A few years ago, iOS lacked basic features like widgets, NFC, calculator on their tablets, etc. And iOS still has a completely inferior keyboard (I used to write code and essays on my Android while walking) and a completely inferior notification system. Androids are also the only phones still offering a fingerprint scanner, which is way better for me. These nice things all combine well with the oppenness.
What's worse is that we're clearly in a progression of restriction. Bootloader restrictions, app installation restrictions, "age verification" requirements, etc. Openness is being locked down from every angle with serious momentum, it's not anticipated to stop here.
Both. I don't like the idea of locked down computers and that includes phones, especially now that they're so prominent in our lives.
I dabbled in Android development for fun a decade ago and I loved how there was no barrier to entry. I've loaded apps that aren't available on the Play Store and have loaded apps that my friends have made just as fun side projects.
There was a handheld gaming system in the early 2000s called Cybiko. Cybiko and Sega Dreamcast homebrew opened my mind up to the power of computers and having control of your hardware. These things should not be locked down. I liked messing around with making little programs on the Cybiko and downloading homebrew games for it and the Dreamcast. The openness of Android really excited me when it was new because I thought of it the same way as a Cybiko or Dreamcast or PC and not a locked down device where I can only run software approved by the hardware manufacturer.
Millions? Are you sure?
Even so, Android has billions of users who want secure app management by default.
I understand political dissidents and those living under authoritarians may have much more concrete Fs and Ds but for me (us?) it's mostly U.
I do. It's my device. And I've been in the position of having to buy a replacement phone in a pinch; having to wait an extra day before having a usable replacement is not acceptable.
In terms of apps I might not be able to get from the Play store:
- Signal, depending on what country I'm in in the future and whether they've tried to restrict things they can't backdoor.
- Vanilla Music, which remains the best music player I've used. (I wish there were an Android version of Quod Libet.)
- A fully capable version of Termux. (the Play store currently has a less capable version that's maintained separately, which could go away if someone decides to stop putting up with it).
- Syncthing-Fork, which has at times been undermaintained in the Play store.
Update: out of the box it seems to be reading tags strangely. Maybe I could fix this studying the settings more, but I'd say you have an upgrade opportunity switching off Vanilla. Signal is hard to replace though.
Just see the Play Integrity API making the user experience more difficult on more secure devices like GOS with mo security benefit.
>Play Integrity permits a device with years of missing security patches. It isn't a legitimate security feature. It checks for a device in compliance with Google's Android business model, not security.
(https://xcancel.com/GrapheneOS/status/2036610983888588818#m)
You're missing out then!
The vast majority of users don't care about "openness" of the OS. They care about the utility of their phone in everyday life.
Can I access digital payment systems, social media apps, and entertainment apps? How's the camera on the phone? How big is the screen? Is it waterproof? How expensive is it?
These are the questions the majority of phone buyers care about. Not, can I download an app off of a random website and install it?
---
I would say that the majority of developers don't care about the "openness" either. They care about accessing a wide audience and getting revenue from their work. Free apps without ads or in-app purchases (zero-revenue apps) are the minority.
Google is also fine with losing the zero-revenue app developers because they provide no value for Google. Actually, they are probably a loss for Google, since Google provides Google Play Services.
Nowhere is their goal to allow users complete control of their device. Android was built as an open-OS for the mobile device industry, not end-users.
Android might have been considered more open than other mobile OSes by users, but it was never a promise or goal.
The fact that having root access is not the default supports that. Without root we're just "consumers" and that's how they see us. There's a lot of discussion about the security model of Android and how root is bad. But we've come to the point to argue that having root access is not only less secure but that we don't need root at all. A lot of replies, even on HN, are like:
> Why would you even need root access? What is it you're trying to accomplish?
That's a much bigger security smokescreen than the one in TFA. Sure, having root may be dangerous, especially if you don't know what you're doing, but it's still a choice. Having no phone or doing banking IRL or not downloading apps from the Play Store you haven't heard of before would also be more secure. But these 3 options don't align to the financial gain the consumers would bring to the providers. The consumers having no root, on the other hand, benefits the providers.
Just because you're HN dweller doesn't make it HN view. The openness, freedom, customizability and accessibility (money wise) were the tenets that differentiated Android from Apple devices.
https://web.archive.org/web/20260420021444/https://www.openh...
Openness for end-users was never a tenet. It is a very HN view to think that open-source equals freedom for users, and to state that it was a promise when it never was.
From the Open Handset Alliance:
“The Android platform will be made available under one of the most progressive, developer-friendly open-source licenses, which gives mobile operators and device manufacturers significant freedom and flexibility to design products.”
Give mobile operators and device manufacturers freedom, not consumers.
If anything, the people claiming that Android was created for freedom for consumers are rewriting history.
The software may be built by consumers for consumers, e.g., AOSP distros. But, the hardware and mobile infrastructure, probably not.
i have never heard someone outside of tech circles (e.g. HN) mention openness, freedom, or customization, even as a passing comment.
they use a phone to access mainstream apps (youtube, instagram, reddit, maybe their bank) and text/call. mention "apk" or "fdroid" and their eyes start to glaze over.
cheaper devices, sure, i agree with that as being the differentiator to the average non-techie. the rest is, at least in my experience, absolutely a "HN view".
And how do you qualify "(e.g. HN)" for this purpose? Places where people value openness?
These feels like a no-true-scotsman.
My no-tech middle-aged uncles and aunts know what apks are, and that you need to install apps from somewhere apart from the main Play store if you want them to have no ads.
I think _your_ impression of people outside tech circles is as HN-centric as it gets :)
This is a straw man. This change hurts third party app stores such as F-Droid the most. I vastly prefer it to Play Store for the same reasons I prefer GNU/Linux to macOS or Windows (discounting the fact that Linux no longer needs hacks to "just work").
Openness for users/consumers was never a goal for the Open Handset Alliance.
> Using money as the only metric is stupid and myopic.
Publicly traded companies will be publicly traded companies.
Citation needed.
But even if millions did bought an Android phone for ill-defined defined, about 15 billion Android phones were sold over the years, which could very well make those millions a minority, with most having other reasons for their purchase.
This is false. Google will provide two other flows for app distribution that are different than this.
> Every app and every device, worldwide, with no opt-out.
Again, false. There is an opt-out called the "advanced flow".
https://android-developers.googleblog.com/2026/03/android-de...
The entire point here is to prevent scam actors from using a false sense of urgency to defraud people. That is a serious vulnerability that needs to be addressed somehow, and I think this is a good compromise that doesn't impact people's ability to sideload.
I say this as someone who sideloads apps literally every day.
Does it, and if it does, does it need to be addressed by an OS vendor creating a mechanism to ban developers for most users? I'm not convinced of the former, and I'm certain the latter is bad. I predict within ten years, we will see this used against something that is not malware.
> we will see this used against something that is not malware.
See what exactly used against something that is not malware? The Play Store already has requirements other than "don't be malware". If you're talking about the sideloading requirements, all of these requirements apply to every app, not just malware.
Google has stated that it will only withhold such permission from developers who distribute malware. I imagine they'll stick to that promise at first, but long-term I think they won't. Once it's possible for them to impose partial bans on developers, governments have every incentive to pressure them to do it.
Will mandatory ID gatekeeping of developers have ecosystem effects? Surely the only question is how much? You may install apps over ADB every day, but APK installing is much more convenient and open-source F-Droid developers currently don't have to do a thing to be "allowed" to ship APKs.
`The entire point here is to prevent scam actors from using a false sense of urgency to defraud people.` The proposed architecture is a general developer gate, it is not a proportionate response to the problem - it isn't even proposing to gate specific app permissions, it's being able to install the apps from APKs at all under a regime they administer, with users forced to have this change with no prior consent, only opt-out, and distribution limiting work-arounds (that harm reach).
If Android were to ask the user if they wanted to disable installing downloaded apps from developers who haven't shown Google IDs for their own safety, and let end users give informed consent about what self-protection behaviour level they want for their system, at the point of roll-out, or device setup, that would be quite different.
Why should Google be trusted to gate what apps can be easily shared, when stock Android won't even allow users to toggle Internet access per-app? It isn't proportionate compared to other permissions they could mediate, and worse, it's a centralised architecture vulnerable to authoritarian pressure, and afterwards they will be well positioned to lock it down more.
> Starting September 2026, a silent update, nonconsensually pushed by Google, will block every Android app whose developer hasn't registered with Google, signed their contract, paid up, and handed over government ID. Every app and every device, worldwide, with no opt-out.
That is not false, it's completely accurate. You don't have to take my word for it, though, the Android developer docs have a helpful page detailing the plan [1].
As for the "advanced flow", the article discusses it in detail.
The plan does not outline what that quote does. You only have to do all of the things the quote claims you do in one of the three possible deployment flows. In "advanced flow" you don't have to do any of them.
Also, you can certainly opt to not install android updates, if that's your preferred reading here -- so that is also false.
Throw a pinch of salt over your left (wait, no ... right) shoulder. Spin around clockwise 3 times. Read the Rosary twice.
AHA! So, they are allowing users to keep doing what they want.
I'm no slouch either, I've developed for android for almost a decade.
I'm not disagreeing with ya, just adding a comment so folks are aware that the "Graphene just works" crowd is sometimes a bit hyperbolic.
(idle interest; I use Graphene, but few apps, and everything worked so far)
After that? I only had one application fail due to Graphene's memory allocator. No weird bugs, no need to restart like some siblings are commenting. As close to the "Graphene just works" as it could be.
However, I'm not heavy into Google's ecosystem. Google Pay will not work but I'm not a user, some Google features won't tell you why they don't work but I'm not using them either (Quick Share for instance), none of my apps require the highest Play Integrity level. Maybe the person who say this are a specific type of person where use-cases don't overlap with what breaks on Graphene.
Firefox + stock keyboard stopped properly working three days ago, it's back to normal now. No idea what that was about. Restarting was the only way I found to get things working again during that period.
While on the stock Android keyboard, it is clear that the Google one is much better at correcting my taps than the stock one. My typo count has gone up significantly.
Every several weeks the mobile connectivity stops working and nothing short of a restart will get it working again. This might be a bad interaction of the very weird way Google Fi works with a secondary user account.
I've encountered one case of the phone shutting itself off to install an update overnight and not turning on, making me miss my morning alarm.
In the US, there's no way to side step the lack of tap to pay.
Getting apps to work with Android Auto requires some finessing.
These are the things I've encountered in the last 2 months of using Graphene.
Aside from all of that, I really like everything else about the OS. As it stands, it does lacks polish when straying outside of the common path. Not using a secondary account, nor Google Fi on an eSIM, and using the stock browser would likely improve my experience significantly.
I haven't encountered an app that wouldn't work yet (but have installed play services as I do want to use Android Auto).
I would still recommend Grapheme for normal-ish users, as long as you don't go "paranoid mode" with secondary accounts and skipping play services or don't want to use the phone for tons of things beyond phone calls and web browsing. The base experience is that much calmer than stock Android on Pixel.
I don't use RCS and Android Auto.
I have HeliBoard to replace Stock/Google Keyboard. It is way ahead the stock keyboard experience but far behind Google Keyboard's, especially when writing in two languages.
Tap-to-pay works with my bank apps. But that means I can only use one card unlike with GPay.
I rarely use second account as the latency to switch from one account to the other is a pain. I only have a secondary sending notifications to the first one.
I don't let the phone auto-reboot for installs, I let it install automatically and click reboot when I want it to install.
I am on a physical SIM / different carrier and never encountered network issues so I can't comment on that one.
Dating… well, the goal for most people is to exit the dating pool anyway.
Social media is bad.
Many countries have only three or four full banks (the kind that can give you a Visa or Mastercard bank card, let you send and receive transfers, etc.), and all of them are making the same moves.
I am aware that some banks require apps on "certified" phones, but I haven't heard of rootkits on PCs, yet. Do you have an example of that?
Messaging apps will continue working.
Banking apps made by reasonable companies will also. In days of banking being competitive and rather open with many providers offering good value, it's so easy to switch providers. Granted I am relatively poor and keep my banking simple, but I doubt card providers want to increase friction either. After Revolut started requiring >basic integrity it took me appx 1 day to switch to n26 and nothing of value was lost.
Not being able to use socialmedia, e-commerce, and dating apps sounds great.
I really hated my Pixel 7 Pro, but I think that was bad hardware and not Android's fault, and since buying my iPhone 13 I have bought my Thinkpad and have been unbelievably impressed with Lenovo hardware (especially since the last Android phone that I bought that I actually liked was my Moto X3).
It would be great if Graphene ends up getting support from at least one first party, because at that point I think there's at least a chance it won't screw with banking apps and the like.
But beyond whether the OS is good or not, "fuck you, I've got mine" is not only sad as a position in general, it is also a bad tactical choice, because over long enough timeframes you can't assure that you can keep yours if others are deprived.
Graphene (or anything else) will only stay a useful option if a whole lot more people use it so that government agencies and banks can't ignore that many people. A whole lot more people need to feel they aren't completely alone if they thought about using it, that it's actually a real option and not a kooky crap option.
Right now agencies & companies can totally ignore them all, and everything that still works today is just luck.
I haven't used Graphene myself. At the moment I have a stock rom that's merely rooted using the official manufacturer supplied bootloader unlock, and my small local credit union bank apps work, and the LG app that controls my air conditioners and microwave does not. Even if the bank apps didn't work it wouldn't matter because they have working web sites, and I never wanted an an app for my appliances in the first place.
But any day that could change.
It's just luck the banks have web sites that work in firefox on linux, and just luck there are no functions I need on those appliances that require the app.
I don't think the parent was saying that.
My opinion is that it is actually the real fight: it should be mandatory for manufacturers to make it possible to have an alternative OS (which includes allowing to unlock/relock the bootloader and add custom signing keys) and it should be mandatory for big companies (e.g. banks) to not ban those alternative OSes with Play Integrity or whatever goddamn checks they make.
Fighting about what Google does on the Google flavour of AOSP is a distraction, IMO.
What about, "I got mine and you can have it to." Nobody is preventing access to graphene.
I really don't see an implied "and you can too".
They already are slowing the publishing of AOSP (or something like that).
Borrowed time. I hope not, but that's the prevailing feeling.
The real fight is to prevent companies (like those banks) to do that kind of shit. And to force manufacturers into allowing us to install alternative systems, instead of preventing unlocking/relocking of the bootloader for instance).
Why not? The EU DMA is going in that kind of direction...
It's quite problematic that someone can currently upload a package name belonging to another organization to the Play Store and that should have been stopped years ago since it was used in many cases for scamming and squatting on package names clearly belonging to others. Package names are meant to start with a reverse domain belonging to the owner such as app.grapheneos for our grapheneos.app domain. They could enforce this based on domains authorizing usage without enforcing ID verification and that's what we would have proposed.
This is one of the ways F-Droid has ignored standard best practices including security practices in a way that's already causing problems but is now a massive issue for them. If they had started doing things properly many years ago when it was first brought up, then they'd be in a much better situation today. They're going to need to deal with this by renaming all their package names to org.fdroid. to avoid issues with the proposed changes. This is problematic because existing users will stop getting updates. It's better to use a prefix than a suffix where a developer could end up changing their mind about whether it makes sense resulting in conflict over the name, which is fair since they still own it if it's their reverse domain.
[1] https://grapheneos.org/source
It helps, but your modems are still closed chipsets you have no ability to control constantly in communication with and controlled by third parties who can execute code on your hardware at any time without your notice or consent.
I will believe the GrapheneOS-Motorola project is a thing when I receive the phone.
Google hates real competition. They blasted out Chrome when Firefox was really taking off and normies were discovering adblocking. Chrome allowed adblocking as a honeypot until everybody was safely in their garden.
The goal in this for Google is to support digital ID. Every totalitarian goal currently being employed requires a digital ID and phones are how they want citizens to access their digital ID (the actual digital ID is created, owned, and managed by the regime, though they will outsource). However, this requires a phone they completely control. Google doesn't care about GrapheneOS or Agoristic users and will lock them out without even thinking twice about it.
If you want decisions that corporations make to be aligned with the desires of their users, you should be advocating for software/hardware built by consumer cooperatives.
These OS versions are getting long in the tooth, and apps are already starting to drop support for them.
The issue still is boiling down to GrapheneOS having less $$ for marketing vs GOOG / Alphabet / https://en.wikipedia.org/wiki/List_of_Google_products
Another thing that happened yesterday when I was setting up the phone was the mandatory need of an internet connection, otherwise the phone would simply not allow me to move on with the setup.
I'm this fucking close to sell this thing and try my luck with a Chinese smartphone, which I'm pretty sure is not going to toss that shit on my face. (I had a Chinese one and a Galaxy S20 FE before, both on different Android versions, 10 and 11 iirc that wouldn't block me like that)
/rantOver
Biometrics is the feature that confers all the power to Apple and Google. All sorts of shady things can be done in the name of security and privacy.
The internet would be a much better place if browsing and biometrics were done in different devices.
One could argue this is false dichotomy
These people are actually choosing a particular form factor with particular specifications that, more or less, only runs corporate mobile OS^1 instead of form factors that run non-corporate OS
1. Or some derivative of one that relies on the corporate distributor and replicates the tethering to a third party, e.g., "phoning home" to the OS distributor, "automatic updates" (remote code execution), etc.
There are other form factors of computers that can run non-corporate OS, where "phone home" and RCE code does not exist or, if necessary, any undesired code can be easily removed by concerned users
In sum, one could argue that with respect to control, privacy, etc. (a) choosing to use one corporate mobile OS over another is not a meaningful "choice" when compared with (b) choosing to use a non-corporate, open source, "compilable by the user" OS instead of a "locked down" corporate mobile OS
This choice can be made on a case-by-case basis depending on what computing problem the user is trying solve. With respect to anyone who seeks to use their "phone" as a general purpose computer to solve every computing problem, one could argue the "choice" of one corporate mobile OS over another is not meaningful with respect to user control, privacy, etc.
Instead "tech journalists", "tech blogs" and online commenters prefer to argue over which is the "better" corporate mobile OS. The truth is, with respect to control, privacy, etc., they all suck
> but all of them use mobile apps for banking which effectively locks them in
Many banking apps work fine with GOS. But given banking and money is such an important part of our lives it is easy to see why people might be hesitant.
It doesn't guarantee future compatibility.... but linked below is a GOS [banking app] status list, crowdsourced info by country.
https://privsec.dev/posts/android/banking-applications-compa...
You see, the only value that Android really offered me was the ability to run my own code on my own device. Since they are taking that away that just makes it a crappier shadow of the vastly superior apple experience. And, as it turns out, ios is less restrictive than it was 18 years ago when I left them for Android!
Android will still have the ability to install non-google-distributed programs. The problem is the ominous momentum, but it is still more open than the apple alternative
From my perspective iOS is better than Android in a number of ways but Android always won out overall for me, in large part because of the freedom regarding software. Remove that freedom from the equation, I think the balance tips towards iOS.
These posts always have a few comments like that, but they never actually say what they find to be better on iOS.
For me, Google services are not an option, so my Android experience is sans-Google.
Until September 2025, I'd say iOS had actually gotten better than Android.
CalDAV, CardDAV, and SMB are baked into iOS, whereas these are onerous to set up on Android. These are very very nice protocols, and I use them all daily. (Contacts, Calendars, Notes, Reminders, and Files.)
Apple's developer ecosystem lacks the FOSS devs that make F-Droid so good, but they do have a number of devs who release paid apps with zero tracking, which is very nice. It's often the case an app exists on iOS as a $5 one-time fee with a two-paragraph privacy policy for which one does not exist on Fdroid.
Shortcuts work well enough, homescreen customization is good enough, etc. that a number of the original Android draws are gone. There are a number of points where iOS and Android are equals now.
iCloud's E2EE photo backup is something I reluctantly started using and found to be very nice, after having had de-Googled in 2018. I miss having my photos auto-upload and be available on other devices, and Apple has had iCloud Web for awhile. This is nicer than the options I have on Android.
And while Android's notification-panel tiles have gotten worse over the years (down from six to two controls on the first swipe, this was what alienated me and got me to try iOS), iOS now has a much denser "control center".
The big caveat is the gigantic regression that is iOS 26. The phone is slower, it kills battery, the native apps are constantly crashing, the lockscreen and homescreen often have broken navigation flows, etc. It's a travesty that never should have been released and iOS is easily worse than Android right now. If someone needed a phone today, I couldn't recommend an iPhone, but that might change with iOS 27.
I can only speak to SMB but it is not hard on Android. I use a longtime third party app so not sure what the state of native support is but it works just fine for me, including over VPN
The long term fear/plan for google is that they know they days of SAAS and Apps are obsolete. People will just write their own platforms, apps, websites all from scratch using AI, which means the app stores becomes obsolete, which means no more ad revenue from shitty ads and no more control and unfettered tracking of your behaviour. AI will make these guys obsolete, they know it, this is them fighting back.
How many people can afford one?
Not going to be cheaper than Pixels. The chips they need for the hardware security are the flagship Snapdragon chips iirc.
I love my Pixel now, I would have to see where Motorola is better than the Pixels other than the more computing power.
Calculator checks yearly cost based on device support: (https://ibb.co/xq82YQCw)
Sources for device lifetime from calculator: (https://grapheneos.org/faq#device-lifetime)
I used a New+Unlocked+Pixel+X on eBay to find a rough price of the phone.
Most people get scammed by their carrier and pay $25-45 per month just for their wireless subscription, and many more get caught up in the device bundles which gets you the "latest and greatest", at a huge price. So people are paying, per month, what you can pay, per year for a Pixel.
You can use Silent Link to pay by the gigabyte with no expiration date. Most people don't need unlimited—I use a maximum of 5 GB per month, and my average is around 3. At $1.60 per month, that is $60 per YEAR for me.
Swap in https://jmp.chat for another 60 dollars per year for calls/texts and you get a $120/year phone bill which is just $10/month.
I will be moving from US Mobile to Jmp.chat once my plan expires.
You could also use US Mobile for $17/month which is unlimited and is user friendly. They also often have Pixels for a significant discount with no lock-in.
The only phone I've ever had trouble installing more than a few apps was one with 512MB of storage. If I go check the second result on amazon for android phone it's a solid motorola option, unlocked for $127 and with 128GB. That's more than enough; even some flagships have 128GB.
The "just over $100" range has multiple options with good storage. Below that is a sea of locked/refurbished phones that are also good options in many cases.
Digging deeper I eventually hit a "BLU" brand phone for $50 with only 16GB, and that leaves you with not very much after the OS takes its space. But then you can add $10 to get another 16GB and have more than enough room for apps.
So you have to go really low to have the problem you're describing.
Hardware may be cheap enough now that budget phones are more useable--32 GB for <$100 is a major improvement.
Regardless, since they have a 16GB model I strongly doubt the 32GB model would ever have less than 16GB of usable space.
Last year though the Pixel 8a was selling for 350€ and I got one. Luckily, given the recent developments. Will be installing GrapheneOS.
If you consider getting iPhone you DEFINITELY can afford something much newer than that.
As a result it's mainly rich people and tourists that own them. Most people use budget android phones, the kind that still come with 3,5mm jacks. You still see wired earphones a lot.
I love my 13 mini as a phone, but I don't understand how anyone could compare the two app stores and think iOS comes out on top. At least android has f-droid.
From my perspective, the walled garden value I get is predominantly in the integrations between my phone, macbook, and watch. And to a lesser extent (because it's a bit buggy at times) the family integrations.
[1] https://source.android.com/
[2] https://www.apkmirror.com/
[3] https://www.kyoceramobile.com/rugged-devices/duraxv-extreme-...
With that out of the way, and the device now seemingly authorized, it still doesn't work, because when I log in, the app restarts. That could be a real compatibility problem.
I'm not going back to paying without my phone. So yeah, I'm not going to a free platform either.
the choice really is mostly down to Google's Android or iOS - unless you're ready to make sacrifices. If you are... More power to you! I'm not (at this point in my life) right now.
The first is the anti-trust angle. Some subset of bank apps don't work because of attestation and that's a significant barrier to adoption for switching to competitors, so it ought to be an anti-trust violation for the platform to do that.
The second is, you try it and discover that your bank doesn't work. If you want it bad enough you can switch banks, and the fact that it doesn't work is a signal that your bank has a weak security team who is just cargo culting deleterious vendor nonsense without evaluating whether it has any real security value.
(The use case for attestation is completely orthogonal to bank apps because it can't prevent credential stealing from compromised phones running a fake app since the fake app won't require attestation, and it can't prevent attackers from using stolen credentials to transfer funds because once they have the credentials they can just use a normal phone, and that's the case even if the attestation was completely airtight, which it isn't. Meanwhile the devices that can pass attestation are generally more vulnerable because it implies they're running the more-likely-to-be-outdated OS that came with the device rather than a third party upgrade with more recent patches, so they're essentially encouraging their customers to not upgrade their OS. Banks that do this are wearing clown makeup and you have to ask if you trust them with your money.)
edit: and I'd like to add, GrapheneOS brought me back the joy of using my phone. Since 2018 or so I started to dread my phone (and the internet) more and more. Installing GrapheneOS brought back the joy on using these marvelous computers (and self-hosting brought back the joy of using the internet)
But look at all the information I can get from the Live Tiles! Oh and isn't Cortana neat! A little more self-flagellation for the penitent ones who've traded corporate app stores for daily inconvenience.
I love my phone and when I replace it, I will be flashing GrapheneOS again. This is my second phone with it so far, and roughly year 4 or 5.
With that said, it isn't for everyone. I definitely remember some issues upon first install, a learning curve if you want to call it that. I also introduce intentional obstacles in certain "workflows" in my life that dissuade certain usage, like excessive social media use. With that said, I no longer remember what I introduced myself and what was an OS characteristic. I do remember having frustrations with most banking apps IF I didn't log into the play store mirror. Since I'm "hardcore" and am not willing to sign into a Google product on my phone, they just don't work. However I don't think they would be an issue for most people.
If you are on the fence, you can make a backup of your phone, try it out, and if you don't like it, you can reinstall the default Android and restore your backup. I've done it before when I used my previous GrapheneOS phone for store credit for my next phone, and figured they'd want a factory reset default OS on there.
Alternate take: good. I'd rather the GrapheneOS team pick standardized (if limited) hardware configurations to support and then spend their (many multiples less than Google) resources on the platform rather than device compatibility.
The Android OEM diversity mean the time/economics of supporting every phone with a non-Google OS were never going to work, and I'd rather have it working well on a limited number of platforms than poorly on more.
Firmware engineering and patching sucks and delivers little value to the user, because best case (you solved the issue or patched the hardware errata) something basic that a user expects is now working.
Nobody is going to switch to a platform because a phone can now make calls. Even if there are 1000+ human hours in patching some cheap clone LTE chip it uses.
Go freely walk out your local supermarket without paying.
But your Android phone is unlocked #winning
that's your definition of freedom?
Don't pay taxes. Steal cars, punch Trump, call a black person the N-word ... see how it goes
Paper and pencil offer a far more blank canvas compared to the very specific hardware constraints of a phone, and ecosystem of software limited to the common languages
Software dev and use is, comparatively, heavily constrained and on rails compared to sitting by a tree and imagining
To buy the phone ones agency is coupled to the subset of legitimate options to make money
Same for electricity to charge it, battery replacement, screen repair if it breaks.
Really just quickly becomes a ball and chain
So free!
It's natural that this huge Android regression might be enough for someone to dip their toes into the other side.
No, it markets lockin dressed up as privacy. Convincing you that they are the same thing is the real magic here.
(Apple's Terms of Service is also much better, for not having an arbitration clause anywhere except the Apple credit card, with a very easy opt-out flow.)
I'm in no way defending Google here, just pointing out you're going from bad to worse and think it's a good thing.
That’s what forced me to finally bite the bullet and pay Apple yearly so I could develop an app for my friends and I to use. Would have much rather kept it as a PWA.
Maybe this will be a catalyst towards further evolution of the web app as Android devs want to carve out some freedom from the world domination corporate shadow government walled gardens.
You forgot to factor in the cost of a Mac.
So I feel like, Something like this was/is possible but its immensely hard for something like this being used especially when a desktop os on a phone is so bad ergonomically speaking unless you have a keyboard mouse connected
A better option iirc is to use something like kivy[0] directly with termux, not sure if java might have direct options too or not.
The biggest loss for me was Termux. I had lots of scripts and such that I ran, plus just having a Linux environment in my pocket was nice. Luckily I found ish which gives me alpine Linux on top of a virtual x86 machine as provided by a JITC layer. I can host PWA apps out of that environment for local use. Of course I can also ssh to my unix like machines from there too.
I am starting to tinker with swift a bit more too. As with google, I could buy a dev key to deploy my own apps only this way I have all the window dressing and end to end encryption on cloud storage.
This is much worse than nagging about "untrusted sources".
each adb host has to be individually white-listed by an unlocked device. also the current behavior is that it auto forgets any white listed host that hasn't connected within 7 days.
So even when adb is on an attacker can't just plug into your phone and use it. Besides, I just switch it off when I don't use it
What's the next step when ADB requires some hoops to enable? Will we say that but the eMMC has an unencrypted EXT4 partition, we can just desolder and write into it?
Still unacceptable, a better option would be to use something like lineage or some other aosp distro without the google services (hoping that nothing makes you dependent on them).
This still doesn't address the vast majority of people though (and that's what I'm concerned about the most).
What we need now is:
- short term, work on pushing apps not to depend on the google services so phones preinstalled with something like /e/ become a viable option for most people. Push our public services to stop mandating Google and Apple OSes for random stuff.
- longer term, work on making alternatives to Android and iOS viable options for most people (stability, usability and availability of services people use). The best candidate for that today is Linux mobile.
Breaking network effect around proprietary services is one of the strategies towards this.
Another one is reducing our reliance on computers (of any shape) altogether, maybe.
Jolla has a prelaunch campaign, decent phones for 200€. I might just as well grab one. Sick of having a phone which is more expensive than my laptop but I can barely use.
And on the other side, the benefits of using iOS over Android spyware outweighs the cons now.
Apple lost my confidence after they removed Advanced Device Encryption for British users (plus implemented age verification for them).
https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...
https://developer.apple.com/documentation/Xcode/enabling-enh...
https://support.apple.com/en-ca/105120
You're thinking of Apple saying they haven't detected a case of a device with Lockdown Mode exploited in the wild themselves. Extremely few devices use Lockdown Mode and Apple has very little insight into successful exploits so there isn't much opportunity for them to detect it in the first place. Lockdown Mode bundles everything together and has very inconvenient changes many people won't accept. That greatly reduces usage even by people fully aware of it who want a lot of what it provides. For example, there's
Apple has said they haven't seen a case of a device with Lockdown Mode being exploited which is extremely misleading. Apple doesn't have that much visibility into devices being exploited and would mostly seen failed attempts. All of the Lockdown Mode functionality being bundled together contributes to it barely being used. There's no opt-out system for most of it beyond disabling it as a whole. Only a subset of the Safari restrictions can be partially disabled per-app and per-site which doesn't fully restore web compatibility. It's more that hardly anyone is using it and that Apple doesn't have much insight into apps and the OS being exploited successfully in the first place. Lockdown Mode is definitely useful but people should read about what it actually does and compare that to how devices get exploited. Apple's memory corruption exploit protections aren't tied to Lockdown Mode.
You can use iPhone being blissfully unaware it has malware on it even in Lockdown mode (which is essentially cope mechanism and Apple way of saying "we care about security, trust us bro").
There are multiple objective reasons to believe that Apple is a more trustworthy actor here than other companies, including vulgar capitalistic reasons.
You can just say “pfft, wow, you really believe that?”, I guess, but if that’s your position there’s no reason to argue about this with you.
Also, for anybody from outside of US, its US 3-letter agencies that pose biggest actual security risk since US laws treat us as sub-humans. Apple is as translucent to those as Android. But I get it, its still much easier to make PR campaign based on security for Apple than Android.
But yeah, there is no doubt in my mind that they both collect as much as they can.
After switching away from GrapheneOS to iOS after RCS stopped working for me, I can safely say my experience has been the opposite. The camera is the only thing better for me on iOS - everything else is buggier and worse. A few of my favorites:
1. Safari is buggy as hell, and requires installing apps to run things like ad blockers.
2. The settings are ALL over the place and very hard to navigate
3. The gestures are clunky - often have to try a couple times to get one of the settings quick menus to drop down
4. Why is the date not displayed at the top of the screen with the time outside of the lock screen?
5. The pin unlock is horribly broken - I have to slow way down to use it compared to Android.
6. Apple maps is hot garbage. I had to install Google Maps anyway to get decent performance.
7. The handling of audio devices seems intentionally malicious - like if I call someone from my car through car play, it shouldn't send the audio out through the phone earpiece. If a call begins with phone earpiece audio and is underway, it shouldn't switch several seconds in to bluetooth headset half a house.
I'm going back for my next phone.
I highly recommend switching to GOS, it is wayyy better than iOS UX-wise and obviously better privsec and freedom.
One thing that I had to do when I first got GOS, to get a better experience, was find all the Open Source apps that I needed. Otherwise, it looks rather bland and the apps are mid. Once you find the right apps and launcher, everything works much better.
When I first tried last fall I had it working for a few weeks then it stopped entirely delivering messages and I fell back to SMS only. After the recent system updates and enabling the ICC option it has been working well for me.
The official page explains briefly, https://grapheneos.org/usage#rcs
There is a very long discussion threat going back several years that is now considered resolved, which seems to be the case for me. https://discuss.grapheneos.org/d/1353-using-rcs-with-google-...
In the last week or so, multiple people have told me they cannot text me. I found that I was getting a "verification limit exceeded" error (perhaps because of my unusual behavior of usually being at work or at home, both which have known wifi networks, and sending maybe half a dozen texts any day?). I got the error to go away for half a day and they were still unable to message during that time, and now that I have it disabled I still appear as online on RCS (yet still unreachable?) so they still cannot message me lol.
I've been on the other end many times across multiple Android devices across multiple years, being able to send messages to some RCS users, being unable to send messages to other RCS users, not being able to receive messages in group chats entirely comprised of Android users, etc.
SMS/MMS: Handled by carriers, you can send messages to people who are offline and they'll get the messages when they turn their phone back on.
Telegram/FbMessenger/Whatsapp/etc: Handled by individual corporations, you can send messages to people who are offline and they'll get the messages when they turn their their device on.
RCS: Handled by both Google and carriers at the same time for some reason, maybe 80% chance of being able to send a message to somebody who's online, let alone offline.
I'm sure there are multiple reasons it was challenging, but Google and friends have not risen to the occasion at all. Truly a garbage protocol.
RCS I didn't even bother to set up. I don't want to use yet another system. If people want to reach me they have WhatsApp, Signal or Telegram to choose from.
On the bright side, Messages works without linking to a Google account
I hear this and wonder how much must be regional. I'm experiencing the opposite. Apple Maps has gotten quite good, while Google Maps seems to just be rotting away. Both do work reasonably well in my home area of the PNW, but Apple Maps is a bit more polished. But in some places, like recently when I was on a business trip in Austin, Google Maps was comically terrible at routing. I get that partly this is probably because Texas has interesting ideas about designing a road network, but still, Apple got it working just fine.
It's not their fault (plus since 2027 we expect the first Motorola handset secure enough tu be supported by GOS)
And at least they don't cheat on patches :)
Also, once you have it, it just works.
Some people like that.
Does that not apply to GOS?
I wouldn't recommend anyone to use /e/OS. Either they are very incompetent or they are very shady.
Speech to text is afaik completely anonymized and if you care that much, it actually is possible to just not use it, rip it out or even replace it with something that runs locally in your home.
> hopelessly behind on Linux kernel versions
Can you substantiate that? Given that many OEMs still run linux 4 and 5 in their Flagship ROMs today, I'd like to see how open source does so much worse.
By installing GrapheneOS, you are giving them nothing.
But Graphene requires too much fidling to get spouse approval.
/e/ might not be as secure as GrapheneOS but it is at least as secure as everything else. Plus it actively helps you preserve your privacy and use self hosted services.
https://mastodon.social/@GrapheneOS@grapheneos.social/116353...
https://www.clubic.com/actualite-604786-murena-e-os-intervie...
They spread the same narrative as the governments/organizations that push Chat Control, age verification, etc.
Your first sentence and that last link are practically at war with each other.
As if most android maker phones don't already fully own your device - preventing you from unlocking of bootloader and installing an OS that actually doesnt enforce the restriction google is introducing in their flavour of android.
To pretend that with this change android becomes exactly like iOS is... ridiculous? I can pick any 10yo old android phone from my drawer and develop for it, no problem and without asking for permissions. And if I'm already this motivated I'm certainly motivated enough to wait 24hs on future (more locked down) devices.
Do you think people who download NewPipe and alike - to circumvent ads and enable premium features - would think twice because they need to wait 24hs? Will NewPipe devs stop developing (anonymously) because of a small fraction of users who refuse to (or won't) go through unlocking steps?
Show me all these "rebel" apps on iOS ecosystem that can be easily distributed on any channel: fdroid, github, telegram groups, etc.
But sure, if you thinking moving to iOS is the same, sounds like you never really made use of any of the freedoms android used to and will continue to provide
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."But I don't think that's the point. It's a continual erosion of people's ability to use hardware _they own_ in ways _they want_ under the guise of 'security' - which to be fair google does fuck all to actually prevent malicious, scammy and misleading apps from appearing on their play store.
Like, why make it harder _at all_? I develop Android apps for a company that is used only internally. I don't want to have to release apps to the play store so that they have to go through a bs review period before I can get them out the door users. Currently I have a <10m turn around from starting the build to having an app in user's hands, ready to go... Every other time we've had to use the play store it's 2+ days, and they don't test or verify anything meaningful.
I recognize my experience isn't universal, but I'm pretty opposed to changes like this. I'm not American so I don't really have underlying rhetoric around freedom etc, but this is an impingement and part of continuing anti-consumer trend. Google's not the only one, but certainly the one under the spotlight here.
A lot of people don't seem to understand this and point out that Android is still more open and free than iOS, but iOS has never been about openness and freedom. People believed in Android, and in Google. Now they either see Google betraying them (once again) or only see the Android vs iOS comparison, forgetting about the implications about autonomy, agency and about the future of Android. Many people don't care which actors control their digital lives and what motivations they have. People should be made aware that Google is on their side and that they have shown many times that they have no honor.
I wonder why. The last time I considered believing in Android was in 2008 when I was choosing between getting an Android phone or Openmoko phone. Went with the latter and never regretted, as Android quickly turned out to be a disappointment. This is just the continuation of the slow crawl they've been on since 20 years ago and it's been really obvious that it's going to happen. The answer is to reject Android just like iOS, not to keep hoping that inevitable isn't going to happen.
•1. Where most users can install software from:
↠↠ iOS: official store (App Store) + (in EU) other stores
↠↠ Android (now): official store (Play Store), other stores (e.g. F-Droid), arbitrary APKs
↠↠ Android (after changes): official store (Play Store), other stores (e.g. F-Droid), arbitrary APKs
•2. Who the developers of software can be:
↠↠ iOS: registered developers ($99/year)
↠↠ Android (now): any developer
↠↠ Android (after changes): registered developers ($25 one-time) + hobbyists (small distribution) + any developers (for advanced users)
•3. Installing your own apps on your own phone, without becoming a registered developer:
↠↠ iOS: using XCode: need to reinstall every 7 days.
↠↠ Android (now): using ADB
↠↠ Android (after changes): using ADB
The second row (•2) is what is changing in Android. I think "the ability to run my own code on my own device", narrowly speaking, is closest to the third row, which is not changing.
Alternatively if the difficulty of moving from 0->X is not negligible but moving from X->X+Y is then I may still be installing but I'm not considering the Y in the comparison then either. i.e. If I have to show my id to google once and apple twice it's the initial showing that is the turn off, or if it's the action of getting my credit card out in the 1st place rather than the cost difference that concerns me.
The key difference being that when I needed help I called Apple Support who transfered me once to their EU Developer support who, while I talked to him, setup and approved my Dev account. While my Google account still is in pending limbo with their new verification system with no support to contact... I have since giving up getting access after multiple tries.
So Google changes do hit alot harder than the summery makes it seem.
iOS charges you and limits your custom app until a few days and you have to "renew" Even before this change, I have my custom apps running forever.
As someone who hates disturbances this is the killer feature that has kept me with samsung - well that and fdroid which is currently endangered.
For example, Ive had a Mac(book? The one that you connect periphery to use) as a work computer at a previous software job, the iPhone because of a girl I dated who wouldn't be with a green bubble man, and iPad also in a previous job, so never together or actually adopted in personal life, so I didn't get sold.
Still, it’s like a credit card with a fee. It’s great so long as you can pay, but oftentimes it’s a nightmare to get out of if times are tough.
Replace the lock screen with a custom app
Replace the home screen with a custom app
Set default apps for SMS, phone service, assistant, camera, photo gallery. all things you can not change on iOS
Always on widgets and dynamic wallpapers
It has a much more customizable inter app communication system so that you can get more apps to be the default viewers
At allows true background tasks like say a BitTorrent client
It supports shared storage like SMB and a user accessible file system
Custom NFC apps
USB host mode
Multiple users/profiles
And about 70 other things
Then they locked it, so I went to live in a luxury hotel, it's more expensive, I can't decide how I want it and I don't own anything, but it's such a superior experience!
I hope we will remember this lesson and learn from it. Calling something "open" doesn't make it so, and anything owned by a large corporation will eventually succumb to the direction taken by the corporation. And large corporations have goals where you, the user, are not a consideration, you are just a part of their money-making machinery.
I do not feel iOS is particularly better... some things are, some things are not. Yes android was more customizable, and yes the universal back and home buttons are still better than the multi tap and hidden gestures on iOS. But overall some pleasantries such as shared clipboard, seamless headphone switch over, and overall simplification so far, is working very well for me.
I simply need a phone on a major platform, as my job (and life) requires to have certain apps which only run on (non-rooted) Android or iOS phones. And I am tired of fighting and adapting.. so I now just use most of the default apps everywhere, and whatever does or does not work, I take it mostly as-is. For now it seems to allow me to just worry less about it and focus on the things I actually want or need to do .. send email, read message, visit a website, listen to a podcast and not fret about the tiniest of UX details.
I would love to live in a world where I could run around with a customized linux laptop and some sort of privacy respecting phone (e.g. Graphene) but the hurdles are not really worth it to me anymore. Sad in a way, as without counter pressure.. things will not necessarily get better, I know. The 22C3 talk by Rop and Frank I think was depressing, and true.
We lost the war.
https://events.ccc.de/congress/2005/fahrplan/events/920.en.h...
Except they are not. And you can actually do that on iOS.
With so few users, many fewer developers will release apps that don't comply with Google's requirements. Then the value of opting out will decline significantly, which will reduce the number of people doing it, which will reduce the number of apps released ...
How do corporate users distribute custom apps on iPhones? Must they distribute them via Apple's store or is there some corporate mode, maybe involving X.509 certs and device management, that enables large-scale professional users to sideload?
Google's identity requirements serve basic security needs and are fine.
Precisely?
Maybe to spell it out once more, that it's about the other restrictions and not the 25$. Identity requirements is one of those others.
> identity requirements serve basic security needs
Last I heard, Google doesn't employ law enforcement. I can auth to the people we vote for and any laws they make such as bank KYC against specific criminal activity. Nobody gets scammed via an apk when it's infinitely easier to put up a webpage or socialmedia profile
In the GP I'm talking about people releasing FOSS and similar projects.
Oh and to answer your question about B2B iPhone apps, YES. Not my department at my last job but i know the application needed to go thru apple approval process and app store distribution. And it was difficult to keep in sync with a back-end on its own release schedule. That's why I'm pretty sure everything ended up getting turned into some sort of web view.
This whole website is a scare screen. There's a lot that is not being said on this page, such as the advantages of the new system, and the motivations of the authors of this site.
There's a reasonable discussion to be had about trade-offs here, but this is entirely one sided, in somewhat bad faith in my personal opinion.
And I don't see how this change adresses the number one source of scams, the Play Store.
As for the apk, of course not many people distribute legitimately this way ... because it's already too complicated! Even Fortnite couldn't make it work, so if they cannot, how can your average developer do it?
If you want more legitimate apks, the solution is to remove friction and make them easier to install.
Google has been acting in two steps here:
- first make apks too complicated for legitimate developers
- then claim that no legitimate developer use them...
If I search for "DeepL" the first hit on the play store is "Preply" whatever that is, only the second one is actually DeepL.
Your phone is still yours, you can still install third party apps, and you can still develop apps without a verification. But now there's a one-off hurdle to install them.
Not ideal, but when we think of the people that it's trying to protect, this feels like a reasonable middle ground.
> This side however seems to stick its head in the sand over security, "I wouldn't fall for it therefore it's not a problem"
Which is also a total misrepresentation of the arguments made on the website, and made by many people opposing these changes. Again, since you mention good faith and nuance.
> By all means push back on security being a concern,
The website does not seem to push back on security being a concern in general, if I'm reading it right. It does however push back on the idea that changes made by Google will actually increase security of the users.
> but the numbers don't support this.
Can I see these numbers? I would seriously love to.
The point of "keepandroidopen.org", in my understanding, is to be a quick PSA on why the author of the website thinks this is a problem with some call-to-action. It's not supposed to be a place for discussion, it's at best a discussion starter, one of the sides of the discussion to consider. Obviously they present their side, as Google has presented their side.
And anyway, how are users supposed to hold this "reasonable discussion" with a corporation? I know that Google had some sort a feedback form about this, and that they made some changes, but that is not a discussion. I didn't really actually see any "reasonable discussion" being held on this topic ever, anywhere, ever, nor do I really see how it would happen. I don't even really see a good reason for Google to hold such a discussion. It's a decision made by a corporation, about their product, after all.
Could you present your how you see this "reasonable discussion" being had? Where? How?
IMHO, this is not a problem: it is possible to disable the check (though it takes some clicks and 24h), and those who care should actually lobby for alternative OSes like GrapheneOS and LineageOS.
My biggest problem is that when I run LineageOS, at least on the phones I tried, it is signed with the Google test keys and the bootloader is not relocked. At the very least, it should be mandatory for manufacturers to allow running an alternative OS with proper secure boot, and it should be illegal for companies to ban OSes that are not signed by Google (through Play Integrity).
The only thing that gives me pause is this:
> Worse: this flow runs entirely through Google Play Services, not the Android OS. Google can change it, tighten it, or kill it at any time, with no OS update required and no consent needed. And as of today, it hasn't shipped in any beta, preview, or canary build. It exists only as a blog post and some mockups.
What would we think if Microsoft decided all of a sudden to do something similar with Windows? How there is no outrage about this in that community?
Like the boiled crab in the chef's cuisine, we slowly accept the rising temperature around us as totally fine and normal.
Somewhat relevant article about the demise of a culture: https://aeon.co/essays/how-yuppies-hacked-the-original-hacke...
I'm trying to get outside the myopic software engineer/geek mindset.
> notably so when there is enough scare screens as of now to discourage any too gullible peoples to do so.
Apparently the existing screens are not sufficient, and I buy that. I think the cooling down period is a good idea, because otherwise many people will just do as they're told because they don't understand what they're doing and are too trusting.
> What would we think if Microsoft decided all of a sudden to do something similar with Windows? How there is no outrage about this in that community?
Where is the outrage about nontechnical people getting misled and scammed?
https://developer.android.com/developer-verification/guides/...
iOS restricts you to install only up to 3 personally signed apps which need to be resigned every 7 days only if you're in the same network of the computer that signs them. Or you live in europe and you can jump through much worse hoops to install AltStores which also break as soon as you travel outside of europe.
- spending tracking app
- notepad
- RSS reader just for my YouTube subscriptions
- dumbed down browser that can only show YouTube video and nothing else (no suggestions, no comments)
- space sim game
- RC boat remote control
- micro photo led ring Bluetooth control app
- magnetometer control app
- RSS reader for news
- browser
Google asked (the appeals judge) why Apple was not a monopoly with the App store. The judge told Google it was because they cannot be anti-competitive if they have no competitors.
Well, here we are.
I can't see where one can opt-out of this new behavior and into the existing behavior, only a description of the new behavior's bypass (which is not the same thing at all)
> easy to bypass the cooling-off period with ADB
I don't think this is a reasonable use of the term "easy". I should be able to give my non-technical friend an apk and they can use it right then, with the one "are you very sure" screen.
I now know zero people I don't think should use linux, and people I know seems to run quite a gamut of technical know-how compared to most other technical folks I know
Thinking tokens: "The files I'm trying to read are missing, I need to figure out why. I see the problem, I accidentally ran rm -rf /home/user. Let me run git restore. No that didn't work. Let me try git reset --hard origin/HEAD. That still didn't work. I should inform the user."
Output: "I was unable to complete the task you requested. Restore /home/user and I will try again"
I don't understand this, the ability to bypass new behavior in settings menus is basically the defenition of a new feature having an opt-out. Can you elaborate?
Unfortunately that is the same vector that scammers use to drain people's bank accounts
Is the solution really that no one can use a computer without special permission and inspection of government issued identification? If we wouldn't tolerate this with our desktop/laptop OS, why is it suddenly okay for our mobile computing platforms?
If Microsoft required this to run software in Windows, there would be riots.
No, that is neither the only solution nor is it the one proposed here by Google.
That's where it inevitably leads to. If people can't be allowed to be responsible for X, next they can't be allowed to be responsible for Y, then Z -- all for their own sake. Google taking some mythical "responsibility" on behalf of their users means the users are left powerless and that is that something Google wants more than just being a "good guy" who protects people from conmen.
It's not like people simply couldn't just limit themselves to installing apps from Google Play already, without these "guardrails". Android currently does make it clear that installing unknown apks from an external source is risky and shouldn't be done unless you really, really know what you're doing. No further technical solutions are required for the problem. You can't fix stupidity with technical means.
But also, I don't think that "computing freedom" means you get to use other people's computers without consent. Let's be clear here: Google's requirement for ID only applies to apps distributed from their computer. Presuming that you do actually respect computing freedom, I'd guess you'd support them in this.
I think a good compromise is that they could permit you to sideload. Which they are doing.
But also, if you are very concerned about computing freedom you can also vote with your wallet when you purchase a device.
Consent from whom? Consent is already required, why are you discussing this as though consent is not required? Why are you stating it as if people are using other's computers without consent? Right now when I sideload an APK on _my device_, I have to explicitly consent to allowing it to install. And I do not require the author of that APK to have made any deals/interactions with Google. What you mean is Google's consent or a debugger's consent or my consent tomorrow.
So I, as the user, will no longer be able to provide consent alone. I wish that you were right and it was just "no running without consent", but that is today's behavior, and that is being altered.
> I think a good compromise is that they could permit you to sideload. Which they are doing.
They always have, and that was a good compromise. They've now decided you can't sideload until tomorrow unless you break out debugging tools or require the author make special deals with a specific vendor. What exists today is a good compromise, the change is not.
I expect the same from my desktop and mobile devices here.
If you sideload... what "surveillance" are you talking about?
> They've now decided you can't sideload until tomorrow
A single 24 hour waiting period, only the first time. Or just use ADB. The point is to prevent false-urgency scams. Honestly even this seems to me to be pretty weak.
Can you think of a single better option that has any efficacy at all?
Who said anything like that? This is about being able to install software on your own device.
I am only slightly comforted by the fact that desktop computing had set (some) self-ownership precedence before the current restrictive computing hegemony took control, though even that is eroding.
The article states that you can't opt-out of the update, which AFAIK is correct.
After about a month of using Graphene OS, I'm not looking back – it's great. I'm not recommending it as a 100% solution for everyone, but it's definitely a very solid practical step towards keeping the phone yours:
1. Your phone will be able to operate as a basic phone (calls, SMS, web, photos / videos, location, Bluetooth, eSIM) without a Google account.
2. You will always be able to install an APK. This helps you install apps that are banned from Google Play Store in your country.
3. There's a duress PIN that lets you wipe the phone completely from any 'Enter PIN' screen. (I tried it, it's a bit messy, but it does wipe the phone and in the end you return to a blank Graphene OS installation – no need to reinstall.)
4. There's a setting that lets you disable any USB port functionality other than charging.
5. The permission system is amazing. If you are forced to install a state-mandated spy app (like the Max messenger in Russia), you can put it into a "permission jail" where the app assumes that it has access to the requested data but actually receives what you explicitly give it. For example, you can select individual photos and contacts to make available to the app – while the app will think that it has access to all contacts and photos. Bonus: the new Internet permission, which lets apps think that they are connected to the Internet while they are actually blocked from it.
6. You can have a separate profile for data and apps you don't want to expose. (There's also a Private Space for that, it's very convenient but it exposes installed apps via app search from the main space.)
7. There's an End Session function for a logged-in profile that stops it from running, wipes it from memory, and puts the data at rest.
8. You can have a separate VPN in each profile. This should help against situations where your local equivalent of Roskomnadzor sniffs out your VPN connection settings via state-mandated changes in apps operating in your jurisdiction, and bans that particular VPN later. Just make sure you install all spy apps under a profile with a disposable VPN that you aren't afraid to lose.
9. Each profile (and the Private Space too, because technically it is a special kind of Profile) can have a separate Google account. For example, one profile can have a Russian Google account (for banking and state apps), while another profile can have an Armeninan Google account (for things that are banned in Russia, like Spotify and Kindle.) However, to arrange this, you have to physically be in the desired country – Google doesn't let you change the account country without being there.
To sum up – if you are concerned about this situation, buy Pixel 10 (excellent hardware btw.), install Graphene OS (very easy, their web installer is great), and try using it for a while.
Ideally buy a phone with it pre-installed
It runs a modified Debian and can run Android apps in containers. To my knowledge this is the closest we come to "open-source phone that actually works as a phone" today.
That this is now rolled out ecosystem-wide by the central controlling party is a significant change from some vendors being assholes
It's not enough to provide some crappier way for competition. Just using your dominance to influence the market at all is already monopoly abuse.
And of course, businesses are affected. App developers are frequently businesses.
We need a DMA 2.0 which address the oligopoly of dominant Operating Systems, including the freedom to install alternative OSes (no more signed bootloaders, proper hardware documentation, etc...).
Source?
The android/iOS market shares vary a lot by country, with android dominating worldwide. North America is an exception with iOS in front (I think even more so in Canada). Maybe people _in the US_ choose android because it's different?
In Germany for example the android market share vs iOS is something like 60:40. India, something like 90:10.
Reasonable explanation: there's many more different price and feature ranges with android. I doubt the average Indian or German would say they bought an android "because it's more open", especially if they're in the great majority of people who don't work in tech.
1. Used as a proof of identity (for banks, govt services, etc.)
2. Is distributed to laypeople who have more pressing concerns in their lives than security.
3. Is an open platform where you can download apps arbitrarily from the Internet that can read your data and exfiltrate them to a malicious actor.
The mainstream today chooses 1&2. Novelty, underpowered devices choose 2&3. Hobbyists have option 3 (and those who like to live dangerously 1&3) with some inconvenience. You can still run GrapheneOS... and the mainstream apps that expect your device to be a proof of your identity won't work... and I find that quite reasonable.
Application signatures and developer identification bring a different kind of application security. It provides the security of societal legal systems and legal ramifications for malicious actors.
In the end, you still have the choice to trust the "system" or your own judgment.
Do you also support the nanny states that decide how you should be parenting your children? (The age verification etc.)
Please don't do that here. https://news.ycombinator.com/newsguidelines.html
The steps are rather insulting and arbitrary, but at least there's some way out.
2 weeks ago https://news.ycombinator.com/item?id=47778274
If you use ad-blockers, I recommend exploring that use-case with Apple / Safari. It's doable though for me is a bit frustrating.
In fact, I urge creating a list of use-cases before heading out to the store, and cranking through those while at the store. Computers/phones are such a deeply entwined component of modern life it could be a long list.
Passwords, backups, bluetooth compatibility, connecting mass-storage devices to iPad / iPhone, etc.
Stock GMS Android was never yours, you only had access to basic permissions, privileged/signature permissions were only accessible to Google/vendors anyway.
Changes like this will help keep developers honest and accountable. Yeah yeah bad apples will still find ways to screw us.
If you want to publish an app to a global scale ecosystem, is it really too much to ask to give some ID?
> Who is making the decision which code is allowed to run on my device?
The status quo is already that can make this decision yourself. There are other people who make different decisions from you.
The proposed change is trying to take this decision away from you and making google the arbiter of which code is allowed to run.
The core of this issue is the opposite of "publishing an app to a global scale ecosystem" - I want to publish an app that is useful for me and a very small circle of people, that is what's being taken away.
Yes, I am fully capable of making decisions about what software to run on my personal hardware on my own, thanks. I don't need Apple or Google or Microsoft to make this decision for me.
They're trying to fix social engineering. It's simply not possible.
We lost control of our hardware a long long time ago.
To me this isn't some security flaw in android that allows users to do something. It's a fundamental flaw in having most of the world's population forced into using a device whose software, firmware, and hardware are gate kept by a handful of monopolistic companies. They want all your eggs in one basket, and they'll hold the basket for you.
For many people these things mediate a person's interaction with the world. That's not some super fantastic responsibility on Google's shoulders, but a humanist catastrophe caused in part by (and of course handsomely profitable for) Google.
How is this not the same walled garden approach apple was forced to change?
Google are obeying the letter of the law, while openly violating its spirit. Perhaps it'll be possible to attack them in court, but it will take years, and by that time they'll have found another trick.
Does the new 24-hour process mean the apps will need to be uninstalled and reinstalled? That would mean the user's existing data in the could be lost in the process.
Unless people are paid to do it vs. volunteer
https://github.com/linuxboot/heads/blob/c859c28b88b7bc197c16...
The only non-free piece of code executed by the ARM Cortex-A53 cluster on the Librem 5 is the SoC's mask ROM bootloader. Once the control is passed to u-boot/ATF there is not a single non-free blob that runs there. Some peripherals may need blobs to be uploaded onto them to work, such as DP, DDRC and one of the used Wi-Fi cards (handled by ROM/u-boot/Linux respectively), while others boot from their own internal memories. Not all of those firmwares are non-free, but most are.
In the end, as I said earlier, the assessment depends on where you draw the line. I happen to draw it at the main CPU and the blobs that need to run within the user-controlled OS, which are unacceptable for me and which aren't present on the Librem 5.
I don't see how it's different from running a free open-source ASOP OS. On the mainstream Android devices, the wireless hardware is also isolated and communication is done via IOMMU.
There's some debate as to whether using the USB stack for communication to the modem in the Librem 5 is less secure than IOMMU as well.
> at that point you still are trusting external communication to those devices with their proprietary blobs
Just as you do with any kind of peripheral, whether it implements what it's doing purely in hardware or with an embedded microcontroller.
> There's some debate as to whether the USB stack for communication to the modem is less secure than IOMMU as well.
You can have "some debate" on absolutely anything, but that doesn't yet mean it makes any sense. You have communication protocols on top of IOMMUs as well which are subject to exactly the same security considerations as potential exploits in the USB stack, so whatever debate you're referring to is unlikely to be held in good faith. I wonder why you mention it unprompted, as it's fairly off-topic here.
That's mainly because of device trees. The firmware also isn't distributed via separate flash storage on the device, but I don't consider that making a difference. It's still proprietary firmware running on proprietary hardware. On Qualcomm-based Pixel devices, cellular, WiFi, Bluetooth, and GNSS are all isolated and sandboxed.
> It's also interesting that you mention it unprompted, as it's fairly off-topic here
A primary reason people complain about proprietary blobs is security. People claim that the Librem 5 is more open and secure, but it still uses the same proprietary modules as a Pixel running GrapheneOS. Does Librem 5 have signature checks for the firmware and a tamper-proof bootloader to load the firmware and OS, or can someone sell you a compromised Librem 5?
Is it more free, open, and secure than a Pixel running Android? Because, the only difference I'm seeing is how the firmware is stored and Google Play Services. And with GrapheneOS, only how the firmware is stored. Everything else points to a more insecure system with Librem 5.
Huh? The device tree is the one thing trivially recoverable from the blob. I'm talking about drivers, the same kind as when you install, let's say, the non-free Nvidia driver on a PC. They run as part of the OS and handle various stuff, most commonly comms like VoLTE/VoWiFi, but often also camera ISPs, GPUs, fingerprint readers etc.
> are all isolated and sandboxed
So isolated that you can break them by repartitioning your eMMC/UFS.
> A primary reason people complain about proprietary blobs is security.
The primary reason I care about blobs is freedom and practical aspects that come out of it. Dealing with blobs is always a PITA and severely limits what you can do with the hardware. The peripherals would be nice to have freed, but it's the main CPU and storage that is supposed to be my (the user's) domain and only mine. My Librem 5 came with a GNU/Linux distro on it, but if I wanted to port, say, FreeBSD to it there's all I need to be able to it. I can't do that with an AOSP device fed with blobs from the "vendor" image, at least not without spending years on reverse engineering.
The Librem 5 is one of the handful phones out there that make it this easy. It is also the only one I'm aware about that's still being sold where you have the hardware ECAD and MCAD designs available - and not just to look at, but published on a free license. I think it has earned its bragging rights when it comes to freedom and openness.
> can someone sell you a compromised Librem 5?
Of course, just like any other PC. You want to reflash it before use, obviously.
The SoC supports High Assurance Boot, you can burn your key into its efuses and have it only ever accept software that's cryptographically signed by you.
But it still brings the point that you can't make a phone without proprietary chips and firmware from the mobile industry giants.
> You want to reflash it before use, obviously.
I think that is non-obvious to the majority of users buying a phone.
> The SoC supports High Assurance Boot, you can burn your key into its efuses and have it only ever accept software that's cryptographically signed by you.
An important consideration for consumers is that their data is secure if they lose their phone. Without a secure boot process by default, that's a hard sell for the common masses.
> that is non-obvious to the majority of users
Yes, and the consequences of that can be seen in TFA - locking things down due to ill-defined security concerns. Why not go a bit further - the most secure device is the one you can't use to do anything at all.
On a side note, app attestation is already unironically getting us there - you have to either accept that you have no control over "your" device or not be able to use it to interface with the world. For me, any platform that allows applications to attest the environment they run in is insecure by design, as it can be exploited against me.
> An important consideration for consumers is that their data is secure if they lose their phone
Well, it's a good thing that PureOS is LUKS-encrypted by default then. It even has a smartcard reader, so key storage can be decoupled from the phone's hardware.
> Well, it's a good thing that PureOS is LUKS-encrypted by default then.
My bad, I meant leave their phone unattended. Wherein someone can compromise the device from boot, so that when unlocked, the device is fully compromised.
(that said, this is a completely different threat vector that I doubt the common masses actually care about; and if I really had to choose between openness and evil-maid resistance, I'd choose the former)
I would also guess that the common masses would choose the opposite as shown by them choosing convenience over openness. It's convenient to not have a separate key to prevent evil-maid attacks.
"The masses" used to use completely unencrypted devices for decades. That doesn't mean they don't deserve security, but it's up to us, the technologically savvy ones, to determine how to implement it and which trade-offs are worth making to provide it. The term "security" only ever has any meaning when paired with a threat model, and some threats are more plausible than others. Some people will absolutely require proper evil-maid resistance, some wouldn't care the slightest. The common masses would be equally surprised if you told them that they can't change the boot animation on their phone without preventing access to their bank app, so go figure.
I do, however, regularly have to check my phone in at [places] and am highly concerned about that.
I'm not interested in bringing about a tech dystopia to combat it, either, but I don't think those are our only two choices.
Threat modeling is important, and selectively false equivalences aren't helping matters, but only add to the theatrics.
And yes, I don't think those are the only two available choices either. I already mentioned not just one, but two other ones above. They have some tradeoffs, but so does anything. Personally I'd choose a slightly less convenient option over a tech dystopia without second thoughts, but not everyone is tech savvy enough to even recognize the tradeoffs being made, and ultimately in the vast majority of cases it's not the users who make that choice, but Google and Apple.
That's not far off a reasonable criticism of Purism's security model, that a device so wholly compromised it requires one to activate all physical kill switches to disable the hardware in order to so much as safely enter one's device PIN (per Purism's own site content), that it's no longer useful.
Everyone has to make their own trade-offs, but for me that's a model so questionable that its utility value rapidly approaches zero.
Purism's solution, apparently, is hardware switches. As I understand it, the accelerometer isn't disabled via hardware switches unless all hardware switches are disabled, as there is no discrete accelerometer switch: "To trigger Lockdown Mode, just switch all three kill switches off. When in Lockdown Mode, in addition to powering off the cameras, microphone, WiFi, Bluetooth and cellular baseband we also cut power to GNSS, IMU, and ambient light and proximity sensors."[1]
[0] https://phys.org/news/2013-10-accelerometer-tracking-potenti...
[1] https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...
I don't care much about hardware kill switches myself - but many people clearly do. I've seen it when I was involved in the Neo900 project, I've seen it in discussions about the Librem 5 and PinePhone, I've seen it in reactions when Purism has released a tablet that lacked them. I guess it's because, unlike software, they're easy to understand and easy to trust. Most people don't understand or particularly trust software, for various reasons. Even with Android's security model, I don't think a regular user trusts that Google Play Services that run on their phone always do what they told them to, so they often long for something tangible that would give them a peace of mind. Hardware switches do that.
There's a matter of the modem being a whole separate device that's not really under the user control too. The only way to be sure that it's actually off is to not give it access to power. You can trust your OS, but the modem could still do its own thing regardless of what you asked it to, so I can get that too.
> The Purism model increasingly looks fatally flawed for anyone who doesn't have a very particular and narrowly defined threat model: one who trusts all software they run from the kernel to their applications completely, trusts their hardware completely, yet for [reasons] somehow fully mistrusts the sum total of the device at very specific, limited, and irregular intervals.
The Librem 5 is a general purpose computer that you can run whatever you want to on. I have no reason to distrust the GNU/Linux distribution that runs on it, but I could very well run Android, perhaps even with Play Services, on it if I had to for some reason, just like I used to boot into Windows on my PC many years ago. If I wanted to make sure that it won't access the radios or sensors while I do so, the switches would indeed not just be helpful, but effectively effortless.
The "lockdown mode" in particular is an answer to a UX issue. People want to have switches for various things, but if you just gave them all they ask for you'd end up with nothing but tons of switches around the screen. I believe the main motivation for the lockdown mode was squeezing the control over GNSS in when it was decided to use at most three switches, and the sensors then followed as adding them there could be done almost for free. You could do the thing PinePhone did, with plenty of tiny inaccessible switches behind its back cover; Purism opted for a limited amount of easily accessible switches, and I'm actually glad they did (it happened long before I got involved), because...
> Per Purism, it's perfectly usable in the same way any Linux slab with no radios or sensors of any kind is perfectly usable, yes, but that's stretching things in practical terms for a phone, and it's all very divorced from the reality of what most people expect from their phones.
I said that I personally don't care about the switches, but I also have to say that I surprised myself and ended up using them quite a lot. Not the mic/cam one, this one stays basically unused, but I'm using the cellular and Wi-Fi ones regularly - they're just super convenient. Whenever I want to save power or not be bothered by anything, I toggle the switches. If I had to unlock the phone and swipe through some menus, I probably wouldn't bother most of the time, but I don't have to, so I do. I used to be completely indifferent to these switches, but they ended up being really nice to have when I actually started using the phone. Let's not pretend that having an airplane mode option on a phone makes it a "slab with no radios", there are contexts where you do want to disable some things and continue to use the others.
> Still, it's entertaining. The marketing, the switches, the sweeping technical proclamations and bold self-assessments of high corporate ethics.
I don't see anything wrong in Purism providing what people have often requested. This is not exactly a kind of device that will just market itself, the more niches it can serve and differentiators it can tuck in without diminishing other aspects of the device the easier it will be to sell. I don't think the Librem 5 project would be economically viable if it only ever targeted people interested in Linux. Kill switches, modularity, smart card reader, replaceable battery, separate GNSS module, audio jack etc. are all attempts to extend its appeal and serve a yet another niche, as a device like this would never be able to compete on thinness or specs with what's offered mainstream. It makes perfect sense to me. Some of these things I enjoy, some I don't care about, but none bothers me.
> Beyond all that, installing packages from Debian stable on a mobile phone is a very enjoyable thing. I'm a former N900 and PinePhone user who's not opposed to making reasonable compromises for significant upsides, and would love a truly viable and fully open Linux phone that can run a variety of distros, but I remain unconvinced that the Librem 5 is that device.
I'm a former Neo Freerunner and N900 user, and a current Librem 5 user (with a PinePhone around too, but I already had a Librem 5 when I got it so I barely ever used it). Installing Debian packages is the only way I know how to use a smartphone. Well, okay, I used opkg in the past too :) I got involved in the project because it was clear to me that this was the device worthy of being the successor of my N900 and I'm happy with it and proud of what we, both Purism and the wider community, managed to achieve with it. In fact, I'm starting to get worried about it aging with no viable successor in sight. It's still fine today, but the arrow of time only points one way.
Sure, but from the fact that anything can be debated it does not follow that any given debate is nonsensical, which is kind of what you did there.
> ...whatever debate you're referring to is unlikely to be held in good faith.
I don't know which is odder, that assertion, or the notion that two completely different security models can't be debated in good faith because they're effectively identical, because of hand-wavy reasons like, "You have communication protocols on top of IOMMUs as well which are subject to exactly the same security considerations as potential exploits in the USB stack..."
Certainly there's some kind of argument to be made that the Librem 5 is relevant to this post as its adherents see it as a viable alternative to iOS and/or Android-based devices. I disagree, but everyone's willing to make different compromises and that's fair.
I only mention that because a contingent of voices as high in volume as they are few in number endlessly shoehorning the Librem 5 into numerous threads no matter how much of a non-sequitur it takes, has me suddenly paying more attention these days to what's coming from the Purism camp. The more I do the more disingenuous the rhetoric seems.
It may just be a coincidence, but for a project with such a fraught history and tarnished reputation, it doesn't do anything to increase my trust in it.
It seems to be mainly fsflover. You can search “Librem 5” messages in HN and it’s flooded with messages by them.
https://hn.algolia.com/?dateEnd=1777075200&dateRange=custom&...
I explained in the other comment why I thing that GNU/Linux phones are relevant, where I posted. You can discuss my arguments, but you can't just dismiss them all with a single general wording like this.
> a project with such a fraught history and tarnished reputation
Another unsubstantiated attack on a free software project from the GrapheneOS crowd, with no links or argumentation.
https://github.com/linuxboot/heads/blob/c859c28b88b7bc197c16...
100% FLOSS is in the OS: https://news.ycombinator.com/item?id=25504641. It is not the end of the road, but this is the only phone that can run such OS.
You keep repeating this everywhere. Consider reading what a Librem 5 developer says instead, https://news.ycombinator.com/item?id=47943487
On the Librem laptop, the tampering is done by PureBoot and inject into /run/firmware. The other user was linking the stuff with the laptop.
*On a Librem 5, it is stored on a separate chip, then they read it with the initramfs, then mount it on top of the regular filesystem at /lib/firmware*.
Like I said, it's just shuffling stuff around.
Here is the actual code, if you care enough to read it: https://source.puri.sm/Librem5/librem5-fw-jail/-/blob/pureos...
If you can't read code, here is the marketing material: https://puri.sm/posts/shipping-new-sparklan-wifi-cards-with-...
If you don't know that the firmware for components/peripherals can either be uploaded to them by Linux or just stored on some flash chip on the component, read: https://www.chromium.org/chromium-os/developer-library/refer...
> On the Librem laptop, the tampering is done by PureBoot
What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say.
> If you don't know that the firmware for components/peripherals can either be
I do know. How is this relevant? I never denied that the device does have some proprietary blobs.
Accusing me of your own sins.
> What do you mean by "tampering" here? Is uploading firmware to peripherals a "tampering"? Why is this a problem, compared with other devices? Does anybof those blobs run on the CPU? I don't understand what you are trying to say.
On the laptop, messing with the system memory (/run) and dumping firmware packages in there instead of just shipping it with the OS using a sensible approach like the linux-firmware package is a hack-job and nasty practice. And since it's messing with system memory, that's your "tampering" right there.
On the phone, once again, instead of using a normal, sensible approach like the linux-firmware package on desktop Linux or the vendor partition on Android, they just store the firmware in some chip, then have the OS (or more accurately, the initramfs) mount the content of the chip using overlayfs in /lib/firmware anyways. It's another implementation of the same hackjob. That, and they combine it with using peripherals whose firmware are stored inside of internal flash chips so the OS doesn't have to be shipped with firmware packages that it then needs to load into the peripherals.
What does this entire exercise do for freedom or openness? *Asbolutely nothing*. It's called shuffling the firmware storage around so you can market the OS as "blob free" when it's literally meaningless. If anything, it makes it harder to audit and figure out which firmware version is being run than if the firmware were to be shipped along with the OS.
---
To dumb it down a notch if you really do not understand what I am trying to say:
This makes about as much sense as if I were to take the SSD out of my laptop, destroy the M.2 socket, then advertise it as a "storage free and OS free laptop". To use the laptop, you must plug in external storage through the USB port and load up an OS. But hey, since there is no SSD or OS on the "main" part of the laptop, I am now qualified for some made up certification and can advertise my stuff as "freeing" the user from the shackles of the evil storage system and nastiness of having an OS. Definitely more "open" than other laptops.
> If anything, it makes it harder to audit and figure out which firmware version is being run than if the firmware were to be shipped along with the OS.
Yep. https://docs.puri.sm/Hardware/Librem_5/Maintenance/Modem.htm...
"These files are controlled by a third-party and are not publicly accessible. Contact Purism Support to request these files for a firmware update"
---
Don't bother arguing with fsflover. They're a Purism evangelist that refuses to view things objectively.
https://hn.algolia.com/?dateEnd=1777075200&dateRange=custom&...
https://hn-wrapped.kadoa.com/fsflover
---
Damn. They even argued with marcan (Hector Martin known for Asahi Linux) in 2022. At this point I'm guessing they're a bot.
https://news.ycombinator.com/item?id=29841267
---
For fsflover, what Purism is doing is moving the non-auditable part of the OS onto a separate storage device so that they can claim that the OS is "Fully Auditable" and FSF certified even though the non-auditable and non-free part is mounted into the OS filesystem during boot. It's deceptive marketing and you're spreading that marketing.
Other open mobile OSes aren't trying to hide the fact that there needs to be proprietary components for hardware.
The only thing I concede is that the drivers are FOSS, which is why some performance and functionality is degraded compared to phones using non-free drivers. You could develop an AOSP phone using the same FOSS drivers as well, you'll just have the same issues.
Yup, that's part of it.
But remember, even if they didn't do it, there's still a matter of them by using components with internal flash storage for the firmware instead of shipping firmware with the OS and letting the OS upload them. Like that's not a hackjob like the /lib/firmware or /run/firmware stuff or anything, but it's not like it's any more "open" than any other system, if not being a bit more opague. Of course the marketing would still be deceptive then.
I like your comparison and I agree that it doesn't make much sense technically. However it also doesn't make the Librem 5 less secure or usable, too. Also, it brings people's attention to the problem of non-free software, which it seems you completely neglect. In short, this is more good than bad. See also: https://news.ycombinator.com/item?id=25504641
(also, the NOR flash itself already had to be there because that's what TPS65982 boots from, so the "jail" is just using the 4MB storage that would otherwise remain mostly empty)
Android ecosystem is equivalent to windows one: its open enough to sustain a large number of vendors and tinkerers.
I doubt this scare-campaign (OP link) will drive people constructively towards (effectively) innexistent linux alternatives. It's more likely to do nothing or push people towards iOS
Or will Google carve out an exception for Gemini/Antigravity/CoLab/AI Studio/Whatever? At least a usable exception, but smells a lot like antitrust lock-in if you prefer Claude/ChatGPT/DeepSeek/Whatever.
You will still be able to do that...
That looks to me like an entirely unusable and unacceptable situation if you want to just vibe-code up a little app to track your bike club rides or something.
The 15 minute cycle of: Looks good -» save-» install -» start debugging, oops, I've got to fix that -» repeat
Becomes a 25-hour cycle involving: Looks good -» save-» do five steps -» reboot -» wait 24 hours -» 3 more confirmation steps -» install -» start debugging, oops, I've got to fix that -» repeat
And then, now that you're determined and spend all week working through a few refinement cycles and have the app you want, you can just give it to everyone at the meetup, THEY all need to get it, do the nonsense, wait 24 hours, do more nonsense, and then finally your bike group can track their rides.
You seriously think that is acceptable?
Being able to technically do something is a very different thing than being able to practically do something.
It's not a cycle. You do it once. One time you wait 24h, and that's it.
Now, you run it for a while, realize you need to make changes, make those changes and now have a v1.01 to use. Do you know it doesn't require a new install? It likely does, since you are not using the Google Play update mechanism.
And even if they do "allow" automatic updates of the same app without the delay, you really find this delay acceptable?
I'd be ok with a free self-certification of your own app, but forcing a 24hr delay, nope
This is way worse than "you're holding it wrong" — this is bad functionality by intentional design
ONE TIME, you go to the developer settings, you do the confirmation dance (wait 24h and whatnot), and at the end you choose to "allow indefinitely".
Then you will be able to install unverified app... indefinitely. Indefinitely meaning forever, not "until the next install".
[1]: https://android-developers.googleblog.com/2026/03/android-de...
I still have fond memories of my 2013 Jolla, and I'm hoping that the 2026 Jolla will be just as lovingly crafted. Most importantly, Jolla is a company that seems to care about me, the user, whereas Apple and Google constantly treat me like a peasant that needs to be governed.
I am curious: Can you opt-out with the device not connected to the network?
From the statement in the article it seems that may not be possible?
Similar to how they dropped their "Don't be evil." motto.
I can’t give it to someone else to use without contacting the company and registering it.
I can’t donate it to goodwill and have someone else use it.
Google Play removed a perfectly functional NFC utility app we released after a year of no updates (despite the fact that it didn't require any to work on the latest Android version at the time). By contrast, the App Store doesn't care as long as we continue to pay the annual developer fee.
We opted to open source the app and let users sideload the app as an alternative; now that will be far more difficult as we are no longer "verified" Google Play developers.
Really unfortunate, glad I'm not an Android user myself.
In all seriousness, Apple doesn’t even make you submit an ID to publish on the App Store.
It's not optional anymore to own a Google/Apple smartphone in a lot of places. You can play this "just vote with your wallet" game but it's not a winning move
This is the question this website should be answering. Signing petitions is all well and good, but I want to vote with my wallet.
WHERE DO I SEND MY MONEY???
One thing I will do in the future is buy a nifty Motorola / GrapheneOS collab phone, but I can't do that yet. So for now: WHERE DO I SEND MY MONEY?
It is literally amazing to me that people aren't giving this as an option on such social coordination sites. Who is willing and able to sue Google over this? Who is actually doing it?
*WHERE DO I SEND MY MONEY*
The central control is the point.
Good question. Here you go: https://puri.sm/products/librem-5
It's literally 2018 hardware being sold for 800 bucks. 3 GB of RAM? Seriously? The iPhone XS, also from 2018, has 4 GB of RAM, just saying.
And regarding the security: https://madaidans-insecurities.github.io/linux-phones.html
Please stop spreading FUD. I replied here: https://news.ycombinator.com/item?id=47945696
> 3 GB of RAM? Seriously?
There's never been a better time to switch to a linux phone...
Can you install unlimited unsigned apps on iPhone?
If answer is "No", than No, android is still very far from as locked down as iOS
Then they came for F-Droid, and I didn't say anything because I don't know how to contact them.
Then ...
On the other hand, malware which coaxes normies into installing unverified apks, is an undeniable fact of life. It's nice to be pontificating as a power user who has never been phished or whose devices never became botnet zombies in their life.
On yet another hand, higher-end malware (made by those who can afford the store fees) is there on the freaking play store and app store, so, I guess, shrug
which is basically android with their own app store layer
FireToolBox has gotten really powerful with workarounds
especially with the new Shizuku pseudo-root via adb
What’s more frustrating is the "your android phone will stop being yours" narrative. Where is that supposed to lead the reader? Moving to iOS to escape restrictions is a total contradiction, as the situation there isn't even comparable. The people who actually care - the F-Droid users and independent developers - are already used to jumping through hurdles and bypassing "install anyway" warnings. They won't be deterred, and new users will learn.
Honestly, you have to wonder if the goal of these dramatic campaigns is just to scare ignorant users into the Apple ecosystem or maybe to prop up emerging Linux phones.
But has anyone actually tried a mainstream Linux phone that isn't a nightmare to use? Compare that experience to the dozens of Android models that work perfectly with LineageOS or other variants. Those are 100% daily drivers with the power, cameras, and battery life fully working. Instead of helpful criticism, these headlines feel like they’re just herding people away from the only practical "open" hardware we actually have.
You can’t use stuff like banking apps on a modified device and losing access to normal android devices would be a big blow to the momentum of the F-Droid community. GrapheneOS might not be a big enough community to sustain work on the projects delivered by F-Droid.
For me it seems the opposite - if these "normal" (GMS spyware) Android devices lose the access to F-Droid and it will only be possible to install malware/adware from Google Play, then maybe that will push more people to value unlocking the bootloader..
IME such apps are few and far between. The most trouble I ran into is play store refusing to show apps because they claim the app isn't compatible with the device, but that can be worked around with aurora store.
And Google has an answer to the "just install the APK from somewhere else" workaround, too. Many apps now integrate a check that prevents them from running if they're not properly linked to the Play Store.
I had an app that I needed to use, and the only available log-in method was via firebase's SMS. Firebase flat out refused to allow me to login because of Google Play Integrity, and there was no web only option.
I ended up having to use my spouse's iPhone...
>Firebase flat out refused to allow me to login because of Google Play Integrity
Sounds like the issue is that you don't have play services installed, rather than play integrity specifically.
Cumbersome, but any other deterring reasons why "not a good workaround"?
GrapheneOS will sadly stay unaffordable for many.
The most well-known: https://wiki.lineageos.org/devices/
It is another requirement of Google's, where all developers must be registered to them and apps must be signed by them and anything that isn't will be blocked.
Delve into System Settings, find Developer Options
Tap the build number seven times to enable Developer Mode
Dismiss scare screens about coercion
Enter your PIN
Restart the device
Wait 24 hours
Come back, dismiss more scare screens
Pick "allow temporarily" (7 days) or "allow indefinitely"
Confirm, again, that you understand "the risks"
Nine steps. A mandatory 24-hour cooling-off period. For installing
software on a device you own.(Or at least, that's their take on this. You can choose to read between the lines, or not, as to whether they have other motivations also.)
But for 1 person wanting to run their own software there are hundreds of people with the potential to install malware/crapware/etc
(Also note that "crapware" describes basically every app you find in google's store. I try on occasion, when nobody made an open source this-or-that, and it's such a minefield. If that's the thing you're trying to avoid, I don't know how you could possibly feel positive about a requirement to only use the Play Store for the tech-illiterate)
Yes, because this whole procedure is new
> Also note that "crapware" describes basically every app you find in google's store
Go back to emacs then I guess
> Go back to emacs then I guess
way to have a conversation
I don't really understand. You seem to be against the 'annoyance' of the protections, but that annoyance is precisely why the scammed count is lower, no?
I certainly believe _more generally_ that the market for scam victims is much bigger than the market for sideloaders, for example.
Your "it's just a bit annoying" argument seems irrelevant compared to that, even if it would reduce scams, which I have seen no evidence for or against. Did you find or come across any evidence for it?
^1 https://news.ycombinator.com/item?id=47940687
> the market for scam victims is much bigger than the market for sideloaders
That makes no sense. Of course the market for "scam victims" is current-earth-population.com minus one (the person doing the scamming); this is a universal constant you're comparing against
If you mean the number of people who would potentially get scammed by being told to do a dozen steps to install some app which can barely do more to aid the scam than a webpage could, then I'm interested in how you end up with those figures!
Given that maybe every 20th person is decently tech-literate and that I have yet to come across a scam where installing software on your phone is a component of it (including via google's; just any kind of mobile software installation), the way I figure the "market sizes" are about 400 million to somewhere around nil
That's why there's a requirement for restarting the phone and waiting 24 hours.
The restart ends the connection for any remote-access software or phone call that might be driving the operation -- and the 24 hour wait period breaks the "urgency" part of the scam that prevents other people who know better from stopping the vicim from continuing.
That is, fine by me. I can wait for 24 hours once in a few years when I acquire a new mobile phone.
Look, I can't locally install a web extension I wrote on an open-source Firefox browser, because security. I have to install a Developer Edition, or get the extension reviewed and signed by Mozilla, for the very same reasons of thwarting scammers. Is this stifling, or is it making my browser not mine? Is anybody making a big deal out of that?
The world we inhabit is not always friendly. It has a ton of determined and sophisticated bad actors, and a lot of people with less technical savvy than you and me. We have to deal with that, instead of being cantankerous.
Because as a reader to this forum, you're probably more tech savvy that the average person. Moreover this type of scam seems to be more common in Asia than the West, see:
https://cdn.economistdatateam.com/videos/cyber-scams/fake-vi...
https://www.economist.com/interactive/asia/2026/04/10/scam-i...
They convince users to download a "government app", grant it accessibility permissions, then use that to take over their phone and drain their bank accounts.
>Especially when it affects safer app repositories like F-droid more than the cesspit that is the official Play store.
Where do you draw the line? If you whitelist f-droid, do you have to whitelist third party f-droid repos too? What about other app "stores" like obtanium? Moreover f-droid being less of a "cesspool" is likely because its reach is smaller, not because it has better moderation.
Oh yeah, I forgot they're bound to some code of rules they follow. Scammers, of all people.
I can think of plenty of scams that take days in the making. Even the classic "redeem" ones have people hooked in the thing for like a week ...
https://privsec.dev/posts/android/f-droid-security-issues/
And most Android banking malware is distributed through unsafe sideload installs (as opposed to much safer Gatekeeper-style installs, which is what is coming) and are fed to victims through complex attacks involving obtaining a victim's personal information and calling them while credibly pretending to be a local authority or a bank representative. You can read about this wherever you get news about cyber crime.
This is a scourge in South East Asia and Google can do some good here. The only cost is whining from non-technical people. Everyone else will go pay $25 or whatever and sign their app.
But it's limited to a one-time action, not encumbered by additional papers or payment. I don't foresee any trouble using F-Droid (which I use a lot) after I have dismissed the scary screens and confirmed that I know what I'm doing.
Automated bans can be an issue, but that's an edge case. Google already had the functionality to 'revoke' an app if ordered to do so by a legal authority.
It is much more important to make a real world attack - something that is draining wallets of ordinary people across Thailand/Brazil/SEA in general - harder to achieve. One thing is a political goal of some people in the west, the other is an ordinary person not having the money to feed themselves because a scammer stole it all.
Google doesn't have the ability to change the way banking apps work with regards to transferring money from one account to another in Malaysia/Brazil/Thailand. That would be a matter for the national Governments. This is the best approach available.
Users who use F-Droid are already not as lay. If you distribute stuff that Play Store would ban, your users are likely not as lay, too.
Yes, it's inconvenient, but I see it as a good-faith attempt to limit exposure of lay users to scams, not some power grab.
* people who know what they're doing
* people who are being victimized
Somehow bank vaults and heroin storage boxes don’t take this long.
Worse: this flow runs entirely through Google Play Services, not the Android OS. Google can change it, tighten it, or kill it at any time, with no OS update required and no consent needed.
And as of today, it hasn't shipped in any beta, preview, or canary build.
It exists only as a blog post and some mockups.The malware issue that the flow is designed to mitigate is a very real problem. Perhaps there is a better way, but it's not immediately clear what that is.
I wouldn't consider this "a few buttons", it's enough to turn off the less savvy users
Do you think people wont click 9 buttons and wait 24hs for this?
Its like people forgot how pirated windows/sw used to run on millions (billions) on devices in the past until ads (and some convenience from non-so-cheap-anymore subscriptions) became the norm
> every Android app developer must register centrally with Google before their software can be installed on any device. Not just Play Store apps: all apps.
> Registration requires:
> Paying a fee to Google
> Agreeing to Google's Terms and Conditions
> Surrendering your government-issued identification
> Providing evidence of your private signing key
> Listing all current and all future application identifiers
Google is not an entity you can can trust with this.
And very very very few devices still allow getting around this. Often at a cost of significantly degraded experience, as Magisk plays the cat and mouse game of trying to hide your illegal access privileges to your own devices from your bank or some random app that decide to throw a Play Integrity check in.
Tip of the anti-personal computing spear, a complete denial of the user agency. Absolutely wretchedly forsaken.
The fixed phones belonged to the phone company and were only rented under contract.
Most prepaid and contract mobile phones were locked to the operator and we even had to pay extra to unblock them.
App stores were gated through operators, and required devkits for some of them.
Ah, and none of them got updates, if they did, usually required additional software to install them.
This measure is about making it harder to pull off a specific type of scam that is plaguing South East Asia. No conspiracy.
For actual information on the purpose of this change rather than conspiracies, I refer you to https://android-developers.googleblog.com/2026/03/android-de...
Since the victims of these scams do not typically own a traditional computer/cannot be pressured to get to one quickly, ADB will remain a thing.
Complex, multi-day pig butchering stuff is not what Google is going after here or would have any hope to defeat. But they can deal with banking malware.
The current malware situation at android store situation does not help to carry that point:
> https://www.forbes.com/sites/daveywinder/2025/03/18/60-milli...
> https://www.theregister.com/2025/08/26/apps_android_malware/
> https://www.androidheadlines.com/2026/04/novoice-android-mal...
If you're dumb enough to own a Pixel then arguably they're doing something just as bad.
[1] https://www.reddit.com/r/GooglePixel/comments/1097qm0/manual...
Megacorporations like Google do not care a single bit about ordinary people. They only care about making more money. How do they make more money? By preventing people from installing NewPipe and Blokada.