I'd secretly hoped the Chrome incident was bigger than it turned out to be. The world needs something like this to remind ourselves why centralization of any kind is fucking evil, regardless of the pin-up CEOs involved.
I'd secretly hoped the Chrome incident was bigger than it turned out to be. The world needs something like this to remind ourselves why centralization of any kind is fucking evil, regardless of the pin-up CEOs involved.
Also notice that this bug was not a pure cloud bug: there was a bug in the client Sync code, i.e. in the browser; but this bug was only activated when the Sync servers also misbehaved, so it could be prevented with a server-only fix/workaround. Still it doesn't count as a real "cloud crash", not any more than an HTML renderer crash that only happens if some website sends corrupt content.
Is there a source for this?
The protocol does not require mutual authentication. Your ability to install to the phone from the Play site is not dependent on your phone authenticating you being logged into the site. The phone simply trusts whatever Google sends.
If you have a Google account, then you trust Google. If you don't trust Google then it would seem silly to have a Google account.
The ultimatum you describe (which is also the present reality) isn't the only possibility here. Even a simple confirmation dialog box is enough to prevent a situation where an evil actor could silently mass-install malware on every Android device, or for that matter an authoritarian actor installing legal spyware outside the device owner's control.
The simple fact is that there is a socket connected on the phone to my left, with exactly the features I just described. Just as it can produce apps at my leisure, similarly it can be used for less desirable actions. In the past, Google have used this legitimately to remove malware, but it's not Google I'm concerned about. One nationstate (China) has already shown Google's production environment little more than a few nasty PDFs sent to the right e-mail addresses away.
As for remote wipe, that's a feature of the platform – search for 'android device administrator'.