Android without the mothership
lwn.net
lwn.net
Many apps are open source (e.g., github, wordpress, coinbase, 2FA apps compatible with many services) and so are available through f-droid. Others, like TextSecure are really easy to build from source and install.
I have occasionally downloaded apps through one of the APK downloader services mentioned in the article comments -- I've had mixed luck. Some work flawlessly, others don't work at all without the google apps.
It would be awesome to see Mozilla's location service [0] integrated into Cyanogen to replace the google location services (which are of course disabled if you don't install google apps).
Are you sure about this? This may be unique to Touchwiz or something, but you can save a contact to either the device or to Google contacts.
I have no problems whatsoever storing contacts on my device...and my friend puts all his on his SIM card.
I really want to switchover to a proper CardDav/CalDav setup that actually supports "Tasks" in my calendar, exactly how Google doesn't and continually fails to.
I wish there were a trustworthy source of prebuilt pure AOSP ROMS, like the source images Google release. Compiling them is no small feat and I'm worried I'll brick my device.
With a stock AOSP ROM + Fastmail contacts & calendaring, I think I'll finally have the minimalist install I am looking for.
My only problem in the past was absolutely horrid syncing and GPS battery drain with Cyanogenmod. I keep going back to try, since first running it on my HTC G1 about 4 years ago. No other ROM gives me trouble, only Cyanogenmod. This is why I'm interested in a 'plain vanilla' as possible AOSP ROM. I'm back on stock 4.4 (rooted) and looking to move back to a non-gapps version soon.
What's wrong with Cyanogenmod? They even provide a dead easy installer which unlocks the bootloader, changes the recovery and then flashes the ROM. And they support a good number of devices out there.
BaiKal[1] is just this. It too is open-source, and it's a million times lighter. Literally. I've gone from 100% CPU use to complete idling. It is also self-contained via Sqlite, with no need for "heavy" things like MySQL backing.
The only bad thing is that it might be harder to get running on a shared host, due to its "web-app" part being hosted in a sub-directory of the actual application-structure.
One of the biggest issue of running Apps (open source or not) is the inclusion of the Play Store API in the app itself. These apps when not logged into the play store usually crash with NullPointerExceptions. Please... if you are an Android developer... expect your third-party services/APIs to be missing or to crash and handle that case... If you include the Map API or several other Google Services APIs in your app and the Play Store is missing or the user does not have a registered account... calls to those services will most likely result in NullPointerExceptions. Tell me to deal with it, don't crash.
Developers would be able to see from the crash reports how many NPEs from missing Play Services they're getting and prioritise accordingly.
Not the good ones. Normal operation isn't when you're dealing with a mobile device, there could be any number of reasons why your app can't reach a certain service delivered by some API so better to be prepared for that eventuality.
You have to balance the tradeoffs of bloated code and pointless error checking with adding features and improving the program. The more error checking code one writes the more one must maintain and the higher the potential for bugs.
That's an artifact of the chosen environment. Not checking for errors in that environment is a bug.
Besides that what do you do to handle the loss of something your app requires as a basic service? A nice error beats NullPointer but not by much.
And related to null-checking, I took the pervasive approach in one of my apps for fun. It's hilarious - almost 1/3 of my app is checking if something is null. Makes you wish for a switch to a language where nulls don't exist unless explicitly asked for.
Google In-App purchases are safe, so if that's how you monetize, I don't see why the app should be allowed to work anywhere else but in Google's environment.
It's different if the app is open source or you don't need to monetize (sadly, not everyone can afford that luxury), but even there it depends on how important those Play Store API features are to the functionality of the app.
Even if they're currently fully unmonetized, many such apps exist on the Play store because they can be updated at any time to include in app purchases, etc.
I just don't think that you can follow some rule dogmatically, because for some it might be worth the exposure, for some the extra costs might outweigh the benefits.
This is something that I would decide on a case by case basis.
Sure you can, if the rule is "don't write shitty software that crashes". In which scenario do you think users are more likely to buy: when an app crashes with no indication of what caused it, or if an app pops up a message along the lines of "we couldn't connect to Google Play; is it disabled for some reason?"
They have a NetworkLocation replacement which uses Apple's location services, and the dev is planning to add Mozilla Location services in the future. It also replaces Google Maps with OSM.
[1] http://forum.xda-developers.com/showthread.php?t=1715375
[1]: https://github.com/WhisperSystems/TextSecure/issues/127
If you can suggest viable alternatives, I am certain that the team would love to drop Google from it.
[1]: http://download.osmand.net/releases/ [2]: https://code.google.com/p/osmand/
the value of Android,for most people, is in Google services... not in Linux.People dont care what os android is running,the fact that it is Linux is irrelevant for them,(but not for google).
> copy all the APIs and create an independent alternative that lets you build apps that use features from Play Services, without tying your app to Google. Ideally one can then choose what to do from just stubbing them out, filling them with 3rd party alternatives, or providing custom implementations.
And who's going to copy all that,for you,for free?
> I would think a nice collaboration between Amazon, Microsoft, some Chinese players and maybe even Yahoo could do quite a nice job of this. And now you want to depend on Amazon and Microsoft and Yahoo,is that your vision of independence? And why Amazon or Microsoft would do that when they are pushing for their own closed mobile plateform?
Your message is basically "someone do something",not understanding what the success of the plateform is about : Google Services.And then you are calling to players that are even worse offenders than Google when it comes to closed plateforms. What you say makes no sense.
You cant run all the services Google provides for free , with no string attached ,it cannot work. And that's why mobile oses that dont provide these kind of services will flop,all of them,because people now feel entitled to get them for free.
What I am suggesting is that there are coalition of interests - Android manufacturers that share the situation of being outside of Google's ecosystem. All these manufacturers want apps, and the apps are all on Google Play. They therefore have a very strong interest in having those apps run without modification on their own platforms which is achievable only if someone clones the Google APIs. It seems to me only a matter of time before the incentive to create this gets high enough that someone actually does it.
Yes, but it might be just another big company which does it, and in an 'all or nothing' fashion. In that case you would have a choice (Google or XBigCorp), but I'm guessing you really want to be able to mix and match, and have different parts of the Play APIs served by different apps/daemons/companies/whatever.
It's doable. By amateurs and professionals with passion and spare time.
This is what most people fail to realize.
Google could just swap Linux with BSD, QNX, VxWorks,.... and no one would notice, besides those that hack around the official APIs.
What if we modify the client libraries such that they still use Google services but push the content (such as messages, contacts etc.) in encrypted form. This would be no different than using GMail but with an offline client with PGP.
I don't know how, e.g. Xiaomi, does this. However, it would be a reasonable strategy to first provide API compatibility for all important Play features, so that apps not targeting the platform 'just work'. Once app developers see Xiaomi as the primary platform (or at least one of the 'must support' ones) then you can create your own API definition for new stuff, knowing that developers will do the work to support your platform, but that this code won't necessarily work with your less powerful competitors' products.
From http://en.wikipedia.org/wiki/Replicant_(operating_system) :
> Replicant is a free and open source operating system based on the Android mobile platform, which aims to replace all proprietary Android components with their free software counterparts.
So I think that at some point maybe the Replicant guys might get to a point where they do what you are looking for, if they haven't already.
NOGAPPS on the other hand, is an attempt to replace Google Play Services while keeping API compatibility so that apps continue to run.
There's some indication that Samsung is preparing to do just that:
http://www.mercurynews.com/business/ci_24507761/samsung-tryi...
http://gigaom.com/2013/10/28/samsung-is-pulling-another-amaz...
The only future is a real linux phone, debian or ubuntu mobile, where one day there will be effortless desktop/tablet/mobile unified development. Why push for developers to waste time porting between c++ and java?
The Mozilla foundation has our best interests at heart much more than Google and while it's not C++, html5/javascript is certainly an open enough platform which basically everything has started to target anyways.
Sure, a pure linux phone would be cool in some ways, but FirefoxOS seems much closer, realer, and every bit as awesome.
The purpose of reimplementation is generally to screw consumers. There's nothing special about a phone that requires you to put everything into a VM. I don't know why firefox is doing it. I did order a development phone, though, because if it takes off, I want a share:)
To make it more accessible. Way more people can make web page than make QT or GTK GUI. Way more people can do Javascript than can program in C or C++.
That means, that everyone is stuck with html and js, but I think it's worth it.
Linux phones are real. I've been using one exclusively for the past 5 years.
Yes, using something like C# and Mono would be a huge win.
It's a shame that the software landscape is so dominated by large corporations, who demand a tithe of our data every time we want to use a device.
We could call the infrastructure that makes this possible ... a virtual machine:
In the end, I think it's a good thing that AOSP doesn't have a dependency on some cloud service, be it Google's or someone else's. The unfortunate downside is that developers might forget that the cloud service they want is not available.
If you look at the dividing line between proprietary and open source stuff coming out of Google, the usual deciding factor is whether it relies on their (proprietary) server side components to operate. Google is all about the cloud so a lot of useful stuff does rely on that. In Play services we see things like Maps (needs the servers), Wallet and in-app billing (needs the servers), G+ (needs the servers), multiplayer gaming (you get the idea), GDrive, ads, cloud messaging etc. There's one or two things in there that maybe don't rely on the cloud (I don't know enough about Cast to say) but that's mostly it.
So if you find all your apps are relying on Google Play Services what it really means is that the bar has simply been raised, and now people expect apps that deeply integrate with services provided by huge, expensive datacenters.
Ideally Play Services would be a shim that different providers could satisfy. It isn't, but Android has lots of support for building such things like intent resolution, so if a realistic competitor emerged and developers cared enough to support it, the OS would certainly help them.
Google has open sourced a fully featured mobile operating system, with an already free kernel, an optimized and secure app runtime for mobile applications that they keep on improving, a completely functional and usually well-liked user interface, open development tools and even a set of open source core applications needed for basic smartphone functionality. As this article demonstrates, Android is perfectly usable if you can get over the first world problem of no direct access to Google's services.
People have been absolutely free to do whatever they want with this complete OS what they want for years, and Android comes with no obligation whatsoever to lock down phones. There is absolutely no reason why any alternative to Android, including Ubuntu and FirefoxOS, would be any different at all if or when they gain enough popularity. Phone vendors and carriers will continue to lock down the hardware they sell and be reluctant to share code. There is just nothing different about these alternatives compared to Android.
The problems of locking down and shitty attitude towards open source is a problem with the market, not with Android.
> all the man power being donated to the project is just going to line google's pockets and lock us further into closed hardware and barely opensource phones.
Nobody except Google (and some minor contributions from phone vendors) contributes to core Android. It's an example of an extreme cathedral model[1], where only members of the Open Handset Alliance[2] have access during development. There are many open source forks/derivatives that only help you in increasing the freedom with what you can do with your phone.
> Why push for developers to waste time porting between c++ and java?
Because there are considerable advantages to running in Android's runtime when it comes to resource management, security, and because one consistent application framework is better than many competing libraries creating an inconsistent mess on desktop Linux.
[1]: http://en.wikipedia.org/wiki/The_Cathedral_and_the_Bazaar
Its interesting how Google forces handset makers to ship Google's proprietary software if they wish to use the Android "brand". However, they don't care if handset makers ship device driver code thus crippling the ability of anyone wishing to create a fully working AOSP ROM. I suppose in Googles eyes, Android = more data for Google to mine/sell/profit-from. Not surprising or disappointing. The Advertising business is not pretty.
I find it somewhat of a cognitive dissonnance. People complain about Google's increasing grasp on common Android whereas the most compelling parts of the system are fully available for free unlimited use by everyone. Plug in your cloud provider of choice, or none at all, and you're ready to go. Yet people don't complain about the full propietary lock-in on other platforms.
Also, please stop the tiresome meme that "Google/FB/MS/Cloud company X sells your data". These companies sell personalized advertisements, they do not sell your data.
Yeah..AOSP "works".. if you happen to have the driver binary blobs (which are not open source), which only work for some android builds on a handful of devices which are blessed by google. Open source indeed.
Oh and those binary blobs.. those are LICENSED. You are not allowed to make an android build and distribute it, if it contains those blobs. And without those blobs the ROMS are useless because you need drivers for basic things like your camera, phone radio, etc.
Google have taken the Open Source ideology and bastardized it to fit their commercial needs. And look, I have no problems with companies making money, but then you don't get to also say how "open source friendly" you are, when clearly you're just using open source as a marketing ploy.
>These companies sell personalized advertisements, they do not sell your data.
Feel free to explain this clause in Google's privacy policy.
http://www.google.com/intl/en/policies/privacy/
>We may share aggregated, non-personally identifiable information publicly and with our partners – like publishers, advertisers or connected sites.
Ah you're one of the people that thinks open source also comes with a mandatory ideology. That it's not good enough if source is released for everyone unless there are also other strings attached. We can leave this in disagreement then.
> Feel free to explain this clause in Google's privacy policy.
You have to redefine a lot of words if "sharing aggregated non-personally identifiable information" (e.g. statistics of "how many people aged 18-25 are seeing my ad?") is to mean the same as "selling your data".
https://www.google.com/policies/technologies/
> We don’t sell users’ personal information.
Now, who is redefining words?
>That it's not good enough if source is released for everyone unless there are also other strings attached.
Where can I find the source for those binary blobs?
>You have to redefine a lot of words if "sharing aggregated non-personally identifiable information" is to mean the same as "selling your data"
Thankfully, no redefinition is needed. That information is MY DATA. Sharing DOES NOT exclude monetary transactions. My general experience has been that companies do not share anything of value for free.
>(e.g. statistics of "how many people aged 18-25 are seeing my ad?")
e.g. aggregated statistics of people aged 20-21 living in the zipcode XXXXX who have lung cancer. Oops.. turns out, its just one person.
>We don’t sell users’ personal information.
Tell that to Google. They're contradicting themselves.
As well as a monopoly market share of smartphones, it's now expanding into other areas such as cars, TVs (again), robots, internet delivery and so on.
Monopoly market shares are fairly common in technology, but it becomes dangerous when any single company gets to control too many of them....
Right now, my only three hopes are Jolla, people attempting to port Freemantle to GTA04, and the people just trying to bring the Hildon UI to jessie which also runs on GTA04.
http://talk.maemo.org/showthread.php?t=93251 http://talk.maemo.org/showthread.php?t=91308
I probably should mention UbuntuOS as another hope, but I simply don't trust Ubuntu to deliver something that resembles traditional Linux. If they do, I'm in.
My hopes for Tizen were bashed to hell by this: https://www.tizen.org/irclogs/%23tizen.2013-01-20.log.html
( https://en.wikipedia.org/wiki/Rasterman - well known for http://www.enlightenment.org/ )
Phone manufacturers aren't interested in being servants, only masters.
Credentials: I was running Linux before Linux was cool, it was called Minix.
That made it pretty unusable for all but the most tech savvy.
Android is used in more and more fields other than phones and tablets these days, in those fields Google service is deemed not helpful, and totally unneeded. A working AoSP plus a few specialized apps will do that job perfectly well. I hope Cranogenmod will provide a viable approach in that space(non-phone and non-tablet market segment)
Sadly, good communication for newbies and outsiders has never been the Free Software movement's strong suit.
Like seriously, no swyping in aosp keyboard? so i install google keyboard, then i might as well have everything. one piece of proprietary software from google, might as well go all the way.
Though i still get most of my apps from f-droid and will use an open source alternative if its as good or better. example: i prefer cyanogenmod gallery to google+ and vlc to google music, poweramp
Last time I noticed this "disconnect" was when I looked into running TextSecure on my desktop. Sadly it seems that there isn't really any good way of doing that (yet). I'd imagine that these days you could whip something up with LXC and Android-x86, but it would obviously need some effort to make it really smooth experience.
But I'm not sure that either the developers of CyanogenMod or the business-minded people have a firm idea of what CyanogenMod should be or can be.
They have the advantage that, unlike Ubuntu, they are born with a good shot at doing a remunerative business in integrations for OEMs. The question is, is there a business in doing alternative ecosystem integrations, and are any of those alternative ecosystems free and open.
Apps in F-Droid have been lacking, and there are some FOSS apps in Google Play that are not in F-Droid, which is unfortunate. However, I have had a pleasant experience living Google- and proprietary-free on my Android phone. Really, the only thing I miss is Maps.
Interesting. Isn't this against any Google terms?
It's really not in Google's interest to prevent users from putting GApps back on their devices.
Also, the article glossed over an important issue; the need to use closed-source proprietary binary blob drivers to make the hardware usable. With drivers running in kernel space, the potential damage of an intentionally or unintentionally bad driver is pretty much unlimited.
The most problematic drivers are usually the graphics drivers due to complexity and their impact on both system and battery performance. Since the companies making the graphics chips (well, they're often just graphics cores within the main processor IC rather than separate chips) like nVidia, Qualcomm, Arm Inc (mali), and Broadcom (to a lesser degree lately) refuse to release the documentation necessary for open source hackers to write drivers, tons of unnecessary effort is wasted in attempts to reverse engineer the binary blob drivers so open source drivers can be written.
There are quite a few efforts under way to produce open source drivers for various graphics "chips" on various types of ARM systems. Here are a few links I've collected:
http://bloggingthemonkey.blogspot.com/
https://github.com/grate-driver/grate/wiki
https://github.com/laanwj/etna_viv/wiki
http://www.raspberrypi.org/a-birthday-present-from-broadcom/
https://news.ycombinator.com/item?id=7320828
I haven't seen anyone succeed in making a fully open source blob-free phone yet, but people are working towards that goal.
Unfortunately, even if open source devs eventually solve all of the blob driver (and chip documentation!) problems, there will still be an unknown, untested, and unaudited chunk of code running on phones that cannot be legally altered; it's the baseband processor.
http://en.wikipedia.org/wiki/Baseband_processor
Since the baseband processor controls the radio(s), it's actually against the law (FCC in the US) to modify the broadcast/receive power levels or frequencies. As such, each baseband processor has to be tested and certified by the FCC, and any change means it has to be tested and recertified again.
As for mobile browsers, this is specifically why I use NoScript, even in beta on Android (ironically called NSA-NoScript Anywhere).
It might not be perfect, but most of the time, like my laptop, I do not need JS or Flash unless there is a very specific reason, and I will not help these a-holes trace me.
And I am also, like others here, who got a new phone and now exclusively use FDroid. No Google Apps. It is a lower power cheaper phone with shoddier processor, and I can run minimally 2+ days without Google Play and shitty proprietary apps. So at least I recommend it.
It's one of the rare instance where people can act completely irrationally (to the point of paranoia), and people will accept it as completely normal and expected.
I hope you realize how silly all of this will sound 20 years from now.
It's one of the rare instances where people can act as corporations of thousands of people will act in their long term interest and continue to do so indefinitely into the future with no oversight or transparency into their actions.
I hope you realize how silly all of this will sound 20 years from now.
Edit: This is obviously a parody of the parent comment. It doesn't absolutely reflect my views but I feel it is at least as valid a view as the parent. I do sometimes trust in certain places but I'm often uncomfortable and Google is one of the last companies I want to trust with massive amounts of personal information.
I don't give them access to information to keep it secure. They shouldn't even need permission to access it. I share information with the world to make it a better place. There's no point in living in the dark.
To keep information for yourself is selfish. To expect that others will keep it secret for you is foolish.
I'm in favor of complete transparency, and I do not favor individuals or corporations in that matter.
All these can be intimate personal details at times. They may provide information about health, sexual partners and activity. They can also reveal journalistic sources and high level company meetings that might give rise to insider trading.
Is this all information that should in your view be completely transparent.
That's great! Profit while it's still free. We'll soon have to pay to get businesses to track us.
> All these can be intimate personal details at times. They may provide information about health, sexual partners and activity. They can also reveal journalistic sources and high level company meetings that might give rise to insider trading.
All of these things are great too! What do you not see?
In case anyone is taking your position seriously Google don't necessarily share the information about you with you. Secondly in twenty years time when someone has obtained high office Google will still have the records of them visiting prostitutes/gay bars/anti-gay marriage events (whatever is disapproved of in 2035) and Google[0] or a disreputable employee[1] will blackmail them.
[0] Google 2014 obviously wouldn't do something so disreputable but give it 20 years of falling marketshare, decreasing quality of management and desperation and who knows where it might be.
[1] Likewise todays controls on data may be tight but who knows when they might be dismantled when they get in the way of profit.
Google should definitely share information concerning me with me (or information concerning anyone with everyone). But whether or not they do it shouldn't have any legal implication. They can be evil (as in not transparent) if they wish.
Whether or not large corporations that gather data about people (such as Google) are evil or not doesn't concern me. I would hold the same position if Skynet existed. They deserve this right just as much as anyone else.
It's a dead end because, if the average person can't do it, then strong privacy will forever be on the fringes of society, something only weirdos and techies are worried about. It'll be vulnerable to the 'if you don't have anything to hide [like me]...' arguments.
The answer is instead, I think, strong legal protections on personal information such that we can trust third parties with our information. That third parties are bound by consumer protection and privacy laws to only use the information in acceptable ways and only reveal the information under due process, such as court orders (sparingly given).
People who care about privacy should work with our legal and legislative systems, not against them.
However, I don't believe that regulation and laws are solution to anything. I also don't think that it's reasonable to expect entities, even large ones, to be 100% secure and keep your data secret at all time. Ultimately, I'm convinced that the world has MUCH MORE to gain from transparency than from privacy (secrecy).
Fundamentally, what makes you think that people actually should have a right to privacy? Where does that expectation come from, if not as a side-effect of inefficient communication? People believe that they're entitled to privacy, but I can't find any reasonable argument for it.
I don't see many people claiming their right to lie, their right to fraud, their right to steal. What makes privacy so different?
> I don't see many people claiming their right to lie, their right to fraud, their right to steal. What makes privacy so different?
Well, for one thing, privacy is neither immoral nor illegal. How are these things even related?
You don't own yourself. Everything you do is an interaction with the world (including your own body and mind), which belongs to everyone equally.
Whether or not the imperfect beings we are want to hide things from others doesn't justify it to be right. People want to keep things private because they gain something from it. There's a lot of things I want from this world, but society don't hand them to me in the form of a fundamental right.
> Well, for one thing, privacy is neither immoral nor illegal. How are these things even related?
Says who? I would argue that privacy is actually immoral. Above all, though, what's immoral is to make illegal any non-coercive acquisition of data. Making that illegal is the real mistake here. And I don't suggest we make privacy illegal, that wouldn't be possible.
This is an extreme view. How can we even begin to talk about desires and rights under this assumption? If I don't own myself, how can I own anything? We have to throw out the idea of property, the concept of theft and so on. Is murder even wrong in this context?
Of course.
> Is murder even wrong in this context?
Murder is not wrong. Murder is just an action that reflects a decision. Whether it's good or not depends entirely on whether the outcome is optimal or not. Murder is not qualitatively different from, say, breaking a window. The only difference is one of quantity and scale. Generally, much more time and energy is invested in a living person than in the creation and installation of a window.