10,443 karma · joined May 4, 2011
More about me: tim.fyi
If the power isn't enough to power a device, that's annoying, but it's strictly better than when we had a unique power cable per-device. We've replaced "carry a charger per device" with "carry one charger for your highest power device, and it can do everything else too". And even with just a low-power cable you can usually trickle-charge overnight or something.
The only optional feature you'll run into that may or may not work at all is monitor support. Would it be better to have a whole different USB-C2 spec which requires display support (and so is significantly more expensive)? If the connector is the same you have the same problem (it's just labelling) and if it's not that sounds like you've just invented display cables which your monitor almost certainly supports today anyway.
This would completely defeat the point.
There is a range of needs for cables. Some devices have simple needs for power/data transfer/extra functionality, and some devices have more. A $3 USB-powered lamp does not need a cable for gigabit data transfer and 100W charging - this cable would be more expensive than the product. Similarly, new features & performance levels will emerge and we want to be able to use these in new cables backward compatibly.
Given a range of needs, you have two options:
- A single cross-compatible connector, but with a range of capabilities
- Different types of connector for every capability
We used to be in the latter situation, USB-C is an attempt to do the former. Having different capabilities for same-shaped cables is the goal.
Labelling would be great, but standardizing one single spec for all cables would defeat the point.
In practice, obviously most personal payments are well under that margin, so within-EU bank transfers are defacto instant everywhere. Most banking apps I've seen don't even show an 'instant/slow' option any more, it's just all instant.
If we gatekeep service access to specific implementation attestations, it becomes much harder for new implementations to emerge. It doesn't really matter who controls the process.
In that sense, it's always bad. In this specific scenario for example it directly blocks emergence of alternative Android ROMs and Android-mostly-compatible devices like the various Linux phones.
There may be times where that downside is worthwhile, but it's always a downside, and we should very strongly discourage attestation wherever possible on that basis for the health of both the tech ecosystem and the business market around it.
I think the challenges here exist but the reality is overblown to be honest, the vast majority of banking apps (everything that isn't struck through in that list) work just fine.
Fully agree the concern is discouraging adoption though. I would love to see more of a solution here, it seems like purely anti-competitive behaviour by Android that will block competitors emerging.
That said - it is their business, they're broadly well reviewed, and they're clearly incentivised to give scrubbing your data out a good go.
More generally, if you're in a jurisdiction with GDPR-like rules (which is a lot of the world nowadays) the brokers themselves have formal policies & tools for removing your data and chasing people manually myself occasionally I've found it quite effective.
You're certainly not going to get anything removed from any three-letter agencies or purely malicious people. Most of the discussion here though is around data brokers, who are generally large serious businesses who will at least follow the letter of the law. You've got pretty good odds of getting your data removed from any non-trivial businesses, if you follow their carefully hidden data collection policy links and then quote your local legislation and their privacy team in a polite but firm (and repetitive) way.
It's a paid service, they track data brokers datasets (I assume they just act as a buyer for as many as they can) and then manually request your removal from all of them, and then aggressively follow up and chase it for you. Interesting business model, even if it's annoying that the world means you need it.
I didn't know about this, so I looked it up: it's because they sell prescription-only abortion medication and ship directly to consumers, where it's legally only available via prescription and medical oversight. Fundamentally they're blocked for ignoring medical regulations. There were some appeals, but the argument is that access to abortion medication is already a well-protected right, so that this is dangerous and unnecessary, and it's not possible to block that while unblocking the rest of their educational resources.
Is this intended to imply that Spain has particularly high levels of sports betting, or issues with gambling? All the stats I can see suggest the opposite, and there's already plenty of tight restrictions on local gambling businesses (sports sponsorship ban, welcome bonus ban, almost no public advertising, etc). At a quick google, it looks like the 'Spanish gambling racket' for sports is tiny, gambling problem stats far lower than UK/France/Italy, and most gambling that does happen is the lotteries etc instead, which has its sins, but is a very different beast.
Is there something specific you're getting at?
The Spanish equivalent (Bizum) is merging into Wero is not a token use case, it's absolutely massive here. The absolute standard for peer-to-peer payments, more than 30 million users (>65% of the population), and they already launched contactless terminals for in-person commercial payments this month (https://euroweeklynews.com/2026/04/03/bizum-goes-contactless...).
They're publicly agreeing that only users using their approved mobile devices are allowed to do banking, and competitors cannot. I'm not sure how much more clearly anti-competitive this could be.
I wouldn't be surprised if they're slurping telemetry en route, and it's convenient for them that using their app helps nudge you towards Makerworld (their ecosystem for 3d prints, which is presumably good marketing) but I very strongly suspect "make it effortless for non-technical users to use the device with just a phone" was the original & primary driver.
I think it's an odd hill for them to die on, but it's not a totally unreasonable position - the cloud is other people's computers, other people can have rules about what you can do with their computers. Just because a client is open-source, doesn't mean you're allowed to use the server.
If you're using developer mode running everything locally (or remotely over your own VPN, like the author here) then I think this makes zero difference.
In theory, every EU state will have to support this soon so users can use it to verify age privately online. Still work to do to roll this out for real, but the technological part is very much already happening and I think the rollout plan is committed.
If you sell medical devices (apparently even down to toothbrushes) in the USA, you have to follow FDA rules. If you sell children's toys in the EU, you've had to follow EU consumer regulations (e.g. CE mark) at least since the 90s. Going back to the 70s, if you sold a physical product in the US as a foreign company you had to follow local rules about maximum delivery times and minimum warranties. If you don't follow the rules, your shipments get blocked at customs, and any marketplaces (Amazon) selling your products get fines as well for not verifying you appropriately, so marketplaces will verify and ban your business too if you blatantly violate local rules (e.g. selling devices containing radios without FCC approval). If you're selling laptops at any scale, you need to follow the local rules for every country you ship to.
There'll certainly be cases everywhere where enforcement isn't perfect (if you contact a tiny vendor in China and they ship to you directly and you sign for & pay the customs yourself, in practice you'll get away with it, or you can always travel to a country to buy a product and carry it back personally) but in the general case local regs on physical product sales are not unusual or optional at all.
Whether it's actually anonymous in practice, and/or whether it starts to go further than that (websites asking for verified gender? First name? City? Full DOB?) will be a real concern but I think there'd be plenty of push back and tech will end up setting norms here through the browser APIs & permissions prompts. In theory in this is all covered under GDPR anyway so requesting or storing information that's not necessary is illegal anyway, and at least explicit requests are less secret than invisible tracking of the same thing - much easier to reject individually, and to litigate abuse collectively.
Interestingly, Europe is about to try this: the Cyber Resilience Act is going to become obligatory for all sold digital products (hardware & software) by the end of 2027, with a bunch of strict minimum requirements: no hardcoded default passwords, must check for known vulnerabilities in components/dependencies, encryption for data at rest, automatic security updates by default (which must be separate from functionality updates), etc.
Remains to be seen whether this'll help, but good to see somebody have a go at fixing this.
Supporting free competition with and within the Android market is in theory what these teams are all about so hopefully with enough voices they'll push harder on it. I'd love to see a shift here that makes non-Google/Apple-controlled mobile a possible option (even if it's a Linux-on-desktop-style niche for the foreseeable future)