The USA with its corporations setting a new, unbeatable WR in any% glitchless turning into a dictatorship with zero human rights or freedoms.
Android
DROID DOES
Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.
The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:
Rules
1. All posts must be relevant to Android devices/operating system.
2. Posts cannot be illegal or NSFW material.
3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.
4. Non-whitelisted bots will be banned.
5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.
6. Memes are not allowed to be posts, but are allowed in the comments.
7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.
8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.
Community Resources:
We are Android girls*,
In our Lemmy.world.
The back is plastic,
It's fantastic.
*Well, not just girls: people of all gender identities are welcomed here.
Our Partner Communities:
I imagine I'm gonna get downvoted for this, but I have no idea what F-Droid is.
FDroid is an alternative app store where its main focus is Free (libre) software. Free in the sense of freedom. They have also strong focus on tracking. Under app, you have "anti-feature" that tell you that part of its code is not opensource or that there is sensible data. :)
You should visit their website. ;)
Here is some info from their website :)
F-Droid is an installable catalogue of FOSS (Free and Open Source Software) applications for the Android platform. The client makes it easy to browse, install, and keep track of updates on your device.
FDroid respects your privacy. We don’t track you, or your device. We don’t track what you install. You don’t need an account to use the client, and it sends no additional identifying data when communicating with our web servers, other than its version number.
We don’t even allow you to install other applications from the repository that track you, unless you first enable ‘Tracking’ in the AntiFeatures section of preferences.
Any personal data you decide to give us (e.g. your email address when registering for an account to post on the forum) goes no further than us, and will not be used for anything other than allowing you to maintain your account.
Google fdroid or use chatgpt
Disclaimer: I have been a maintainer for LineageOS and a long time user.
Whoever advocates for LineageOS don't get it. Using LineageOS will not fix any issue like this.
Already today using LineageOS means give up on banking apps, ID apps, and even McDonald's and some games like Pokemon.
Yeah because Google with play intergrity now demands valid keys that gets invalidated as soon Google detect they are used for such usage. The cat and mouse game suddenly got much harder to beat.
So no, using LineageOS will soon be possible only with secondary devices and not your primary that you will need for your actual stuff to work.
Counterpoint: I use the McDonald's app where it belongs - on a giant greasy ordering kiosk.
But seriously, banks have websites. Everyone and everything has a website.
I don't need Android apps at the cost of my privacy or at the cost of control of my devices.
I use GrapheneOS as my only phone, and I have done so for years.
Whatever the topic, I don't need an app for that.
I don’t know about the US but on this side of the pond banks have their own 2nd factor apps. So to log in to a bank’s website you need an app - quite probably with play integrity.
That sounds extremely inconvenient. Individual apps for 2FA? No thanks. I'm good with KeePass and Aegis, both open source, encrypted, and don't require any extra hardware.
Dang. Y'all need to pick better credit unions. MFA rolling token is an open standard. Any single app can support all of my (correctly implemented) tokens. I prefer Aegis, but they (correctly implemented MFA apps) all work.
I don't want to trust my money to someone who can't implement standards compliant MFA.
That would scare the daylights out of me.
Well, they have a kind of 2FA since at least 30 years, long before rolling tokens were all over the place. Their latest implementations are as simple to use as Steam 2FA. If a bank isn’t able to implement a proper 2FA login there’s a ton of other security issues to worry about. Lastly, I think by using their own implementation/app they prevent their customers from using compromised apps.
If a bank isn’t able to implement a proper 2FA login there’s a ton of other security issues to worry about.
Exactly. Any organization whose MFA doesn't work on Aegis, I take action to protect myself from their incompetence.
Lastly, I think by using their own implementation/app they prevent their customers from using compromised apps.
I'm sure they claim that. But I still recognize it as simple incompetence. They aren't able or willing to hire someone with the Cybersecurity expertise to implement a relatively simple open specification.
Y'all are welcome to risk your money there. It's probably insured anyway, right?
For me, that's too much risk. Even if insurance makes me whole, getting robbed is a huge pain.
Exactly. Any organization whose MFA doesn’t work on Aegis, I take action to protect myself from their incompetence.
That'll surely end their business. /s
I’m sure they claim that. But I still recognize it as simple incompetence. They aren’t able or willing to hire someone with the Cybersecurity expertise to implement a relatively simple open specification.
Just out of curiosity: What percentage of the population is capable of running Graphene/Aegis? What percentage, regardless of capability, is willing to do so?
Creators of popular OSS regularly warn about downloading their stuff elsewhere or pay for it. How do you think that would apply to any 2FA application?
Now think of how stupid the average person is, and realize half of them are stupider than that. (love some George Carlin). Given that even (very) stupid people have and need bank accounts: How would you implement an authentication that can't easily be compromised to ripp off stupid people?*
* Let's just assume that you, the lead developer, are not at all "incompetent", quite the opposite. Also take into consideration that you need to keep cost down (hint: That means you want no one to call support because of 3rd party applications!).
This is actually a solved problem:
The credit union mplements (purchases from a competent vendor) their own custom branded standards compliant MFA solution.
This is what competent organizations already do.
Because the app is standards compliant, experts use Aegis instead of the branded app. Everyone else sticks with the branded app.
Also because the app is standards compliant, provided by a specialized vendor, and occasionally being used in unusual ways by expert users, serious security mistakes are much less likely to happen, and less likely to only be noticed by attackers.
I don't expect my credit union to tell me to use Aegis - I expect them to use a credible MFA vendor that interoperates correctly when I do use Aegis.
That's insane, I have never heard of such a thing, but I'm in the US where most banks don't even have non-sms second factor.
Counter-counterpoint:
Banks use their app to generate the otp and they reinvented the wheel so if you want to login you need to install it, can't use a generic authenticator. I am not aware of any single bank in the EU that allows the use of generic authenticators.
For McDonald's, using the app gives at least 50% off. A menu in the app costs 5 euro while on the store kiosk costs 12 euro. I do not personally care because I find their food to be just barely edible, but I understand why there's a need to install the app
Fucking google at it again. Straight up turning into apple.
If you see a Googler, spit in its face
You can blame the courts for this one. They basically ruled "Apple isn't a monopoly, because they don't even LET other people compete in the first place". (which is about a bass-ackwards as it gets but whatever)
Google saw this and went "shit..." so they're rushing to implement the same thing.
Why the Google identity check is completely useless:
Step 1: scammer acquires stolen id card
What's the difference between malware developed anonymously and malware developed anonymously but registered under a fake id? It can be installed today and it can be installed tomorrow. Do they really believe that malware developers will doxx themselves when publishing their malware?
When Android stops working properly, I'll move back to a dumb/feature phone. My wife will hate it, but so be it.
Some friends and I were talking about the feasibility of that earlier today.
It's possible, assuming that you never need to use your phone as an MFA method, never need to scan a QR code, or never need to use an app for something because they lack a web version.
My company recently required us to have mandatory fun at a baseball stadium. Apparently, Ballpark MLB is the only way to receive tickets and get into the park... I had to sign up for some stupid account and download some stupid app because my company required it.
The future is stupid.
Looks like I'm searching for a device that can run LineageOS, then.
🤗
If this comes to pass, f-droid might get closed as the userbase dwindles. Many apps will also cease to be developed and be left without updates. You will not get out with just updating to LineageOS. We should be looking at Linux phones at that point.
Linux Phones have a few software hurdles to pass through to get usable.
The biggest problem right now is adoption and contribution to the ecosystem, but there's a few things in the way of outright using Linux apps on a phone. One is that most Linux apps aren't made to be verical. Some newer ones can adapt to it, but many of the apps you likely would depend on using a Linux laptop are almost unusable on a Linux phone, like... vlc, for instance.
The network stack isn't as beaten to death for 4G and 5G as Android's is. I work in a slightly iffy area, and on Android I'd have times where I'd lose signal, but it would always come back within 5-10 minutes or so. There'd be times on Linux when it wouldn't until I'd missed two calls and three texts and an hour and a half had gone by because the system was choking on a comma or a misplaced semicolon it found somewhere in the background and wouldn't reset until I forced airplane mode off and on. If I was at home, or in the city, I'd never notice this problem, but the second I hit a road trip or went to work, boy.
Also, and this is just my phone, my OP6T had iffy microphone and earpiece settings. Pulse Audio was at the forefront of this audio stack almost entirely unchanged from its appearance on gnome or kde and on a phone it's just confusing and obtuse as to what app is using what and what even is what. If you got it right, it was fine, then the next call it wouldn't be, or would change back, again, probably more the 6T being a 6T than anything else.
I think right now, in this interim period, I'm going to buy a hotspot that I can just slip a sim card into and tether a Linux phone to it. I can use Conversations on Waydroid and use JMP.chat to send phone calls and texts over XMPP. I did fine on my OP6T for my actual use of a phone. I was browsin', I was textin', I was sendin' messages, I was doin' terminal stuff, administratin' my servers, readin', listening to musicn'. It was fine. Will do some experimenting.
Still using LOS, haven't looked back...
DOWN WITH GOOGLE
DOWN WITH GOOGLE
DOWN WITH GOOGLE
...
really hope someone finds a way to break google's block on apks that aren't registered. with more and more manufacturers locking down bootloaders, changing roms is no longer an option.