Top
Best
New

Posted by shscs911 12 hours ago

Android May Soon Restrict On-Device ADB(kitsumed.github.io)
719 points | 320 commentspage 3
falsemyrmidon 3 hours ago|
So glad we're becoming as locked down as iOS
gitowiec 10 hours ago||
Thank you for telling me about Shizuku! Android world is so vast and full of resources
chii 5 hours ago|
> Android world is so vast and full of resources

and google is doing all they can to try shut it down, because they saw how profitable a walled garden like iOS really is.

999900000999 5 hours ago||
I just installed CachyOS on one of my laptops. I like Open Suse a bit more, but my vpn and a few other applications work better on Arch.

Android is turning into the iOS/OSX/Win11 model. It’s not your device, you’re just renting it.

You need permission to install applications, or do anything else outside of consuming subscription services.

Where are the Linux phones ?

createful 4 hours ago|
Linux phones exist but work on a limited number of devices (see PostMarketOS) or Linux primary devices like Purism or Pinephone (which I've heard are expensive). That's the primary issue, you either need to buy an expensive and potentially underpowered phone OR have one that is supported most of the way with PostMarketOS (Wifi, SIM card, GPU, etc. sometimes may not work even though the phone can boot PostMarketOS).

I personally don't have a problem with a mediocre-performance phone but it should not be expensive. Not to mention app ecosystems - there aren't a lot of Linux apps for Linux phones.

zzril 1 hour ago|||
I've paid 200€ for my PinePhone. It is underpowered, but at least it doesn't have to waste its resources on rendering ads.

Where Android/iPhone users have "apps", I mostly end up writing small shell scripts around existing linux tools. My alarm clock "app" is realized via cron jobs; my TOTP "app" is a one-liner around `oathtool`.

Messenger apps are a bit tricky; I'll probably end up hosting my own matrix homeserver and then have bridges running for Signal and the likes.

righthand 2 hours ago|||
There are plenty of apps for Linux phones because you get all of the Linux software automatically. What there isn’t plenty of is commercial pop culture apps from social media companies, banks, and other businesses but for some of those you can run an android emulator or use their website.
throw9394999 11 hours ago||
This assumes user is the only person with physical access to unlocked phone.

All sorts of goverment agencies, airport security, even teachers now have access. And such attacks can be trivially automated, so even low paid worker can do it.

SXX 11 hours ago|
This is solvable by adding big huge warning that ADB is running. Not by removing feature.
xg15 9 hours ago|||
That huge warning would also be permanently shown for everyone using Shinzuku apps. I think that UX would neither be desirable nor increase security.
_flux 7 hours ago||
..for the very little number of people who use them?

Arguably it would be highly preferable compared to the option of not being able to use them at all.

throw9394999 10 hours ago|||
Just use opensource phone os!
tonyhart7 10 hours ago||
android is open source
hypendev 10 hours ago||
Android had a tradeoff - less vertical integration and more annoyances, a bit worse software quality, for a more open, customisable and utility-like experience. I loved that.

Now, the tradeoff is - less vertical integration, double the integration layer trash (Google & OEM) and a much more locked down experience. But the quality of it hasn't improved, it just got worse.

Doesn't make sense anymore. They can now do 99% of the same things, but iOS has a better quality OS, better apps and better vertical integration.

Not even vertical integration, actually just any kind. FFS it's 2026 and the recommended android way to send a photo to your mac/PC is "upload to google photos and hope it decides to sync".

chii 5 hours ago|
> send a photo to your mac/PC is "upload to google photos and hope it decides to sync".

and conveniently, google now has access to your photo, the meta data, and potentially able to scan it for advertising purposes.

mdp2021 11 hours ago||
Step back to the other issue (referenced in the page*), that Google would pushing on devices something that blocks applications that do not come from play.google.com . Was it not established that Google can only push that update on devices with a google account?

* https://keepandroidopen.org/

3form 11 hours ago||
What I find most annoying aspect of all software from 2010s onwards is this stupid discourse and associated results:

- some people want A, or A might even be already in use

- A is problematic for $MODERATE_OR_MILD_REASON

- B is introduced and made default

- a config switch between A and B is never considered

So, so tiring. If I want to bind ADB to localhost, _let me_. It's my device and my problem, ffs.

Arbortheus 11 hours ago||
Toxic max security.

Not everyone has the same threat model as you, $BIGTECHCORP.

rightbyte 11 hours ago|||
Isn't security just an excuse to push user hostile features?

Like, if security was a concern we would have simpler systems and still use 2fa devices for banks etc.

SXX 11 hours ago||
Sometimes it's truly useful featutes, but having no toggle in settings making it terrible.

Like iPhone idle auto-reboot every 3 days. After a while they added "Allow Idle Reboot" flag but it only accessible via MDM and require device wipe and for switching it to be a managed device.

TeMPOraL 10 hours ago||
What would that be useful for anyway? Sounds like something aimed to prevent people from reusing their old/secondary devices for IoT.
SXX 5 hours ago|||
> What would that be useful for anyway?

It puts iPhone in cold boot state if for instance police or any agency confiscate it from you. Better tamper proofing.

RobotToaster 10 hours ago|||
Hides memory leaks
TeMPOraL 10 hours ago||
Right, that too. But that's a reason to recommend regular reboots[0], not to force them, and "3 days of inactivity" is a suspiciously specific time that I also saw mentioned in Android settings somewhere the other day.

--

[0] - Which I find deeply ironic, in that merely a decade ago, people would laugh at Windows with its "reboot after installs, reboot in case of problems" approach, and now frequent reboots are seen as Standard Security and Stability Practice on *nix systems, both mobile and server-bound...

pirates 8 hours ago||
I have no issue restarting my iOS/Mac/Linux machines because the time to get back to doing fun or productive stuff is measured in seconds. And usually you only have to restart one time. Windows used to take ages, and often you’d reboot only find out that something else that requires a reboot only triggered because of the previous reboot, so you were sometimes in for 2-3 restarts.

It’s not like that anymore in my experience at least but the stigma stuck.

SXX 11 hours ago||||
They dont care about security; only about control.

There are hundreds of millions of outdated Android devices that all Google attestation systems consider secure even though they all running Linux kernel that was never ever updated and can be rooted by anything.

Now try to install your own firmware on them without said outdated kernel... How dare you.

jorvi 10 hours ago||
Technically the security works, just for their threat model. An exploit would need root and root means you likely cannot pass attestation AFAIK. The fact that this same exploiter can download all your contacts photos and texts is immaterial to, say, Disney, who want attestation only to prevent ripping of their content.
SXX 5 hours ago|||
No it doesnt actually work because its possible to do privilege escalaction without tampering with firmware or filesystem or triggering other markera. OS will be practically rooted while passing attestation just fine.

Only things attestation do is security theater and messing up people ability to use software of their choosing.

chii 5 hours ago|||
Security, but not for you, is no security.
surajrmal 2 hours ago||
Have you read the android security model? It's a multi party security model which considers apps and users as equals. It's a legitimate security model and just because it's not what you want doesn't mean it's wrong.is it user hostile? Maybe. But that is different than saying it offers no security. It's also not worth bickering about every small decision that is made in line with that security model. If you want a different one, push for it via alternative OS.
pjmlp 11 hours ago||||
Ask Jeeves toolbar disagrees.
einpoklum 11 hours ago|||
It's not even "max security". We are talking about those big tech corps which are infamous for sharing all of your private information with the government, and analyzing it so as to manipulate you in to buying things, and possibly for other obscure commercial purpuses.
chii 5 hours ago||
They securely share your private info with their advertising partners. You know that no hackers that didnt pay google would get access to that information.
stavros 11 hours ago|||
Google doesn't want you to be able to skip YouTube ads. It's as simple as that.
surajrmal 2 hours ago||
More specifically apps and users have equal agency in the android security model. Which comes down to the fact that if you don't own the app you can't control its experience. This feels grounded to me. Push for more open source apps where you retain control and ownership.
stavros 2 hours ago||
No, I bought the device, I should be able to do whatever I want with it.
surajrmal 2 hours ago||
And app developers have the right to not offer their services to users who don't give them the security model they want.

You are free to install a custom OS which provides you the security model you desire. You have choices.

stavros 1 hour ago||
No, when you can't participate in modern society without specific apps, I would argue those developers, in fact, don't have the right to not offer me their services.
altairprime 11 hours ago|||
No one's requested the config switch from A to B with a restriction that's acceptable to those seeking B. Idealism doesn't tend to offer compromises, and so Idealism tends to lose when it doesn't make a convincing case to regulators. Here's a simple and easy to implement example compromise that could be offered today:

"Changing between A and B requires a device reset."

Most people are going to flat out refuse to wipe their device for a phisher, especially since it'll log them out of everything and trigger all sorts of "new device on your account" warnings everywhere if it's done without their knowledge.

Sure, this is mildly annoying for the 1% that have good reason for A — but it's annoying once per device rather than losing A for good as is happening now. Sure, Google will deny service to A. They're doing that no matter what, either b/c they remove A or b/c they deny A, but this forces them to construct and defend a case for why users who went through the hassle of wiping their device to switch to A ought to be denied access to the app store, and that's a critically absent case in regulatory circles right now. (See also Graphene vs. the EU age check app.)

That's all it would take to protect B from A, but no one asks for it, and no one presses Google publicly for it, and so of course Google isn't doing it. No megacorp will help you walk off the Golden Path without some sort of extrinsic pressure. I see a great deal of clamor around wanting A, but absolutely none of the 'here's a mild annoyance that we came up with as a valid and safe compromise' clamor that would make them look incompetent in the public eye, provide further leverage for EU antitrust steps regarding Android itself, and give them a way to continue to protect users who need B for safety, while allowing those of us who want A to pursue it.

Perhaps other styles of compromise exist, too? As far as I can determine, no one else is thinking about this in terms of "what compromises will developers offer that continue to protect non-developers?", and so I have no other examples to offer. I'd sure love to see more ideas, more effort invested into offering serious and real compromises rather than inflexible resistance of every real safety improvement.

ducktective 11 hours ago||
>a config switch between A and B is never considered

And why should modern corpo maintain additional complexity to pander to 1% of privacy-aware tech-savvy users?

arjie 2 hours ago||
Looks like some developer just suggested an idea. Doesn’t seem concrete.
QwenGlazer9000 4 hours ago||
I'm sick of having my shit be locked down because of "security".

Do these people even know tech illiterate people? They couldn't enable ADB even with instructions.

hn_submit 7 hours ago|
LEA, Customs and intelligence agencies regularly use GDB to hack and extract information from an Android phone. So in that sense it may be a valid concern and reason to restrict this.

However, I'm pretty sure these entities will already have negotiated exemptions from the restrictions so in that sense they don't add much security.

felooboolooomba 7 hours ago|
Yeah, and they regularly use USB cables to do that too.
More comments...