Hacker Newsnew | past | comments | ask | show | jobs | submit | whatsupdog's commentslogin

But that open mobile OS is still a fork of Android, which is too hell bent on privacy (which is not a bad cause, but something that masses don't care about). We should focus on an OS which is hell bent on UX, UI and other features that masses crave.

None of that helps the OP issue of hardware attestation for reCaptcha.




We all agree. But what's the solution? We know 99% of the users don't care. So, the only pressure point is phone manufacturers. I don't have any power to influence anybody significant in this space. I feel helpless.

For me, it's litigation, because the nature of GMS and Play Integrity is highly anticompetitive and these shouldn't even be legal (and most likely already aren't)..

See, mobile phone vendors have their hands tied - they can offer bootloader unlocking, but they can't touch Google spyware, otherwise they won't be "certified", won't be able to use Google Play or even the name Android.. That's of course not enough for Google, they also want to go after users which of such systems / modified systems (with unlocked bootloader) - that's what "Play Integrity" is about, they work hard to make sure the phone gets as useless as possible.. Together those two basically prevent vendors from making the mobile privacy landscape any better.

In the EU, we should outlaw Play Integrity first, by mandating that security level attestation might only be done in a way there's an independent auditing body that might certify alternative operating systems (these could use standard Android attestation) based on objective security criteria, not the Google spyware criteria. I heard about the "UnifiedAttestation" initiative but I'm not sure what's the progress on that.. not that I'm a fan of attestation at all, but you need to understand that it's a different thing when you attest the security model of the system, and a different thing where a system being "secure" actually implies Google spyware must be installed. For banking apps, I'd just want a secure OS, like GrapheneOS - without GMS.

Howver, the main antitrust investigation should happen in the US, only US courts can bring relevant Google executives to justice.


The phones without tracking are so rare that I don't think we can even say that the users do not care, they simply never had the option

The truly independent solution is GNU/Linux. Sent from my Librem 5.

Why is there no Librem 6? Librem 5 is 7 years old, it's a low-end smartphone with a flagship price tag :(

Oh wait they released "Liberty Phone" - still low end(!), this time with absurdly high price.. You can get true linux phone 10x cheaper by buying something that supports PostmarketOS

Your post sounds like you're trying to spread FUD.

Librem says the Liberty phone is the same, it just costs more because it is assembled in the U.S. for people, companies, or governments that don't want it intercepted and modified by a bad actor.


This might justify the price of Liberty Phone, but doesn't invalidate my claim that these phones are low-end by todays standards.

Why no hardware upgrade after 7 years?


You can't easily find vendors supporting free drivers: https://puri.sm/posts/breaking-ground/

Also this: https://puri.sm/posts/the-danger-of-focusing-on-specs/


I don't think it's going to be a savior... the same things that make Android hard to modify can happen just as easily when GNU/Linux phones become popular.

How? Linux development is not steered by a monopolist acting to gain the maximal profit. It is distributed over many entities.

Well one way would be just like how Android phone manufacturers are doing it now... with locked bootloaders and binary blobs. Even current GNU/Linux phones still largely need blobs to work properly.

This is misleading. The blobs are only in the firmware, not in the OS, not in the bootloader, not running on the CPU.

Having a technical possibility to lock down GNU/Linux phones in principle in undefined future by undefined entity that doesn't even produce them yet is a FUD argument.


Not true, current GNU/Linux have OS-level blobs

PureOS running on my phone is endorsed by the FSF, i.e., has no blobs whatsoever: https://news.ycombinator.com/item?id=25504641

Half of the entire internet is Meta properties.

That’s the other half.

Coincidentally also PHP.


Facebook started out PHP; but they ship-of-theseus'ed it into Hack by replacing the standard library, the language, and the runtime engine, so now it's a totally different thing with only a few superficial similarities (FWIW IMO Hack is much better than PHP, I'm sad that it never gained traction...)

Much of what was good in Hack just got rolled into PHP.

Illegal immigrants =/= marginalized people

No person is illegal

"person is immigrating illegally" not "illegal person is immigrating"

You might want to campaign to get rid of the entire concept of citizenship then. Until you manage to get people onboard with that, the lawful thing to do is to support legal enforcement of the laws on the book, which most people also agree with in this case.

Just came across something relevant today: https://hanker.app/blog/how-hanker-cut-90k-a-year-by-moving-...

Digitalocean's (not related to them in any way) app platform (and I'm sure many other cloud providers) provides almost everything that vercel does, at a fraction of the cost. I'm surprised this is not a well known fact.


This post appears to be AI generated (or heavily edited). eg “This wasn’t just about saving money. It was about gaining control over how our system works”

People should also look at Railway especially if majority of your users are in a single region because you will only really pay a price during active times and during times with low activity you will pay almost nothing.

The title could have been "People who stare at walls". The subtle patriarchy of hacker news users peeps up it's head once in a while.


I think it's supposed to be a riff on "men who state at goats".


But then it would not have been a "Pune" or "play on words"


And coke. Not the cold drink.


you get another taste of coke every time you clear 100 tickets. not the cold drink.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: