Comment Re:Governments and AI (Score 1, Troll) 56
Comment Re:So what? (Score 1) 156
Comment Re:implications for other distributions (Score 3, Insightful) 83
Comment Re:Google walked back on this, what's the issue? (Score 1) 55
I don't accept that premise. If there were, methods would have been open to discussion by the community and one of the actually privacy-preserving alternatives would have been chosen, such as having every website declare the age bracket in the HTTP header, legal determination it cannot be informed incorrectly, parenting tools within devices coming enabled by default and, if not opted-out, which only the adult buyer would be able to do after showing proof of purchase (no identity required), and browsers and the like only allowing connections to online services that matched the enabled configuration.
The way it's being implemented is the reverse of that and gives the government access to deanonimizable tracking. We know it's almost certainly deanonimizable because Snowden's files have shown how intelligence agencies deliberately include very subtle weaknesses in government-mandated cryptographic standards, protocols and methods, so any such must be assumed to contain one or more backdoors irrespective of them being seemingly impossible, as there's no feasible way to prove they don't other than blind trust.
The rule of thumb is that every single time politicians claim "think of the children!" without including in the proposed law objective measurable metrics the law is presumed to improve, plus requirements that if the improvement doesn't happen within a specific period of time the proposal must be cancelled, isn't about children, but it's rather levying popular emotional reactions to induce layers of false consciousness.
Comment Re:Google walked back on this, what's the issue? (Score 1) 55
You're supposing the EU doesn't like the control this gives them. Consider how they're pushing privacy invasive age verification all around, and tying the process to people using verified iOS and Android devices. With ADC they'll be able to know exactly who made this or that app they dislike, and it will give them another means by which they can request specific apps providing features the EU doesn't approve of can be disabled.
Besides, if they prevent Google from limiting their system in a way similar to how Apple is limited, that argument might down the line be used to demand the same openness from apple, otherwise both platforms aren't competing on an equal footing.
The trick to understand how these things work is to think like a lawyer, not like an engineer.
Comment Re:Google walked back on this, what's the issue? (Score 1) 55
The EU wouldn't care. Google's model as described is still way less restrictive than Apple's, and they've approved Apple's. If Apple's model was found to be acceptable, so will Google's.
Their answer to F-Droid will be quite simple: change how it works so it's compatible with how the ADC works by either registering for a single ADC key and being liable for all apps on the store, or by allowing every developer providing apps through F-Droid to have its own ADC and liability. And if F-Droid doesn't want to do either, there's always the alternative of becoming an ADB-based store that installs apps via USB cable or whatever after the user unlocks sideloading through the new process.
The EU will look at all this and answer "yeah, that's reasonable", and that'll be it.
Comment Re:Google walked back on this, what's the issue? (Score 1) 55
That's the limited distribution version of the ADC. It has these limits:
What can a limited distribution account do?
* Register apps
* Share apps with up to 20 devices that end-users have explicitly authorized.
How does app sharing work?
Sharing apps with a limited number of devices is achieved through a secure handshake process involving QR codes or links, user consent on the device, and registration using the Android Developer Console.
Check if this account type is right for you
The following are common use cases for a limited distribution account:
I am a(n): Hobbyist
I build apps to: Share with family and friends, or for personal use. My apps have no commercial intent.
So, not viable for the scale of F-Droid, or for any application that has more than 20 users, assuming each user would install it on a single device. And yes, they've figured quite well what they're going to do.
Comment Re:Google walked back on this, what's the issue? (Score 1) 55
I found these ToS by searching. I'm not quite sure this is the most up-to-date version, as I don't have a Google developer account and don't want to create a new one to check, but it says these things:
5. (...) You may not use the ADC:
* beyond the intended ADC functionality outlined in the Terms and other ADC documentation;
* to engage in, promote or encourage illegal activity or abusive behavior; (...)
* to access any other Google product or service in a manner that violates the terms of service of such other Google product or service.
6.3 Google may make changes to the Terms at any time with notice and the opportunity to decline further use of the ADC. (...)
6.4 If You do not agree with the modifications to the Terms, You may terminate Your use of the ADC, which will be Your sole and exclusive remedy. You agree that Your continued use of the ADC constitutes Your agreement to the modifications of the Terms.
6.5 If You violate any of the Terms or if You distribute malware or other harmful applications, Google may terminate Your access to the ADC.
7.2 You agree that if Google does not exercise or enforce any legal right or remedy contained in the Terms (or which Google has the benefit of under any applicable law), this will not be taken to be a formal waiver of Google's rights and that those rights or remedies will still be available to Google.
Plenty of apps on F-Droid violate these. Several are illegal in different countries, while others directly violate the ToS of individual Google products. Since F-Droid would be the one signing on all of them, its own ADC use could be cut, and then trying to install apps signed with that terminated ADC key would fail.
Comment Re:Google walked back on this, what's the issue? (Score 1) 55
someone will register and then sign F-Droid and all the apps offered on F-Droid
The problem with that is that Google says it will ban developers whose apps signed this way violate its ToS, which can have anything they want on it, so F-Droid will have to policy apps uploaded to make sure they comply with their own and Google's ToS, and if some gets through that review and does violate Google's, since it'd be signed by F-Droid, that might mean that one account responsible for all F-Droid apps being banned out of a sudden, and with it all F-Droid-installed apps on a single go.
I imagine an alternative is for F-Droid to stop using its own signature and having developers sign their apps themselves. Reproducible builds would still exist to check whether the user-provided signed version matches the rebuilt version, or however that works, but the signatures would be individualized.
Comment Re: GrapheneOS (Score 3, Interesting) 55
the alternatives only supported very few phones.
I only purchase phones I know I can install alternative OSes on. When one of my current ones is getting too old and in need of replacement, I research what the current alternative Android OSes are, chose a bunch I find are nice enough, then find the list of devices supported, the chose one from among those that's within my budget range. Those tend to be Motorola, whether officially or via some hack.
I don't buy a phone to play games, which means most any phone is performant enough for my needs, so I go with the cheapest option that does what I actually need. This also means that warranty is irrelevant: if the phone breaks for some weird reason, which is rate, getting it serviced by paying for the service, or buying a new one outright, aren't a big deal. Hence, the moment the new phone arrives I follow the procedure to get it unlocked, then the new ROM into. Sometimes with Google apps, sometimes without, depending on what I'm using it for.
As for bank apps and the like, I keep an old, tiny, cheap phone with stock, years-old Android that banks, due to mysteries of the universe, consider "secure" despite having hundreds of unpatched holes all the way down to the kernel. When I need to do banking I pick it from the docs drawer, turn it on, do what I need, turn it off, and back into the drawer it goes. For everyday use I have a debit/credit card, no app necessary with them.
Streaming is a loss, but eh, YouTube works well enough either with the official app, an alternative one, or a mobile browser, so good enough for watching something on the go. For me that suffices.
But yes, for those for whose use case is way more mainstream that's certainly not a good fit.