|
|
Log in / Subscribe / Register

Android 13 released

Version 13 of the Android system has landed in the Android Open Source Project; the list of changes is long.

To help users focus on the notifications that are most important to them, Android 13 introduces a new notifications runtime permission. Apps now need to request the notification permission from the user before posting notifications.


to post comments

Android 13 released

Posted Aug 15, 2022 21:46 UTC (Mon) by d4no0 (guest, #115694) [Link] (51 responses)

as always, fuck the developers, fuck the maintainers, we are strictly working on improving the UX, and fixing with breakung changes all the mistakes we made along the way, if you can't keep up it is your problem

Android 13 released

Posted Aug 15, 2022 23:42 UTC (Mon) by scientes (guest, #83068) [Link] (8 responses)

Pretty much.

And Android has a high-security mode where you need Google's permissions to install applications.

And GBoard likes to phone home.

Android 13 released

Posted Aug 16, 2022 6:02 UTC (Tue) by oldtomas (guest, #72579) [Link] (7 responses)

It's surveillance capitalism, what did you expect?

What's surprising to me is that, twenty years ago, Microsoft got served with a monopoly lawsuit (with no teeth, but I disgress) for far less.

Corporate seems to have infiltrated legal more efficiently since then.

Android 13 released

Posted Aug 16, 2022 7:25 UTC (Tue) by Wol (subscriber, #4433) [Link] (6 responses)

Far less what?

MS was convicted of deliberately damaging competition, and deserved it.

If all this is about is that apps now need permission to bombard their users with notifications, then where's the damage? To either competition, or end users?

And given that such notifications are now scientifically behind why Social Media is considered "addictive and harmful", the evidence is that what Google have done is a "Good Thing". Pretty much the first thing I do with any new app (and I don't have many!) is to disable notifications. If I don't need to do that any more, brilliant!!!

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 10:25 UTC (Tue) by eru (subscriber, #2753) [Link] (4 responses)

Agreed about notifications. Almost the only place where they are useful are messaging apps like WhatsApp. Opt-in is the way to go.

Android 13 released

Posted Aug 16, 2022 11:27 UTC (Tue) by Wol (subscriber, #4433) [Link] (3 responses)

Actually, I'd say the place they are MOST HARMFUL is messaging apps like WhatsApp, GMail, Google Messenger ...

Opinions may vary! :-)

Cheers,
Wol

Android 13 released

Posted Aug 17, 2022 17:36 UTC (Wed) by intelfx (subscriber, #130118) [Link] (2 responses)

That would depend _significantly_ on how exactly (and what for exactly) you are using those apps, and on the kind of contacts you are communicating with.

If I'm using $IM as a social network and mail equivalent, subscribing to "channels" and "groups" and leaving my IM handle for various companies to message me back, then I'd better stow all the notifications to where the sun doesn't shine. But if I'm using $IM to stay in contact with my dear friends and loved ones, of course I want notifications. I can always mask them temporarily when I really don't want to be disturbed.

Android 13 released

Posted Aug 18, 2022 8:21 UTC (Thu) by cortana (subscriber, #24596) [Link] (1 responses)

Sounds like what we need is some kind of concept of 'circles' of contacts that can have different notification & privacy settings applied to them...

Android 13 released

Posted Aug 22, 2022 17:33 UTC (Mon) by juliank (guest, #45896) [Link]

We already have settings per conversation, but I do admire your Google+ reference.

Android 13 released

Posted Aug 17, 2022 6:26 UTC (Wed) by oldtomas (guest, #72579) [Link]

"If all this is about is that apps now need permission to bombard their users with notifications, then where's the damage?"

Let me continue in my cynical (but not totally unrealistic, alas) branch.

Of course they will zealously protect their livestock (that's us!) from parasites. The latter threaten the yield, after all!

Android 13 released

Posted Aug 16, 2022 6:27 UTC (Tue) by burki99 (subscriber, #17149) [Link] (40 responses)

Can you tone it down a bit? I don’t use Android, I hope no one forces you to use it. If you don’t like it, just ignore it and keep your kindness and happiness.

Android 13 released

Posted Aug 16, 2022 8:52 UTC (Tue) by LtWorf (subscriber, #124958) [Link] (39 responses)

Can't really ignore it though.

We are at a point where shops require you to pay by phone only, entrances can be bought by phone only and so on.

Android 13 released

Posted Aug 16, 2022 9:48 UTC (Tue) by Wol (subscriber, #4433) [Link] (22 responses)

Dunno about you, but that's likely to trigger disability discrimination legislation over here. My aged in-laws CAN'T DO smartphones, my rather younger wife has major problems down to the fact she's disabled. I refuse to have any finance stuff on my phone (and I don't think it's got NFR or whatever that technology is ...)

When I go out we mostly use a Blue Badge to park, but if I went out on my own and all I could find was "use your phone to pay for parking", I'd just turn round and go home (or somewhere else).

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 12:07 UTC (Tue) by Vipketsh (guest, #134480) [Link] (5 responses)

How inevitably the legislation is satisfied and the end goal is reached (making you carry a tracking device around) is by keeping the alternative around but making it as painful to use as possible.

You can avoid not using the phone only for so long. When every place requires you to pay for parking through some app you don't really have an choice anymore: either you do as they ask or you lock yourself in your own house.

Android 13 released

Posted Aug 16, 2022 12:36 UTC (Tue) by Wol (subscriber, #4433) [Link] (3 responses)

> When every place requires you to pay for parking through some app you don't really have an choice anymore: either you do as they ask or you lock yourself in your own house.

I think you mean you don't have ANY choice. You are forced to stay at home. Doing as they ask IS NOT AN OPTION. Which is why it's illegal under disability legislation. (I doubt that will stop companies et al trying.)

Unfortunately, I deal a lot with people who do not use technology. And it drives me up the wall when clueless idiots say "let's teach them to use it". Far too many people I help have LOST THE ABILITY to use technology, the only thing that's going to get them back on line is a meatspace slave who does everything for them! (If we want to have a video call with the in-laws, I have to go over the road, set it up for them, and then come home!!!)

At the end of the day, the elderly and disabled are going to have to keep an eye out to make sure this stuff is not taken away from them. And sadly the clueless idiots who are responsible won't even realise there's a problem until they wonder why THEY can't go out the house any more ... :-(

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 15:18 UTC (Tue) by Vipketsh (guest, #134480) [Link] (2 responses)

> I think you mean you don't have ANY choice.

I meant you *practically* don't have a choice. In theory they always give you a choice, but it's like in The Godfather: "either your signature or your blood" -- the one option has such pain associated with it that it makes no sense to ever choose it.

I know how this plays out around here: you either pay for parking with your phone or you take your crutches, wheelchair or whatever disability aid you need, take a kilometer hike around the block to get to the other side of the building, have a wild debate with the security guard to let you through, go down two stories of stairs, through some dark corridors only to arrive at a machine where you could buy a parking ticket for coins if it would be operational. When you unwind your tour and get back to your car you notice that you are now the proud owner of a nice big fine for parking illegally. Even if you don't have a disability doing all this is madness.

The law, in theory, protects the disabled but that doesn't stop places from doing the above and if you sue the place you end up in court for, on average, five years (no joke) with the parking place arguing that they did all they could because they have all this infrastructure in place for the disabled (as above). The court's ruling ends up stating something like "you parked without paying for it, therefore you are to pay the fine." and they will also note that "the place did miss out on some of their responsibilities". Note how they don't say that the parking place has to fix their garbage.

Android 13 released

Posted Aug 16, 2022 16:02 UTC (Tue) by Wol (subscriber, #4433) [Link] (1 responses)

Over here, I think the ruling will say "By making it difficult for disabled people to pay, the parking place has broken the law. Case dismissed. Oh, by the way, unless you fix that, any more cases will get you done for malicious prosecution."

Okay, it takes someone brave enough to test it, but it also takes a parking operator brave enough to stand up and fight the disability rights brigade ...

Cheers,
Wol

Android 13 released

Posted Aug 22, 2022 4:22 UTC (Mon) by NYKevin (subscriber, #129325) [Link]

Meanwhile, in the US, you can sue them for damages. This has led to the predictable nuisance litigation, but it also means that the phrase "not ADA compliant" is enough to strike fear into the heart of the average soulless bureaucrat over here, and quite often they will try to fix problems without a lawsuit actually needing to be filed.

Android 13 released

Posted Aug 19, 2022 14:41 UTC (Fri) by immibis (subscriber, #105511) [Link]

in sanely designed cities, a third option is: don't drive

Android 13 released

Posted Aug 16, 2022 20:00 UTC (Tue) by LtWorf (subscriber, #124958) [Link] (15 responses)

In italy we have a digital authentication thingy that requires a smartphone to run a proprietary 2FA

The post office can authenticate you via SMS, but they cap it at 10 SMS per month, so that you must install the app to auth more than that.

In Rome there was no ticket office for the colosseum. Got to do it online and show the qr code.

In Sweden things are even worse, they love to feel futuristic and have no thoughts about privacy at all. So for example to obtain student discount for public transport you need an app to show that you are a student. They also make tickets cost more if bought at the machines rather than from the apps.

Android 13 released

Posted Aug 17, 2022 1:50 UTC (Wed) by linuxrocks123 (subscriber, #34648) [Link] (10 responses)

Europe sounds awful. Here in the States -- or at least in my state -- 2FA is universally just an email or SMS. The 2FA providers I've personally experienced will even call you on a landline if you prefer. The only smartphone-requiring thing I've run into is an app that tracks how you drive so insurance companies can give you a discount if you don't drive like a moron. That particular application really kind of does require an Internet connection, GPS, and accelerometer. They do have some insurance carriers that actually distribute specialized dongles that no doubt have a cell modem in them, but those obviously cost money, so a smartphone seems a reasonable way to do it for me.

2FA (was Android 13 released)

Posted Aug 17, 2022 12:53 UTC (Wed) by dskoll (subscriber, #1630) [Link] (7 responses)

There's also TOTP (AKA Google Authenticator) for 2FA, which I prefer to both SMS and email.

There are plenty of open-source TOTP implementations, so you don't have to run it on a proprietary smartphone.

2FA (was Android 13 released)

Posted Aug 17, 2022 17:50 UTC (Wed) by LtWorf (subscriber, #124958) [Link]

Those sites do not use TOTP but a home made thing, so you can't just use any generator. Also the app phones back when you set up the authenticator, making sure you can't have the authenticator on more than one device.

They also check if the phone has been rooted -_-

2FA (was Android 13 released)

Posted Aug 18, 2022 8:25 UTC (Thu) by cortana (subscriber, #24596) [Link] (5 responses)

I'm up to 14 accounts in FreeOTP and I'm starting to wonder if there isn't a better way...?

2FA (was Android 13 released)

Posted Aug 18, 2022 15:58 UTC (Thu) by mathstuf (subscriber, #69389) [Link] (1 responses)

I'd recommend not using your phone to host these secrets. I have something like 30-40 TOTP secrets at this point and use `oathtool` to access them because I don't want them to uniquely live on a device that fits in a lot of one-way places in this world. Granted the USB key is even smaller, but at least I can make duplicates of it (and I do).

2FA (was Android 13 released)

Posted Aug 19, 2022 8:02 UTC (Fri) by cortana (subscriber, #24596) [Link]

Oh, I certainly make sure that each service is recoverable if necessary. For some dumb services that only support a single TOTP key, I take great pains to duplicate the secret into KeePassXC (which lets you copy a TOTP code for an entry to the clipboard by pressing Ctrl+T, it's also useful when one's phone is in another room...)

2FA (was Android 13 released)

Posted Aug 22, 2022 4:38 UTC (Mon) by NYKevin (subscriber, #129325) [Link] (2 responses)

The better way would be for everyone to migrate to hardware security keys (WebAuthn/U2F), because the device identifies the site for you and is therefore immune* to phishing, unlike TOTP.** But that would require users to buy a $20 dongle, and there are people for whom that is an unacceptable economic barrier. There are also people who can easily afford it, but who don't care enough about their security to actually complete the purchase. As a result, deployment has been rather limited.

* It is not immune if the attacker manages to get a fake HTTPS certificate for the target domain *and* MitM your internet. But the average user probably should not be trying to defend against nation-state actors. Also, a social engineering attack which involves installing malware on the user's computer is quite a bit more powerful than "ordinary" phishing and has to be considered a different type of attack altogether - there's basically no way to defend against socially-engineered malware unless you want to lock down everyone's computer like a DoD workstation.
** TOTP is not immune to phishing, because the attacker can enter your credentials on the real site right after you enter them on the fake site, and prompt you for the TOTP code in real time. This attack also works on SMS, prompt-based 2FA, and just about every other "type in a one-time code" system, and SMS also has separate attack vectors involving the SIM and carrier. This does not work on WebAuthn, because the security key gets the domain name directly from the browser and produces a credential which incorporates said domain name, so a credential given to a fake site will be invalid for the real site, and no amount of user confusion or social engineering (short of "please install this malware on your computer") can convince the security key to give up a real credential.

2FA (was Android 13 released)

Posted Aug 22, 2022 17:52 UTC (Mon) by LtWorf (subscriber, #124958) [Link] (1 responses)

For me… it depends.

If I'm securing my fb or reddit account, I want to use "abc" as password and be done with it. It depends on the value of the account and the difficulty to talk to someone to rescue the account.

If I lose my smart token that I need for bank access, I can just show up to the bank with a valid ID and get a new one. But if I set up my gmail account with a token, if I lose the token I lost access forever. Google will never ever help me fix the issue.

I can back up a seed but not a real object that can get lost, wet, destroyed.

I recently got one of those FIDO keys that google is imposing on python maintainers. They gave me some "rescue codes". If I lose that file and the FIDO key my account could be locked forever with no recourse. Luckily one can also set up TOTP to have some redundancy.

Funnily enough twine doesn't support 2FA anyway; so to do uploads I need to use a token stored in a text file instead of typing my password as I did before :D

2FA (was Android 13 released)

Posted Aug 23, 2022 18:19 UTC (Tue) by jem (subscriber, #24231) [Link]

>But if I set up my gmail account with a token, if I lose the token I lost access forever. Google will never ever help me fix the issue.

The same can be said for many other 2FA mechanisms. If you use the Authenticator app and drop your phone in the ocean, you are equally locked out of your account.

On the other hand, you can register two different 2FA mechanisms for gmail. You can have the Authenticator app as backup while normally using the token. If you lose the token, you can get a new one and set it up with the help of the Authenticator app.

Android 13 released

Posted Aug 17, 2022 21:43 UTC (Wed) by marcH (subscriber, #57642) [Link] (1 responses)

On the other hand, most people in the US seriously believe their (immutable) social security number is a password and they don't have their name on their door or mailbox because of fear of so-called "identity theft" = Big Business not checking any identity and then harassing you for money they gave to someone else.

European authorities are also (poorly) trying to keep Big Tech control while campaign finance is basically unlimited in the US; everything and everyone is up for sale.

Android 13 released

Posted Aug 18, 2022 23:44 UTC (Thu) by k8to (guest, #15413) [Link]

It's both funny and sad when businesses instead of asking for my social security number as a password, ask for only the last four digits. You know, for security.

Android 13 released

Posted Aug 22, 2022 13:34 UTC (Mon) by Wol (subscriber, #4433) [Link] (3 responses)

> They also make tickets cost more if bought at the machines rather than from the apps.

I think the machine is one of the most expensive ways to buy tickets in London, BUT ...

You can buy an Oyster card (which can be topped up at machines, by direct debit, by standing order, by whatever. So a plain Oyster card can be tracked, but it's the card that's tracked, not the user. If you've got an account with auto-topup it's still the card, but they've got a name to associated it. I'm going to get my "Boris Pass" later this year - an Oyster Photocard so only I can use it. That's a smart card which can be used on all London Transport, and goes out some distance into the home counties. The nice thing about that, is that you pay for whatever transport you use, but it's also capped on a daily basis - if your transport individually adds up to more than a daily pass, you only get charged for a pass.

Or, instead of using an Oyster, you can use any smart debit/credit card. Of course, sods law, (a) the usage area of a debit/credit card doesn't quite match the Oyster, and my commute one terminus is in the debit/credit area, but not the Oyster area. Seeing as the Boris Pass gives me free off-peak travel, that's a pain because it covers 90% of my journey but not the terminus! I wouldn't mind paying the cost of using my Boris "outside of the free area", but I can't ...

Both Oyster, and credit/debit, are deliberately the cheapest way to get your tickets. On the buses, they're the only way unless you buy a daily pass. The unfortunate side effect is you can't pay for more than one person on the same card :-(

Cheers,
Wol

Android 13 released

Posted Aug 22, 2022 17:43 UTC (Mon) by LtWorf (subscriber, #124958) [Link] (2 responses)

I wasn't talking about London. I don't live there.

OT but london machines scam newcomers: they call it 24h ticket but it expires at the nearest midnight… i made the mistake of buying a 24h ticket at 23.00 because I'd use it the next day.

In Rome 24h means 24h.

Android 13 released

Posted Aug 23, 2022 8:17 UTC (Tue) by geert (subscriber, #98403) [Link] (1 responses)

We had a similar experience with a week pass in Vienna: don't buy it when visiting for a weekend.

Android 13 released

Posted Aug 23, 2022 12:10 UTC (Tue) by Wol (subscriber, #4433) [Link]

I've never heard a london pass called a 24hr pass. It's always referred to as a daily pass. And if I'm right they actually expire about 5:30 am.

We have night buses, and night trains, and I think the previous day's pass always works on them. You need a new pass for anything classified as morning, though.

I must admit I was pleasantly surprised in Venice, though. We got off the train and I saw 72hr Vaporetto passes advertised. As we were there for four days - 72hrs - I bought one each for me and my then bride, expecting them not to be valid on our last day. They were! They died about the same time we got onto the water taxi back to the airport.

We probably didn't get our moneys worth out of them, but simply knowing we could jump on any bus, any time, whenever we fancied, was more than worth it :-)

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 10:00 UTC (Tue) by kreijack (guest, #43513) [Link] (15 responses)

I can add an experience where my employer pay me some "fringe benefit" via the Endered circuit which requires an app installed in the phone [*]. In EU you need a phone to allow certain operation with the online bank.
However I suppose that this kind of apps run also on iPhone.

Anyway I think that the main client of Google (or Apple) is the final customer and not the developer. And this makes sense. So if they think that something provides a benefit for the user, they are open to change the API even if in a non backward compatibility way.

Finally we have to face the reality, in order to be able to sustain a "market app" way of providing the app, they (as developer, phone manufacturer ...) need also to be able to "control" all the way that an app can interact with the users. Yes this means that the more technical skilled users have less degree of control.

Soon we will need to put in discussion if the OS producer (google, or Microsoft or apple or Debian...) has to the right has to manage the policy (allow or not allow to a certain thing) and the right to develop the application for their OS. I am sure that the 3rd is in conflict with the first. I am not sure about the 2nd.

Until now linux doesn't have this issue because the "distribution model" add a "filter" to the packages. This prevent that a package if "annoying" is distribuited. I fear that the flatpack (and all the others like that) model bypassing the "distribution model" soon will need the same "control" measure.

[*] May be that this kind of payment, due to favorable taxes, has some constraint which are country related (Italy law in this case).

Android 13 released

Posted Aug 16, 2022 11:24 UTC (Tue) by Wol (subscriber, #4433) [Link]

I think the fact it's a fringe benefit would get round the UK "Truck Acts", which forbid employers from "paying in kind". My employer has some sort of "bonus scheme" to which I've never signed up for, and into which they've made a bunch of "ex gratia" payments. Certainly my attempts to take advantage of these schemes with my employer has led to a LOT of friction with the system.

There seems to be a whole bunch of these "intermediary" schemes nowadays where A buys something for B on the scheme, and if B never cashes it in, I guess the intermediary walks away with the money. A is unlikely to get a refund. Mostly if I'm B I just throw the stuff in the bin - imho claiming isn't worth the hassle - and if anything it makes me *less* likely to do business with A in future.

If there's no immediate, obvious, benefit I just can't be arsed. I got given a "Love to Shop" voucher a while back. My wife's disabled. We don't go High Street shopping. It expired before we even went near a shop that took it, I think ... (assuming they sold anything I wanted!!!)

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 12:23 UTC (Tue) by Vipketsh (guest, #134480) [Link] (1 responses)

> I think that the main client of Google (or Apple) is the final customer and not the developer.

There is competition between Apple & Google, so in reality both the customer and the developer needs to be catered to. If one platform puts too much burden on the developer they will simply develop only for the other. Unfortunately, I think, the developer is more important than the user simply because one developer represents more than a single user so if you piss off half your developers you loose more than half your user base, but piss off half your users you loose only half your users.

This case is really just much ado about nothing. How many people really check what permissions an app requests ? Most will simply click "Allow" however often required to use the app and this is just one more of those. I would wager that there are far fewer still who decide not to use an app after learning all the permissions it wants.

Seriously, though, if any of the two big brands would put the final customer first, phones these days would actually be personal computing devices first and foremost and most definitely not a platform for spyware as it is today.

Android 13 released

Posted Aug 16, 2022 20:07 UTC (Tue) by LtWorf (subscriber, #124958) [Link]

> if any of the two big brands would put the final customer first

I think they started like that, but they have a constant need to squeeze for money.

Android 13 released

Posted Aug 16, 2022 16:04 UTC (Tue) by wtarreau (subscriber, #51152) [Link] (6 responses)

> In EU you need a phone to allow certain operation with the online bank. However I suppose that this kind of apps run also on iPhone.

A phone, yes, not necessarily a smartphone. I receive them on my landline phone where a synthetic voice dictates the letters to type for the secret code.

Android 13 released

Posted Aug 16, 2022 19:11 UTC (Tue) by Wol (subscriber, #4433) [Link] (5 responses)

> A phone, yes, not necessarily a smartphone. I receive them on my landline phone where a synthetic voice dictates the letters to type for the secret code.

Until the telco upgrades you to "digital voice" and breaks it ...

Cheers,
Wol

Android 13 released

Posted Aug 17, 2022 14:26 UTC (Wed) by wtarreau (subscriber, #51152) [Link] (4 responses)

How would that break ?

Android 13 released

Posted Aug 19, 2022 16:05 UTC (Fri) by flussence (guest, #85566) [Link] (3 responses)

Presumably something like...

Landline: Try sending SMS -> the exchange rejects it at send time because they know the line type -> fall back on dictated code

VOIP line: Try sending SMS -> it succeeds -> it actually fails because the receiver is still a headless landline handset, and the SMS is now lost in limbo somewhere

Android 13 released

Posted Aug 20, 2022 23:10 UTC (Sat) by Fowl (subscriber, #65667) [Link]

Telstra (the previously government owned monopoly Australian telco) had a text to speech system set up to automatically read SMS sent to (their?) landlines. I wonder if that still exists.

Android 13 released

Posted Sep 7, 2022 14:41 UTC (Wed) by niallmcgee (subscriber, #123265) [Link] (1 responses)

For some (I think most?) UK operators, if the landline has an SMS-enabled phone then the SMS is delivered just as it would be to a mobile phone. If there isn't an SMS-enabled phone, the phone rings and when answered (by subscriber or voicemail) the message is read through a text-to-speech engine.

IME it works mostly the same whether the line is VOIP or POTS.

Operators at the "value" end of the market may be different, of course!

Android 13 released

Posted Sep 7, 2022 15:29 UTC (Wed) by Wol (subscriber, #4433) [Link]

> IME it works mostly the same whether the line is VOIP or POTS.

IME it's broken if the line is VOIP ... (I'm with BT, FTTP, digital voice, Home Hub 7). As in, the phone appears not to "ring" at all. An SMS enabled phone should take the call before the ring tone engages, or the phone should ring to enable the voice message to be given. Our phone just does not ring at all ...

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 16:06 UTC (Tue) by qyliss (subscriber, #131684) [Link]

> In EU you need a phone to allow certain operation with the online bank.

Only if you have a very bad bank. AIUI, the rules just mandate some unique per transaction second factor. Various banks implement this using a mobile app, SMS, or a standalone TAN generator device. There are probably other ways of doing it as well.

"Strong Customer Authentication" is the term to look up here. :)

Android 13 released

Posted Aug 16, 2022 20:05 UTC (Tue) by LtWorf (subscriber, #124958) [Link]

> In EU you need a phone to allow certain operation with the online bank.

Actually the EU directive recommends the use of dedicated device for authentication (a smart token). But those costs so banks make people install apps instead.

My bank removed smart tokens in favour of apps, and blamed it on the EU. They literally do whatever they want because there is no consequence for them.

Android 13 released

Posted Aug 17, 2022 5:30 UTC (Wed) by eduperez (guest, #11232) [Link] (1 responses)

> Anyway I think that the main client of Google (or Apple) is the final customer and not the developer.

The main client is always the one who pays the bills; as Android is free to the end user, the main client has to be somebody else... who pays Google? the advertisers, they are the main client!

Android 13 released

Posted Aug 17, 2022 10:22 UTC (Wed) by excors (subscriber, #95769) [Link]

> The main client is always the one who pays the bills; as Android is free to the end user, the main client has to be somebody else... who pays Google? the advertisers, they are the main client!

Google makes over $11B/year revenue from the Play Store, mainly selling apps and in-app purchases to Android users (https://www.reuters.com/technology/google-play-app-store-...). I don't think anyone knows how much Android contributes to mobile ad income, but one guesstimate is that Android setting Google as the default search engine is worth $7.5B/year (https://www.kamilfranek.com/how-google-makes-money-from-a...), plus about $2B/year from Google Maps ads.

There are also many smaller sources of non-ad income. E.g. they sell their own Pixel phones. Android integration encourages people to buy other Google hardware (Nest (which also sells an optional subscription), Chromecast, etc) instead of the Apple/Amazon/etc equivalents. There's the Google One subscription for extra cloud storage for your phone's photos. Google Pay/Wallet can take transaction fees from every payment made with your phone.

Ads are certainly important, but an arguably greater amount of money is going directly from Android users to Google for devices and services, so the users really are customers.

Android 13 released

Posted Aug 19, 2022 5:21 UTC (Fri) by oldtomas (guest, #72579) [Link]

"Anyway I think that the main client of Google (or Apple) is the final customer [...]"

This is a widespread misconception, yes. The "user" is for them the product (aka cattle).

"[...] not the developer."

They were trying hard to productize those, too; they just didn't exactly know how. Now Microsoft is succeeding big time with Github (those $7B have to generate some ROI, after all).

No, the customers are the ad industry and their futures.

Android 13 released

Posted Aug 16, 2022 13:39 UTC (Tue) by HelloWorld (guest, #56129) [Link]

Sounds like the kind of OS that a user would like.

last one for my device, sadly...

Posted Aug 16, 2022 13:39 UTC (Tue) by wjlonien (guest, #160296) [Link] (5 responses)

Just updated my Pixel 4a - and this is likely the last major official version of Android I'll get for it, sadly. After another year or so, I'll have to look for free alternatives like MicroG for LineageOS, /e/, or any Linux like Debian if they'll be ready until then...

I'm afraid that that will also be the end of online banking and paying with the phone for me, unless the banks will get their act together as well...

last one for my device, sadly...

Posted Aug 16, 2022 16:20 UTC (Tue) by zdzichu (subscriber, #17118) [Link] (4 responses)

Banks have nothing to do. If you break the chain of trust (by unlocking the bootloader and loading an unproven OS image) you run untrusted device. Which is outside of reasonable risk appetite for banking apps.

last one for my device, sadly...

Posted Aug 16, 2022 18:09 UTC (Tue) by pizza (subscriber, #46) [Link] (3 responses)

....yet you can interact with the same bank using an untrusted web browser on an untrusted computer using a questionably-trustable connection.

last one for my device, sadly...

Posted Aug 17, 2022 9:55 UTC (Wed) by zdzichu (subscriber, #17118) [Link] (2 responses)

We are trailing into the off-topic territory, but when comparing browser-access and app-access to my bank's services there's a huge gape in functionality. Browser gets access only to rudimentary services like wire transfers, and most of the operations have to be acknowledged using a second factor.

Meanwhile, the app on non-rooted phone:
- acts as a second factor (via PUSH notifications). Can be optionally secured by using a biometry. Without app, you are left with SMS (totally unsecure) or voice calls with robovoice dictating you a number. Very cumbersome.
- can be used as a contactless payment provider (with more functionality than Google Pay)
- can act as an identity provider when interacting with e-Government websites
- can be used to automatically pay for highways, parkings, etc.
- can be used to immediately wire-transfer money when you only know recipient's phone number, or even without that with single-use codes.

The last one is interesting. The banks in my country agreed on direct payment system (they call it "Blik"). It works by generating 6-digit code, valid for one minute and representing specific monetary value. If two sides of transaction provide the same code during 1 minute window, money is sent. The attack vector with rooted phone is very simple – malware can "steal" the code while it is displayed, by taking a screenshot or using "accessibility services" to impersonate a screen reader. On non-rooted phone, banking app has an exclusive access to display and it's deemed secure enough. This is not theoretical, this kind of malware is found in the wild.

In conclusion, banking apps offers much wider scope of services than a browser interface, because non-rooted phone platforms are more controllable and thus secure.

last one for my device, sadly...

Posted Aug 17, 2022 10:18 UTC (Wed) by seneca6 (guest, #63916) [Link] (1 responses)

> In conclusion, banking apps offers much wider scope of services than a browser interface, because non-rooted phone platforms are more controllable and thus secure.

Really, you must put that in quotes. "non-rooted" meaning: not rooted BY YOU. If the bank deems a "non-rooted Android 6.0" as secure enough, but an up-to-date Lineage OS as "non-rooted and therefore insecure", well what shall one say.

Fortunately it depends on the bank what they allow you to do in the browser, and for my bank I can keep the app usage at a minimum or through a special device.

I think it will run all down to having one stock Android on the cheapest possible device at home, for all those "practically necessary apps", and a different trusted phone for communication. A bit like Linux in the 90's, where you needed to keep that Windows box or VM around for that one application or game. A shame, really, we've come full circle, and the direction is backwards.

last one for my device, sadly...

Posted Aug 17, 2022 10:20 UTC (Wed) by seneca6 (guest, #63916) [Link]

Lineage OS as "rooted and therefore insecure"

sorry for the typo

Android 13 released

Posted Aug 16, 2022 15:08 UTC (Tue) by mss (subscriber, #138799) [Link] (7 responses)

My main grudge against Android is that Google / AOSP don't maintain all per-phone builds themselves - the way that, for example, OpenWrt does for its supported devices.

The latest OpenWrt version still supports 10+ year old devices, and many even older ones (as long as they have enough Flash and RAM to run it).
At the same time even Google's own Pixel 3A (released like 3 years ago) won't apparently get this new Android version - and third-party Android phones are often abandoned even sooner.

The gold standard of backward compatibility is still x86, however - for example, Debian "bullseye" released a year ago still runs on 32-bit hardware from late 90s.

Android 13 released

Posted Aug 16, 2022 18:58 UTC (Tue) by Wol (subscriber, #4433) [Link] (6 responses)

> My main grudge against Android is that Google / AOSP don't maintain all per-phone builds themselves - the way that, for example, OpenWrt does for its supported devices.

You just shot yourself in the foot with this.

OpenWRT maintains all their SUPPORTED devices. Because, I presume, they themselves ported OpenWRT to said device.

Google probably never even SAW half the per-phone builds before the manufacturer released them for sale. You're asking Google to TAKE OVER maintenance for hardware not on their supported list - a totally different kettle of fish.

Cheers,
Wol

Android 13 released

Posted Aug 16, 2022 22:00 UTC (Tue) by mss (subscriber, #138799) [Link] (5 responses)

OpenWRT maintains all their SUPPORTED devices.
That's right, but the list of devices ideal for OpenWrt is currently 615 entries long.
Plus there's additional list of 256 ideal devices no longer sold, some of which were discontinued by their manufacturers 10 years ago.

If I had 900 phone models to choose from, spanning a decade, that still support the latest Android version then I wouldn't complain.

Google probably never even SAW half the per-phone builds before the manufacturer released them for sale.
That's even more true for OpenWrt-supported devices.

If such a small non-profit like OpenWrt can achieve this level of support for older devices then a $1.5T+ entity (that's making money from Android) surely should be able to do this, too.

Android 13 released

Posted Aug 17, 2022 0:45 UTC (Wed) by Paf (subscriber, #91811) [Link]

OpenWRT is way simpler than Android, and phones much more complicated than routers…

PostmarketOS for long term Android handset suport.

Posted Aug 18, 2022 20:49 UTC (Thu) by tim_small (guest, #35401) [Link] (3 responses)

PostmarketOS supports abandoned phones. You can run PostmarketOS releases, and run Android apps in a container, or you can run AOSP using the kernels that PostmarketOS (and others) maintain and upstream.

Reasonably complete Mainline kernel support for reasonably modern phones is limited to those based on the Qualcomm SDM845, with the best support at the moment being for the Oneplus 6 and 6T. These are high-end phones from around 4 years ago, and are available on the used market at around €/$ 140.

The older (2014) Qualcomm Snapdragon 410/412 (MSM8916) also have reasonable PostmarketOS support with mainline kernels.

Yes, I think it would be reasonable and negligible expense for Google to sponsor this work, although I suspect that with the exception of direct developer support for the Google Pixel etc. line, they could only reasonably do-so by purely monetary contributions without any direct developer assistance (otherwise they get into political problems with other Android device manufacturers regarding which phones are supported).

That having been said, committing to delivering mainline kernel support for all Pixel line phones would set a good example I think.

PostmarketOS for long term Android handset suport.

Posted Aug 20, 2022 13:37 UTC (Sat) by foom (subscriber, #14868) [Link]

One thing that looks nice about postmarketOS is that it seems to avoid using unmaintained ancient vendor kernels, and unmaintained binary blob userspace "drivers".

There could still be issues, since they're still depending on possibly-vulnerable vendor provided firmware blobs, but that's significantly _less_ exposure to unfixable vulnerable code then you'd get by installing one of the myriad of alternative android distros -- all of which seem to just ignore or downplay this glaring security problem.

PostmarketOS for long term Android handset suport.

Posted Aug 26, 2022 3:02 UTC (Fri) by sammythesnake (guest, #17693) [Link] (1 responses)

I got all excited thinking I might have my next non-vendor-provided OS for my android phone but with only two phones on their "main" supported list (the "community" list comes with the caveat "may still have serious issues ... e.g. SMS not working" so not a super-tempting option, even if any phone I've owned were on the list) I'd have to say it'll likely be a while before I'm in a position to benefit...

In the meantime, what I *really* want from Android's permissions system is the ability to treat apps as utterly untrustworthy and plain lie to them - e.g. let them *think* they're the "device admin" app, or can run in the background willy-nilly or that they have my location, or access to any of my (none of your damn business) files outside a specifically allocated folder, or whatever else but feed them my choice of fake data.

As it stands, there isn't even a way to stop an app I'm not even using from bleeding my battery dry and making the app I'm actually *trying* to use lag to unusability, only to get kicked out every time I switch to another app and have to start all over again. (My phone has as much RAM as my laptop, by the way)

Even the "force kill" option and process manager apps kill it only for it to immediately restart :-(

The background problem is at least *partially* solved by using Shelter* to "freeze" them but it's a bandaid working within the functionality Google provides for "my employer"** to control *their* apps on *my* phone(!)

I've tried finding something that will just wrap an app in some shim libraries to let me apply some kind of filtering without luck - I started downloading the code for WayDroid to see if I could learn enough to maybe do something in that direction myself, but when it had downloaded 80+GIGABYTES of code (and was still going!), I gave up on that path :-S

* https://github.com/PeterCxy/Shelter

** I'm self employed(!)

PostmarketOS for long term Android handset suport.

Posted Aug 26, 2022 14:50 UTC (Fri) by mathstuf (subscriber, #69389) [Link]

I'll note that you can use Battery Saver mode to help with some of your issues (I keep it on all the time at least). Extreme Battery Saver mode will go even further. Not sure how much device-admin apps can avoid it. Note that there may be other side effects for some hardware bits in these modes (e.g., location not being given to background apps). Newer Android also let's you keep Batter Saver mode on after unplugging the device from a charger.

Android 13 released

Posted Aug 16, 2022 16:08 UTC (Tue) by wtarreau (subscriber, #51152) [Link] (5 responses)

> Apps now need to request the notification permission from the user before posting notifications.

So even more questions, like those annoying browsers asking if you want to accept notifications now or be reminded later, but no more let you respond "never accept notifications for any site and never ask me again or I switch to your competitor, stupid browser"... Hmmm ?

I'm seeing lots of people accept notifications by laziness or by being fed up with fighting. And this model works essentially based on this: sometimes you're tired and you finally click the wrong box, and suddenly you're getting a new spam channel. As such I *do* want to see something that does *not* ask you and silently rejects them.

Android 13 released

Posted Aug 16, 2022 17:06 UTC (Tue) by mathstuf (subscriber, #69389) [Link] (2 responses)

Huh? I've not seen things get to the "yes, yes forever, or not right now" selection other than the Google "enhanced location services" on Android or Firefox any time recently. I still get asked permissions all the time, but those are all ones that I end up saying "just this one time" to and is exactly the behavior I *want* in that case.

Android 13 released

Posted Aug 16, 2022 20:13 UTC (Tue) by LtWorf (subscriber, #124958) [Link] (1 responses)

I think the issue is that websites know you haven't enabled notifications, so they keep nagging (slack does this). If it was silently blocked it would be better.

I guess it will be the same issue with android, but I'm not sure how the API is implemented there.

Android 13 released

Posted Aug 18, 2022 15:36 UTC (Thu) by mathstuf (subscriber, #69389) [Link]

Slack has never asked for notification access after the first time I open it (per container since I have multiple "slack servers" I connect to). Maybe Firefox is saying "no" on my behalf for me?

Android 13 released

Posted Aug 16, 2022 17:07 UTC (Tue) by ttuttle (subscriber, #51118) [Link]

The browser and OS permission prompts only have "allow" and "deny" (or "don't allow").

There's a common pattern where apps/websites don't want you to click "deny", so they make an 'informal' permission request with "allow" and "maybe later" first.

If you say "allow", they make the 'formal' permission request to the browser/OS, confident that you'll probably click "allow" on that too.

If you say "maybe later", they don't make the 'formal' permission request, so you don't have the opportunity to click "deny", and they can ask you again later.

(Note: I work at Google on Android, but my opinions are my own.)

Android 13 released

Posted Aug 16, 2022 17:19 UTC (Tue) by niner (guest, #26151) [Link]

On Firefox just go to Settings/Privacy&Security/Permissions/Notifications and enable:
"Block new requests asking to allow notifications
This will prevent any websites not listed above from requesting permission to send notifications. Blocking notifications may break some website features."

Android 13 released

Posted Aug 18, 2022 8:11 UTC (Thu) by cortana (subscriber, #24596) [Link] (11 responses)

Version 12 was bad enough--they deliberately hobbled the ability to split windows in order to force people who want to play music on YouTube while in another app to pay for YouTube Premium.

Android 13 released

Posted Aug 18, 2022 11:44 UTC (Thu) by mgedmin (guest, #34497) [Link] (4 responses)

By "hobbled" you mean they made the UI clunkier? (Instead of long-press on the app switch soft button you have to press it, then press the app icon, then select split view.)

Yeah I hate that too.

Android 13 released

Posted Aug 19, 2022 8:06 UTC (Fri) by cortana (subscriber, #24596) [Link] (3 responses)

Now try to change the app on the bottom half of the screen from, say, your web browser to your email client...

Android 13 released

Posted Aug 19, 2022 9:09 UTC (Fri) by mgedmin (guest, #34497) [Link] (2 responses)

I can't, my web browser (Firefox) is already in the top half, playing the youtube video (with uBlock Origin saving me from having to listen to intrusive ads).

Some apps (e.g. Amazon Kindle) declare that they don't support split view, which makes it impossible for me to read books while listening to YouTube music. This is annoying.

Actually, I think Firefox allows me to listen to a video even when the browser is in the background. I have to switch away from it, then open the notifications and unpause the paused playback notification.

Android 13 released

Posted Aug 19, 2022 9:18 UTC (Fri) by mgedmin (guest, #34497) [Link] (1 responses)

Wait, I now tried it in Android 13 and I see what you mean. They changed it so the split view apps now stick together and appear as one in the app switcher! Interesting.

Android 13 released

Posted Aug 19, 2022 14:27 UTC (Fri) by cortana (subscriber, #24596) [Link]

Yeah, it's horrendous. I can't possibly imagine any other reason for this change other than to break the use case of YouTube app on top of screen, and switching between other apps on the bottom.

https://issuetracker.google.com/issues/210345474

Android 13 released

Posted Aug 18, 2022 23:47 UTC (Thu) by k8to (guest, #15413) [Link]

It doesn't address the misbehavior you raise, but I just use youtube from android firefox with the extension to lie to youtube about whether it's visible. Even if they somehow found a way to "fix" that, I'd still interact with youtube this way, because youtube ads have gotten incredibly awful.

Android 13 released

Posted Aug 19, 2022 17:30 UTC (Fri) by immibis (subscriber, #105511) [Link] (3 responses)

Who remembers when the Internet was all abuzz with "I wish I could just pay a small amount per month to disable ads" and then YouTube let you actually do it, and then we didn't?

Android 13 released

Posted Aug 20, 2022 20:47 UTC (Sat) by NAR (subscriber, #1313) [Link]

I did. The government here bought a lot of (negative) ads that were played before the cartoons my kids were watching. This was the only way I could stop these ads on the smart TV.

Android 13 released

Posted Aug 20, 2022 23:12 UTC (Sat) by neilbrown (subscriber, #359) [Link]

Youtube isn't the only source of ads.
If I could pay a small amount per month and it would block ALL ads (or at least 90%), then that would be a very attractive proposition.

Android 13 released

Posted Aug 27, 2022 15:16 UTC (Sat) by flussence (guest, #85566) [Link]

Nobody paid the ransom because that sentiment was entirely manufactured in the first place.

Android 13 released

Posted Aug 26, 2022 3:13 UTC (Fri) by sammythesnake (guest, #17693) [Link]

I just recently installed NewPipe for exactly this use case. It doesn't support being logged in to YouTube for my history and channel subscriptions, but other than that it's a near perfect stand-in for everything I want from YouTube on my phone.

The added features include that the developers "forgot to implement" the adverts part of the interface, let me background (or PIP) videos, and provide an in-app download button in case I want to save it for offline viewing (there's an audio only option, too, which I also use for music or other stuff I might want to listen to multiple times)

Not being asked for the fifth time this week if I want to pay for premium is a nice side benefit, too :-P


Copyright © 2022, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds