Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
> And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
> The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use.
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
Yeah, compared to separate hardware HSMs mobile banking is a massive downgrade in both security as well as user being in control of the hardware they own (by forcing locked down closer source OS & forcing hardware updates).
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.
jjice · · focus · HN ↗
pritambaral · · focus · HN ↗
trinsic2 · · focus · HN ↗
McDyver · · focus · HN ↗
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
ragequittah · · focus · HN ↗
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
g-b-r · · focus · HN ↗
That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.
JumpCrisscross · · focus · HN ↗
To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking.
g-b-r · · focus · HN ↗
The move to apps made things more difficult, if anything
JumpCrisscross · · focus · HN ↗
g-b-r · · focus · HN ↗
And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.
tpxl · · focus · HN ↗
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
landgenoot · · focus · HN ↗
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
m4rtink · · focus · HN ↗
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.