this post was submitted on 05 Nov 2024
138 points (99.3% liked)

Android

17681 readers
40 users here now

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: [email protected]


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it's in violation of the rules.


Support, technical, or app related questions belong in: [email protected]

For fresh communities, lemmy apps, and instance updates: [email protected]

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to [email protected].

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to [email protected].

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it's not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website's name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don't post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities

Lemmy App List

Chat and More


founded 1 year ago
MODERATORS
 

(Rant)

At somepoint, HSBC decided KDE Connect installed via F-Droid is less secure.

Photo of the HSBC UK app urging I install KDE Connect via GPlay or Galaxy Store

Then it decide non-whitelisted keyborads are a security risk. Only Gboard and Samsung Keyboard is confirmed within the whitelist.

Photo of the HSBC UK app telling me to switch input method citing security risk


I understand the point that risk can be introduce at various points, yet this is simply too much. Yeah there are people phone infected by malware but from Play Store. Not a single time I heard one ever happened on F-Droid distributed apps, at least not from the official repo. Also, I will put more trust on an open source keyboard than any proprietary keyboard.

Furthermore, I'm shocked that an app can read my app list, and current keyboard (introduced in Android 14). This just make building a profile much easier as I belive everyone almost have an unique set of apps they like. I don't think any apps need such functionality. Why the f it needs to care what input devices I uses? This make me worry more about untold (aka burried deep in Privacy Policy) data collection.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 18 points 1 week ago (2 children)

how the fuck do they see that you have these apps?? Wasn't it google's justification for destroying /proc and all resource monitor apps with it that they have put querying of installed apps behind a permission?

[–] [email protected] 7 points 1 week ago (1 children)

I saw a bank in my country requiring to have the permission for apps usage, the one that you have to go in settings and toggle it. Refuse and it closes the app

[–] [email protected] 5 points 1 week ago (1 children)

Perhaps you could report it to Google Play for that?

[–] [email protected] 6 points 1 week ago* (last edited 1 week ago)

Google enforces rules only against small devs. Big companies are allowed to do what the fuck they want.

Example with one of those "ad viewing apps disguised as games", every single screenshot is misleading, showing a different game to what actually will be downloaded. It's clearly a violation of Google Play terms that read:

Screenshots must demonstrate the actual in-app or in-game experience, focusing on the core features and content so users can anticipate what the app or game experience will be like. Use captured footage of the app or game itself.

In the example not a single screenshot demonstrate the actual game experience.

Google sees the big cash influx from ad impressions and IAP from whales and is closing all the eyes

Tencent and Alibaba instead are still allowed to illegally fingerprint and track the user by placing tracking data in /Pictures/.gs_fs0 which for some reason they can access even without storage/photo permission

[–] [email protected] 3 points 1 week ago (1 children)

So /proc is virtual so it is only processes and not apps.

The app probably requires a permission that grants it access to that information.

[–] [email protected] 1 points 1 week ago

all apps have their own processes, and the names of the processes were often the package name