Android 4.2 Promotes Piracy? - Nexus 7 General

4.2 multi-user function does not allow apps to be shared between users on the same device. (An app can share the same storage space, but you'd still need to pay for separate copies for each user.)
I'll use OmniWrench's comment on ArsTechnica in lieu of my own argument:
"I ask this as someone who codes for a living - Do you really think families sharing a single device are going to buy multiple copies of the same app? How realistic an expectation is that? Allowing sharing of paid apps on a single device seems like a raw deal for devs certainly, but realistically how many people would actually buy the same thing 2 or more times on the same device?
...
"The consequence of this approach is that my wife will not use my android devices under her account, she'll just occasionally do some stuff "as me", so she won't "feel at home" with the device or android, and hence, won't be as likely to purchase her own device (or apps) down the road."
A counter-argument presented is that Android apps are cheap vs PC apps, so app-sharing isn't needed. But this faceplants upon closer examination. An Android app isn't the functional equivalent of a PC app. A mobile game doesn't have the same content as a PC game. There are also various money-making mechanisms (IAPs) being employed in mobile games that aren't in PC games. But the bottom line is per OmniWrench's above: It's not realistic to expect people to pay for multiple copies of the same app on the same device, no matter what the cost is. People will just use a single account, or they will resort to warez.
This segues into the piracy issue. We all know that apps piracy is rampant on Android, and it's a major detractor for developing the eco. Devs won't play if they can't make money. My feeling is that 4.2 will promote more piracy, by pushing erstwhile legit users to resort to the warez route to make multi-user work per their expectations, ie with app-sharing. It's a slippery slope: Once people make the decision to use warez for certain situations, the natural inclination is that they'll use warez for other situations as well.
Please participate in the poll above, and voice your opinions.

Wow... this really grosses me out. I don't share my phone, but I certainly expected to share my Nexus 7 tablet (with wife and three kids). I don't want any of them in my email or other communication apps, but I'm happy to let them use anything else. I'd really looked forward to easy, one-click, secure sharing of my tablet. But on reading this, I think that I'll just continue to use App Protector to lock down Gmail, etc. The bum thing is that I also have to lock down Chrome, because the bugger either logs users into mail.google.com automatically or offers to do so. Thus, I can't let family members use Chrome at all on my tablet (although Dolphin is a fine substitute).

The adding a second user feature is something that I will never even try.

--
I go through enough gadgets that my wife and kids end up with their own tablets = "I do not share my (latest) toys" .

No it does not, it enables multiple users to use their own apps on the same tablet. Turning one tablet into four different ones.
What people seem to be confusing this with is a "kid's mode", where a different user is allowed limited access to another user's apps.
Either way Google was damned if they did/ damned if they didn't. They let everyone have access to paid apps they tick off devs, they don't they tick off some users.

It is quite a poorly developed idea.
My nexus is a family tablet, with a shared Gmail account.
I was hoping to put on my own Gmail account as a new user to migrate & amalgamate the two accounts' purchases.
No dice.

Concerned Android User.
I knew this was coming in some form or another.The whole thing is whats the right solution..
I actually thought Google would end up putting some type of device id tag in each app. This would allow it to run only on the device it was purchases for. But of course as much as we change devices and buy new ones. This would be very flawed.
Then there is the Each app linked to one google account. The app can then only be installed on a device using that Google account and only on one device at a time.. Well CO-PILOT tried this.. It failed miserably because of the Administration overhead when users switched or upgraded devices.(I was frustrated beyond belief).
I know its different but with windows Apps and programs for the most part are based on cpu id .. well product key generated from that and coa key. To install on that S pacific pc only.
So what would be Fair to everyone. Especially the Developers.. That is what this is all about. fair to developers and still works for users..
My opinion.. Some apps like simple games email type apps and so on are not so personal and should be allowed to carry on as they are.. But i do see how the apps like high end games and work processors apps. Should be maybe Tied to a Device not so much a Google account.. Well rephrase that
They should be somehow tied to a Google account but allowed to Run on One Device at a time.Any user on that device. Maybe pay a small fee per device above its primary device..
We will all have to give some on this Subject to keep app development moving to better app quality . Keeping developers and users Somewhat happy.. But there is not a solution to Keep this fair for both...
I am willing to pay a slight extra amount to use Really good apps on multiple devices. But only apps that truely make my life easier. Well more fun with some of the games.(thou im not big with games )
Sorry this is such a long winded post . There is change in the air.. Someone should start a true real discussion about this. Get Google and app developers involved . Before Google just decides for us.. We will loose on both ends if they do Developers and users..
PIRACY IS NOT A ANSWER TO THE PROBLEM....
you can get around this.. Setup your google account on the second user . Install the apps.. Then remove the account. Should work..
Work around ... Add the second account for this test ..
Primary account is Erica .
second account Erica Renee
I installed my google account to the erica renee user account. Open play store.. go to your apps .They will show as if they are not purchased . EXIT play store. REBOOT THE TABLET. log back into the second account and then you will see apps purchased .. You can install the paid apps..
Exit back to home screen. Go into setting and accounts Open the google account and delete it.. The paid apps from the first account will Be there still and usable.
The app i used to try this was Sketchbook Pro.. So this is not that big of a deal . My huge post above i still agree i would pay a small extra amount to use apps on multi devices. If the apps were worth it..

The only thing I thought about using a second user account is for my 3yr old, since she figured out how to exit out of Kid Mode (I swear this kid is more tech savy than most adults I know)

Problem is, one size does not fit all.
I can certainly see how highly personalized apps, such as games, should warrant a re-purchase of the game. Maybe that's just the developer in me talking, but when you look like online games like SC2, Diablo3 ... you can borrow the "device" to someone, and they could play it, under your account, but it's not the same experience, and neither is it legal under EULas for these games.
However, it is also clear to me that purchasing, for example, a widget (such as HD widgets) should really be tied to device. I made a second account for my wife, and while I appreciate that we can now have different account for Words With Friends, I will not be rebuying HD widgets, so my wife's account loses that ability.
And there are gray areas. Does VPlayer warrant a re-purchase? I don't know. But I can name many very expensive desktop applications that I have used for decades now, sharing them with my family, under the same device - Office, Photoshop, every single single player game.... this is where the confusion comes from. people are just not used to this re-purchase model, and for good reason!

kangy said:
The only thing I thought about using a second user account is for my 3yr old, since she figured out how to exit out of Kid Mode (I swear this kid is more tech savy than most adults I know)
Click to expand...
Click to collapse
Ha! Our 3 year old has figured out the same thing on the phone. He figured out some combination of the right app, going to landscape and back and the brief appearance of the menu bar which gets him to the desktop. We're still not totally sure how he manages it because the sneaky little monster will only do it when we're not looking. No joke.
I was hoping the multi user mode would have allowed me to set up a profile with just the few apps I'll let him play with (he is great at Cut the Rope, Bad Piggies, and all the angry birds).

Google really didn't think about this too deeply. The lead account should be the administrator of the device and when installing an app should be allowed to choose to install "Just for you" / "All users" / "Specific users".. etc etc..
It seems like a really half baked idea especially with the shifting folder tree for user accounts.. Seriously who thought of that idea? It's beyond stupid. Linux has the most simple and effective user and group management and it seems Google tried reinventing the wheel by making it square.

styckx said:
Google really didn't think about this too deeply. The lead account should be the administrator of the device and when installing an app should be allowed to choose to install "Just for you" / "All users" / "Specific users".. etc etc..
It seems like a really half baked idea especially with the shifting folder tree for user accounts.. Seriously who thought of that idea? It's beyond stupid. Linux has the most simple and effective user and group management and it seems Google tried reinventing the wheel by making it square.
Click to expand...
Click to collapse
Its more flat then square.. .
I totally agree with the deciding on What user to install for.. As well there should be settings in the admin account as to what type of apps a user can install. how much disk space they can use.. To really make it usable for what most in here want.. Limit time constraints and so on .
Im sure they will Build more into it as they go.. The way windows does multi user is awesome..
/user
/user/ erica
/user/ erica renee
/user/ guest
I have my /user /erica located on a second partition.. So if i wipe windows no worry about any data because now games email and everything uses the user account for the most part..
Something similar would be awesome..

Poll does not cover my use case.
My daughter can download free games on her ID. She can use my ID if she needs something I purchased.
Bringing up piracy in the context of multi-user is just stupid - people into stealing will and the rest of us won't.
Multiuser has nothing to do with it.
Current Google PlayStore works fine for me. I can download a paid app onto any device I register on my account.
Greedy developers who want more money out of me - can just go find a different customer. I won't buy their product.
I say that as a developer.

SoonerLater said:
Thus, I can't let family members use Chrome at all on my tablet (although Dolphin is a fine substitute).
Click to expand...
Click to collapse
Lol, as if that's a bad thing. Chrome is horrendous. I also think having played apps only work on one user is stupid as well.
Sent from my Nexus 7 using xda premium

I have a solution, though I'm not sure whether it's legal or not.
As you can still add multiple Google-accounts to a user, it's not really a problem, just can just add your google account to the other users,disable sync, switch to your account it in the Play Store, install the apps you want(it's just a matter of seconds,no second download needed)..problem solved.
As for your Kids, delete your Google-Account from their account after installing, the apps should still be available.
Worked for me.

I find myself agreeing with many of the sentiments voiced thus far.
I agree that this is part of Android's maturity process as it grows out of its phone roots. For phones, a per-user license model is the natural choice, as device-sharing isn't common. But once device-sharing is needed, this model breaks, and needs modification.
While there are various workarounds available as mentioned, I think there needs to be an official solution, if only for ease-of-use alone. Normal users shouldn't be expected to jump through hoops for a functionality as basic as sharing a device between family members.
For the short term, I think a restricted-mode (aka kid's mode) for the primary account would be very useful for a family device, more useful than the current fully-segregated acct scheme. This avoids any app-sharing abuse, as the restricted mode can't be used as an independent account.
For the long term, I think a more granular licensing scheme is needed for apps. Example: For a $5 app, an "auxiliary" license (say $1) may be offered for a separate account on the same device. This allows the dev to still make some money, but not large enough to push users to avoid paying the cost of a full second license.
I don't think a per-device scheme would be advisable, as it would get confusing and complicated when mixed in with per-user apps. The more complications to paying, the more people will opt for the easy way out, which is warez.
Speaking of piracy, yes, there will alway be people who pirate no matter what. But the facts are that piracy is a major problem for Android, because it is so damn easy and convenient for people to find pirated apps. The more hassle it is for users to pay for what they want, the more people will pirate. Think of it as a convenience function.
It's also a function of user expectation. As some said, we are used to the PC's per-device licensing model for family devices, and paying multiple times for the same thing on the same device just seems wrong, no matter how you couch the argument. I think users can be weaned away from this to the per-user model, but only gradually, and with carrots to lead the way. Doing an abrupt about-face like the current multiuser implementation would only antagonize the user, and be a recipe for increased piracy. Look no further than the music and movie markets for a taster of the draconian approach.

I consider it to be the same thing as two different devices. My solution there? The official Google one. I add my Google account to the Play Store so when I buy something, my wife can use her tablet, go into the store, switch to my account and install it. I'm in the same boat as one of the previous folks said and upgrade often so I don't anticipate having to worry about the multi user deal. I'd actually rather see the ability to add other accounts that aren't tied to a google account for more of a work / fun separation.

My experience is different.
I have separate Google account for buying app, email, and even contacts.
So, I can still share my purchased apps with multi user setup.
On my main account, I setup in the following order:
- google account for buying app
- then add my Gmail account
On second user:
- my wife Gmail account
- then add the Google account for buying app
And I have no problem installing my purchased apps on both users.
Note that I always buy apps, I don't pirate. Even app as expensive as TomTom.
The thing is... I want to share with my family members. Those are my families, we share a house, television, Nintendo Wii, etc.
I share a desktop computer pc with all the apps.
I always do that, and I don't think that's wrong.
And I don't want to change that.
That should be the way multi user setup in a single device.
If I have to buy multiple copies of app, then that's just greedy, and not practical.
Sent from my Nexus 7 using xda premium
---------- Post added at 10:24 PM ---------- Previous post was at 10:14 PM ----------
I don't think I can agree with calling apps sharing an "abuse" and wrong.
I meant, if I have a tablet with an app there, I am may not give it to my wife or kids to play with it? Just because I bought only one license?
"Sorry kid, this is daddy's toy. You may not play this game, daddy only bought one license"
So for that, I must hide the tablet?
That's absurd.
I have never thought like that ever.
e.mote said:
I find myself agreeing with many of the sentiments voiced thus far.
I agree that this is part of Android's maturity process as it grows out of its phone roots. For phones, a per-user license model is the natural choice, as device-sharing isn't common. But once device-sharing is needed, this model breaks, and needs modification.
While there are various workarounds available as mentioned, I think there needs to be an official solution, if only for ease-of-use alone. Normal users shouldn't be expected to jump through hoops for a functionality as basic as sharing a device between family members.
For the short term, I think a restricted-mode (aka kid's mode) for the primary account would be very useful for a family device, more useful than the current fully-segregated acct scheme. This avoids any app-sharing abuse, as the restricted mode can't be used as an independent account.
For the long term, I think a more granular licensing scheme is needed for apps. Example: For a $5 app, an "auxiliary" license (say $1) may be offered for a separate account on the same device. This allows the dev to still make some money, but not large enough to push users to avoid paying the cost of a full second license.
I don't think a per-device scheme would be advisable, as it would get confusing and complicated when mixed in with per-user apps. The more complications to paying, the more people will opt for the easy way out, which is warez.
Speaking of piracy, yes, there will alway be people who pirate no matter what. But the facts are that piracy is a major problem for Android, because it is so damn easy and convenient for people to find pirated apps. The more hassle it is for users to pay for what they want, the more people will pirate. Think of it as a convenience function.
It's also a function of user expectation. As some said, we are used to the PC's per-device licensing model for family devices, and paying multiple times for the same thing on the same device just seems wrong, no matter how you couch the argument. I think users can be weaned away from this to the per-user model, but only gradually, and with carrots to lead the way. Doing an abrupt about-face like the current multiuser implementation would only antagonize the user, and be a recipe for increased piracy. Look no further than the music and movie markets for a taster of the draconian approach.
Click to expand...
Click to collapse
Sent from my Nexus 7 using xda premium

Perhaps it could be something set at the app level by developers. If a developer doesn't mind his app being used by multiple users on a device then he can allow it in the app itself. However there will also need to be some way of managing this, perhaps via another option on the play store. a simple check box with "make this app available to other users of this device" would be more than enough, and it's either visible only on apps which allow it, or it's greyed out on apps that disallow it with an explanation why.
Devs could then offer single user and multiuser apps for additional cost.

adfad666 said:
Perhaps it could be something set at the app level by developers. If a developer doesn't mind his app being used by multiple users on a device then he can allow it in the app itself. However there will also need to be some way of managing this, perhaps via another option on the play store. a simple check box with "make this app available to other users of this device" would be more than enough, and it's either visible only on apps which allow it, or it's greyed out on apps that disallow it with an explanation why.
Devs could then offer single user and multiuser apps for additional cost.
Click to expand...
Click to collapse
I would agree with this . But i think the best solution is to somehow bind each user to your google app account. And have the app limited to run on say 3-5 devices Only.. As to where you can remove a device when you retire it. Get a new one you can install your apps. Of course some type of device validation. Google has that now with wallet . As far the above with multi user a device. There needs to be in the app manager a way to make this app available for all users.. FIXES Both issues.
Great Replies everyone.. I am so glad to see this thread civil. they usually are not so much

Related

Petition to rid the market if Khalid Shaikh's apps!

I browse the market every day and I see this guy putting apps that consistently get low reviews. His highest ranking app is 3 stars. He spams the market with apps that are overpriced photo galleries that show pics and play sounds of one specific thing. I think we should help him get the message that his high refund/low ranking rates are not giving him. Please reply if you agree that his apps need to stop spamming the market. If you have not tried one yet, look here. I am not doing this to be mean, but he needs to be told not to quit his day job.
Where's the option for "No. I dislike spam apps, but I hate censorship more." ?
So if his apps were malicious would you vote to have them removed? Do you feel spam filters on email are censorship? They fill your box with junk in hopes of making a few dollars off of you. I am against censorship but his apps are rediculous.
So if his apps were malicious would you vote to have them removed?
Click to expand...
Click to collapse
There are rules in place for the Market in regards to malicious apps. There would be no need to vote because the gatekeepers of the Market have already said malicious apps would be removed.
Do you feel spam filters on email are censorship?
Click to expand...
Click to collapse
Of course not. The key difference is who gets to decide what is removed. With a spam filter, each user gets to decide whether he wants to see content or not. Any system that removes apps from the Market (that aren't infringing the basic rules as stated above) without your knowledge and consent is basically censorship, whether the decision is made by ten people at Google or a hundred people on xda-dev.
Not if your email provider passes your email through spamhaus you dont. Also I would ****LOVE**** to have a configureable filter but I doubt we will. As an acceptable alternative, I would like for consistantly low rated and highly returned items to be removed. Guess what walmart does if a product gets returned 80% of the time it is sold. Do they ask you?
Also, I am not trying to start a fight with anyone, just stating my view on the subject.
Darkrift said:
Also, I am not trying to start a fight with anyone, just stating my view on the subject.
Click to expand...
Click to collapse
I don't care to start a fight either; I'm just pointing out that what you are proposing is a path down a slippery slope, and it generally goes against the "open participation" ethos of Android. You should also keep in mind that one person's junk may be another mans treasure. Would I ever buy one of Khalid's lame $5 joke apps (literally, they're joke books!)? No probably not. That doesn't mean that someone else might not want it.
Edit: Just as an example, back in the early days of Market before developers could geotarget the regions for distribution, some Chinese developers put up some app whose interface was completely Chinese. I think it was a Chinese input method or a frontend for a Chinese website. Regardless, the ignorant fresh T-Mobile masses downloaded it, didn't understand what it was for, and then promptly uninstalled it and rated it zero stars. If you do a filtering system based on ratings, you are giving every uninformed ignoramus an equal say in whether an app is allowed to stay or go.
The Markets sucks! It needs the possibility for user to set their own filter
e.g.
dont show apps publiced by Khalid Shaikh! lower than 2stars, more expensive than x$ and so on..
only show apps of a specifig language (e.g. for traffic,taxi,bus,tv gadgets..)
sort for recently updated and so on .. that's what the market app really needs!
bassbox said:
The Markets sucks! It needs the possibility for user to set their own filter
e.g.
dont show apps publiced by Khalid Shaikh! lower than 2stars, more expensive than x$ and so on..
only show apps of a specifig language (e.g. for traffic,taxi,bus,tv gadgets..)
sort for recently updated and so on .. that's what the market app really needs!
Click to expand...
Click to collapse
Yes, the market app needs customizable local (meaning on a user's own device) filters. That will partially solve the problem of crap apps littering the marketplace. However, I think overhauling Market client is low on the Google Android team's priority list. Unfortunately since it is a proprietary closed source app, there is no way for the dev community to take the matter into its own hands.
You would think that the king of searching would have some sort of decent searching on their own platform..
jashsu said:
Yes, the market app needs customizable local (meaning on a user's own device) filters. That will partially solve the problem of crap apps littering the marketplace. However, I think overhauling Market client is low on the Google Android team's priority list. Unfortunately since it is a proprietary closed source app, there is no way for the dev community to take the matter into its own hands.
Click to expand...
Click to collapse
I am planning on developing an interface to the Market which allows for custom filters. I have a prototype Yahoo Pipe, which uses Cyrket to display Market data and allow simple filters. Basically, I can filter out apps that have certain words in the title, are from a certain developer (or more than one), or are below a certain rating threshold.
I will have to agree though on the statement about censorship. While it is true that his apps may be without any true merit, I do not believe that they are (or he is) breaking any of the Market rules or developer agreements. Unfortunately, as we've seen in the the "free" market and the iPhone AppStore, people are willing to download and even spend money on useless apps. I think as long as there is a market for this type of app we will continue to see them. Now, unfortunately that means we all have to deal with him, his apps, and others like him and his apps until either the Market allows for better filtering/sorting or a developer creates this for the community... It is much needed nonetheless.
nEx.Software said:
I am planning on developing an interface to the Market which allows for custom filters. I have a prototype Yahoo Pipe, which uses Cyrket to display Market data and allow simple filters. Basically, I can filter out apps that have certain words in the title, are from a certain developer (or more than one), or are below a certain rating threshold.
Click to expand...
Click to collapse
thats awesome. if its anything like BarTor its going to be good
nEx.Software said:
I am planning on developing an interface to the Market which allows for custom filters. I have a prototype Yahoo Pipe, which uses Cyrket to display Market data and allow simple filters. Basically, I can filter out apps that have certain words in the title, are from a certain developer (or more than one), or are below a certain rating threshold.
Click to expand...
Click to collapse
That's good to hear. What I meant is that the actual Market App itself cannot be modified to work the way we want it to. While being able to display Market data with filtering on a PC is nice, the bulk majority of users are still going to be suffering the standard Market app interface.
Unfortunately, as we've seen in the the "free" market and the iPhone AppStore, people are willing to download and even spend money on useless apps. I think as long as there is a market for this type of app we will continue to see them. Now, unfortunately that means we all have to deal with him, his apps, and others like him
Click to expand...
Click to collapse
There will be more, that much I can assure you. As the Android platform grows, there will be more opportunist developers seeking to make a quick buck. It really is like spam. You throw a line out and because digital publishing is free, anything you get back is profit. There is basically no monetary risk involved in creating and distributing crapware. Atleast we won't have to suffer iPhone's idiotic ninety-nine cent "custom" name dialers. Although the number of soundboards posted daily is reaching dangerous limits...
I intend to make it an Android app. While it won't be a permanent fix,it might be what is needed to get Google moving on updates to the official Market app.
Anyway, on another note. I haven't looked at any one of the apps in question but I would venture a guess that they are in violation of copyright laws and as we have seen with the Tetris clones, Google does take action on matters of copyright. Maybe the best recourse then is to inform this developer of the copyright issues either directly or through Google.
?
Frankly i can't agree with having a dev (does this word really apply in this case) removed from the market for producing crap. However i am completely in favour of spamming his inbox with as much crap as i can possibly manage just to see how he likes it. Free porn search here i come!
Anyone wants to help it's --EMAIL REMOVED-- Yes this is a very childish response but i'm pissed with having to sift through his crap every morning, i think it's only fair!
Ideally google can resolve this issue by allowing to create a list of blocked developers. And the ability to block any apps containing the word soundboard would make my day
nEx.Software an app that was basically cryket.com for the android would be awesome. What would really be sweet was if it had an independant comment system that was filterable as well. So we could ban commenters based on their username, words, etc... Filtering by ratings, developer, keywords, etc.. I love it already. Just link the products to their entries in the market. Basically, cryket for the android with comments... I CAN HAZ IT NOW PLZ K?
Also, I'd love to add IndiaNIC, LLC to the filter list. I'm sure *someone* out there likes that they're putting out 300 e-books about India a day, but I'm sure tired of scrolling past them.
The last thing I'd want is to see rigorous policing on the Android Market. He's spreading expensive crapware but I'm sure people are buying it and I'm sure some actually enjoyed it. I don't think removing his apps from the market is the best solution, keep the market as free from censorship as possible if you ask me.
I think the best solution is market search filters as discussed above.
I agree, the ability to "ignore" certain developers would be nice. The new developer I would instantly add to this list would be IndiaNIC, LLC. or whatever the hell they are called. They have about 40 apps on the market, and I don't think a single one has a comment.
/if anyone affiliated with IndiaNIC, LLC reads this, no offense, but please get the message when nobody is buying what you're selling
The more I think about it, the more I realize a filter would be a better idea than removing junk from the market. While I do not agree that anyone will find his apps useful, I do see the point in letting them choose. But at the same time we should be able to choose not to see his crap. As for IndiaNIC, I disagree with placing them in the same category. They have products with good ratings and seem to be making at least SOME useful apps. While I agree they put out too many at once, they seem to have a market for their apps unlike Khalid Shaikh.
Still, a filter would be better for all. I wish I could edit the poll now to add that as an option
ryan75 said:
/if anyone affiliated with IndiaNIC, LLC reads this, no offense, but please get the message when nobody is buying what you're selling
Click to expand...
Click to collapse
Spammers don't need to "get the message"! They know exactly what they are selling (junk). The whole point is they are trying to make a quick buck. And in the immortal words of P.T. Barnum: "There's a sucker born every minute."
Nevermind the fact that all of those texts can be downloaded for free from manybooks or feedbooks and then read on FBReaderJ...

[Q] [CM7] Security Issues (Viruses, Passwords, Network, Privacy)

I'm just getting started with CM7 and the Nook Color, but I have some general security concerns that perhaps you could help me with?
1. Viruses. I understand that these are real in Android. I've temporarily disabled non-Market apps, but I believe viruses and/or spyware have shown up in Market Apps too. Are there decent AntiVirus apps and what do you recommend?
2. Firewall. What services are open by default? Are there good software firewalls available?
3. Adware. Is it always clear which Market apps are ad-supported? Have apps crossed the line into malicious or near-malicious spyware? (Taking over browsers, redirecting home pages or searches, infecting other apps, etc.)
4. Apparently Google does not require password-confirmation for Market purchases, and no real solution exists, since available apps complicate things and don't address the root issue. Do they have any plans to change that?
5. Where are application and web site passwords, WiFi keys, and the like stored, and are they encrypted?
6. Is there a multi-user / multi-profile facility to allow different users to log in to different desktops and/or applications? (Or is that best accomplished with dual booting.)
7. What major applications are known to "phone home" or otherwise divulge more information than might be expected? I was quite surprised that CM7 itself phones home to CyanogenMod by default, and even with that turned off the ROM Manager still reports usage statistics to Google?
8. Is anyone independently reviewing CyanogenMod itself for privacy and security implications? Right now many of us are relying on a hodgepodge of hacker contributions and the good will of those creating them. I'm sure that anything malicious would eventually come to light, but is anyone proactively checking out the release CM7 distribution, the GApps distribution, and the various installers and packagers? Right now the only verifiable "web of trust" that seems to exist is the good intentions of every contributor, and the general availability of the source code (which should make the review possible, if not particularly easy!).
9. Are there any "best practices" as a user? For example, I've set up a new GMail ID for use with the NC, and haven't yet linked any credit card or payment data. Meanwhile, for the B&N side I've had to submit a credit card number to get access to their market (even to get their "Free" offerings).
10. Any implications for configuring e-mail and/or contacts, etc.? Mass remailing trojans certainly exist on the Windows side.
11. Do the application specific permission settings compare favorably to those of the BlackBerry, and are they easily adjustable after you've already granted permissions to an app?
12. Is there any concept of sandboxing a new app to prevent it from possibly adversely affecting other applications or files?
13. Is there a best practice for how to manage files on both the eMMC and SD card storage, particularly when booting between the two? Can one be locked out from the other?
Okay, that's a baker's dozen. I'll stop now.
Thanks much for any input.
Really? Nobody has an opinion to share on this?
rooting /cm7 / and the purpose behind it may just not be for you. I don't think your going to get an answer your looking for. Also not trying to be rude, but you pretty much wrote a book in your first post. Just ask a question dude.
Thanks for the response, but I asked roughly 13 questions -- would you prefer I "just asked a question" by starting 13 different threads? I certainly wouldn't.
And your first sentence makes it sound as if there's no one here who gives a damn about their own data and that everyone views the Nook Color as a toy -- and I seriously doubt that.
xdabr said:
I'm just getting started with CM7 and the Nook Color, but I have some general security concerns that perhaps you could help me with?
1. Viruses. I understand that these are real in Android. I've temporarily disabled non-Market apps, but I believe viruses and/or spyware have shown up in Market Apps too. Are there decent AntiVirus apps and what do you recommend?
2. Firewall. What services are open by default? Are there good software firewalls available?
3. Adware. Is it always clear which Market apps are ad-supported? Have apps crossed the line into malicious or near-malicious spyware? (Taking over browsers, redirecting home pages or searches, infecting other apps, etc.)
4. Apparently Google does not require password-confirmation for Market purchases, and no real solution exists, since available apps complicate things and don't address the root issue. Do they have any plans to change that?
5. Where are application and web site passwords, WiFi keys, and the like stored, and are they encrypted?
6. Is there a multi-user / multi-profile facility to allow different users to log in to different desktops and/or applications? (Or is that best accomplished with dual booting.)
7. What major applications are known to "phone home" or otherwise divulge more information than might be expected? I was quite surprised that CM7 itself phones home to CyanogenMod by default, and even with that turned off the ROM Manager still reports usage statistics to Google?
8. Is anyone independently reviewing CyanogenMod itself for privacy and security implications? Right now many of us are relying on a hodgepodge of hacker contributions and the good will of those creating them. I'm sure that anything malicious would eventually come to light, but is anyone proactively checking out the release CM7 distribution, the GApps distribution, and the various installers and packagers? Right now the only verifiable "web of trust" that seems to exist is the good intentions of every contributor, and the general availability of the source code (which should make the review possible, if not particularly easy!).
9. Are there any "best practices" as a user? For example, I've set up a new GMail ID for use with the NC, and haven't yet linked any credit card or payment data. Meanwhile, for the B&N side I've had to submit a credit card number to get access to their market (even to get their "Free" offerings).
10. Any implications for configuring e-mail and/or contacts, etc.? Mass remailing trojans certainly exist on the Windows side.
11. Do the application specific permission settings compare favorably to those of the BlackBerry, and are they easily adjustable after you've already granted permissions to an app?
12. Is there any concept of sandboxing a new app to prevent it from possibly adversely affecting other applications or files?
13. Is there a best practice for how to manage files on both the eMMC and SD card storage, particularly when booting between the two? Can one be locked out from the other?
Okay, that's a baker's dozen. I'll stop now.
Thanks much for any input.
Click to expand...
Click to collapse
I have to admit, you come off as rather paranoid, and i am not sure why you are so.
Yes, there have been a couple of problem apps recently, but Google took care of them, and i would not worry. The best security you can have, is looking at what you are installing. The application cannot hide what permissions it needs, so if you have something asking for way more than you think it should need, take that as your first red flag.
Currently, Virus Scans on Android are a joke, and simply unneeded. Don't even waste you time. Firewalls are just about the same, and again, not worth the effort. One thing to keep in mind, that this is a linux system, and is not as prone to the Windows based attacks that you are used to. Things like email spam bots and such are not a problem.
As for Cyannogen - no code is added to the repository without being peer reviewed; and every code submission is available in public records. Frankly, they did not make it to CM7 by stealing people's data, nor is it simply a hodge podge of devs.
Frankly, I think right now more research is in order for ya. Most of what you ask is already discussed in many places, or is never discussed, because it simply isn't a worry...
Thank you, Divine_Madcat, for the advice and explanation. By hodgepodge I was more referring to the multiple installer methods and packages that newbies like me are relying upon to get everything installed easily. There are a lot of them, from a lot of nice people, from preconfigured SD card images to installation methods with modified boot loaders to interface and performance hacks. Even if Cyanogen itself is well maintained it would be pretty easy for someone to include a little trojan in one of those third-party "distributions".
It's not exactly paranoia, I've just seen this happen so often. Trojan horses are certainly not limited to Windows. Worms and other compromises have affected thousands of Unix and Linux machines in the past. Web sites and PHP and Perl scripts and databases and web frameworks regularly see vulnerabilities discovered and/or exploited. So since this device will be used in part by children with access to my credit card, I wanted to know what we're dealing with.
No, I was not familiar with Cyanogen's review practice (which is one reason I asked), so thanks for that reassurance! I will try to learn more as I go.
I do apologize for the length of the OP though -- I was trying to brainstorm and get everything down in one place that related to possible security concerns. It's not as if I'm worried sick about every little point.
One of the apps I install on all my installs is 'Lookout'. This app scans all my programs I install and update and I have heard very good reviews of it.
I did see that Eric Lundcrest did an article today:
http://web.eweek.com/t?r=2&c=38783&l=64&ctl=11B38843F5D4C728CF30E9F23F9E91BB51617&
You can check them out. I haven't tried them all myself and I noticed that he didn't include the app that I recommended above (and I use it on both my Nook and my HTC EVO)
You Should Also be Aware..
that one of the joys of Android (and of course Unix/Linux) is that everything is "sandboxed" unlike Windoze - there are not many apps that interfere with others - that's why it's so easy to install and uninstall from Android. Compare the uninstalling of even a large Android app with that of uninstalling from Windows.
I would not worry about interfering apps
Thanks, doc. I'm moderately familiar with the Unix security model, but not so much with Android. Is sandboxing really accurate? In Linux processes run with particular user rights, much as in Windows but more flexible -- that is, it's just much more common to have different daemons running as different users. Still, I don't think they're really isolated from one another as they might be with a "chroot jails" kind of function...
I don't think electronics are for you, I suggest books and a cabin in the woods.
No virus really exist yet, a few flaws in the code have been found but they are patched quick.
No real firewall, doesn't work quit that way with android.
Yes, it will say in the permissions of the app in the market.
You sign into the market when you first use it, making sure your devise has a lockscreen PW is how you keep it safe.
/data
no
Some apps phone home, check permissions before you install.
All CM code can be seen in the github, you can compile it yourself if you wish.
Use smart internet credit card practices such as only attaching a low limit card to accounts etc.
If the google email server was hacked maybe but all that stuff is stored encrypted on googles end.
Permissions need to be approved of by you if they change.
Android sandboxes all apps.
Dono, I have CM7 on internal and books etc stored on the SD card.
Nanan00, your actual answers were great, but "I don't think electronics are for you, I suggest books and a cabin in the woods." and the similar dismissive post above are exactly the kind of BS condescension that gives some open source communities a bad name. Stop it. Little by little it devalues the entire community and its projects.
Thanks for the substance of your response.
Truthfully... My parents practice pretty much all of the stuff you have said, they're very careful with credit cards and anything that could be used as personal information.
And yet... Someone got ahold of their credit card numbers and bought something for almost 3k last year...
I have no virus software or even firewall software on this computer, it has not received a virus in over 5 years (I know... it needs an upgrade) and I'm running Windows XP SP2.
If you're prone to viruses then go ahead and install some antivirus software. If you're scared about your kids + your credit card + the nook, then have them make all transactions on the computer.
The reason no one is taking this seriously is because Android is to new for there really to be anything worthwhile on the market. People are just now learning how to develop and code for it. So there aren't a bajillion(give or take one or two) viruses or trojans running around the google market.
On top of that, so long as your legally buying your apps from the google market, you have even less to worry about. As google has shown in the past that they'll go ahead and delete it the second they find it.
As far as permissions go, don't get to hung up on it. Everybody trust Pandora and yet it requires more permissions then some of googles own apps. =\
Thank you, Gin1212. I don't use an AntiVirus on my own Windows machines either -- it's more trouble than it's worth when you know what you're doing. (On Android I don't know what I'm doing, yet.)
And yeah, I already made sure to use a disposable credit card number ("ShopSafe") with a limit when setting up the Nook for the young'un. Google Market, thankfully, doesn't require a credit card unless you buy something, so I'll be checking out the free apps for a while (so that's part of why I asked about adware/spyware).
I was approaching the thing as I would any new (to me) full fledged operating system and computer, fully aware it's not the "safe" and dictatorially controlled little world of iOS or, to some extent, BlackBerry OS.
So thanks for the real world advice!
xdabr said:
Nanan00, your actual answers were great, but "I don't think electronics are for you, I suggest books and a cabin in the woods." and the similar dismissive post above are exactly the kind of BS condescension that gives some open source communities a bad name. Stop it. Little by little it devalues the entire community and its projects.
Thanks for the substance of your response.
Click to expand...
Click to collapse
Suffice it to say that Android's and Microsoft's, and even Linux's app model is vastly different. Google does not just act as a repository, as in Linux. From my understanding, Google is rather guarded about it's app market and if anything heretofor is found, the app is yanked from the market immediately.
I agree that website security is more an issue that needs to be looked at, but the lion's share of websites that have virii and adware are aimed at infecting windows machines, but your concerns are noted.
As to the intent of the Devs here, I think you need to understand that these roms, mods and apps are their children, and their passion of the moment. No one goes through all the crap they do just to foment adware. This is their meat and drink and trust me, if there were a dev whose morality came into question, they would police themselves and it would be all here for us to read. There are no secrets here. These aren't script kiddies looking to wreak havoc.
I agree that security is a good thing, but the twin natures of Android are openness and isolation. Each app, at least from my understanding is an island unto itself with rare exception. So I think that while your concerns in themselves are noble, they are unwarranted, and at some points even seem absurd. No offense intended here.
We aren't just drinking the kool-aid here, everyone knows the risks of adopting an unknown and untested ROM, everyone takes the responsibility to themselves when they violate their warranty in search of a better tablet experience. The average person who roots their nook is not your average idiot windows user. We are here because we want more and better than our legacy alientation by microsoft and those who can't think outside of their security model.
Well, there is my Android manifesto. Sorry for rambling.
migrax
No, I appreciate the manifesto -- thanks. Again, I tried to brainstorm and throw the kitchen sink into the original post so as to get everything down in one place. I was hoping it could serve as a general security discussion thread. Not everything there is a huge concern of mine, and sorry if it made things seem absurd.
I appreciate your points about the intentions of the developers and the operation of Google's market (although of course a big selling point is we are NOT limited to that market... conversely, I suppose anything I chose off-market would be something I had by definition come to trust independently).
xdabr said:
Nanan00... "I don't think electronics are for you, I suggest books and a cabin in the woods." and the similar dismissive post above are exactly the kind of BS condescension that gives some open source communities a bad name. Stop it. Little by little it devalues the entire community and its projects.
.
Click to expand...
Click to collapse
I think your overreacting a wee bit too much. I can't speak for Nanan00 but the first sentence of his post feels like a joke. He took the time to write out the answers of OP's question...
Also since you were referring to my post at the top..... I was just being candid with OP.
I read his post, I could see that he was a bit paranoid (IMO) and told him my honest opinion. Which is: Hacking your nook, or any device for that matter, may not be for you. The reasons being that when you hack your device, you inevitably increase its chances of being exposed (even if the increase is small, its there.) I don't feel that I am being arrogant, and I didn't catch that drift from Nanan00. But I wanted to address this since you obviously feel strong that this type of behavior is "devaluing the entire community and its projects."
Anyways to the OP:
Sorry if my post came off rude. I should of taken the time to give you my explanation.
colbur87 said:
I think your overreacting a wee bit too much. I can't speak for Nanan00 but the first sentence of his post feels like a joke. He took the time to write out the answers of OP's question...
Also since you were referring to my post at the top..... I was just being candid with OP.
I read his post, I could see that he was a bit paranoid (IMO) and told him my honest opinion. Which is: Hacking your nook, or any device for that matter, may not be for you. The reasons being that when you hack your device, you inevitably increase its chances of being exposed (even if the increase is small, its there.) I don't feel that I am being arrogant, and I didn't catch that drift from Nanan00. But I wanted to address this since you obviously feel strong that this type of behavior is "devaluing the entire community and its projects."
Anyways to the OP:
Sorry if my post came off rude. I should of taken the time to give you my explanation.
Click to expand...
Click to collapse
Um, colbur87, "OP" and I are the same person.
Asking questions is one way we learn. As an Android newbie many of my questions would apply to any Android device, hacked/rooted or not. If they're not appropriate for this forum, or if no one here thinks they're valid or worth a response, that would be okay. But to say in effect "your concerns are stupid and you don't belong here" is not only insulting, but factually wrong. Just because some people are content to not consider security implications doesn't mean they're not real.
Blithe unquestioning acceptance and faith is more of an Apple iFanboy trait, I would have thought.
And much as with Linux as a whole, positioning "hacked" Android as something not amenable to ordinary consumers is counterproductive.
(By the way, I'm not an ordinary consumer.)
Anyway, I do appreciate the answers people have given.
Wasn't lookig at the names so my bad on the mix up.
Anyways if you still think im being rude even after my previous post then so be it.
im out
Sent from my Desire HD using XDA Premium App
Divine_Madcat said:
The application cannot hide what permissions it needs, so if you have something asking for way more than you think it should need, take that as your first red flag.
Click to expand...
Click to collapse
Actually, that isn't true. There are holes in Android Market, so if app makers really wanted to, they can hide certain permissions even if your app calls out that permission through androidmanifest, which is how the permission is given in the first place. It was shown that even big name developers had exploited this one time or another. Of course this has nothing to do with CM7. Even stock Android phones are vulnerable to this. However, in general, if you download a popular app, you should be able to trust the permissions listed. Unless your the first person to download an app, you'll usually hear back from initial users if there's something funky going on.

About App Piracy

Me and my friend, (who is a budding app developer for android) ran into discussion about "Android JB vs WP8", and after many aspects, we came to "developer benefits", there I said that Android is not good for developers bcoz people SIDELOAD app and nothing can detect a pirated app. That's the sad truth.
But on WP8 there's no way to SIDELOAD app, so No piracy of apps on WP8.
My friend said there are WP8 custom ROMS available and WP8 can also be rooted. So there maybe ways when people use Pirated apps on WP8 also.
So who is correct Me or my friend? Are there ways on WP8.
Sent from my GT-S5570 using xda app-developers app
Apourv said:
Me and my friend, (who is a budding app developer for android) ran into discussion about "Android JB vs WP8", and after many aspects, we came to "developer benefits", there I said that Android is not good for developers bcoz people SIDELOAD app and nothing can detect a pirated app. That's the sad truth.
But on WP8 there's no way to SIDELOAD app, so No piracy of apps on WP8.
My friend said there are WP8 custom ROMS available and WP8 can also be rooted. So there maybe ways when people use Pirated apps on WP8 also.
So who is correct Me or my friend? Are there ways on WP8.
Sent from my GT-S5570 using xda app-developers app
Click to expand...
Click to collapse
You're correct, can't root and you can only sideload apps if you're a developer. No custom roms, no root, your friend's a fandroid who's insecure about their OS.
I think disabling Sideloading is better. Because Wallet services are coming to mobile so chances are high that someone might make app which will hack mobile payment passwords and accounts, using app which people sideload. This might make android insecure, when making NFC payments.
Sent from my GT-S5570 using xda app-developers app
Disable sideloading? And then how are dev supposed to test their apps on their phones ? - the emulator is not a good choice in some cases.
Also, there are no custom roms YET, but I am pretty sure there will be. There's nothing in this world that can be protected from hacking
timotei21 said:
Disable sideloading? And then how are dev supposed to test their apps on their phones ? - the emulator is not a good choice in some cases.
Also, there are no custom roms YET, but I am pretty sure there will be. There's nothing in this world that can be protected from hacking
Click to expand...
Click to collapse
Developers can unlock their phones. Others can't.
Apourv said:
Me and my friend, (who is a budding app developer for android) ran into discussion about "Android JB vs WP8", and after many aspects, we came to "developer benefits", there I said that Android is not good for developers bcoz people SIDELOAD app and nothing can detect a pirated app. That's the sad truth.
But on WP8 there's no way to SIDELOAD app, so No piracy of apps on WP8.
My friend said there are WP8 custom ROMS available and WP8 can also be rooted. So there maybe ways when people use Pirated apps on WP8 also.
So who is correct Me or my friend? Are there ways on WP8.
Sent from my GT-S5570 using xda app-developers app
Click to expand...
Click to collapse
Blocking load of apps is a huge OVERKILL.
Say I wand to write an app, and distribute it freely, and do not want to put it on the market ?
What then ?
Besides that - if the IPhone with all it's locks and vaults can be set to load apps outside the Apple market,
it is safe to say that WinPhone will have the same crack.
Locking the device and limiting the user is a bad thing, and besides alienating your user base it will not do much.
Alienating your user base is never a good tactic, they will leave.
(People who plan to get WinPhone are most likely people who used WinMo - that was totally open to customization and apps from wherever)
Some developers looked into breaking the security on Nokia's WP7 phones and decided it would be to hard but of course there might be ways to do it anyway and allow custom ROMs. Aside from that Marketplace XAPs originally could be modified to be sideloaded on WP7 but this has changed several months ago, when Microsoft started to encrypt the XAP files.
As for modified firmware Microsoft is using Secure Boot to tackle the problem at a much lower level than Android and iOS devices do. Due to that it might be quite some time before anyone figures out a way to do it. And even phones like the HTC One X have not yet been broken (at least the versions that use Nvidias Tegra 3). It was similar with several Sony devices.
But in the end to enable this on a WP8 device it would mean HSPL, CustomROM and modified XAP-Files to allow for pirated Apps. Comparing this to Android where you only modify the APK and allow sideloading using a Checkbox I believe we will a lot more pirated Apps on Android than on WP.
As for: I want to provide my App for free without using the Marketplace - ähm... what would be the benefit to the user? Aside from Hacks they benefit from the fact that Apps are tested for stability, to be Malware-Free and that you can discover them without too much effort right from your phone.
The only thing I believe you're right is that actually lots of people will go for an OS where they can pirate Apps easily. There are enough threads around here were people tell you upfront that they believe that having paid several 100 $ for a device entitles them to get the software for free.
StevieBallz said:
....
As for: I want to provide my App for free without using the Marketplace - ähm... what would be the benefit to the user? Aside from Hacks they benefit from the fact that Apps are tested for stability, to be Malware-Free and that you can discover them without too much effort right from your phone.
....
Click to expand...
Click to collapse
Yeah, right.
Like we saw on apple store, and the android market.
(you must be either kidding, or naive)
And as for users thinking paying few 100$ for a device and thinking it entitles them for free apps - well -
people became used to having free programs, and there are many good free programs.
Besides that - I do not support software piracy, but I do believe that you should have the freedom to do whatever you want with the device you payed a lot of good money for, and that the manufacturer should not put you behind bars and in chains, just so they can make more profit from you.
And dont think otherwise - they lock the device for the sole reason of taking some percentage of the money you pay for the apps,
and no other reason.
So every app would have to pass through their, and only their checkout point, and bring them more money.
Android market has no certification process while Apple's and Microsoft's does.
I didn't try to imply that you would want it for the reason of pirating Apps but for most people this is the reason they desire that feature.
But in the end we're talking about the rationale for developers and that is where your (paid) Apps are a lot better protected on WP or iOS than on Android. If this actually benefits you in the case of WP is a different discussion due to the fact that your potential market is smaller. But given that even though Android has a much bigger marketshare than iOS by now developers make a lot more money on iOS it seems the closed marketplaces actually benefit developers in that regard.
StevieBallz said:
Android market has no certification process while Apple's and Microsoft's does.
I didn't try to imply that you would want it for the reason of pirating Apps but for most people this is the reason they desire that feature.
But in the end we're talking about the rationale for developers and that is where your (paid) Apps are a lot better protected on WP or iOS than on Android. If this actually benefits you in the case of WP is a different discussion due to the fact that your potential market is smaller. But given that even though Android has a much bigger marketshare than iOS by now developers make a lot more money on iOS it seems the closed marketplaces actually benefit developers in that regard.
Click to expand...
Click to collapse
The same goes for PC apps.
And people still develop apps for PCs.
This is, in my opinion, some kind of propaganda (not to say brainwash) from the manufacturers,
who's only intent is to make more profit for themselves, and want to recruit the developers for their own goal.
Software piracy have been here since forever, and the software industry has always been growing.
I still hold my opinion that the manufacturer must not have me in chains and behind bars.
I believe the manufacturer must let me do whatever I want with my device.
Let me load whatever apps i want, from any source, and not limit me or force me to pay them more and more money over the life of the device.
I'm not saying that it is not a valid desire to be able to do those things - I said it benefits developers if they are not possible. They don't have to care about piracy that much. And instead of putting together a sophisticated scheme to protect their applications (like they have been doing on the PC for more then a decade) they can concentrate on the actual content.
Do you believe PC games that came on floppy discs asked you about keys from the manual just for fun or to avoid copies? Do you believe the industry moved to CDs only because of the additional space or because they could not be easily copied for quite some time? Does Diablo 3 require an online connection because they could not implement a game that could run on the PC only?
Providing those protections in the OS itself takes a big burden off most developers. The 30 % cut Apple or Microsoft take is a big part of what big companies would earn with their software, given that they already have payment solutions in place and might be able to provide storage and bandwidth cheaper. For Indie developers it would be a lot harder to organize all this.
But instead of answering the question on pirac that thread was about y you're completely missing the point and going on a crusade (and your points from a users perspective definitely are valid).
Apourv said:
Me and my friend, (who is a budding app developer for android) ran into discussion about "Android JB vs WP8", and after many aspects, we came to "developer benefits", there I said that Android is not good for developers bcoz people SIDELOAD app and nothing can detect a pirated app. That's the sad truth.
But on WP8 there's no way to SIDELOAD app, so No piracy of apps on WP8.
My friend said there are WP8 custom ROMS available and WP8 can also be rooted. So there maybe ways when people use Pirated apps on WP8 also.
So who is correct Me or my friend? Are there ways on WP8.
Sent from my GT-S5570 using xda app-developers app
Click to expand...
Click to collapse
There are no WP8 custom ROMs, only WP7, and only for select devices. As far as I know, app piracy was effectively killed off even for a fully "rooted" WP7 device now that the apps come in an encrypted package. WP8 devices with an SD card can sideload apps, but it's a feature, not an illegal act. You get the encrypted package straight from windowsphone.com, and when you sideload it via SD card, it checks with the marketplace to see if you already own this app and if you have purchased it- otherwise you get the trial.
So android is significantly less secure in this area, your friend is wrong.
StevieBallz said:
I'm not saying that it is not a valid desire to be able to do those things - I said it benefits developers if they are not possible. They don't have to care about piracy that much. And instead of putting together a sophisticated scheme to protect their applications (like they have been doing on the PC for more then a decade) they can concentrate on the actual content.
Do you believe PC games that came on floppy discs asked you about keys from the manual just for fun or to avoid copies? Do you believe the industry moved to CDs only because of the additional space or because they could not be easily copied for quite some time? Does Diablo 3 require an online connection because they could not implement a game that could run on the PC only?
Providing those protections in the OS itself takes a big burden off most developers. The 30 % cut Apple or Microsoft take is a big part of what big companies would earn with their software, given that they already have payment solutions in place and might be able to provide storage and bandwidth cheaper. For Indie developers it would be a lot harder to organize all this.
But instead of answering the question on pirac that thread was about y you're completely missing the point and going on a crusade (and your points from a users perspective definitely are valid).
Click to expand...
Click to collapse
Pretty much this.
As a developer, I love the fact that the WP marketplace protects my app from almost anything a hacker can throw at it, because it protects several aspects I invested in the app:
1) Time. A lot of time. I don't like it when people use what I invested months of research and coding for free, just because they are too lazy to search the marketplace, but are devious enough to google the app and download it from some obscure location (the irony).
2) My intellectual property: I've made the app, therefore I should have complete control over who can download it. How would you feel if you invested a lot in a car, and some random people of the street simply gets in and drives your car away?
3)Coding and researching is certainly not an easy task. If it were, then everyone would be a developer. Pirating my app is like asking me to give away my talents for nothing in return.
Although it is extremely easy for outsiders to judge my app and say it is not worth the money, they really have no idea how much time and effort was put into it. It is a service I provide for you, and as with any service you need to pay for it...upfront or by staring at adds.
Considering that without the OEM I would not be able to create the app at all, and you would not be able to use it either, it is only natural for them to ask a percentage of the profit from the app. It is how business works.
mcosmin222 said:
Pretty much this.
As a developer, I love the fact that the WP marketplace protects my app from almost anything a hacker can throw at it, because it protects several aspects I invested in the app:
1) Time. A lot of time. I don't like it when people use what I invested months of research and coding for free, just because they are too lazy to search the marketplace, but are devious enough to google the app and download it from some obscure location (the irony).
2) My intellectual property: I've made the app, therefore I should have complete control over who can download it. How would you feel if you invested a lot in a car, and some random people of the street simply gets in and drives your car away?
3)Coding and researching is certainly not an easy task. If it were, then everyone would be a developer. Pirating my app is like asking me to give away my talents for nothing in return.
Although it is extremely easy for outsiders to judge my app and say it is not worth the money, they really have no idea how much time and effort was put into it. It is a service I provide for you, and as with any service you need to pay for it...upfront or by staring at adds.
Considering that without the OEM I would not be able to create the app at all, and you would not be able to use it either, it is only natural for them to ask a percentage of the profit from the app. It is how business works.
Click to expand...
Click to collapse
Comparing an App to a car is totally inappropriate.
If someone drove away in your car, you do not have this car anymore.
If someone installed an app you wrote - well, you still have another copy, and can produce a million more copies.
Som30ne said:
Comparing an App to a car is totally inappropriate.
If someone drove away in your car, you do not have this car anymore.
If someone installed an app you wrote - well, you still have another copy, and can produce a million more copies.
Click to expand...
Click to collapse
He has a very simplistic view on piracy, which is what most people who think they're losing something have. It's hard for them to wrap their heads around new concepts like "pirated does not equal lost sales". It's mostly the RIAA's fault that the practice of sharing is deemed amoral and gave it the misnomer: "piracy". Actual sales lost because of piracy are negligible. I'm not saying it's ok for people to just take without paying, I'm saying you need to realize what is actually happening. Most "pirates" are poor students with no money to spare, kids who have no money of their own, and the most numerous "pirate" of all: those who cannot access a store to legally buy the product.
Sent from my Windows 8 device using Board Express Pro
Som30ne said:
The same goes for PC apps.
And people still develop apps for PCs.
This is, in my opinion, some kind of propaganda (not to say brainwash) from the manufacturers,
who's only intent is to make more profit for themselves, and want to recruit the developers for their own goal.
Software piracy have been here since forever, and the software industry has always been growing.
I still hold my opinion that the manufacturer must not have me in chains and behind bars.
I believe the manufacturer must let me do whatever I want with my device.
Let me load whatever apps i want, from any source, and not limit me or force me to pay them more and more money over the life of the device.
Click to expand...
Click to collapse
This. And Also, Poecifer, your just the Fandroid, since the discussion was brought ou with no intention to accuse each other party and start a flame war as usual, so just stfu if you don't have anything useful to say.
As a wp developer, i'd like to say that not beeing able to sideload apps freely at times is just a pain in the a**...personally I own a Sony Xperia J and a Lumia 710...my friend is an Android Dev and doesn't have all this kind of limitation...

Why does Omnirom exist?

Forgive me if this thread is out of place. I mean everything I say with the greatest respect for omnirom's devs and users.
I found out about omnirom recently. I was struck by its motto: "Omni isn’t better, just different." There has to be a better reason to go to the trouble of building a rom that's only going to be slightly different from AOSP or Cyanogenmod.
I want to make a suggestion. As a new android rom, why not fill a need in the community instead of saying, we've got nothing better to offer you, only something different. Novelty wears off and people want more than just "different" from their operating systems.
Can I suggest a huge glaring need in the Android rom space that no major mod is filling? Security and Privacy.
The NSA and other intelligence agencies and corporations are launching attacks on people. Even Google is doing that. Months after I got my new android device, I was shocked when I found that Android was uploading all my contacts and other data to google's servers without asking me.
Read this article (Ars Technica: Google’s iron grip on Android: Controlling open source by any means necessary) to see how Google is making a walled garden with Android.
With 4.4, Google seems to be going even further. They won't stop. Google is using android as a trojan horse to collect information from people and sell it. Facebook is also doing it. The NSA is doing it.
Is there anybody out there who respects people and their privacy any more? I can't think of any major rom that does it.
Omnirom has xplodwild, Dees_Troy and Chainfire and many other talented developers, but why is the only thing they offer us a slightly different rom?!
We techsavvy people want more from our roms than that. Our pressing need in this day and age is not split screen apps. We're being constantly spied on by everybody and being monetised by everyone. What about end-to-end email security via Mailpile and the Dark Mail alliance? What about the Freedombox project?
Omnirom's description says, "Omni is what custom ROMs used to be about – innovation, new features, transparency, community, and freedom." Every android rom innovates new features and they're all open source because Android is open source. Most of them have a community focus. How is Omnirom any different?
Every project needs a reason to exist. I can't see omnirom's reason for existence.
There is a lack of respect for people by governments and corporations. They seek to use us or buy and sell us. Omnirom has the chance to fill a need in FOSS android world: A rom that respects and protects the data and the individual from legalized spying.
Let me respectfully ask this question. Wouldn't it be more reasonable to put all your talents to something useful and filling a need in the android world instead of being another flavour of stock Android?
Hoodahottie said:
Forgive me if this thread is out of place. I mean everything I say with the greatest respect for omnirom's devs and users.
I found out about omnirom recently. I was struck by its motto: "Omni isn’t better, just different." There has to be a better reason to go to the trouble of building a rom that's only going to be slightly different from AOSP or Cyanogenmod.
I want to make a suggestion. As a new android rom, why not fill a need in the community instead of saying, we've got nothing better to offer you, only something different. Novelty wears off and people want more than just "different" from their operating systems.
Can I suggest a huge glaring need in the Android rom space that no major mod is filling? Security and Privacy.
The NSA and other intelligence agencies and corporations are launching attacks on people. Even Google is doing that. Months after I got my new android device, I was shocked when I found that Android was uploading all my contacts and other data to google's servers without asking me.
Read this article (Ars Technica: Google’s iron grip on Android: Controlling open source by any means necessary) to see how Google is making a walled garden with Android.
With 4.4, Google seems to be going even further. They won't stop. Google is using android as a trojan horse to collect information from people and sell it. Facebook is also doing it. The NSA is doing it.
Is there anybody out there who respects people and their privacy any more? I can't think of any major rom that does it.
Omnirom has xplodwild, Dees_Troy and Chainfire and many other talented developers, but why is the only thing they offer us a slightly different rom?!
We techsavvy people want more from our roms than that. Our pressing need in this day and age is not split screen apps. We're being constantly spied on by everybody and being monetised by everyone. What about end-to-end email security via Mailpile and the Dark Mail alliance? What about the Freedombox project?
Omnirom's description says, "Omni is what custom ROMs used to be about – innovation, new features, transparency, community, and freedom." Every android rom innovates new features and they're all open source because Android is open source. Most of them have a community focus. How is Omnirom any different?
Every project needs a reason to exist. I can't see omnirom's reason for existence.
There is a lack of respect for people by governments and corporations. They seek to use us or buy and sell us. Omnirom has the chance to fill a need in FOSS android world: A rom that respects and protects the data and the individual from legalized spying.
Let me respectfully ask this question. Wouldn't it be more reasonable to put all your talents to something useful and filling a need in the android world instead of being another flavour of stock Android?
Click to expand...
Click to collapse
Something that perhaps doesn't come across when reading about Omni is about our thoughts on security and privacy. I'm one of the loudest complainers about the actions of a few companies (Google being the main one), who are using Android as a platform to spy on people.
Make no mistake, Omni will seek to address that. One issue the community faces though is that it is currently at the ebb and whim of Google. If Google decide to do X, pretty much every custom ROM has no real choice other than to follow. The aim of Omni is to offer an alternative "upstream" to look towards, when you find out that Google has started to call home every inbound phone number that it doesn't "recognise", in order to find out if it's a company from Google Maps/Local... And presumably log that forever more with your account...
This is a timely question with a very reassuring response. There is F-Droid instead of PlayStore (but it tends to be a few months behind) and OsmAnd instead of Maps (which is better in some ways). I would like to see more in this direction too.
IMO unless your a spy or a criminal I don't see why someone would care about all that NSA stuff.
Sent from my Nexus 7 using xda app-developers app
pulser_g2 said:
Something that perhaps doesn't come across when reading about Omni is about our thoughts on security and privacy. I'm one of the loudest complainers about the actions of a few companies (Google being the main one), who are using Android as a platform to spy on people.
Make no mistake, Omni will seek to address that. One issue the community faces though is that it is currently at the ebb and whim of Google. If Google decide to do X, pretty much every custom ROM has no real choice other than to follow. The aim of Omni is to offer an alternative "upstream" to look towards, when you find out that Google has started to call home every inbound phone number that it doesn't "recognise", in order to find out if it's a company from Google Maps/Local... And presumably log that forever more with your account...
Click to expand...
Click to collapse
Are you thinking of implementing off the shelf carddav / caldav syncing? Instead of syncing with Google for calendar and contacts, you can sync with any other source (like ownCloud).
Something that Davdroid does.
I am using this setup on my own private Linux server the last few days and seems to work well.
Sent from my TF300T using Tapatalk 4
jonathanxx1 said:
IMO unless your a spy or a criminal I don't see why someone would care about all that NSA stuff.
Sent from my Nexus 7 using xda app-developers app
Click to expand...
Click to collapse
Unfortunately, this is the biggest problem that the security industry (ie. people like me) face, in trying to explain the issues here.
Here's a small example, to show you the problems, not specifically with the NSA, but with anything "cloud". Let's imagine a malicious attacker is going after you...
Let's look at your gmail account. It's likely that you signed up for it with your old Hotmail account (the previously most common type of email service). Most people did. It's also likely that you protect your Gmail account fairly well, but have likely not changed your Hotmail password in a while. That's likely the best way in for an attacker.
Now, before you say "OK, but what's the risk", let's take a look at what information is accessible to someone getting into your Google account.
Firstly, they know the details of all your android devices (IMEI etc) - they know what tablets you have, what phones you have, and their serial numbers and identifiers. They can also carry out a remote wipe on any of your devices via Mobile Device Manager. Let's come back to this later though
From Google Mail, they have a fair idea of what you're up to, based on your communications to other people. They can access your location history, and data-mine that, to figure out where you are. They can also look at your communications with other people via Hangouts and G+, and attempt to work out where you are (or simply use the GPS location). They can access the location sharing features of google's services, and see where you and your family are. They can see you're not at home (getting your address from an email), and go to your house, aware your kids are home alone, and rob the place, abducting them.
When you return home, you meet a scene of devastation. You take out your phone and call the cops. You call 911/999/112/whatever, but the call was intercepted and passed to the attackers, via software that was installed onto your phone remotely (via the play store's remote push system).
At this point, the attacker takes your phone, and puts you in the back of the van. He uses Google Device Manager, and removes the lockscreen password from your phone (via the forgot lockscreen code feature). This also resets your device encryption password to a known one. At this point, all the devices are turned off, and their SIMs removed, and you are driven to a remote location.
The attackers then call your partner (having got their number from your Google contacts), and demand $1 million, while telling your partner that you know they are currently in <name of place from their google shared location feature>. The same remote access toolkit is installed onto their phone (given they had used your email as a recovery email for their Google account), and this permits monitoring of their phone to check if they call 911 etc.
OK, that all sounds far-fetched, but that is all entirely possible. The sheer amount of data being held about you, by google and other cloud providers, is insane. I didn't even go into the possibility of financial theft here. Cellphones are a very important thing to people, and they often take them for granted. Would you consider that when you called 911 in a moment of need, that someone had remote-installed a piece of malicious software, which exploits an android security hole, to replace the dialer app, and route the call to a rogue attacker, pretending to be the emergency services?
The amount of control that "other people" have over a phone running "Google Apps" is immense. Don't just think about the "NSA" aspects of this - consider how devastating it would be if someone had access to your Google account. And now remember that anyone on the technical team of Google could (in theory) issue an access token to your account to a well-paying attacker...
Oh, and one of the best ways an attacker can get into your Google account is simply to steal a phone or tablet, and extract the Google authentication token. Sure, they might not be able to change your password, but they are now "into" the chain, and will be able to start the attack.
If this don't bother you, I don't know what will...
scanno said:
Are you thinking of implementing off the shelf carddav / caldav syncing? Instead of syncing with Google for calendar and contacts, you can sync with any other source (like ownCloud).
Something that Davdroid does.
I am using this setup on my own private Linux server the last few days and seems to work well.
Sent from my TF300T using Tapatalk 4
Click to expand...
Click to collapse
I currently use {Card,Cal}dav syncing via my OwnCloud server. Thanks for the link to DavDroid, I'd not seen it before!
jonathanxx1 said:
IMO unless your a spy or a criminal I don't see why someone would care about all that NSA stuff.
Sent from my Nexus 7 using xda app-developers app
Click to expand...
Click to collapse
It's shocking that so many people don't (want to?) see the actual problem. The whole spying system is not just about tracking down terrorists.
Google, Facebook, etc and even governmental institutions collect our data to predict and influence our future actions.
So please devs, give us the option to be more independent from the big companies.
Gesendet von meinem Find 5 mit Tapatalk
I
pulser_g2 said:
I currently use {Card,Cal}dav syncing via my OwnCloud server. Thanks for the link to DavDroid, I'd not seen it before!
Click to expand...
Click to collapse
DavDroid is a pretty nice solution and you can set it up for multiple accounts.
I am still looking for a good note taking app (using Evernote now) to sync with my OwnCloud server.
Do you have any suggestions for a sort of Evernote replacement that can sync with OwnCloud?
Sent from my Xperia T using Tapatalk
---------- Post added at 03:57 PM ---------- Previous post was at 03:53 PM ----------
boernie said:
It's shocking that so many people don't (want to?) see the actual problem. The whole spying system is not just about tracking down terrorists.
Google, Facebook, etc and even governmental institutions collect our data to predict and influence our future actions.
So please devs, give us the option to be more independent from the big companies.
Gesendet von meinem Find 5 mit Tapatalk
Click to expand...
Click to collapse
For your calendar and contacts there are solutions already. Main problem is where so you store your data. You will need your own server or trusted third party.
Sent from my Xperia T using Tapatalk
I'm trying to set up my own infrastructure
But I was surprised that there was not out-of-the-box solution to use CardDav and CalDav.
Maybe you could include the apps mentioned above as they are/will become open source.
Gesendet von meinem Find 5 mit Tapatalk
scanno said:
I
DavDroid is a pretty nice solution and you can set it up for multiple accounts.
I am still looking for a good note taking app (using Evernote now) to sync with my OwnCloud server.
Do you have any suggestions for a sort of Evernote replacement that can sync with OwnCloud?
Sent from my Xperia T using Tapatalk
---------- Post added at 03:57 PM ---------- Previous post was at 03:53 PM ----------
For your calendar and contacts there are solutions already. Main problem is where so you store your data. You will need your own server or trusted third party.
Sent from my Xperia T using Tapatalk
Click to expand...
Click to collapse
I've found a nice notepad app, but none yet that use OwnCloud sync.
I was thinking about looking into https://github.com/spacecowboy/NotePad and trying to get it working with the API. It would be fairly easy to remove the "closed" bits like Dropbox sync etc, and use the OwnCloud backend. It would also be nice to add proper encryption of notes later on.
Anyone else interested? (I hate android app coding, I can't even get the dependencies to resolve for it to build... Thus contributing to my dislike for ANYTHING java based)
pulser_g2 said:
Something that perhaps doesn't come across when reading about Omni is about our thoughts on security and privacy. I'm one of the loudest complainers about the actions of a few companies (Google being the main one), who are using Android as a platform to spy on people.
Make no mistake, Omni will seek to address that. One issue the community faces though is that it is currently at the ebb and whim of Google. If Google decide to do X, pretty much every custom ROM has no real choice other than to follow. The aim of Omni is to offer an alternative "upstream" to look towards, when you find out that Google has started to call home every inbound phone number that it doesn't "recognise", in order to find out if it's a company from Google Maps/Local... And presumably log that forever more with your account...
Click to expand...
Click to collapse
I'm thrilled to hear this! Do other omnirom devs share your opinion?
I know it's early, but does the omnirom team have specific security/privacy ideas they want to implement?
In the long run, I don't see the Android ecosystem remaining in one piece. It's going to fragment. Amazon has already done it. Samsung may make this move. And people who want privacy and secure communications need a rom (and perhaps it's own app ecosystem) to which they can turn.
Please think about changing your why omnirom page. Right now, its pitch is very weak. Add a section about privacy and security and people will flock to this rom.
boernie said:
It's shocking that so many people don't (want to?) see the actual problem. The whole spying system is not just about tracking down terrorists.
Google, Facebook, etc and even governmental institutions collect our data to predict and influence our future actions.
So please devs, give us the option to be more independent from the big companies.
Gesendet von meinem Find 5 mit Tapatalk
Click to expand...
Click to collapse
I'm absolutely shocked every time I hear people say this. So many people just dismiss the NSA spying because they're not terrorists. They don't have the imagination it takes to understand that today's citizen is tomorrow's terrorist. Every country that spied on it's citizens has oppressed them.
I'm not a spy or terrorist, but I don't want my every thought and action logged away to be used against me later.
boernie said:
I'm trying to set up my own infrastructure
But I was surprised that there was not out-of-the-box solution to use CardDav and CalDav.
Maybe you could include the apps mentioned above as they are/will become open source.
Gesendet von meinem Find 5 mit Tapatalk
Click to expand...
Click to collapse
I can't post links, but if you want your own secure cloud, look at the Freedombox project. It's Debian based and it has some radical ideas. Eben Moglen and Bdale garbee have worked on it since 2010. Eben Moglen's talk about countries spying on citizens came long before the NSA story came to light.
The website is kind of dead, but in August Bdale gave a talk where he said Freedombox 1.0 should come before 2014. It's on youtube.
boernie said:
It's shocking that so many people don't (want to?) see the actual problem. The whole spying system is not just about tracking down terrorists.
Google, Facebook, etc and even governmental institutions collect our data to predict and influence our future actions.
Click to expand...
Click to collapse
There is a pretty simple solution to this!
Don't behave like expected.
Sent from my Find 5 using Tapatalk
Hoodahottie said:
Even Google is doing that. Months after I got my new android device, I was shocked when I found that Android was uploading all my contacts and other data to google's servers without asking me.
We techsavvy people want more
Click to expand...
Click to collapse
With all due respect to the OP, the above is the major problem. While many of us are "tech savvy" to one degree or another, I think we forget how to read sometimes.
When you're given that stack of papers to sign for your mortgage, car loan, credit card or bank account, how many blindly sign where we are told to be the agent of that company? Do you read what you are signing? If you answer yes, why is setting up your phone any different? We are told that such and such information is going to be collected when we sign up for our Google accounts. We are told that additional information is going to be collected when we set up our phone. Every time we start up GPS services, we are told Google is going to use this data they collect.
This causes me to wonder why it takes people by surprise when they learn that Google isn't a computer hardware and software company, but a marketing company. And even more wonder happens when they mention it's without their knowledge. Reading terms of service is important. They spell out exactly what they are going to do and give you the option not to participate. When I worked for IBM in the 80's, I had to sign away any rights to technology I developed while working there (with the exception of anything I started before employment and listed on their agreement). If I didn't want to do that I was my choice to not work there. The same thing happened with Tricord, Wang, Computer Associates, MAI, Excactium, Pivotal, etc
The other response about the NSA is troubling as well. We elect our representatives in this country every two four or six years. How many of those people that you voted into office voted yes to the Patriot Act? You want some scary reading, research the rights we gave up allowing that to happen.
We are innocent until proven guilty. The NSA "spying" doesn't just ensnare terrorist, but easily the whole population of the USA. Their model of two, three and more levels of contact captures everyone. The real question isn't I'm not a terrorist so why does it matter, it is I'm not a terrorist so why are you doing it?
We setup up these phones with the knowledge we would be tracked. We walk down the street and see security cameras watching. Then we complain about it? We allowed it to happen to have a whiz bang new phone or to feel safer.
" Those who would give up Essential Liberty to purchase a little Temporary Safety, deserve neither Liberty nor Safety." Benjamin Franklin
I work in retail. Every year I hear people complain that we set Christmas stuff too early. Those same people are buying their lights, cards and trees in the same visit. If they didn't buy early, we wouldn't set early. If we truly cared about not being used as marketing data, we wouldn't be using these phones. We wouldn't use Google.com to search. We wouldn't re-elect many of those in office at the local state and federal levels.
Sorry for the rant, I'll step of the soapbox and allow this discussion to get back on track.
Sent from my Nexus 4 using Tapatalk
With no disrespect, I wonder if people who ask me to take full responsibility understand life and power.
I understand that I have to take some responsibility for signing on for services and programs, but I blame the government and corporations more because they are many times richer and more powerful than me.
And they take advantage of that.
How many Terms of service agreements have I had to sign to use internet services? If I really read all of their ToS, I wouldn't have time for anything else. I'll bet that the ceos of these companies haven't read the ToS of their own products. They don't have to because they have the money to hire 50 of the best lawyers and ask them to craft a bullet-proof ToS.
They probably spent tens of thousands of dollars on the ToS. And I stand against all of that money and power, with limited time and resources and no law degree. Am I the one to be blamed? They know I'm tired from work, that I don't have a legal background and my attention span is limited and I need this product, and there is no other choice unless I'm willing to suffer a lot.
Often these multinational corporations control the whole market and I don't really have any choice. Look at the phone OS market now. I can choose between Android, iOS or Windows Phone. My choices are an open source OS built to facilitate spying, an overpriced, closed source, simplistic OS built by a company that co-operates with the NSA or a closed source, proprietary phone from an industry giant accused of anti-competitive behaviour and also collaborating with the NSA.
There's no real choice. Not just in the phone industry, but in most places in life. Powerful people don't become powerful by giving everyone else choices and freedom. They take freedom away. You ask me to take responsibility as if I had another, better choice. Apple, Google and Microsoft ToS will be mostly similar and it'll always protect their interests. There are no other real choices. It's always been that way, and why I blame the government, corporations and powerful people more than myself.
To really win, I'd have to devote my life to fighting all these powerful forces and even if I win, I'll have to spend the rest of my life defending against other crooks who'd try to do the same thing. I wouldn't have any time left for a life.
"You ask me to take responsibility as if I had another, better choice."
Who else is responsible for your actions?
"Apple, Google and Microsoft ToS will be mostly similar and it'll always protect their interests. There are no other real choices."
Yes, these companies are in business to make money. That is no different than you having a job to make money.
But do not tell me you or Bill or Steve or Larry do not have à choice. Ever heard of CP/M? An Altair? AltaVista? If you haven't, here is some history.
CP/M was a dominant operating system before DOS. Bill Gates made a choice to create Altair Basic for the Altair microcomputer being sold mail-order. That was the start of Micro-Soft (now Microsoft). He made another choice to create MS-DOS to compete against CP/M for the IBM PC and clones. He made another choice to start work on Windows to compete against Apple's graphical interfaces and IBM's TopView.
Before Steve Jobs made the choice to sell Woz's garage built microcomputer (later named the Apple) there was the Altair mentioned above. They made a choice to build an alternative.
Larry Page and Sergey Brin made the choice to start Google, thinking they could do search better than AltaVista, Yahoo, Excite, HotBot, MetaCrawler, etc.
Powerful people become powerful many times by giving others alternatives. The above mentioned powerful people are examples.
We can make the choice to use prepaid basic phones and not worry about anyone watching us because you don't use personal information to activate.
"To really win, I'd have to devote my life to fighting all these powerful forces"
You should. Doing so makes you powerful. Recently two women changed how one of the world's largest food brands makes their products. One of them eventually dropped out of the spot light and it became the crusade of ONE woman. Kraft Foods is changing how they make some of their Mac and Cheese products due to the efforts of one individual. No more Yellow #5 in their Mac and Cheese products specifically marketed at children. That was a choice she made. A fight that became part of her life.
We all have choices. We are all responsible for our own actions. We can't blame government as a whole because they are largely elected by us. We work to make money to live the life we choose. Corporations (started by individuals) do the same thing.
Sorry again for diverting off topic, but I have a difficult time with responsibility shifting to account for mistakes. We all make them (this reply is probably one of mine). A wise person once said, the man who makes no mistake, usually doesn't make anything worthwhile.
This particular set of threads, all the Omni threads, are what make communities like this work. We can voice opinions, state facts, help with commands to build a repository, compile a kernel, even agree to disagree.
This is how XDA started, while maybe some sections have stayed from the roots, Omni has brought it back full circle.
Sent from my Nexus 4 using Tapatalk
jonathanxx1 said:
IMO unless your a spy or a criminal I don't see why someone would care about all that NSA stuff.
Sent from my Nexus 7 using xda app-developers app
Click to expand...
Click to collapse
You may want to skim through this: http://online.wsj.com/news/articles/SB10001424052748704471504574438900830760842
Some laws (in many? all? countries) are so loosely worded that you're probably breaking some of them right now. Now remember that the government/google/facebook/whoever is watching everything you do. If you ever become "a problem" you're not going to be too difficult to "deal with". Just a potential look at one of the many problems with complete surveillance.
You guys talk about this as if Google, Facebook and all these companies willingly gave up this information.
But the reality is this: the government (NSA) asks for the data. If the companies deny them this, the NSA then goes to obtain a generalized warrant from the FISA courts, secret courts with a 99.7% warrant approval rate, and then obtain the data regardless of what these companies want.
And for those of you who STILL think it's the companies, read this: http://www.washingtonpost.com/world...1d661e-4166-11e3-8b74-d89d714ca4dd_story.html
---------- Post added at 10:38 AM ---------- Previous post was at 10:31 AM ----------
And yes, these companies DO own your data. As soon as you click "I accept these terms" on the registration page, they are now the owners of everything that goes through their online services.
But, here's the catch. Companies are individuals too, as established in Citizens United v. FCC, and are protected under the same rights as any other individual. And it logically follows that because of this, it is a breach on each company's 4th amendment rights for the NSA to obtain generalized warrants, that list NO goal for the investigation, and use these in order to force each company to fork over account details among other things.
frustration pure
one of the most common arguments of those who don't care or don't want to face the
risks of others knowing anything or almost everything of us is:
i have nothing to hide so what !
now to make a point i would like to come up with a very simple and for many
perhaps a bit strange example but i think most will understand what i mean.
ALBEIT I'M ALLOWED TO MAKE LOVE TO MY WIFE AND IT'S TOTALLY LEGAL
AND RIGHT, I DO NOT WANT ANYONE TO LISTEN OR WATCH :laugh:
UNDERSTOOD ?
regards
+1
I've been lurking and decided to give my opinion. First though, let me give a little background. Two years ago I bought my first Nexus and I rooted it right away. I left the bootloader unlocked, the CWM recovery installed, and USB debugging left on. Any app that could log me in automatically I allowed...Ebay, Amazon, Gmail, etc. I thought I was doing a good job protecting my privacy by using a strong password lock and installing Lookout.
I had no idea how easy it was to gain access to all of my data. My ignorance would not have protected me. Now to today. I have a rooted phone, but the bootloader is locked with the stock recovery installed. I will install a custom rom when a good one is available, but the stock recovery will be re-flashed and the bootloader locked when I'm done. I still use Lookout. I'm using LastPass to manage unique strong passwords now...no more saving passwords. I'm waiting for ADB Toggle to be fixed for Kitkat and USB Debugging will be turned off when my phone plugs into a computer. I am constantly looking for ways to protect my data.
To have total convenience, you must give up privacy and security. To have total privacy and security, you must give up convenience. I know that google has access to EVERYTHING I do with my phone and am not happy about it. I try to be informed and balance convenience, privacy, and security.
:good: I second the suggestion that OmniROM should attempt to become the ROM for people who want to protect their privacy and security. :good: There is a lot that can be done at the operating system level that cannot be performed by individual apps. Sure, I love all the features that custom ROMs offer and look forward to see what can be done, but privacy and security are #1 for me.
If you agree, then +1 this post.

Google's thirst for your info.

i guess this is a general subject, but fits in this forum because we're (nexus users) probably more affected than the rest of the android world. In short, i'm not liking Google's thirst for collecting info in order to sell us ads, tailor and filter information that gets to us, or even sell our info to other companies (android police had an article a while back about a company who was doing this). But let's go back in time a bit first...
My first android device was back in 2010, and i've been through a few htc and samsung devices, galaxy nexus, nexus 4 and of course nexus 5. Now, whoever had a galaxy nexus might remember how android was back then, ICS just came out, it was the first version that could actually compete with it's rival OS's, and the official builds on the galaxy nexus were very close to AOSP.
On the nexus 4 we started to see some changes, Chrome replaced AOSP's browser (Browser) even though it was still not ready for that role yet and despite it coming a long way to where it is now, IMO it's still not as good as the stock browser was. Google Play Music also replaced Music as the default music player and so on..
On the nexus 5 Hangouts replaced stock Messaging (in my opinion it also is not ready for that role yet) and last but not least we're witnessing how G+'s Photos is going to replace Gallery (which is simple and fast, works great, and has a mighty lil photo editor).
Let's add to that Photosphere, a feature exclusive to nexus devices, and the Google Experience launcher (exclusive to nexus 5). So we've reached quite a big divergence from AOSP.
Another thing is how Google is forcing it's social network, either through binding playstore/youtube comments with it, photos, G+ sign in, Game hub (Play Games) etc.. Basically, you have to have G+ to be able to do simple stuff.
Also, we all know that one of the reasons they killed microSD support was to get people to use their cloud services, Keep, Drive, GMusic, G+ autobackup photos...
Other than forcing it's services, Google likes to tailor things for us. A simple example is the Youtube app, it's default opening screen is "What to watch" instead of subscriptions.
Also, Google Now is a cool concept, and it can be very helpful, but it kind of adopts the concept of offering you the info (it thinks) you need, according to certain algorithms. And that's the way Google's search engine has been functioning for years. And it's not only a Google thing, everybody does it, facebook, yahoo etc..
If you've read this far, and this subject interests you, watch this TED talk http://www.youtube.com/watch?v=B8ofWFx525s
I've been thinking about this subject for a while, and honestly, i have mixed thoughts about it. I use Google's services and i actually like Google as a company -despite the lil rant above- but i try my best to control what info i share with them, and i'm definitely not liking the route Google is taking with android, causing fragmentation even between nexus devices, closing down a lot of open source services and forcing it's own, and tailoring stuff for me. I don't need someone to think or make decisions on behalf of me, i want to be able to decide what i want to see/read/know about/use. I also want android to stay as open sourced and available to everyone as it can be.
So what's your take on this subject? do you have any concerns about your privacy and the info you share with Google's servers? and how about the android -or should i say Google- experience on the N5 compared to AOSP or past experiences you had with previous nexus devices, do you see any difference?
Google uses your data to build out great services. They also get a lot of money for advertising, and that's just the way it is. Do you think they should give Maps and Gmail away for free to people without getting something in return? Everyone who buys a Nexus device or uses Google's services understands this. You said in your post that Google forces their services on us, but you aren't being forced to use a Nexus device, or use Maps and Gmail. You made that decision yourself, so I don't understand why you're complaining.
Oh no, Google can't do nothing bad. It's Apple's fault.
Sent from my Nexus 5 using Tapatalk
I don't really understand what you are getting at. If you don't like all of the Google services then why not install cyanogen mod? The sole purpose of a business is to make money for it shareholders and Google is a business. They provide amazing apps and services for "free". I put free in quotes because you are indirectly paying for it. No one is forcing you to use Google phones or Google services.
Edit* okay I do understand what you are getting at but I don't feel that Google is hiding it from its users. It's no secret that Google sells ads. That is their business. They can become a more successful business if they gather more information about its users. I am aware of what Google does when I use its services and I accept it because I use the services they provide and don't have to pull out my credit card.
It's not that hard to understand; why are we all flaming this dude? He was just asking for everyone's opinions.
I agree with you 100%. Especially as I initially made the switch from CM9 to CM10, I was really wary about Google Now. It seemed like it was collecting waaaayyyyy too much info. The G+ integration in Google Play and Youtube also ticked me off.
However, the more I think about it, Google is still being sensible. Google Now can't be compared to Siri because Siri can't do crap; Siri just takes what you say and searches it up. Google Now can be turned off, and if you don't want it always tracking your location, just turn off location and it'll turn off all the location-based cards.
I'm also intrigued (not concerned) by Google's recent actions, especially with the acquisition of Moto, the release of Moto X and Moto G, and the introduction of so many GPe devices. Perhaps Google feels threatened by Samsung and feels the need to tighten its grip? The Nexus/GPe community used to be solely dominated by Samsung, but now it's seen entrances by HTC, LG, Asus and Sony. It seems to me that everything Google has done in the past few months has been forced by Scamsung and Crapple, and that we shouldn't really feel concerned in any way...yet.
The whole world runs on information and EVERYONE is trying to collect as much as possible. You might as well let it benefit you. Imagine if you had to pay for an email client, gps, countless news subscriptions, data hosting, and on top of that, had to pay for every new software version as it was made available. Even paid services are focused primarily on learning as much about you as possible. At least they are trying to learn what interests you to offer you something you might actually want!
I for one am very sad to see Google's Android deviate so far from pure Android. I am not a fan of the Google Experience launcher and I miss the beautifully simple AOSP experience. Even when I do run stock android, I fill it up with Google services. I think the point here is that you should choose what you want... ESPECIALLY with a Nexus device. The Nexus has become too commercial with the N5.
Sent from my Nexus 5 using xda app-developers app
I dont want anyone selling my data. I do appreciate that I use many Google services for free so I'm happy for their bots to analyse my data to sell tailored advertising to support these services.
-----------------------
Sent via tapatalk.
I do NOT reply to support queries over PM. Please keep support queries to the Q&A section, so that others may benefit
rootSU said:
I dont want anyone selling my data. I do appreciate that I use many Google services for free so I'm happy for their bots to analyse my data to sell tailored advertising to support these services.
-----------------------
Sent via tapatalk.
I do NOT reply to support queries over PM. Please keep support queries to the Q&A section, so that others may benefit
Click to expand...
Click to collapse
Long as i dont get junk in my email or mailing address, besides what do you got to hide huh? unless you're al qaeda right? or some terrorist..
Google doesn't sell your info to other people, and nor does it "read" your inbox or someone is "reading" it, it looks for certain keywords then deliver ads based on that... test it your self on your phone email your self with any subject and just make a random sentence containing the word viagra, you will now receive ads that have to do with "Male enhancement pills".. google does this to provide cheap devices such as the chromecast and nexus line they want you to buy it in return for your interests then deliver ads based on that then google gets paid by the advertiser or the marketing campain, so lets just call this instead of google stalking you or like mining your information like gold think of it as google trying to see what you're interested into and deliver that to you!
oh also inb4 someone says punctuation is your friend
I've always been very bugged about this that's why I try to download privacy apps to control what permissions they are asking for
Sent from my Nexus 5 using Tapatalk
Google is just a modern day netzero (from back in the days). The sooner you realize that, the better you'll be able to set your expectations.
That being said everything you find worrisome, you can substitute with a different service. It's not being forced to you.
The reality is, you made a calculation that the benefits outweighs the costs. You just may not be conscious of it.
Lastly, the nexus line is pure Google, it's not pure asop. It's Google flavored android, just as htc one is htc flavored android.
Sent from my Nexus 5 using Tapatalk
---------- Post added at 12:08 AM ---------- Previous post was at 12:04 AM ----------
nohcho said:
Oh no, Google can't do nothing bad. It's Apple's fault.
Sent from my Nexus 5 using Tapatalk
Click to expand...
Click to collapse
Stawman
Sent from my Nexus 5 using Tapatalk
markdapimp said:
Long as i dont get junk in my email or mailing address, besides what do you got to hide huh? unless you're al qaeda right? or some terrorist..
Google doesn't sell your info to other people, and nor does it "read" your inbox or someone is "reading" it, it looks for certain keywords then deliver ads based on that...
Click to expand...
Click to collapse
This is exactly my point. You seem to be arguing my point back to me, which makes no sense. Perhaps you misread my post
Nothing online belongs to you.. there are many ways to stay frosty on android.
Sent from my AOSP on HammerHead using Tapatalk
i guess some people didn't get my point, maybe since English is not my native language.
Anyways, as i mentioned in my previous post i do use Google services, and i'm grateful that most of them are free. But it's getting harder and harder to control your privacy. Look at the new location concept in kitkat, you can't switch location OFF completely from the power widget, you have to take additional steps and go into settings. Furthermore, on previous versions, you could use GPS, let's say for sport tracking apps, but deny location from all Google apps. Now you can't do it anymore, even if you use "device only" Google's apps (and facebook and others) are able to ask for your location.
Same goes to the Photos app, if you log in your G+ account, and choose photos from the slide menu, you'll see all your photos, even if they are still only on your device (autobackup OFF), something like the GMusic concept with on-device/cloud music. Honestly, i don't want my photos on G+, and i have a feeling i'll be forced soon to upload them whether i like it or not, just like the location thing.
Also i want to be able to choose what G services i want to use. AOSP still gives that freedom, but no one can deny that Google progressively is stopping to develop AOSP apps, and it's forcing it's own. I think some around here take stuff that Cyanogenmod or the Paranoid team (and others) do for granted. I think people should be thankful for things like 8Sms , Focal and so on, and recognize the effort put in them, and help (test/report bugs) and donate to those devs to encourage them to polish these apps and make them even better. Honestly, i think we were lucky to get to choose what sms client we want as default, if it was up to Google, we wouldn't have that option available.
And lastly, look at what happened to App Ops, it would've been a nice tool to give back control to the end users, but it was killed in the last update with a statement that it was never meant to go public. If they are afraid some people will misuse it and break app-functionality (then whine about it) , well they could've put it in Developer Options right beside ART and the rest of the stuff that can potentially break things on your device.
So as a conclusion, i do like and use Google services, but i also don't want to be forced to share my private data, i just want to be able to do it in the range that i'm comfortable with, and putting everything on Google's servers does not make me feel comfortable :good:
You're never forced to share your data... You don't even have to use your real name on an account!
Sheesh.
Sent from my Nexus 5 using Tapatalk
Cirkustanz said:
You're never forced to share your data... You don't even have to use your real name on an account!
Sheesh.
Sent from my Nexus 5 using Tapatalk
Click to expand...
Click to collapse
That's cool, can I use your name when buying my next phone.... how about my Google store/wallet account, oh yeah and PayPal
makes you wonder why so many laws in the past prohibited such practises... they must of been real stooooopid!! haha
also if it was a bad thing lots of literature would have been written about it, warning us
meangreenie said:
That's cool, can I use your name when buying my next phone.... how about my Google store/wallet account, oh yeah and PayPal
makes you wonder why so many laws in the past prohibited such practises... they must of been real stooooopid!! haha
also if it was a bad thing lots of literature would have been written about it, warning us
Click to expand...
Click to collapse
Don't be silly.
You can pay cash for an Android phone. You can even pay cash for a Nexus 5.
You have the option of paying for mobile purchases with your carrier account, and have you never heard of a pre-paid visa card? There are all kinds of ways to get one without providing any personally identifiable information of any kind. The point of google store purchases being an invasion of your personal information is also entirely moot as you can very easily use an Android phone without making a single purchase on the play store.
You don't even have to use wallet, in fact most Android users CANNOT even use wallet to its fullest since they don't have NFC in their phones.
For real now, if you think your personal data is so valuable and sacred, have fun not having a checking account, loan, a real job, or a real place to live.
You don't even have to have google services running on your phone. This is XDA...install a custom rom and just don't load gapps. Or be even more lazy about it and just disable those apps in settings and they don't run.
That's me being silly. See how that works?
Here's my theory on the issue...
The way I see it is that a person has three choices:
1. Go completely off-the-grid, paying (limited) bills in cash, never engaging with the internet, and forgoing many modern technological conveniences.
2. Allow some personal information here and there, trying to maintain control by engaging with services that can be discontinued when they "cross the line".
3. Allowing access to all personal information online, engaging with anything and everything.
The third is simply not an option for me. I have no desire to have for-profit corporations spamming me with offers for crap I don't want and selling my private, personally identifiable information to anyone and everyone.
The first is really not an option, either. I don't want to be completely cut off from friends or have contacting them be excessively difficult. It is convenient to pay my rent, utilities, and other bills online. Frankly, I'm not good enough with any type of work that allows one to go off the grid to make a living.
So, that leaves me with the second option. I monitor changes to privacy and terms of service policies for the services that I use. I try to limit the services that I use. Obviously, I have a bank account and that comes with the need to provide some information to the bank, but also the ability to monitor my money and immediately flag appropriate people if anything suspicious happens. I have a Google account and a Nexus 5, ergo I use Google's services. And here's what's important to me: I can delete my Google account any time I want. With something like Facebook, it was a lot more difficult to do that once I became uncomfortable with my of the changes Facebook was making. Also, with Google, I can opt-out of many of the services that make me uncomfortable, such as targeted advertising or using my +1's as endorsements. If that ever goes away, I will absolutely reconsider my position. I maintain multiple Google accounts, actually, as a means of limiting who can see what information about me. I have a personal account, which has the most information about me and which is as locked down vis-a-vis Google as I can make it, but which allows my friends and family the best means of interacting with me. I have a professional account, which has only information relevant to my work. I have an "partial-incognito" account, which does not have explicitly identifiable information about me. I have a few completely incognito accounts, which I only ever access through very restricted circumstances, like a proxy server, and have absolutely no information that could be tied back to me. Frankly, that's about the best I can do.
I have chosen to make a tradeoff, information for convenience. The line where I am willing / unwilling to make that tradeoff is a massive grey area and I constantly reevaluate it. Sure, it's annoying to have to stay on top of it, but it's a fact of modern life. As long as Google gives me the option to delete my account whenever I want, I give them the benefit of the doubt and continue providing (limited) information about myself in exchange for some extremely useful services (unfortunately, this isn't the same deal I can make with the NSA).
Lokitez said:
Here's my theory on the issue...
The way I see it is that a person has three choices:
1. Go completely off-the-grid, paying (limited) bills in cash, never engaging with the internet, and forgoing many modern technological conveniences.
2. Allow some personal information here and there, trying to maintain control by engaging with services that can be discontinued when they "cross the line".
3. Allowing access to all personal information online, engaging with anything and everything.
The third is simply not an option for me. I have no desire to have for-profit corporations spamming me with offers for crap I don't want and selling my private, personally identifiable information to anyone and everyone.
The first is really not an option, either. I don't want to be completely cut off from friends or have contacting them be excessively difficult. It is convenient to pay my rent, utilities, and other bills online. Frankly, I'm not good enough with any type of work that allows one to go off the grid to make a living.
So, that leaves me with the second option. I monitor changes to privacy and terms of service policies for the services that I use. I try to limit the services that I use. Obviously, I have a bank account and that comes with the need to provide some information to the bank, but also the ability to monitor my money and immediately flag appropriate people if anything suspicious happens. I have a Google account and a Nexus 5, ergo I use Google's services. And here's what's important to me: I can delete my Google account any time I want. With something like Facebook, it was a lot more difficult to do that once I became uncomfortable with my of the changes Facebook was making. Also, with Google, I can opt-out of many of the services that make me uncomfortable, such as targeted advertising or using my +1's as endorsements. If that ever goes away, I will absolutely reconsider my position. I maintain multiple Google accounts, actually, as a means of limiting who can see what information about me. I have a personal account, which has the most information about me and which is as locked down vis-a-vis Google as I can make it, but which allows my friends and family the best means of interacting with me. I have a professional account, which has only information relevant to my work. I have an "partial-incognito" account, which does not have explicitly identifiable information about me. I have a few completely incognito accounts, which I only ever access through very restricted circumstances, like a proxy server, and have absolutely no information that could be tied back to me. Frankly, that's about the best I can do.
I have chosen to make a tradeoff, information for convenience. The line where I am willing / unwilling to make that tradeoff is a massive grey area and I constantly reevaluate it. Sure, it's annoying to have to stay on top of it, but it's a fact of modern life. As long as Google gives me the option to delete my account whenever I want, I give them the benefit of the doubt and continue providing (limited) information about myself in exchange for some extremely useful services (unfortunately, this isn't the same deal I can make with the NSA).
Click to expand...
Click to collapse
That's the type of answer i was looking for, thank you for this :good:
i can recognize myself in most of the things you wrote, basically that's how i feel about it too. i hope we won't get to the part where we'll have to "reconsider our position", but all the closing down and limitations are an indication that we're heading that way (i hope i'm wrong).
I started this thread to hear what others think about this subject, and to see if maybe i'm being excessively paranoid
Cirkustanz said:
Don't be silly.
You can pay cash for an Android phone. You can even pay cash for a Nexus 5.
You have the option of paying for mobile purchases with your carrier account, and have you never heard of a pre-paid visa card? There are all kinds of ways to get one without providing any personally identifiable information of any kind. The point of google store purchases being an invasion of your personal information is also entirely moot as you can very easily use an Android phone without making a single purchase on the play store.
You don't even have to use wallet, in fact most Android users CANNOT even use wallet to its fullest since they don't have NFC in their phones.
For real now, if you think your personal data is so valuable and sacred, have fun not having a checking account, loan, a real job, or a real place to live.
You don't even have to have google services running on your phone. This is XDA...install a custom rom and just don't load gapps. Or be even more lazy about it and just disable those apps in settings and they don't run.
That's me being silly. See how that works?
Click to expand...
Click to collapse
well none of that was my point, but don't worry about it. your willing to give my and my children's freedom away.. no argument will ever be good enough for you to stop you doing that.
Personally i don't care what Google knows about me (i'm not that interesting and i got nothing to hide - heck let the NSA spy on me too. don't care). I love their services and don't see anything wrong with them using my info to make $$. They are providing me with a service that makes my life a lot easier/better. I also really like the consolidation of Google aps and services and the synergy it creates. Google may force you to use one service to access part of another, but they do not force you to use anything you choose not to. If you don't like G+ integration, don't use Google's suite. I'm not trying to flame the OP, but i just don't get the point of this post. If you don't like something the best way is the speak with your wallet. If enough people do that maybe Google will pay attention.
---------- Post added at 12:58 PM ---------- Previous post was at 12:49 PM ----------
rayiskon said:
That's the type of answer i was looking for, thank you for this :good:
i can recognize myself in most of the things you wrote, basically that's how i feel about it too. i hope we won't get to the part where we'll have to "reconsider our position", but all the closing down and limitations are an indication that we're heading that way (i hope i'm wrong).
I started this thread to hear what others think about this subject, and to see if maybe i'm being excessively paranoid
Click to expand...
Click to collapse
this is why you started the thread? to hear opinions that validate your own? i thought it was to spark discussion?

Categories

Resources