HN user

aboringusername

1,636 karma
Posts2
Comments248
View on HN

Well, it depends on the application and context. I don't think a homeless person at the library is going to be booking a $1000-a-night room in downtown Los Angeles.

However, services that homeless people will be using should factor in their target audience (such as the homeless not having a phone at all, or maybe not one that's up to date even).

However, like it or not, having a modern up to date device is becoming essential for even rudimentary basic access to society. Whether that's right or wrong it's where we are.

I suppose it's now become a default assumption every customer is going to own a smart phone that complies with this requirement?

It seems on iOS you'll even need to download an application, which is quite a bit of friction.

In the current economic times, adding minutes onto the user journey is not going to result in increased sales, I suspect the data will prove the opposite.

Using a mobile device is bad enough as it is: TOTP, email, SMS codes, 3DS etc, while you can say this is part of the "flow", it's too much. I can see many abandoned journeys from this.

I don't actually see this as a problem, and instead it's a PSA everyone needs to internalize:

If you put data onto a networked device it may be sent to some place else.

If you don't want your data being shared:

Use a device that does not have any networking capability (both hardware and software wise)

Use a pen and paper, you can shred and destroy as you see fit.

If you're using an application on a mobile device with mobile data/wifi, the chances are, your data is being uploaded.

It's not like the Google Play store hasn't been known to host malicious apps, yet you are not required to wait 24 hours before you install apps from their store.

I suspect they are hoping users just give up and go to the play store instead. Google touts about "Play Protect" which scans all apps on the device, even those from unknown sources so these measures can barely be justified.

Imagine if Microsoft said you need to wait 24 hours before installing a program not from their store, which is against the entire premise of windows.

Computing, I once believed was based on an open idea that people made software and you could install it freely, yes there are bad actors, but that's why we had antivirus and other protection methods, now we're inch by inch losing those freedoms. iOS wants you to enter your date of birth now.

The future feels very uncertain, but we need to protect the little freedoms we have left, once they're gone, they're gone for good.

I'm not sure why there's a need to update anything every 2-3 years. In fact, the pace of change becomes exhausting in itself. In my day-to-day life, things are mostly well designed systems and processes; there's a stable code of practice when driving cars, going to the shops, picking up the shopping, paying for the items and then storing them.

What part of that process needs to change every 2-3 years? Because some 'angel investor' says we need growth which means pushing updates to make it appear like you're doing something?

old.reddit has worked the same for the last 10 years now, new.reddit is absolutely awful. That's what 2-3 years of 'change' gets you.

In fact, this website itself remains largely the same. Why change for the sake of it?

Agreed. Food now is made to order, rather than being ready and waiting (likely to reduce stock waste). Last time I went there was hardly a queue, wasn't rush-hour (was quite dead actually, few staff, fewer customers).

Food still took 15 minutes, fries were cold, the main meal was nice but was overall disappointing for the eye-watering cost compared to days gone by.

And a few guys collecting for delivery which has split their focus from in-resturant customers.

Can see why people have moved on.

This is a trend that's probably going to continue and widen the rich-poor divide. Take airlines, there's only so many seats they can offer day to day, and with planes retiring from service and new planes slow to be delivered the inequality will only increase, and the market will shift to more affluential customers.

The likes of McDonald's will need to understand who their new customer base is quite carefully and market around that if they are to stay relevant. Sadly their products to me are garbage now; slow service, cold fries, awful oil. Obviously they've had to adapt but it's just expensive slop.

And in the UK they have had scandals around sexual harassment, which hasn't helped their image/branding.

I would argue QPR updates are functionality and subject to the 6 month test.

I would also argue a closed source release in August 2025 would start the first 6 month timer (February 2026) and the source code release to trigger another timer (if they differed in any way between the closed source release).

A lot of this law is abstract and only if the EU challenges Google's approach would it be decided how it's meant to be applied in reality.

It's a rather intriguing concept, because it can be the case that the binaries Google released in QPR1 and their source code are different in some way. OEMs must ship QPR1 as Google released publicly within 6 months.

If this open-source release was to contain new patches, they must now ship these changes within 6 months. The Pixel OS release counts as the first 6 month timer. The source code release, by definition, now counts as the 2nd timer.

I expect the closed source binaries and public source code to be the same, but that may not always be the case. So OEMs are expected to at least in 6 months ship an update with the open-source code.

Before the EU law, Android would release monthly bulletins, and patches would take about a month before being released on Pixel devices, once known as 'best in class' security. GrapheneOS have themselves admitted this has changed from 1 month to 4. This has been done to comply with this new EU law.

Now, we have patches already for March 2026 in November 2025. Once the March 2025 patches are shipped by Google, OEMs have 4 months for all OEMs to ship it (deadline being July 2026).

Consider this scenario:

Patch for bug lands January 2026. Google decides to either release a Pixel OS update or release the source code in 8 months time containing this patch for whatever reason. Then a 4 month timer starts for all OEMs to ship that patch. Meaning a patch that has existed from January 2026 can now be shipped by January 2027 under this system and fully comply with the law. This patch may be under active exploit as OEMs have leaked it which again, GrapheneOS have admitted is happening.

Previously, patches would be landing within the month. All google must do is ensure this patch is not included in any pixel OS update or public source code release.

Yes, Google is responsible, but when the EU touts laws as fining 4% of global turnover (in the case of GDPR), then they are going to be taken seriously, which means OEMs demanding Google not release the update for Pixel/source code until they are ready and use this loophole as they are doing.

The loser is ultimately the end user who has a weaker more exploitable device for months.

You're not reading the interpretation correctly:

at the latest 4 months after the public release of the source code of an update of the underlying operating system

So if somebody reverse engineers the patch, or releases the patch under embargo (which the OEMs would have the source code) that would count as a 'public release'. So GrapheneOS can ship closed source patches as you are right, they are not the provider. If GrapheneOS released the source code they are getting from their OEM then it would count as a 'public release of the source code'.

A patch in itself can be considered an 'update of the underlying operating system' and therefore the moment it becomes public it needs to be patched by all OEMs within 4 months.

GrapheneOS have themselves said that if somebody did reverse engineer the closed source blobs and posted them publicly they could then ship the patches openly at that point but not until.

It must be stated a lot of the wording of this clause and interperetation of what is/is not considered 'publicly releasing source code' is up for debate/courts to settle.

It absolutely has everything to do with this new law. For the first time, depending on when Google releases source code, or releases a Pixel update, the timer (4 months for security, 6 months functionality) starts. This has never existed before in Android OS' history that updates are timed (in law) according to Pixel updates/software updates or open source releases. This law also applies to Apple but they will have no problems as they are compliant anyway as they control software/hardware entirely and it's closed source.

This is the entire reason AOSP went private/closed source, and why Google is delaying security patches as per GrapheneOS. The March 2026 patches are already released by GrapheneOS as closed source blobs. They are not allowed to release them as open source by embargo (essentially NDA). Why do you think Pixel hasn't shipped security patches earmarked for March 2026? There are some critical bugs those patches fix, why not release them today, right now or next month? Because if Pixel releases just a single patch, via a Pixel update or posts it on AOSP, the 4 month timer begins for every single OEM with a phone in the EU. By making the patches under embargo, Google gets to control exactly when the timer starts to coordinate with their OEMs. So the slowest OEM gets to control the entirety of Androids security model.

Ask yourself, why doesn't GrapheneOS just release their patches publicly/open source? Why have different 'security releases' with closed source blobs?

Because if they did:

1: They lose their partner OEM access to these patches

2: Every OEM would be required to release those same patches 4 months to the day GrapheneOS releases them.

See my comment [1]. This is already happening with security patches and GrapheneOS has already commented on their socials about the situation.

It's quite bad as security patches used to take around a month, now it's around 4 months and the patches are being leaked to threat actors who can exploit the bugs until the patches are released.

Example: A patch is fixed on September 1st, released under embargo/closed source to all OEMs. Pixel issues the patch in December 1st publicly (either source code/software update), they now have until April 1st (4 months) to release it according to the law. So the patch is 7 months old before it has to be released according to the law.

All the march 2026 updates are done, now, today, and ready/waiting, but they are not released by Pixel/open source. Once that happens the timer will begin.

This EU law has made security far worse.

[1] https://news.ycombinator.com/item?id=45914692

And what does 'released' mean in this context? GrapheneOS has very publicly stated that security patches are under embargo, and they already have patches for the March 2026 release. See [1]:

2025110800: All of the Android 16 security patches from the current December 2025, January 2026, February 2026 and March 2026 Android Security Bulletins are included in the 2025110801 security preview release. List of additional fixed CVEs:

So, have they been released? No. So the clock hasn't started ticking yet. This EU law made security worse for everyone as patches that are done today are not released for 4+ months.

Note: These are CLOSED source blobs GrapheneOS is shipping. If they were open source, the 4 months clock would trigger immediately but they are not allowed to do this themselves as they get the patches from an OEM partner. GrapheneOS shipping these CLOSED source blobs, that Google has NOT released does not trigger the timer.

I do accept that QPR1 was 'released' by Google on Pixel months ago, and therefore the timer started, however, Google will likely pick and chose what is best for OS updates/security patches. It explains why AOSP is now private/closed source and embargos are being used to get around the laws requirements.

[1] https://grapheneos.org/releases#2025110800

From the EU law:

(c) security updates or corrective updates mentioned under point (a) need to be available to the user at the latest 4 months after the public release of the source code of an update of the underlying operating system or, if the source code is not publicly released, after an update of the same operating system is released by the operating system provider or on any other product of the same brand;

(d) functionality updates mentioned under point (a) need to be available to the user at the latest 6 months after the public release of the source code of an update of the underlying operating system or, if the source code is not publicly released, after an update of the same operating system is released by the operating system provider or on any other product of the same brand;

(c) security updates or corrective updates mentioned under point (a) need to be available to the user at the latest 4 months after the public release of the source code of an update of the underlying operating system or, if the source code is not publicly released, after an update of the same operating system is released by the operating system provider or on any other product of the same brand;

(d) functionality updates mentioned under point (a) need to be available to the user at the latest 6 months after the public release of the source code of an update of the underlying operating system or, if the source code is not publicly released, after an update of the same operating system is released by the operating system provider or on any other product of the same brand;

So if Google releases an update for Pixel, the 'clock' starts ticking from that date, otherwise, it goes by when the source code is released. Google can pick and choose what works best for them and their partners according to these rules.

Hence why delaying the source code may be preferable. This is why security patches are being delayed as per GrapheneOS (under embargo)

For example: Google releases Android 20, under embargo to all OEMS, this is not released on Pixel, is entirely closed source (hence why AOSP is now private) and therefore doesn't trigger the law. Android 20 could be ready for months, but until it's released on Pixel or open source, those clauses are not triggered. This is already happening to security patches, see my comment above.

Who cares? I mean, obviously this author, but pointing out "GDPR this" and "GDPR that" isn't going to make a difference or move the needle. Many companies have given up on GDPR - I've made requests and had blanket refusals to provide data.

Report them, you say? Many DPC's such as the Irish DPC are very friendly in terms of their lax approach to the regulation, just ask Max Schrems, he's been at this for years. I think the EU and the regulators do not have resources to enforce the law, so whilst there are requirements to protect customer data, nothing bad happens if you don't. Just check the top of HN as I write this [1] "Checkout.com hacked, refuses ransom payment, donates to security labs". Will anyone be arrested, charged, fined, or otherwise penalized? Nope, not a chance. I 100% guarantee absolutely nothing will happen as a result of this article. GPT makes it so easy to capture user data these days and people will just willingly hand it over.

The truth is, you should be very careful what data you hand out, always. Use an alias, use privacy tools, always be weary and check if they have a privacy policy, check to see if it works (make a dummy account, do GDPR request, if no reply, be weary).

If they are not serious about privacy, stop, think and act accordingly. While it is a disgrace what these individuals have done, individuals need to take personal responsibility just as in a real world, would you trust a random stranger giving you pills? Hopefully not!

[1] https://news.ycombinator.com/item?id=45912698

We really need to banish the term "sideloading". Installing apps on a terminal is just that, and for as long as I remember on windows, Linux it has always been just that.

Google mentions about being on a call, and being tricked into handing over codes. So why not use signals and huristics to decide?

If user is on a call, block any ability to install a shady app. Implement a cool down before that functionality is restored (say 24 hours). It can also detect where the user is based to add additional protection (such as mandating the use of play protect to scan the app before it's activated and add another cool down regardless).

There's lots of ways to help protect the user but it's wrong to ultimately control them. The real world is full of scary dangers that technology is trying to solve but is actively making things worse (such as computerized safety systems in cars).

Ultimately, the user is responsible and whilst it's palpable Google would want to reduce harm in this specific way, we know authoritarian governments would also love to be able to dictate what software people can run. The harm to democracy is simply too great in favor of saving a few people's money.

Steam Machine 8 months ago

Games publishers/developers are going to have to wind in their necks a little. Whilst memory is abundant it's also still quite expensive. We should still be aiming for efficiency and the chances are 16gb+ are in the minority here. Fact is, the more VRAM and compute you demand the smaller your customer-base becomes.

I've played many games with 8GB VRAM* and will do so for the forseeable. If that's not enough, I am not a customer. Simple as.

The truth is, there is going to be a massive motivation with the likes of Steam Deck/Machine to actually make titles that are optimised and perform well within their hardware parameters. It's money you won't want to ignore.

*One example was Silent Hill remake on PC, which used the unreal engine. It was optimised beautifully and ran without visual glitches and stutters even with the highest graphic demands on a 8GB RTX

A great example of this is the 'networking' permission. Being able to control which app can speak to the WAN/LAN is a very important security consideration. Instead, every Android app can send any data it wants without the user being able to have a say in the matter. A lot of apps work just fine without being able to 'phone home'.

Thankfully there's the likes of GrapheneOS, however, with Google's recent changes, unless their OEM partner pulls through, their days are likely numbered.

The only reason Google has decided to lock-down Android is because of apps like ICEblock and the ability for anonymous individuals to mass distribute information that governments do not like. Now, they'll be able to hunt you down by requesting Google hand over every ID document that they process. This sets a chilling precedent for free speech. It enables governments to go after those who dare 'speak out' by using platforms to their advantage. You can no longer 'hide in the shadows' and will need to put your entire identity on the line for your morals and convictions.

Of course, if they could do this with Windows, Linux et al they absolutely would. And general purpose computing will, eventually, be closed and locked down, much like what we are seeing with the internet and ID laws. People would have, and did, think such ideas would be unthinkable 10-15 years ago. Yet little-by-little the screws are being ever tightened. The government wishes to tightly control the information flow and decide what is 'best for you' to see. Preferably their chosen propaganda.

Work-arounds that exist today will likely be closed and forbidden in the future. VPNs to bypass age laws, ADB to bypass install-blocks will all be obsolete. You will be required to identify yourself at all times. I half-expect Google to deprecate and remove the concept of VPN's/ADB on Android entirely and laws will be passed to that affect (restricting the apps themselves, or access to the APIs to verified Android devices/Google accounts). If you don't believe me, you only need to see [1] for the direction of travel.

There is little interest from the regulators to stop this. Perhaps the useless CMA will 'investigate' in 5 years time, decide Google perhaps abused its monopoly and then do absolutely nothing because they have no real re-course over an American company. It's likely governments support this position and will not do anything to influence a change of direction.

Eventually, Linux itself will go the same way, people are just waiting for Torvalds to retire from the project to make their moves, but make no mistake, open general-purpose computing is under threat and there is going to be little we can do to reverse the current trends towards closely monitored and controlled computing.

[1] https://developer.android.com/google/play/age-signals/overvi...

This will most likely be expanded in the future to limit access to certain 'dangerous' APIs like ADB/VPN's etc. This can also be used 'in app' and across the entire OS to shape your experience of what you can see and do. I wouldn't be surprised if 'unlocking bootloader' required an 18+ verified device.

Just reading the first correspondence from Ofcom and this section in particular:

What should I do if there is confidential information in my response?

You must provide all the information requested, even if you consider that the information, or any part of it, is confidential (for example, because of its commercial sensitivity).

If you consider that any of the information you are required to provide is confidential, you should clearly identify the relevant information and explain in writing your reasons for considering it confidential (for example, the reasons why you consider disclosure of the information will seriously and prejudicially affect the interests of your business, a third party or the private affairs of an individual. You may find it helpful to do this in a separate document marked ‘confidential information’

Ofcom will take into account any claims that information should be considered confidential. However, it is for Ofcom to decide what is or is not confidential, taking into account any relevant common law and statutory definitions. We do not accept unjustified or unsubstantiated claims of confidentiality. Blanket claims of confidentiality covering entire documents or types of information are also unhelpful and will rarely be accepted. For example, we would expect stakeholders to consider whether the fact of the document’s existence or particular elements of the document (e.g. its title or metadata such as to/from/date/subject or other specific content) are not confidential. You should therefore identify specific words, numbers, phrases or pieces of information you consider to be confidential. You may also find it helpful to categorise your explanations as Category A, Category B etc

Any confidential information provided to Ofcom is subject to restrictions on its further disclosure under the common law of confidence. In many cases, information provided to Ofcom is also subject to statutory restrictions relating to the disclosure of that information (regardless of whether that information is confidential information). For this reason, we do not generally consider it necessary to sign non-disclosure agreements. Our general approach to the disclosure of information is set out below.

For the avoidance of doubt, you are not required to provide information that is legally privileged and you can redact specific parts of documents that are legally privileged. However, where you withhold information on the basis that it is privileged you should provide Ofcom with a summary of the nature of the information and an explanation of why you consider it to be privileged. Please note that just because an email is sent to or from a legal adviser does not mean it is necessarily a legally privileged communication. Further information is available in paragraph 3.18 of our Online Safety Information Powers Guidance.

So ofcom's position is:

We want your data, you will give us your data, the GDPR does not apply to you, and if it does, we will decide whether it does. You must explain yourself to us. You must not redact anything. Even if you think you can redact anything (you know, because GDPR) you cannot redact anything. The GDPR and data protection laws do not apply because we have said so. You are required to break confidentiality agreements. We will not sign an NDA because we do not need to and we will not justify ourselves to you in any way shape or form.

We are the UK, and therefore, because we asked you to, you will comply with our every demand, whim and whimper. Otherwise we will continue to send strongly worded emails.

And fine you. And block you. Because that's the only thing we can do. And you best not advertise VPN's or we'll...Send another sternly worded email!

Good job UK!

(I cannot see how that paragraph is in any way legal, it must break the EU/UK's data protection laws in trying to compel disclosure of third party data. I cannot see any court in the UK ever upholding that paragraph if legally challenged as it's way above Ofcom's remit to be demanding confidential data. In any case, they should absolutely be required to sign NDA's)

I've often wondered if there is a way you can be malicious with this, a way of 'beating' them at their own game.

1: Make random files full of absolute garbage data

2: Upload 5GB of garbage data, delete (free limit capacity)

3: Repeat 1 and 2, forever, 24/7.

At 10mbps it would take 68.3 minutes, at 50mbps it would take 13.7 minutes to upload 5gb.

At 10mbps you could upload 5gb 7665 times, at 50mbps 38,325 times a year.

that works out to 38,325gb/10mbps and 191,625 GB at 50mbps per year

So yeah, if Microsoft wants to allow a user to upload 10's of thousands of completely worthless useless bytes of data and delete and reupload why not?

Anyone care to think how many hard drives you could destroy with the constant writing? And you could also automate downloads too, so they have to deal with reads.

Let's see how long they want your 'data' for then ey?

Consider it a digital form of 'fly tipping' and it's completely free, legal and they have begged you to do it!

Another aspect of this is why Apple/Google let this happen in the first place. GrapheneOS is the only mobile OS I can think of that lets you disable networking on an per-app level. Why does a period tracking app need to send data to meta (why does it even need networking access at all)? Why is there no affordance of user-level choice/control that allows users to explicitly see the exact packets of data being sent off device? It would be trival for apps to have to present a list of allowed IPs/hostnames, and users to consent/not otherwise the app is not allowed on the play store.

Simply put, it should not be possible to simply send arbitrary data without some sort of user consent/control, and to me, this is where the GDPR has utterly failed. I hope one day users are given a legal right to control what data is sent off their device to a remote server with serious consequences for non-compliance.

Yes, because that's how the internet is designed to work, a VPN just routes packets to another location with the nice side effect of being able to use another IP address.

Countries have tried to enforce censorship but even places like China have gaps that are exploitable if you have the right tools and knowledge.

Everyone should be learning about how to bypass state overreach, it's an obligation of its people.

We are in a community of hackers. There are tools such as VPNs which are effective at bypassing these requirements. That will likely change in a few years as the government will want to crack down on circumvention techniqus. The law is incidious enough to actually suggested that educating people on how to bypass the checks is not allowed - I sincerely hope no court ever upholds that otherwise the very act of education is at threat.

So the end result is using tools such as VPNs or fake videos to bypass the system. Or creating new communities which do not have such restrictions (but they won't be able to be big platforms anymore as they will fall into scope).

So you could have 1000's of smaller bulletin boards. Once they get large enough they'd need to shut down and restart in order to not be within scope.

Alternatively there could be some legal challenges on the way to define the scope of their powers (so far there's not been any enforcement conclusions to challenge, although there are some investigations by OFCOM ongoing)

The claim is that the data is "deleted", but there is no way to actually verify it is in fact being deleted (and the chances are data itself might be stored in say AWS which may have its own way of "deleting" data, such as in backups, caches, multiple regions etc (however they have their own legal process which may not allow data to be deleted in the event of a law enforcement request, and there's no way for anyone using the service to understand who is actually handling the data as it passes by their servers, which could be suspectable to interception etc)). Truth is, the data is much too valuable, and is useful for long term storage to know what somebody looked like or who they were when accessing content online. The UK has the RIPA so they could serve a technology notice for data to be retained and prevent disclosure of that fact. Apple was recently involved in such a request to disable advanced data protection, and the UK government is disgusted by E2EE and the very idea they cannot access every piece of data they like on demand, and wanted the entire thing held in secret.

So the reality is, assume everything on the internet is being archived, including any scans you do, and adjust the threat model accordingly. The UK government will absolutely be able to access this information and know all about what you've been doing if you're foolish enough to actually submit legitimate information.