back

by privong·11y ago·view on hn ↗
Install f-droid and use the phone without a Google account.

One unfortunate complication with this is that using the phone without a Google account means one will likely miss out on security updates. As Google fights android fragementation by moving more functionality into user-upgradeable apps, not having a Google account means one cannot update things like Google Play Services. I imagine there are security fixes which go into those updates.

Of course, one could disable those specific apps. However, in the example I used—Play Services—disabling (or having an old version of) it means TextSecure's push messaging does not work, for example. Going off on a bit of a tangent, I would be interested to see a discussion between Moxie and Jacob about this aspect of things. Is it worth having a Google account if it means you have encrypted push messaging? Is is worth not having a Google account if it means you cannot have encrypted push messaging? (Yes, encrypted sms would still work without the Google account).

In the event someone points out the TextSecure APK is only distributed within Google Play, it is relatively straightforward to build TextSecure from source. So, not having a Google account does not preclude one from using TextSecure. And one can use the push messaging via Play Services without a Google account, provided a compatible version of Play Services is on the phone.

3 comments
If the number one priority is having a secure phone, why would you want to install the notoriously leaky Google apps? Google uses dark patterns and opt-out all over the place to send tons of data back to HQ.

Once again, if security and privacy are your number one priority, why wouldn't you compile TextSecure yourself, or at least get it from a trusted source?

My point was that it is not a simple trade-off between "privacy and security" and a lack of those things. In order to get software updates for critical components of the phone, you may need to get a google account, sacrificing some of the "privacy" for software "security". Obviously it does not have to be this way, but it is the way Google has mandated it in their ecosystem.

Edit: One can make the case that it's better to use encrypted SMS with TextSecure, rather than using the push messaging. But, from a metadata standpoint, I believe the push messaging might be better. SMS metadata seems to be automatically handed over to the US government, while they would likely need to issue a NSL, warrant, etc. to get that same information from Google. So using the push messaging may side-step some of the metadata collection that is happening.

There's always the ug (micro-g) GAPPs replacements, still waiting for someone to release compiled binaries and a guide so I can try it out for myself.

https://github.com/microg

the thing I never got is why is having the Google account an issue if you never use their apps?
I think because they still collect information from your phone and correlate it under your Google Account. I created an account solely to install software (security) updates to the built-in components, and it greedily grabbed my contacts from my OwnCloud instance and sync'ed them to my Google Account. As colordrops mentioned in another reply, they are very sneaky about building a user profile.
And they always upload usage data, how many times you opened which app, how long it stayed in background and how often you used it in foreground, overall use time, etc.

For all installed apps, all the time.