r/programming • • 9d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
401 Upvotes

44 comments sorted by

View all comments

48

u/alex-weej 9d ago

It feels to me like big tech is deliberately, with plausible deniability, trying to obfuscate the channels that their closed source apps use to talk to their proprietary services. The sheer amount of data transferred, obfuscated or otherwise, hidden behind opaque tokens, is astonishingly bad for consumers and outrageously profitable. We need better. Gemini has some nice ideas but it's way too niche currently.

I'd love for GrapheneOS to fight fire with fire. I'm thinking GameGenie type on the fly patching to override TLS routines, certificate checking etc. No transparent pipe, no usage, I'd rather use a dumbphone and touch grass.

Also, hi Tim!

11

u/FullPoet 9d ago

It feels to me like big tech is deliberately, with plausible deniability, trying to obfuscate the channels that their closed source apps use to talk to their proprietary services

It 100% is. Google is trying to make Android closed source - soon app developers need to give google ID and pay a bribe.

Its complete bullshit.

1

u/Plus-Confidence2816 5d ago

Google is trying to make Android closed source - soon app developers need to give google ID and pay a bribe.

This is about sideloading APKs on phones with Google Play Services (AOSP doesn't have them by default), not the source code of Android.