Android May Soon Restrict On-Device ADB

shscs911 899 points 442 comments July 25, 2026
kitsumed.github.io · View on Hacker News

Discussion Highlights (19 comments)

luqtas

finally my children will be secure and my bank account impenetrable!

3form

What I find most annoying aspect of all software from 2010s onwards is this stupid discourse and associated results: - some people want A, or A might even be already in use - A is problematic for $MODERATE_OR_MILD_REASON - B is introduced and made default - a config switch between A and B is never considered So, so tiring. If I want to bind ADB to localhost, _let me_. It's my device and my problem, ffs.

coffee33go

https://archive.ph/gla4i In case it is made private.

throawayonthe

that seems pretty reasonable actually

satvikpendem

Of course this was bound to happen, next you're telling me people will be surprised that the 24 hour limit for side loading will turn into some indefinite time period.

throw9394999

This assumes user is the only person with physical access to unlocked phone. All sorts of goverment agencies, airport security, even teachers now have access. And such attacks can be trivially automated, so even low paid worker can do it.

charcircuit

adb connecting a device to itself is just bad design and a hack. Either the capabilities should just be granted directly to the app or it should all be blocked.

eviks

> Spamming the thread will only cause Google developers to lock the issue, ignore valuable community feedback, or stop sharing public updates about this change entirely. So nothing would change (they can also lock away your "valuable community feedback" because what bothers them is the criticism itself), thus feel free to express your approval

mdp2021

Step back to the other issue (referenced in the page*), that Google would pushing on devices something that blocks applications that do not come from play.google.com . Was it not established that Google can only push that update on devices with a google account? * https://keepandroidopen.org/

microtonal

I am generally in favor of security improvements, but I do not really see much of a benefit here. This attack vector requires both that the user enabled developer settings and that they have remote adb enabled. So, this does not seem to be a realistic attack vector for 99.9% of the users and most of the other 0.1% probably know what they are doing. The other proposed change (to restrict access to certain interfaces or IP addresses) seems good, but why not allow developers to restrict access localhost ? It reeks of trying to block Shizuku, Canta, etc. using a way that only makes it look like a side-effect.

magic_hamster

This is about control, not security. As in, Google's control over your device, your experience, your features and choices. This and Google just isn't interested in supporting an open OS anymore. Maybe they think it makes them liable. Either way the writing is on the wall, and has been for a while.

returnInfinity

bullish on google stock revenue must go up

IvanK_net

I am worried that this might happen to websites soon. If you want your website to be openable on Apple devices, you would have to pay Apple a fee each month. If you want your website to be openable on Android devices, you would have to pay Google a fee ecah month, etc.

peheje

We need Linux on phones. Bank apps not needed as long as I can use browser. But do need some things like wireless cards, popular apps like Sonos and Spotify working.

NSPG911

goodbye shizuku i guess, and maybe termux

ignoramous

The article overlooks security implications from spyware, which is a huge problem not only for financial applications, but personal safety, too [0]. Per FTC, a stalkerware will: geo locate, read call list & record calls, read notifications, texts, & possibly emails, access gallery, camera, & files, and monitor network activity. [1] You could do all of those with "on-device adb" (in some cases, with just the appropriate permissions), without root access. Stalkerware & financial fraud enabled merely due to the scale & reach of Android (half of humanity uses it!) and lack of basic security literacy warrants such protective measures, as (Thaler & Sunstein would like to remind us) defaults matter. With conspiracies abound, we must not lose sight of tech safety and related issues, which almost exclusively affect the most vulnerable & the most disadvantaged. [0] https://www.techsafety.org/spyware-and-stalkerware-phone-sur... [1] https://consumer.ftc.gov/articles/stalkerware-what-know

OsrsNeedsf2P

I'm so done with Android and iOS. I already carry around 2 phones because neither will give me exactly what I want, maybe it's time for a 3rd running Linux..?

gitowiec

Thank you for telling me about Shizuku! Android world is so vast and full of resources

userbinator

It's frankly amazing how many Google developers will associate their real identities and contact info with such hostility, believing they're invincible. Perhaps they should be subjected to the full force of the First Amendment.

Semantic search powered by Rivestack pgvector
14,850 stories · 138,743 chunks indexed