A family member installed an app into their Android phone from the Play Store.
It was innocent enough until it asked for a truckload of permissions, like being able to change the launcher, which they ofc tapped "Allow" to since permission request fatigue is real and still a bit of an unsolved problem.
So the app delivered on its promise and changed their phone's launcher. It had a fake Gmail widget that showed them their mail but, of course, wasn't actually tied to the actual Gmail app and was an easy way of getting a refresh token for their account.
Bingo bango bongo: their email was now at risk.
They changed their password after I told them to right away upon them asking me to look at their phone because "it was slow."
> Magic link auth isn't any less secure than any site that has a password-reset flow.
Which is exactly the problem. Cloning someone's SIM/eSIM and immediately performing password resets is a well-known security issue.
Yeah I don't trust SMS either, that's why I said email. You can do a lot more to protect your email account than your phone number.
It's very disconcerting to think about how many malicious apps like that must exist in the Play Store, but again, gaining access to someone's Google account is still game over if that's how you're syncing passkeys.
I haven't left because there are still circles of people I follow that haven't bailed. Once a large enough majority move to Bluesky, I'll start browsing that app more.
On the other hand, I might start posting on Bluesky more because as of a week ago, I'm shadowbanned on X. I know people throw that term around, but nobody on the site can see any of my reply tweets, even me (unless I scroll my account's 'replies' tab); people who've followed me for years are asking why their tweet has a ghost reply.
I don't think X has that much of an incentive to filter out bots while keeping around accounts like me (200 followers, will never pay for Premium). The slightly higher effort bots that glaze tech CEOs will be basically indistinguishable from the real people glazing tech CEOs because they're wannabe founders trying to network/cloutfarm. And that style of dead internet is fine with Elon.
> Once a large enough majority move to Bluesky, I'll start browsing that app more
The problem is a network effect. Lot of people rage quit X and then they return to it because they realize the reach isn't there on Bluesky, and whenever that happens it just sends strong signals
I don't really like X either, I feel like the feed algorithm isn't very good and just shows the same thing repeated by multiple accounts.
I'm trying to objectively view the two platforms without the partisan rhetorics. There isn't that many places besides Threads.
I personally like the old php forums which had a real presence.
What's funny is that people who use social media to drive traffic seem to consistently say they get more real click throughs to their content from bsky than twitter, despite having a fraction of the follower counts and post engagement that they have on twitter (even before all the barriers Musk enacted to keep users on twitter).
My initial suspicion was that my account was flagged because I only used the web version (the PWA experience on mobile is pretty good) so I've been using the Android app the last few days, and I'll see if that has any signal on my account.
In another view days I'll try filing a support ticket, maybe claiming something like "I was mass-reported by DSA leftists for my right-wing views"; things along those lines have gotten some peoples' permanent suspensions lifted.
> as of a week ago, I'm shadowbanned on X. I know people throw that term around, but nobody on the site can see any of my reply tweets, even me
This is honestly the real value of nitter far beyond anti-Musk shriekers being obsessed with and addicted to X but not wanting to log into X. Nitter seems to simply give you everything - and you can plainly see which tweets are getting huge distribution and which ones nobody is seeing.
You might be correct but the link you've pasted is still of the original copyrighted breakbeat, not a recreation, on a site again falling victim to what it offers for free and Creative Commons not being free or Creative Commons.
The arbitrariness of app store review hasn't been the greatest on the Google side, for me lately anyway. I got dinged for having an E-rating for my TV show info app that displays an official promo image for an episode of Landman, where a character has a wound with some blood on his face.
I pointed out that there were a couple other E-rated apps that show the exact same image, and many more T-rated ones that only warn of "In-App Purchases" — no "Violence" label. One of the latter is the official Google TV app [0], so I sent some screenshots of that, and asked if maybe they were "crushing the competition" by avoiding their own review process, to see if that would escalate my case (no such luck).
Source? And if somebody hacks my Gmail account, won't they be able to access my Google-synced passkeys?
Magic link auth isn't any less secure than any site that has a password-reset flow.
reply