A big win for Android interoperability

(openhomefoundation.org)

145 points | by soheilpro 1 day ago

16 comments

  • shiandow 2 hours ago
    I don't care about any of these, I just want to be able to have whatever Google pay does without Google.

    You could claim that's not an android problem but if you do I don't think you've ever had to explain to people your phone doesn't have a Google Play store.

    • inigyou 10 minutes ago
      You are free to reverse engineer the whole system and find a way to make it work. The world will love you. I suspect there will be a Google hardware attestation at the core of it, but understanding how it works is still huge progress.
    • giantg2 49 minutes ago
      Why would anyone who cares enough about security/privacy to run a de-googled phone want to use a tap to pay app?
      • microtonal 13 minutes ago
        People use alternatives for many different reasons (or multiple at the same time):

        - They might want privacy from Google. Using Google Pay probably doesn't make much sense.

        - Security protection against Google. Google can remotely brick devices with unsandboxed Play Services. After blocking of ICC officials and all the Greenland threats, it's not odd that some European citizens would like to block this Google/US government attack vector.

        - They want a clean phone without all kinds of crap like Gemini preinstalled.

        - They want to reduce dependence on big tech/Google product in general.

        In cases 2-4, using Google Pay with sandboxed Google Play services may be an acceptable compromise for convenience.

      • collabs 9 minutes ago
        Without Google doesn't mean the same thing for everyone. I got a Motorola g moto stylus 2025 and have been running an experiment for almost a year now in which I use this device without ever logging into the device with a Google account. Fdroid and obtainium work flawlessly. Aurora Store works for the most part but some apps won't even let me open them without a play store signed in account which is sad.
      • podgietaru 19 minutes ago
        Because it’s convenient?
        • inigyou 18 minutes ago
          I agree, it's very convenient to have a phone full of corporate malware. But I thought the point of GrapheneOS was to escape that. My corporate malware only runs on my secure card processor which sits in a pocket glued to my phone.
      • Shish2k 15 minutes ago
        Some people like to have choices other than "all" and "nothing"
      • estimator7292 7 minutes ago
        [dead]
    • wffurr 8 minutes ago
      A phone case with your NFC credit card in a pocket on the back. Boom, problem solved.
    • pitchlatte 1 hour ago
      blows my mind that there’s not a single open solution for mobile wallets and nobody is saying anything.
      • inigyou 58 minutes ago
        You have to negotiate directly with Visa to convince them why they should accept your system. How will you convince them?
        • NooneAtAll3 10 minutes ago
          so what you're saying is we should be looking at competitors of Visa
        • m12k 46 minutes ago
          We desperately need to break Visa's stranglehold on access to the consumer side of commerce. As long as everyone's only innovating and competing on the merchant side of things, we're not really going to get anywhere.
          • inigyou 27 minutes ago
            You're free to make your own card network. How will you convince banks to issue your cards and merchants to accept them?
            • _ZeD_ 17 minutes ago
              You mean like the EU digital wallet
              • inigyou 9 minutes ago
                You're free to try and make something like that.
      • tjoff 1 hour ago
        Because a normal card is superior in most practical cases?
        • BatteryMountain 46 minutes ago
          I'm starting to come the the same conclusion, but not for practical reasons. My thinking is about privacy. If I buy some chocolates from retailer X (with or without their loyalty system), these parties will know what I purchased and where: The retailer, the bank, the merchant (visa/mc), wallet provider (Google/Apple/Samsung). Any upstream 3rd parties for analytics, big data warehouses, ai companies (fraud detection, spending predictions), marketing companies, research companies, manufacturers. Then there are bluetooth beacons, microphones, cameras, facial recognition, keyboard/screen capture (Gboard, Samsung Keyboard, Whatsapp texts). Then there is sms and popup notification on device that gets ingested by x amount of systems too. So the whole pipe just exists to gather as much as possible data to sell me more stuff. Having a card will take some of them out of the loop or less rich metadata than using a digital wallet.
          • inigyou 7 minutes ago
            A card is a good step to reduce that. I want to go farther and pay cash as much as possible, but it's not trivial to manage when all I have is a pocket full of coins. Is there a 3D printed wallet with slots sized for European coins so you can quickly identify and extract the coins you need instead of rummaging through a mixed pocket?
        • wltr 57 minutes ago
          No it’s not, all of my and my extended family cards (for… like a decade!) are never even leave the envelope they come in. I’m not sure I personally know people who use physical cards over Google or Apple Pay. I have seen the cards being used in the wild, of course. But I’m having hard time remembering anyone I personally know who does that.
          • inigyou 6 minutes ago
            How strange that culture is so different in different places. You can just start using them, though. Literally just swipe your card whenever you would swipe your phone.

            Do you guys not have wallets with card slots?

        • askonomm 1 hour ago
          It is? I haven’t carried my wallet around in years, because Apple Wallet does everything I need. Concert tickets, boarding passes, bank cards, public transport cards, etc. A physical wallet and cards in comparison feels like stone age technology.
          • giantg2 47 minutes ago
            Don't you still have to carry cards for things that aren't digitally excepted, such as a drivers license in most states?
          • tjoff 56 minutes ago
            Yes it is. Doesn't break if drop it for one. Much smaller than a phone. Isn't tied to apples ecosystem. etc.

            I get that you might want one if you are a tech maximalist with a single focus. But that doesn't mean you should stop carrying your card.

          • inigyou 57 minutes ago
            Banks and card networks will only accept proprietary shitware as payment. Would you rather keep the malware confined to a separate processor chip or would you let it run on your phone?
            • wltr 53 minutes ago
              In other words, would you like to have your physical card to be lost or stolen and someone paying with it? As small amounts don’t ask for a pin confirmation. Having my phone stolen is pretty much another level of attack.
              • tjoff 45 minutes ago
                Yes... that $25 if they manage to get even that before it is blocked I can live with. Loosing my phone, even if they can't do anything with it is a whole other scenario. Now I can't even get home.
          • ajsnigrutin 14 minutes ago
            And your battery goes empty, and you just lost everything. Or your phone falls to the ground and breaks.

            And to add to payments, the store loyalty apps are the worst... Lidl over here has an app only (no physical loyalty card), and they should be hanged for developing that... first of all, you're waiting in line while a grandma takes her phone out of her purse, then unlock it, and of course android is not satisfied with her fingerprint right then but also wants a pin... then all apps, then scroll down to L, find LidlPlus app, tap on it... QR code? Nope, not yet! First you get a daily coupon wheel of fortune, tap, wait for it to spin, see what your award is... and if it's something that she just bought, she has to manually activate that coupon in the menu (again, tap, find, tap, tap back), and then click the card button to get the qr code to scan... it's literally minutes sometimes of just waiting, instead of scanning a simple qr code on a plastic card pulled from the wallet.

            We even had one of our telcos break down (full internet loss, country wide), POS terminals not working at all, and there are actually people with zero cash with them, not even like 50 euros (for just-in-case (like this))... and then you have to wait for them to turn around, take their stuff back and go home hungry.

      • tonyhart7 1 hour ago
        "open solution for mobile wallets"

        define open wallet then

    • ulrikrasmussen 1 hour ago
      There's Curve Pay which works on GrapheneOS
      • codethief 11 minutes ago
        What cards & banks does it work with these days? Last time I checked, it wasn't really a serious alternative.
      • stkdump 43 minutes ago
        The whole GrapheneOS thing is a bit of a joke. So you either have to buy google hardware or you run google software.

        Anyway, looking forward to the widespread introduction of Wero. Maybe there will be some options for third party roms in the name of digital soveranity. Seems like they want to make the EUDI wallet for digital documents no-google capable for that reason at least.

        • inigyou 28 minutes ago
          You think Google puts backdoors in their hardware? They've consistently been one of the most open hardware brands since the start, always allowing bootloader unlocking and relocking and providing all required open source code. This is not the same as their software which is invasive spyware.
    • tjpnz 1 hour ago
      Google should've been broken up eons ago.
  • nolist_policy 3 hours ago
    Very nice, here are the 11 Android features that must be made accessible to third party's: https://digital-markets-act.ec.europa.eu/developer-portal/in...

    My favorites:

    > 6. Structured on-device integration

    > AI services will be able to easily interact with other apps installed on the device and perform tasks on behalf of the user within those apps, for tasks that the apps and the user have chosen to make available to AI services. These tasks include “send a message”, “create a note”, “schedule a meeting”. This includes access to certain Google apps (i.e.Gmail, Calendar, Drive, Docs, Maps, YouTube, Messages and Phone) that Alphabet will make available through operating system-level integration channels.

    > [...]

    > For instance, Android implements structured on-device integration through App Functions, which developers can enable for their apps, and which can be accessed by AI services without being reserved anymore for Google services, such as Google Assistant or Gemini.

    > 7. Screen automation

    > AI services will be able to automate multi-step tasks within apps, on behalf of the user upon their consent. They will do so by imitating user behaviour in a separate virtual window, which makes it possible for the assistant to complete the task in the background, while the user can do something else. [...]

    > Android implements screen automation via Computer Control, which can automatically access apps, and which is currently reserved for Google’s services, such as Gemini.

    > 9. System-level on-device models

    > AI services will be able to call on existing on-device models (“ODMs”), including the Gemini Nano ODMs, that are part of the DMA designated operating system, already preinstalled on Android devices and already made accessible to third parties. As a result of the measures, third-party AI services will have guarantees of equal access (for example, in terms of performance) to ODMs, as Google’s services. [...]

    > 10. On-device model implementation

    > Third parties will be able to install, run and use on-device models (ODMs) under the same hardware‑resource and background‑execution conditions that Google’s own models enjoy, and will allow their ODMs to be shared centrally with other apps. [...]

    • Aachen 7 minutes ago
      Strange page, it keeps repeating that there are 11 features and then lists four or five, thrice over, and all can be summarised as "equal access for AI voice assistants and dependencies thereof". Then there's some FAQ about the timeline and such. At the very bottom is a link to what seems to be the legal details but ends you up on a search page. Unfolding the only result, there is a link to the 'decision text', which of course you can't just read as text but need to get as a PDF download so the lines can't be broken up and the text is super hard to read using, say, an android phone or screen reader. This format ought to die already.

      Anyway, the actual decision text: https://ec.europa.eu/competition/digital_markets_act/cases/2...

  • OldMatey 2 hours ago
    This is a fabulous ruling and the EU continues (for the moment at least) to be the biggest champion of holding corporations to account and pushing back on entrenched tech power. I know there are bunch of concerning things like chat control getting pushed through but at least there is a counterbalance in other areas as well.
    • afh1 2 hours ago
      [flagged]
      • xgbi 41 minutes ago
        Show us recent rulings in the federal level in the US in favor of people/consumers and ill bail.
  • aatd86 2 hours ago
    Funnily enough, I think it is in Google's best interest to comply and do the best work they can. Besides security that they might want to guarantee up to a limit, that would boost Android usage, also including their own hardware.

    The future lies in a large, local-friendly ecosystem and the hardware to support it.

    Gate keeping software makes even less sense nowadays.

    The competition is on compute offering. Cheaper, faster, at scale. They can have a competitive advantage over incumbents if they stay smart.

    • microtonal 1 hour ago
      Funnily enough, I think it is in Google's best interest to comply and do the best work they can. Besides security that they might want to guarantee up to a limit, that would boost Android usage, also including their own hardware.

      It is not necessarily a competitive advantage, because Apple needs to do the same (which is why they aren't releasing the new iOS 27 Siri, etc. in the EU).

      Apple and Google just took different approaches: Google just released their stuff in violation of the DMA and had the EU come at them. Apple chose to be in compliance before before releasing their assistant updates, though they tried to lobby the EC in favor of releasing now with the promise of adding interoperability in N months.

      I am completely in favor of this. But for Google/Apple the best outcome giving their own assistance preferential treatment. More subscription income.

    • nolist_policy 2 hours ago
      Exactly, this ruling makes Android stronger.
  • aboardRat4 2 hours ago
    This is all smoke and mirrors.

    The core issue is not "Google not allowing a feature", it's that small businesses cannot buy phones, install a patched version of Android without a restriction and sell them to make money.

    Until this problem is solved, everything else is palliative.

    • leni536 1 hour ago
      I recently learned that there is a business doing exactly that:

      https://iode.tech/

      I don't think it's high volume, I think this is done by some of the microg folks.

      But OEMs probably do everything in their power to make this business model unviable or at least not scale.

      • microtonal 1 hour ago
        It is one of many projects that make alternative, AOSP-based operating systems (e.g. GrapheneOS, LineageOS, /e/OS), and some of them sell devices for an additional source of income (e.g. Murena who develop /e/OS also does this).
    • azangru 2 hours ago
      > it's that small businesses cannot buy phones, install a patched version of Android without a restriction

      Pardon my ignorance; but why would Android need to be patched? Is it because it wouldn't run on the phone hardware otherwise?

      • aboardRat4 2 hours ago
        >Is it because it wouldn't run on the phone hardware otherwise?

        Because those 11 features mentioned in the OP post need to be unlocked.

    • pipes 2 hours ago
      What prevents this? I always assumed they could.
      • shock 32 minutes ago
        Bootloaders are locked and most of them are unlockable.
        • inigyou 3 minutes ago
          Most of them are *not unlockable.

          Some of the ones that seem unlockable are actually not unlockable in practice. Like Xiaomi which provides an unlock option that doesn't work unless you work for Xiaomi.

      • aboardRat4 2 hours ago
        https://www.theguardian.com/commentisfree/2026/jan/10/trump-...

        DMCA and other anti-circumvention regulations.

        • pipes 1 hour ago
          That was a good read. But I still thought anyone can take graphene os and put it in a phone and sell it? Maybe there is specific licensing restrictions in the android license that stop this.
    • aatd86 2 hours ago
      Who wants a bootleg Android that sends all your call logs who knows where? xD
      • microtonal 1 hour ago
        Ah, yes, the Google/Apple narrative of "if we open the ecosystem, all users' data is at risk". Meanwhile, they are the companies that continuously harvest behavioral data from phones, put backdoors for law enforcement through weak defaults (iCloud backups are not E2E encrypted, unless you enable ADP), etc. All this while, GrapheneOS, LineageOS, etc. provide real, provable privacy.

        Please stop parroting surveillance tech company's narratives.

      • aboardRat4 2 hours ago
        Emm.. as if Samsung doesn't..?
  • ramblurr 3 hours ago
    Is this ruling related to https://keepandroidopen.org/ at all? It's not clear to me..
  • motbus3 33 minutes ago
    I wonder what happened to the laws the limited market monopoly and trust
  • hollow-moe 2 hours ago
    What a shame. How much time and €M spent just to deign allow you to do some very specific stuff on their devices (in 5 years at least once the trials and shenanigans settle) ? Obviously it doesn't include the "answering call screening" for example, which requires very privileged APIs accessible only by "system" apps, i.e. the ones preinstalled in the ROM. How about RCS ? Remember RCS the "open" standard replacing SMS ?
    • microtonal 2 hours ago
      RCS is a nothingburger in Europe, virtually everybody uses WhatsApp (and a smaller group also Signal, etc.). RCS is especially relevant to the US where many people use iMessage and the downgrade path is SMS/MMS.
      • hollow-moe 1 hour ago
        Whoops my bad then, disregard previous post. Creating a facebook account at once with my national id in addition to my carrier subscription. Gotta love US dependency.
        • inigyou 2 minutes ago
          WhatsApp accounts aren't linked to Facebook accounts - well, not publicly - I'm sure they know you're the same person on the backend. You only need a phone number to sign up to WhatsApp. If that wasn't the case, it wouldn't be as popular.
  • Cider9986 2 hours ago
    So they are gonna add these to AOSP?
    • hollow-moe 2 hours ago
      Obviously no, it will be another API in Google Mobile Services and you'll have to register to them to be allowed to use it.
  • rswail 1 hour ago
    Does this apply to Apple to have something separate to Siri in iOS?
  • JoshTriplett 2 hours ago
    Now if only these rulings also covered attestation.
    • microtonal 2 hours ago
      Indeed. This ruling seems to be targeted at AI specifically. It is a great ruling, because it allows proper competition of other assistants with Google's (and Bixby). However, IMO the bigger evil is all the anti-competitive stuff that make it impossible for competitors to Android/iOS to enter the market, including European products like SailfishOS, such as remote attestation and the things that flow from it (e.g. no tap-to-pay support with most banks). The EC seems very pre-occupied with competition inside Android/iOS, while completely forgetting about competition between mobile OSes.

      It is also pretty jarring to see the EU talk a lot about sovereignty, but then further entrenching the Android/iOS duopoly by baking remote attestation into the EUDI reference wallet (and copied into the national wallets), effectively shutting out alternative systems yet again.

      Yes, I know that the EU consists of a lot of bodies and sometimes the right hand doesn't know what the left hand does. But man, sometimes I wish there was a stronger single, long-term vision. Somehow they seem to have forgotten about January this year (Greenland threats) and that as long as we fully depend on Android/iOS, etc. the US could shut down pretty much all modern communication infra. But instead of solving these vulnerabilities now and pouring money into alternatives, we (as the EU) drag ourselves down into battles of just how much we can do on the terrain of some feudal overlords.

      It seems like there is a short window where we still have AOSP systems that could be workable for the large population (outside remote attestation, pretty much all apps run on GrapheneOS, microG, etc.) and Google's strong arming through developer verification and remote attestation could still be put back in the box. But the EC does nada, nothing (presumably).

      • inigyou 1 minute ago
        Phone-tap-to-pay is not a real blocker. In fact I think it should be illegal for all vendors. Just use your physical plastic card. Stick it on the back of your phone if you like.
      • eszed 1 hour ago
        I agree that attestation is the biggest deal. My current hope is that the upcoming GrapheneOS phones will be able to achieve that. It's really up to a manufacturer being able to strong-arm third-parties - banks and such - into accepting their chain of trust, and Motorola may be able to do that.
        • microtonal 22 minutes ago
          I don't think the upcoming Motorola phones will change this by themselves. As far as I understand, Motorola will not directly sell GrapheneOS phones. They will make phones that fulfill the hardware requirements and work with the GrapheneOS team to make the firmware available, etc. It will still be up to the user to install GrapheneOS.

          That has benefits - you do not have to trust Motorola not to ship stuff that you wouldn't want in the image. They are pristine images that the GrapheneOS project provides. But it also probably doesn't get Motorola in hot water with Google, since they partially do the same as Google does (provide phones with unlocked bootloaders) and what Google used to do (open drivers, device trees, etc.). Plus there are other OEMs that have similar partnerships with other projects (e.g. Fairphone).

          into accepting their chain of trust

          It's GrapheneOS who will sign the images, not Motorola.

          Speaking of Europe, Motorola is probably not big enough here to strong-arm parties. Besides that, I don't think they will do that, since they have to stay in good graces with Google for distributing GMS Android.

          I think for Motorola, there are three wins: 1. GrapheneOS has hundreds of thousands of users now, for a smaller OEM capturing some of that market is a significant addition; 2. they want to have a security-focused offering; GrapheneOS can provide that; and 3. they probably want to strengthen their position towards Google. Samsung has their own app store, device finding ecosystem, etc., this tells Google - if you take too much power, we can go our own way. If the Motorola-GrapheneOS experiment is successful, this could provide a similar contingency plan that might hold Google from trying to reign in OEMs too much. This is a real risk for Google - Pixel is so small in terms of marketshare that if, say Samsung, would go on its own, Google Android is pretty much dead.

          At any rate, I think Motorola-GrapheneOS can have more of an indirect effect. I think Play Integrity remote attestation will fall if GrapheneOS can quickly get so many users that they become a force to reckon with. In the past, it helped when GrapheneOS users e-mailed an app developer that switched to strong Play Integrity. This will be much more powerful if the GrapheneOS user base grows 10x and more growth is probably possible if there are non-Google devices (especially because part of the potential user base does not want to give a cent to Google).

          Getting the EU to ban Play Integrity as-is probably has a much larger chance of succeeding though. This is why I always recommend people to file a DMA complaint/contact the DMA team when some app gets blocked on alternative ROMs due to Play Integrity. The DMA team needs to see/feel that this affects a lot of real people.

      • tonyhart7 1 hour ago
        I mean EU have 20 years to make android/ios competition and they aren't able to replicate it so its them to blame

        also they should not abandon Nokia back then

  • deepnet 3 hours ago
    Stallman was right : without the four freedoms your software owns you rather than vis-a-versa.

    Interoperability is the key to breaking out of walled gardens and owning your own data and digital self.

    This is a big win but google will fight back it seems instead of embracing interoperability.

    It may seem trivial but using a small DSP running a tiny model to provide a battery efficient always on wake up call for home AI is huge.

    As a carer for elders who rely on AI to use modern devices in the face of their difficulty keeping up with interface changes this bodes well.

    Gatekeeping AI and the future with hidden features is straight out of the bad old days of M$’s embrace, extend and extinguish.

    I embraced AI to let my elders control their home and they love being in control but are constantly frustrated with UI changes and often find themselves stuck unable to call me with ‘Alexa call Daniel’ which provides them with hope if they wake stuck in a nightmare.

    Come on google, please don’t be evil embrace interoperability and the open source community.

    Well done Eff, Cory Doctorow and the Pirate parties of Europe for this small win

  • stavros 4 hours ago
    Excellent, now please force them to open up app installation again!
  • Varsham_26 26 minutes ago
    [dead]
  • deadlast2 2 hours ago
    Now let's bite the apple.
  • Brian_K_White 4 hours ago
    Is "in the EU" the new "in mice"?
    • Almondsetat 3 hours ago
      Considering it has the same population as the US, are you also mice?
      • Pay08 2 hours ago
        The EU has approximately 110 million more people than the USA.
    • stavros 4 hours ago
      Only if you consider Europeans mice, I guess?