>and scammers can theoretically let you open up an adb shell and run an am command
It requires a lot more steps to do this. Finding another computer, installing Android dev tools, finding a cable to connect them. In reality this adds a lot of friction.
>How do you know nothing will happen to already-installed apps and their data, when the user hasn't had time yet to go through the annoyance unlock procedure?
Extrapolation based off how play services has handled things so far and how Google has explained what will happen. Of course without looking at the actual code I can't say for 100% certainty, but from my perspective fdroid is fear mongering here as there is no evidence that supports this viewpoint. If they had evidence to back these dramatic claims up I would be less critical on them.
> It requires a lot more steps to do this. Finding another computer, installing Android dev tools, finding a cable to connect them. In reality this adds a lot of friction.
That's exactly the point. I think it's fair to require people to use a command line (and go through the steps that we already need to get there) to do advanced things. My grandma is an excellent comprehenseless button presser but, when faced with an "MS DOS" window, even she would be stumped at how to fuck up her system :-). Yet that's not what Google is doing and thus I concluded in that paragraph:
> > it's just about ecosystem control and not actually for user safety.
Regarding destruction of data, Android does actively remove people's data unasked. Just today I got another one of these notifications "you haven't used these apps in the last 3 months, we've removed the permissions you've set", and I previously made the mistake of ignoring that annoyance but now I know it'll move to stage 2 "we've removed your user data, enjoy!" after something like half a year. One of those apps is one of the 2FA apps I have and need less than once a year for e.g. an insolvency I'm involved in (a slow process). They'd remove the hard-to-recover 2FA secrets if I don't actively move to prevent that. (Having root for making backups makes this a bit less impactful thankfully, but the average person doesn't know how to make full-system backups.)
It requires a lot more steps to do this. Finding another computer, installing Android dev tools, finding a cable to connect them. In reality this adds a lot of friction.
>How do you know nothing will happen to already-installed apps and their data, when the user hasn't had time yet to go through the annoyance unlock procedure?
Extrapolation based off how play services has handled things so far and how Google has explained what will happen. Of course without looking at the actual code I can't say for 100% certainty, but from my perspective fdroid is fear mongering here as there is no evidence that supports this viewpoint. If they had evidence to back these dramatic claims up I would be less critical on them.