Live data from Hacker News

What we talk about when we talk about sideloading

f-droid.org

201–210 of 646 posts

Re: What we talk about when we talk about sideloading

#201

Earlier quoted context omitted.

Hey, question. While I'm also miffed about Google's decision and see your point about the term sideloading, there is another elephant in the room you seem to not be addressing here. You write: > “Sideloading is Not Going Away” is clear, concise, and false_ But isn't Google saying that you will still be able to sideload via ADB ? Which would mean their statement is true, and that your claim that Google's statement is…

As I understand it, the delivery mechanism won't matter: Play Store,ADB, F-Droid, Bluetooth, or website. If the APK isn't signed by a Google-approved developer, it's not going to install. If there's some ADB command that one can issue to install unsigned APKs for now, it's a temporary reprieve at best. Two Android versions later, the update from Google will read "Only 0.02% of users installed apps using adb, but the…

No, that adb command is how you test install things. They wouldn't want to force public uploads to Play just to test.

Re: What we talk about when we talk about sideloading

#202

Is this seeking Google’s approval for the app? Or is the condition app be signed by a verified user? The latter means side loading is still viable for apps from known developers . This way anyone who is known who may create malware and will not be free from prosecution

It is the latter. The app has to be signed, and the signer has to register "real" identity with Google. Approval of the app itself is not a part of the process.

Yes, sideloading will still be viable from known developers.

Probably malware developers will still be free from prosecution -- what moron is going to distribute malware with their own identity attached to it? But it means when the malware gets caught (which it does) you can't just roll a new APK with a different signature. You've burned a developer identity and need a new one. Those are harder to come by, and so it rate-limits malware distribution.

Re: What we talk about when we talk about sideloading

#203

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

Hey, question. While I'm also miffed about Google's decision and see your point about the term sideloading, there is another elephant in the room you seem to not be addressing here. You write: > “Sideloading is Not Going Away” is clear, concise, and false_ But isn't Google saying that you will still be able to sideload via ADB ? Which would mean their statement is true, and that your claim that Google's statement is…

adb is a developer tool. You need a tethered and trusted computer to be able to transfer an app using adb, and you need to enable "developer mode" on the device, which is an arcane dance that involves navigation through an obscure tree of settings and then quickly tapping a mystery spot 5+ times. Google can't block adb, because that is how Android apps are developed and tested, just how Apple cannot block their developer tools from being able to transfer apps onto an iPhone.

This is so far from a realistic and acceptable substitute that I question the honesty of anyone who claims that "adb will still work, so no problem!"

I hope that explains my seemingly critical omission.

Re: What we talk about when we talk about sideloading

#204
post #30
post #3

I realize F-droid has an understandably strong opinion here, but this writing is disingenuous. From the post: > Regardless, the term “sideload” was coined to insinuate that there is something dark and sinister about the process, as if the user were making an end-run around safeguards that are designed to keep you protected and secure. But if we reluctantly accept that “sideloading” is a term that has wriggled its way…

You argue here that google is technically correct because they’re correctly using sideload. But that isn’t the point people are angry about. The point is that sideload was a misnomer. Correctly Android users were able to install packages and now cannot. This is anti consumer and breaks the social contract. Anyway this is so disingenuous that I think it’s astroturf. Here’s the meme we should’ve spreading: Chrome and A…

> Correctly Android users were able to install packages and now cannot.

Not only has nothing happened yet, but this is also untrue.

Re: What we talk about when we talk about sideloading

#205
post #84

Earlier quoted context omitted.

> and "installing" doesn't work because that doesn't distinguish from installing from the Play Store I'm not choosing sides, but why do you need a term to distinguish from installing from the Play Store? On my Debian machine I install git from apt (officially supported) but also install Anki from a tarball I downloaded from a website. Same term `install`.

Because Google isn't trying to prevent installing, just "sideloading".

I hereby name the thing that Google wants to allow "supplicating an app(lication)". Installing puts software on a device. Supplicating asks Google for an app, and maybe it gets installed.

Re: What we talk about when we talk about sideloading

#206

Earlier quoted context omitted.

As I understand it, the delivery mechanism won't matter: Play Store,ADB, F-Droid, Bluetooth, or website. If the APK isn't signed by a Google-approved developer, it's not going to install. If there's some ADB command that one can issue to install unsigned APKs for now, it's a temporary reprieve at best. Two Android versions later, the update from Google will read "Only 0.02% of users installed apps using adb, but the…

No, that adb command is how you test install things. They wouldn't want to force public uploads to Play just to test.

They could go the apple way and sign an annoyingly shortlived cert.

Re: What we talk about when we talk about sideloading

#207

I think we could set the bar substantially higher. Don't even bother with discussion of sideloading. Talk about bounded transactions and device control. What is needed is: Once I have purchased a device, the transaction is over. I then have 100% control over that device and the hardware maker, the retailer, and the OS maker have a combined 0% control.

People always say things like these, and I wish it were that way too. Maybe if history had gone a little differently. But what's the point of defining these standards now? Is the world where this is the reality still feasible? It seems nearly impossible, unless you're an extremely wealthy and influential individual. What I'm seeing is that we never will move to a world where a device that you bought is truly "yours"…

Ubuntu for android?

Re: What we talk about when we talk about sideloading

#208
post #193
post #182

Earlier quoted context omitted.

Forcing ADB may as well be a ban, if you don't see that, you're pretty out of touch with consumers. Sideloading is already hard enough for many, forcing the use of an extra computer, a dev tool in the CLI, and dev mode is way way outside what people will do

The number of people that don't even own a general purpose computer is huge. And for those that do, ADB is a ridiculous thing to get setup for a particular device. I get paid to work on android software, and I don't even want to put up with the hassle.

you don't need a computer to run adb. there's install with options

Re: What we talk about when we talk about sideloading

#209

Earlier quoted context omitted.

put a fork in it, it's done,almost! android that is. linux phones are comming up fast, and will be set up to run the droid apps we like. but big props to fdroid just used "etchdroid" to transfer a linux iso to a thumb drive and boot a new desk top, and if I get a few bucks ahead I will buy a dev board from these guys https://liberux.net/ flinuxoid?, flinux?

Linux phones are...what? Oh, just like Linux won the desktop. Never mind.

As far as I'm concerned, it did. Linux is far and away the best OS for my needs so I'll keep using it.

Did it "win" more of some metric of perfusion / capital versus the other big two? Perhaps some, mostly not. Who cares. The market is dumb.

What matters here is whether the capability exists at all. When it comes to phones, I'm still leery about linux. Support isn't quite wide enough and for a device that I need 110% reliability out of we ain't there yet.

I do know one thing - the effects of closed ecosystems that caused 99.99999% of servers to use linux, will eventually come for interface hardware. Companies have periodic bouts of psychosis that make their walled gardens inherently unreliable. It's just a whole lot slower in a realm that doesn't iterate at web-speed. Will that mean everybody uses linux phones in the future? Of course not. But I do hope it will mean I get to put my own phone together with an OS I own, someday. That would be an unequivocal good.

Re: What we talk about when we talk about sideloading

#210
post #161
post #83

I’m honestly very tired of this argument, everything about it is bad. Features aren’t rights, if you want a phone that let’s you run whatever you want, buy one or make it yourself. What you’re trying is to use the force of the state to make mandatory a feature that not only 99% users won’t use, it vastly increases the attack surface for most of them, specially the most vulnerable. If anyone were trying to create a wo…

It's a proper argument on its surface, complete with claim, warrant, and impact. "Features aren't rights" > see: Consumer Rights. "Force of the state making sideloading mandatory is bad" > ...Except we have antitrust laws? The Play Store becomes the only source of apps, all transactions are routed through Google Billing? Not a problem for you? "99% users won't use" > Except for when Google demands that transactions h…

> "Features aren't rights" > see: Consumer Rights.

Consumer rights aren’t features, and they’re very intentionally written to not be.

> "Force of the state making sideloading mandatory is bad" > ...Except we have antitrust laws?

Then sue them over those.

> Listen, either it's the case that "sideloading" is a threat to normies or it's not. Are normies your 1% or 99% of users? I thought according to you 99% of users won't sideload.

I meant that 99% of users aren’t afraid by the term “sideloading”. That you’re not using something doesn’t mean you’re afraid of it, it just means you don’t want it.

> you're right, why not let corporations be corporations and do anti-consumer things, they'll be very good to us (while they lobby the state).

Because corporations tend to die when they do anti-consumer things, but governments keep doing anti-citizen things without much trouble.

Post reply on HN