Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

41–50 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#41

Earlier quoted context omitted.

I don't see that on the page

They already announced it. Here they only mention the special case where it does not apply: > In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee. i.e. Government-issued ID and fees are needed for more than 20 device…

Enforcement of the device restriction would also mean they also are collecting information from your device about the app.

Re: Google details new 24-hour process to sideload unverified Android apps

#42

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

We'll see when this rolls out, but I don't foresee the package manager checking for developer mode when launching "unverified" apps, just when installing them. AFAICT the verification service is only queried on install currently.

Googler here (community engagement for Android) - I looked into the developer options question, and it's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled.

If you turn off developer options, then to turn off the advanced flow, you would first have to turn developer options back on.

Re: Google details new 24-hour process to sideload unverified Android apps

#43

Earlier quoted context omitted.

I predict that they're going to introduce further restrictions, but I think the restrictions will only apply to certain powerful Android permissions. The use case they're trying to protect against is malware authors "coaching" users to install their app. In November, they specifically called out anonymous malware apps with the permission to intercept text messages and phone calls (circumventing two-factor authenticat…

> But it should be very hard/expensive for a malware author to anonymously distribute an app with the permission to intercept texts and calls. And how hard/expensive should it be for the developer of a legitimate F/OSS app to intercept calls/texts?

For a security-sensitive permission like intercepting texts and calls, I'm not sure it makes sense for that to be anonymous at all, not even for local development, not even for students/hobbyists.

Getting someone to verify their identity before they have the permission to completely takeover my phone feels pretty reasonable to me. It should be a cheap, one-time process to verify your identity and develop an app with that much power.

I can already hear the reply, "What a slippery slope! First Google will make you verify identity for complete phone takeovers, but soon enough they'll try to verify developer identity for all apps."

But if I'm forced to choose between "any malware author can anonymously intercept texts and calls" or "only identified developers can do that, and maybe someday Google will go too far with it," I'm definitely picking the latter.

Re: Google details new 24-hour process to sideload unverified Android apps

#44

The forced ID for developers outside the Play store is already killing open source projects you could get on F-Droid. The EU really needs to identify this platform gatekeeping as a threat. As an EU citizen I should not be forced to give government ID to a US company, which can blacklist me without recourse, in order to share apps with other EU citizens on devices we own.

[flagged]

The DSA covers App stores with a large numbers of users - this is about allowing users side load unsigned apps. Afaik there is no requirement to identify the developers of applications that can be installed on a vendors platform (outside the app store). Otherwise Microsoft would require Government ID to compile and email someone an EXE.

Re: Google details new 24-hour process to sideload unverified Android apps

#45
post #13

Seems like a very reasonable compromise. What's the catch?

I don't find it reasonable that Google wants to make me wait 24h to install software on a device I own.

Meh. I get the annoyance, but it's a one time cost for a small subset of their users. I would prefer if there was a flow during device setup that allowed you to opt into developer mode (with all the attendant big scary warnings), but it's a pretty reasonable balance for the vast majority of their users. (I suspect the number of scammers that are able to get a victim to buy a whole new device and onboard it is probably very low).

Re: Google details new 24-hour process to sideload unverified Android apps

#47

Seems like a very reasonable compromise. What's the catch?

Developers, including non-US citizens, are forced to give Google their government ID to distribute apps. This enables Google to track and censor projects, like NewPipe, an alternative open source Youtube frontend, by revoking signing permissions for developers.

>Developers, including non-US citizens, are forced to give Google their government ID to distribute apps.

Developers can choose to not undergo verification, thereby remaining anonymous. The only change is that their applications will need to be installed via ADB and/or this new advanced flow on certified Android devices.

Either way, you can still distribute your apps wherever you want. If you verify your identity, then there are no changes to the existing installation flow from a user perspective. If you choose not to verify your identity, then the installation will still be possible but only through high-friction methods (ADB, advanced flow). These methods are high-friction so anonymous scammers can't easily coerce their victims into installing malicious software.

Re: Google details new 24-hour process to sideload unverified Android apps

#48
post #35

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

> - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? What apps are those? I've yet to run into any of my banking apps that refuse to run with developer mode enabled. I've seen a few that do that for rooted phones but that's a different story. I've been running android for a decade…

RBC in Canada for instance, just having developer mode enabled blocks it here

Re: Google details new 24-hour process to sideload unverified Android apps

#50

Seems like a very reasonable compromise. What's the catch?

Developers, including non-US citizens, are forced to give Google their government ID to distribute apps. This enables Google to track and censor projects, like NewPipe, an alternative open source Youtube frontend, by revoking signing permissions for developers.

That's not correct - the flow described in the post outlines the requirements to install any apps that haven't had their signature registered with Google.

That means those apps still keep on existing, they are just more of a hassle to install.

Post reply on HN