Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

51–60 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#51
post #25

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

The one-day waiting period is so arbitrary. Have they demonstrated any supporting data? We know google loves to flaunt data. Something like Github's approach of forcing users to type the name of the repo they wish to delete would seem to be more than sufficient to protect technically disinclined users while still allowing technically aware users to do what they please with their own device.

To paste code into the chrome dev console you just need to type “allow pasting”

Re: Google details new 24-hour process to sideload unverified Android apps

#54
post #30
post #25

Earlier quoted context omitted.

The one-day waiting period is so arbitrary. Have they demonstrated any supporting data? We know google loves to flaunt data. Something like Github's approach of forcing users to type the name of the repo they wish to delete would seem to be more than sufficient to protect technically disinclined users while still allowing technically aware users to do what they please with their own device.

> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.

Sure, but what about a 30 minute delay? 1 hour? 2 hour?

24 is just so long.

But also, my expectation is that a scammer is going to just automate the flow here anyways. Cool, you hit the "24 hour" wait period, I'll call you back tomorrow, the next day, or the next day and continue the scam process.

It might stop some less sophisticated spammers for a little bit, but I expect that it'll just be a few tweaks to make it work again.

Re: Google details new 24-hour process to sideload unverified Android apps

#55
It's not like the Google Play store hasn't been known to host malicious apps, yet you are not required to wait 24 hours before you install apps from their store.

I suspect they are hoping users just give up and go to the play store instead. Google touts about "Play Protect" which scans all apps on the device, even those from unknown sources so these measures can barely be justified.

Imagine if Microsoft said you need to wait 24 hours before installing a program not from their store, which is against the entire premise of windows.

Computing, I once believed was based on an open idea that people made software and you could install it freely, yes there are bad actors, but that's why we had antivirus and other protection methods, now we're inch by inch losing those freedoms. iOS wants you to enter your date of birth now.

The future feels very uncertain, but we need to protect the little freedoms we have left, once they're gone, they're gone for good.

Re: Google details new 24-hour process to sideload unverified Android apps

#56

I'm generally OK with this, but the 24 hour hang time does seem a bit onerous. Most of the apps on my phone are installed from F-Droid. I guess the next time I get a new phone I'll have to wait at least 24 hours for it to become useful. I'm seriously considering Graphene for a next personal device and whatever the cheapest iOS device is for work.

If my employer wants me to use a phone for work, they can buy whatever phone they want for me. I'm not going to buy a separate one just for them.

Re: Google details new 24-hour process to sideload unverified Android apps

#57

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

So... we're just going to move the scam into convincing the end user to run an application on their PC to ADB sideload the Scam App. Got it, simple enough. It's not hard to coach a user into clicking the "no, I'm not being coached" button, too, to guide them towards the ADB enable flow.

Re: Google details new 24-hour process to sideload unverified Android apps

#58

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

> ADB installs are not impacted by the waiting period, so that is an option if you need to install certain unregistered applications immediately.

Someone is just going to make a nice GUI application for sideloading apks with a single drag-and-drop, so if your idea is that ADB is a way to ensure only "users who know what they're doing" are gonna sideload, you've done nothing. This is all security theatre.

Re: Google details new 24-hour process to sideload unverified Android apps

#59

I'm generally OK with this, but the 24 hour hang time does seem a bit onerous. Most of the apps on my phone are installed from F-Droid. I guess the next time I get a new phone I'll have to wait at least 24 hours for it to become useful. I'm seriously considering Graphene for a next personal device and whatever the cheapest iOS device is for work.

The apps might not be available though. Many developers are simply stopping in the face of Google's invasive policies. I don't blame them. Say goodbye to useful apps like Newpipe.

I don't see anything on NewPipe's website about not continuing development?

Re: Google details new 24-hour process to sideload unverified Android apps

#60
post #38

Earlier quoted context omitted.

> But it should be very hard/expensive for a malware author to anonymously distribute an app with the permission to intercept texts and calls. And how hard/expensive should it be for the developer of a legitimate F/OSS app to intercept calls/texts?

Yep, I have a legitimate use case for exactly this. It integrates directly with my application and gives it native phone capabilities that are unavailable if I were to use a VoIP provider of any kind.

As a legitimate developer developing an app with the power to take over the phone, I think it's appropriate to ask you to verify your identity. It should be an affordable one-time verification process.

This should not be required for apps that do HTTPS requests and store app-local data, like 99%+ of all apps, including 99% of F-Droid apps.

But, in my opinion, the benefit of anonymity to you is much smaller than the harm of anonymous malware authors coaching/coercing users to install phone-takeover apps.

(I'm sure you and I won't agree about this; I bet you have a principled stand that you should be able to anonymously distribute malware phone-takeover apps because "I own my device," and so everyone must be vulnerable to being coerced to install malware under that ethical principle. It's a reasonable stance, but I don't share it, and I don't think most people share it.)

Post reply on HN