Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

61–70 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#61

I'll say it again: this isn't a problem for Android to solve. Scammers will naturally adapt their "processes" to account for this 24-hour requirement and IMO it might make it seem more legitimate to the victim because there's less urgency. The onus of protecting people's wealth should fall on the bank / institution who manages that persons wealth. Nevertheless, this solution is better than ID verification for devs.

Why should the bank/institution be responsible for protecting individuals from themselves? They don't have police power- protecting people from bad actors is like, the reason to have a state. If the state wishes to farm it out to third parties, then we don't need the state anymore!

Re: Google details new 24-hour process to sideload unverified Android apps

#62
post #30
post #25

Earlier quoted context omitted.

The one-day waiting period is so arbitrary. Have they demonstrated any supporting data? We know google loves to flaunt data. Something like Github's approach of forcing users to type the name of the repo they wish to delete would seem to be more than sufficient to protect technically disinclined users while still allowing technically aware users to do what they please with their own device.

> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.

Have you ever watched Kitboga? Scammers call people back all the time. They keep spreadsheets of their marks like a CRM. It takes time to build trust and victimize someone, and these scammers are very patient.

Re: Google details new 24-hour process to sideload unverified Android apps

#63
post #30
post #25

Earlier quoted context omitted.

The one-day waiting period is so arbitrary. Have they demonstrated any supporting data? We know google loves to flaunt data. Something like Github's approach of forcing users to type the name of the repo they wish to delete would seem to be more than sufficient to protect technically disinclined users while still allowing technically aware users to do what they please with their own device.

> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.

Scammers already will spend multiple days on a scam call. Watch some Kitboga videos, he'll strings them along for a week.

"Google will call you again tomorrow to get you your refund."

There, we've successfully circumvented all of Google's security engineering on this "feature."

Re: Google details new 24-hour process to sideload unverified Android apps

#64
Is there an accurate, neutral third party link about this that we can make the primary link instead?

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...?

Edit: I've put one up there now - if there's a better article, let us know and we can change it again. I put the submitted URL in the toptext.

Re: Google details new 24-hour process to sideload unverified Android apps

#65
Do you need a Google account to opt out of the restriction? It says something about authenticating.

I don't have a Google account on my Androids. But I can't remove play services on them, sadly. As an intermediate protection I just don't sign in to Google play, that gives them at least a bit less identifying information to play with.

I hope this can be done without a Google account.

Re: Google details new 24-hour process to sideload unverified Android apps

#66

I'll say it again: this isn't a problem for Android to solve. Scammers will naturally adapt their "processes" to account for this 24-hour requirement and IMO it might make it seem more legitimate to the victim because there's less urgency. The onus of protecting people's wealth should fall on the bank / institution who manages that persons wealth. Nevertheless, this solution is better than ID verification for devs.

Why should the bank/institution be responsible for protecting individuals from themselves? They don't have police power- protecting people from bad actors is like, the reason to have a state. If the state wishes to farm it out to third parties, then we don't need the state anymore!

The bank/institution is where the money is leaving from therefore they should implement policies that protect vulnerable customers like seniors, for example. I don't know how that looks but it seems reasonable that they could put limits on an account flagged "vulnerable person"

I'm not sure what you're getting at with the rant about police power and a state? Google isn't the government either. What would legislation provide that banks can't already do today?

Re: Google details new 24-hour process to sideload unverified Android apps

#67
post #35

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

> - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? What apps are those? I've yet to run into any of my banking apps that refuse to run with developer mode enabled. I've seen a few that do that for rooted phones but that's a different story. I've been running android for a decade…

Wero in Europe. It's really insane. They make wero to make us less dependent on US tech and then hamstring it in this way.

Re: Google details new 24-hour process to sideload unverified Android apps

#68
Death, taxes and escalating safety are the only certainities in this tech dominated world. So, be ready for more safety in the next round few months/years down the line. Eventually Android will become as secure as ios. We need a third alternative before that day comes.

It's not a win by any means. I hope that we don't stop making noise.

Re: Google details new 24-hour process to sideload unverified Android apps

#69

I'll say it again: this isn't a problem for Android to solve. Scammers will naturally adapt their "processes" to account for this 24-hour requirement and IMO it might make it seem more legitimate to the victim because there's less urgency. The onus of protecting people's wealth should fall on the bank / institution who manages that persons wealth. Nevertheless, this solution is better than ID verification for devs.

Why should the bank/institution be responsible for protecting individuals from themselves? They don't have police power- protecting people from bad actors is like, the reason to have a state. If the state wishes to farm it out to third parties, then we don't need the state anymore!

Yea I have no idea why the original commenter thinks Banks should have the power to tell me what I can and can't do with my own money.

It's nice that Zelle has checks and identity information shown to you when you're sending money, but if I click through 5 screens that say "Yes I know this person" but I actually don't.....no amount of regulation is going to solve that.

Re: Google details new 24-hour process to sideload unverified Android apps

#70
post #2

tl;dr: - You need to enable developer mode - You need to click through a few scare dialogs - You need to wait 24h once I wonder how long this will last before they lock it down further. There was a lot of pushback this time around and they still ended up increasing the temperature of the metaphorical boiling frog. It still seems like they're pushing towards the Apple model where those who don't want to self-dox and/o…

Will these measures eliminate fraud? Of course not. What a shame; I guess we'll need to lock down the platform even further.

This is so overt.

Post reply on HN