Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

221–230 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#221
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

I “get” technology so I understand how you got here.

But this is the wrong take. I expect to go to a restaurant and not die from the food… and I want nothing to do with the inner workings of the kitchen. I just want to know any restaurant I go into will be safe. Society has made restaurants safe, either because of government pressure or it’s good for business.

How is that not a fair ask for technology, too? We all have things we know well, and then there’s reasons we’re alive that we don’t even know exist because someone took care of it.

It’s unreasonable to only allow people to participate in society once they understand every nuance.

Re: Google details new 24-hour process to sideload unverified Android apps

#222
post #156

Earlier quoted context omitted.

I was always under the impression security was a red herring and the real reason was control. Google wants to own the device and rent it to users with revocable terms the same way SaaS subscription software works. Locking down what can run is a key step in that process

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

Then don't issue an app. Issue people cards to pay with and let them come to the bank for weird transactions.

Re: Google details new 24-hour process to sideload unverified Android apps

#223

I'd rather not have to go through this ritual, but I appreciate that there is a genuine security problem that google are trying to address. I also suspect that they have other motivations bound-up in this - principally discouraging use of alternative app stores. But basically I could live with this process. Yeah, I know... Stockholm syndrome... Although I may not have to live with it, as none of my present devices ar…

I don't think developers targeting alternative app stores would care much about having to perform verified developer registration. Particularly apps that are available in both Play Store and alternative app stores.

Re: Google details new 24-hour process to sideload unverified Android apps

#224
post #185
post #112

Earlier quoted context omitted.

This is hopefully an exciting time to consider a Motorola device, since they are partnering with GrapheneOS, but I worry that Google will block Google Play Services on any device that doesn't comply, so this might actually be a demoralizing time to be a GrapheneOS fan, when we watch them worm their stupid walled garden nonsense into the Motorola version of it.

Blocking Play might not be that bad if some frameworks/efforts crop up to allow easily targeting devices without it.

The vast majority of apks work just fine without Google libraries. In some rare cases, things such as notifications that depend on Google's servers may not work if the developers haven't not implemented an alternative backend such as a direct connection.

Re: Google details new 24-hour process to sideload unverified Android apps

#225
post #213
post #150

Earlier quoted context omitted.

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

It's kinda dumb that you can't tap your card. At least they have a phone option, but really, why no CC?

I'm guessing it's a lot more expensive to install and maintain card readers than to essentially just have signs prompting people to use their phone.

Re: Google details new 24-hour process to sideload unverified Android apps

#226
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

I “get” technology so I understand how you got here. But this is the wrong take. I expect to go to a restaurant and not die from the food… and I want nothing to do with the inner workings of the kitchen. I just want to know any restaurant I go into will be safe. Society has made restaurants safe, either because of government pressure or it’s good for business. How is that not a fair ask for technology, too? We all ha…

You could torture the analogy more and say that this is more like saying "it is possible to make bad food and kill yourself at home, so we require everyone to go to a restaurant."

Re: Google details new 24-hour process to sideload unverified Android apps

#227
post #68

Death, taxes and escalating safety are the only certainities in this tech dominated world. So, be ready for more safety in the next round few months/years down the line. Eventually Android will become as secure as ios. We need a third alternative before that day comes. It's not a win by any means. I hope that we don't stop making noise.

Google serves ads with known scams and nothing seems done about it. Yet, they are concerned about this. It has nothing to do with safety, but everything to do with control. I remember when Google disabled call recording in Android, so you no longer could record scammers. Thanks to recording I was able to get money back from insurance company that claimed they absolutely didn't sell me this and that over the phone (pa…

> I remember when Google disabled call recording in Android, so you no longer could record scammers.

Citation needed. My Pixel 7a with the latest updates has settings for call recording in the phone app. Since I never screwed around with it, I'd assume these are the defaults:

Call recording is turned on, with "asks to record calls" set

Automatically delete recordings is "never"

Automatically record calls with non-contacts is off

No specific numbers to automatically record calls are set

There is also a note that you have to agree to their ToS to use it, and I'd also suggest being careful if you live in a jurisdiction that requires two-party consent for recording.

In any case, I'm of the opinion that if F-Droid goes, I'm basically going to treat this as a feature phone and stay away from third-party apps in general aside from "musts" like banking.

Re: Google details new 24-hour process to sideload unverified Android apps

#228
post #157

Earlier quoted context omitted.

> Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. This isn't about how skilled a person is, it is about tackling social engineering. The article gave the example of someone posing as a relative, it could also be a blackmail scheme, but it could also be the carefully planned takeover of a respected open source project (ahem, xz). What I am…

There's quite a gap between this sort of opportunistic scamming that's happening all over the world and targeted multi-year campaigns that probably require the resources of a nation state.

True, but that kinda misses the point.

One way to look at it: there are many open source projects targeting Android, projects that gain some sense of legitimacy over being open source yet have few (if any) eyes vetting them. Or, perhaps, the project is legitimate but people are getting third-party builds. That is what F-Droid does. That is what the developer of a third-party ROM does. It would not require the resources of a nation state to compromise them. I am not trying to cast a shadow on open source projects or F-Droid here. I am simply using them as an example because I use said software and am familiar with that ecosystem. The same goes for any software obtained outside of the Play Store, and it's likely worse since there is no transparency in those cases. Heck, the same goes for software obtained through the Play Store (but we're probably talking about nation state resources on that front).

Another way to look at it: we are only considering a specific avenue for exploitation here. If you close it off, the criminals will look for others. I would be surprised if they weren't looking for ways to bypass Google's checks. I would be surprised if they weren't looking for weaknesses in popular apps. Then there is social engineering. While convincing someone to install software is likely desirable, it certainly isn't the only approach.

Either way, I don't think Google's approach is solving the problem and I think it is going to do a huge amount of damage. Let's face it: major corporations aren't a paragon of goodness, yet Google's shift is handing them the market.

Re: Google details new 24-hour process to sideload unverified Android apps

#229
post #105
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> just should not use smartphones and the internet That's ridiculous. Phones are being made more and more of a requirement to participate in society, including by governments.

If the government wants to force me to use a certain device, it should give me that device.

Re: Google details new 24-hour process to sideload unverified Android apps

#230
post #49

This is eminently reasonable. Now if only Android would allow for stronger sandboxing of apps (i.e. lie to them about any and all system settings).

I think it's only reasonable if you can install updates without having to do the whole dance (assuming you do the 7-day rather than permanent unlock).
Post reply on HN