Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

241–250 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#241
post #30

Earlier quoted context omitted.

> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.

Right, this friction makes it much harder for a scammer to get away with saying something like, "wire me $10,000 right now or you won't see your child ever again!" as the potential victim is forced to wait 24 hours before they can install the scammer's malicious app, thus giving them time to think about it and/or call their trusted contacts.

The sheer arrogance that you think someone manipulated successfully will just re-think the situation and ask their friends/family. The naivety to assume all scammers are impulsive fools and don't do this for a living, as their primary line of work.

So Google's going to add some nonsense abstraction layer and when this fails to curb the problem after a 24 hour wait, it will be extended more maybe a week, and more information must be collected to release it. We all know how this goes.

Re: Google details new 24-hour process to sideload unverified Android apps

#242
post #194
post #150

Earlier quoted context omitted.

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

There are places in EU too where parking meters have disappeared and payments are only done through apps. And I am talking about public space in the street, not private parkings.

Re: Google details new 24-hour process to sideload unverified Android apps

#244
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> At this point I'm convinced that there's something deeply wrong with how our society treats technology.

The problem isnt with technology. The problem is with physical ownership versus copyright/trademark/patent ownership in abeyance of physical ownership.

I go to a store and buy a device. I have a receipt showing a legal and good sale. This device isnt mine, even if a receipt says so.

The software (and now theres ALWAYS software) isnt mine and can never be mine. My ownership is degraded because a company can claim that I didn't buy a copy of software, or that its only licensed, or they retain control remotely.

And the situation is even worse if the company claims its a "digital restriction", ala DMCA. Then even my 1st amendment speech rights are abrogated AND my ownership rights are ignored.

It would not be hard to right this sinking ship.

     1. Abolish DMCA.
     2. Establish that first sale doctrine is priority above copyright/patent/trademark
     3. Tax these 'virtual property rights'
     4. Have FTC find any remote control of sold goods be considered as fraudulently classified indefinite rental (want to rent? State it as such)

Re: Google details new 24-hour process to sideload unverified Android apps

#245
post #72

Honestly, if coerced sideloading is a real attack vector , then this seems to be a pretty fair compromise. I just remain skeptical that this tactic is successful on modern Android, with all the settings and scare screens you need to go through in order to sideload an app and grant dangerous permissions. I expect scammers will move to pre-packaged software with a bundled ADB client for Windows/Mac, then the flow is "e…

> Honestly, if coerced sideloading is a real attack vector , [...] I don't believe that it is. I follow this "scene" pretty closely, and that means I read about successful scams all the time. They happen in huge numbers. Yet I have never encountered a reliable report of one that utilized a "sideloaded"[1] malicious app. Not once. Phishing email messages and web sites, sure. This change will not help counter those, th…

This is the thing that bothers me the most about this. It is as if even the HN crowd is taking it as given that malware is this big problem for banking on Android but in reality there seems to be very little evidence to back this up. I regularly read local (Finnish) news stories about scams and they always seem to be about purely social engineering via whatsapp or the scammer calling their number and convincing the victim they are a banking official or police etc.

That's why I'm inclined to believe Google is just using safety as an excuse to further leverage their monopoly.

Re: Google details new 24-hour process to sideload unverified Android apps

#246
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution.

Those groups of people are Google's paying customers. Google will, of course, defer to the ones who need more help to be safe online over the ones who don't. That's how you create a safe ecosystem.

Re: Google details new 24-hour process to sideload unverified Android apps

#247
Tbh, I love this flow. They truely think for users, all users not just advanced users. Unlike Apple, Apple just think for its ecosystem, its money.

  How the advanced flow works for users

  Enable developer mode in system settings: Activating this is simple. This prevents accidental triggers or "one-tap" bypasses often used in high-pressure scams.
  Confirm you aren't being coached: There is a quick check to make sure that no one is talking you into turning off your security. While power users know how to vet apps, scammers often pressure victims into disabling protections.
  Restart your phone and reauthenticate: This cuts off any remote access or active phone calls a scammer might be using to watch what you’re doing.
  Come back after the protective waiting period and verify: There is a one-time, one-day wait and then you can confirm that this is really you who’s making this change with our biometric authentication (fingerprint or face unlock) or device PIN. Scammers rely on manufactured urgency, so this breaks their spell and gives you time to think.
  Install apps: Once you confirm you understand the risks, you’re all set to install apps from unverified developers, with the option of enabling for 7 days or indefinitely. For safety, you’ll still see a warning that the app is from an unverified developer, but you can just tap “Install Anyway.”

Re: Google details new 24-hour process to sideload unverified Android apps

#248

Earlier quoted context omitted.

You could torture the analogy more and say that this is more like saying "it is possible to make bad food and kill yourself at home, so we require everyone to go to a restaurant."

Well, I mean, do you know many houses burn down because someone fell asleep while frying a pork chop? We should just get rid of kitchens at home because it's just not safe.

Oil fires cause immense damage to property and life! I don’t know why stoves are allowed in homes at all. Worse yet, they don’t implement any age verification, so a child can just turn on the burner! It’s crazy!

Re: Google details new 24-hour process to sideload unverified Android apps

#249
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

I “get” technology so I understand how you got here. But this is the wrong take. I expect to go to a restaurant and not die from the food… and I want nothing to do with the inner workings of the kitchen. I just want to know any restaurant I go into will be safe. Society has made restaurants safe, either because of government pressure or it’s good for business. How is that not a fair ask for technology, too? We all ha…

Because no amount of safeguards put up by the restaurant is going to protect you from getting sick of you decide to empty a bottle of bleach into your meal.

Re: Google details new 24-hour process to sideload unverified Android apps

#250
post #35

Earlier quoted context omitted.

> - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? What apps are those? I've yet to run into any of my banking apps that refuse to run with developer mode enabled. I've seen a few that do that for rooted phones but that's a different story. I've been running android for a decade…

Wero in Europe. It's really insane. They make wero to make us less dependent on US tech and then hamstring it in this way.

I can use Wero just fine in my banking app. Can't try the app that's called Wero in the Play store because it just directs me to my banking app. But I can open it at least ...
Post reply on HN