Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

321–330 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#321

Earlier quoted context omitted.

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

I wish we had technical solutions that offered both. For example, a kernel like SeL4, which could directly run sandboxed applications, like banking apps. Apps run in this way could prove they are running in a sandbox. Then also allow the kernel to run linux as a process, and run whatever you like there, however you want. Its technically possible at the device level. The hard part seems to be UX. Do you show trusted a…

> (She contacted the bank and the police, and they managed to reverse the transactions and get her her money back. But she was a mess for a few days.)

And this almost certainly means that the bank took a fraud-related monetary loss, because the regulatory framework that governs banks makes it difficult for them to refuse to return their customer's money on the grounds that it was actually your piano teacher's fault for being stupid with her bank app on her smartphone (also, even if it were legal to do so, doing this regularly would create a lot of bad press for the bank). And they're unlikely to recover the losses from the actual scammers.

Fraud losses are something that banks track internally and attempt to minimize when possible and when it doesn't trade-off against other goals they have, such as maintaining regulatory compliance or costing more money than the fraud does. This means that banks - really, any regulated financial institution at all that has a smartphone app - have a financial incentive to encourage Apple and Google to build functionality into their mass-market smartphone OSs that locks them down and makes it harder for attackers to scam ordinary, unsophisticated customers in this way. They have zero incentive to lobby to make smartphone platforms more open. And there's a lot more technically-unsophisticated users like your piano teacher than there are free-software-enthusiasts who care about their smartphone OS provider not locking down the OS.

I think this is a bad thing, but then I'm personally a free-software-enthusiast, not a technically-unsophisticated smartphone user.

Re: Google details new 24-hour process to sideload unverified Android apps

#322
post #2

tl;dr: - You need to enable developer mode - You need to click through a few scare dialogs - You need to wait 24h once I wonder how long this will last before they lock it down further. There was a lot of pushback this time around and they still ended up increasing the temperature of the metaphorical boiling frog. It still seems like they're pushing towards the Apple model where those who don't want to self-dox and/o…

Will these measures eliminate fraud? Of course not. What a shame; I guess we'll need to lock down the platform even further. This is so overt.

I propose we ban all computing devices to prevent fraud and harm to children.

Re: Google details new 24-hour process to sideload unverified Android apps

#323
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

How is it unsustainable when iOS has enforced even stricter rules for its nearly 20 year lifespan?

Android has about 2/3 worldwide market share and it hasn't had anything like this before. Many people, myself included, chose it exactly because it allows the installation of modded, pirated, or otherwise non-store-worthy apps.

Re: Google details new 24-hour process to sideload unverified Android apps

#324

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

If it helps, the 24-hour wait is a one-time process. You do it once, click the toggle to allow installing unregistered apps indefinitely, and then install whatever you want. You can even turn off developer options afterwards, per my understanding, and it won't impact your ability to install unregistered apps.

For now.

Re: Google details new 24-hour process to sideload unverified Android apps

#325
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

Could the technophobes please just buy different smartphones? If certain people want to opt in to locked down devices, I think that's okay. But please give me a device that lets me do whatever I want. (And still lets me participate in modern society—I can't live with a Linux phone).

Apple's argument for locking down the iPhone but not the Mac has always been some variation of "Mac users are professionals and iPhones are for everyone." Fine! Where can I buy the unrestricted iPhone? As far as I'm concerned, basically every problem could be solved if Apple would put the Security Research Device on an unlisted page of their online store for the general public. Normies won't buy it, and I will.

Re: Google details new 24-hour process to sideload unverified Android apps

#326

Earlier quoted context omitted.

Idiocracy needs a spiritual "sequel" with modern times.

It is called baseline reality, unfortunately. We haven't started watering crops with salt-water but it's only a matter of time.

Israelis have a plan for that in Gaza.

https://www.scientificamerican.com/article/as-israel-floods-...

Re: Google details new 24-hour process to sideload unverified Android apps

#327

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

The only reason I run android over iOS is the freedom to install things I want on it. A waiting period is unacceptable as Android has proven that it can't be trusted not to tighten the grip further.

Reconsider.

Re: Google details new 24-hour process to sideload unverified Android apps

#328
post #292
post #194

Earlier quoted context omitted.

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

no way will they go back to coin-operated. That would mean they have to pay employees to walk up and down to collect coins.

And maintain them, which I suspect costs even more. Parking meters do fiddly work, out in all weather, where people hate them and do all kinds of vandalism.

It doesn't surprise me that they want to make hardware maintenance your problem.

Re: Google details new 24-hour process to sideload unverified Android apps

#329
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

I don't know if Google is making the right choice here, but I do believe that technology should be for anyone (anyone who wants it, at least). How do you plan to decide who gets to use internet banking and who doesn't? That doesn't seem like a good road to be going down, either.

People themselves will decide. Same way they decided whether they wanted to buy a computer in the 00s. It's just that those who decide to not have internet banking should not be disadvantaged by the society compared to those who have it.

Re: Google details new 24-hour process to sideload unverified Android apps

#330
post #28

Earlier quoted context omitted.

> some apps (e.g., banking apps) will refuse to operate and such when developer mode is on JFC. Why would an app be allowed to know this? Just another datapoint for fingerprinting.

Yes, it is really dumb that some of these settings are exposed to all apps with no permission gating [0]. But it will likely always be possible to fingerprint based on enabled developer options because there are preferences which can only be enabled via the developer options UI and (arguably) need to be visible to apps. 0: https://developer.android.com/reference/android/provider/Set...

What might help better is having permissions that you can set separate settings that can be read for different apps (including the possibility to return errors instead of the actual values), even if they can be read by default you can also change them per apps. (This has other benefits as well, including possibility of some settings not working properly due to a bug, you can then work around it.)
Post reply on HN