Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

341–350 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#341

Earlier quoted context omitted.

1) The one-time, one-day waiting period only applies if you go through the advanced flow to allow installing unregistered apps. You can still install registered apps (ie. apps made by developers who have verified their identity) even if they're distributed outside the Play Store. 2) You can use ADB to immediately install unregistered apps. ADB installs are not subject to the waiting period.

So let's say I'm F-Droid, an organization making a direct competitor to the Google Play Store and openly pointing out how much scammy shit is available in that store. My options are 1) submit my identity to Google (my competitor) so they can identify me and choose to revoke that verification at any point, or 2) I can tell all my users that they must go through these scary dialogs AND wait 1 day before they can use my…

It's really ridiculous.

You'd think regulators should make Google ship a 'Choose my store(s)' screen at setup, but Google thinks the opposite is the case and Google should also be able to control app distribution outside of the Playstore.

Re: Google details new 24-hour process to sideload unverified Android apps

#342

As an idea, what about allowing the 24 hours to be bypassed using adb (edit: bypass to allow indefinitely, not just install a single app)? I understand there is some problem trying to be solved here, but honestly this is still quite frustrating for legitimate uses. If this is the direction that computing is moving, I'd really rather there were separate products available for power users/devs that reflected our differ…

As an idea, what about letting me install on my own device whatever I want? This is ridiculous. Google is trying to dismantle the concept of ownership and personal autonomy. Do not give them any ground.

[dead]

Re: Google details new 24-hour process to sideload unverified Android apps

#343
post #182

Earlier quoted context omitted.

3) And how can we keep on using F-Droid and other app stores? 4) How can we install apps made by devs who won't do the verification dance with Google?

Developers who distribute Android apps on other app stores are not strictly required to undergo verification and thus can remain anonymous, but if they choose not to, then later this year (when the enforcement of verification goes active) their apps can only be installed on certified Android devices via ADB and/or the new advanced flow. Thus, you can still install unregistered apps if they're distributed via F-Droid…

I only hope this brilliant proposal is met with a new advanced fine from regulators.

Re: Google details new 24-hour process to sideload unverified Android apps

#344
post #156

Earlier quoted context omitted.

I was always under the impression security was a red herring and the real reason was control. Google wants to own the device and rent it to users with revocable terms the same way SaaS subscription software works. Locking down what can run is a key step in that process

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

Yeah, I worked at a bank once. I was told following policy and using dependencies with known vulnerabilities so my ass was covered was more important than actually making sure things were secure (it was someone else's problem to get that update through the layers of approval!). Needless to say, I didn't last long

Re: Google details new 24-hour process to sideload unverified Android apps

#345
post #222

Earlier quoted context omitted.

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

Then don't issue an app. Issue people cards to pay with and let them come to the bank for weird transactions.

This 100%. I don't understand why everything needs to be an app nowadays. Some things are best done in person and without to technology. No, I won't install some shitty app that requests location and network access to order lunch. If a venue does not provide a paper menu and accept cash, they have just lost my custom.

Re: Google details new 24-hour process to sideload unverified Android apps

#346

Earlier quoted context omitted.

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

I wish we had technical solutions that offered both. For example, a kernel like SeL4, which could directly run sandboxed applications, like banking apps. Apps run in this way could prove they are running in a sandbox. Then also allow the kernel to run linux as a process, and run whatever you like there, however you want. Its technically possible at the device level. The hard part seems to be UX. Do you show trusted a…

Web browsers already handle sandboxing

Re: Google details new 24-hour process to sideload unverified Android apps

#347
The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks.

I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

Re: Google details new 24-hour process to sideload unverified Android apps

#348

Earlier quoted context omitted.

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

I wish we had technical solutions that offered both. For example, a kernel like SeL4, which could directly run sandboxed applications, like banking apps. Apps run in this way could prove they are running in a sandbox. Then also allow the kernel to run linux as a process, and run whatever you like there, however you want. Its technically possible at the device level. The hard part seems to be UX. Do you show trusted a…

> As far as I could tell, they did it by convincing her to install some android app on her phone and then grant that app accessibility permissions.

Did she make it through the non-google play app install flow?

Re: Google details new 24-hour process to sideload unverified Android apps

#349
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. Those groups of people are Google's paying customers. Google will, of course, defer to the ones who need more help to be safe online over the ones who don't. That's how you create a safe ecosystem.

What's then left as Google's advantage? I'm really not interested in buying myself a cage, but if Google will make me choose between two cages then Apple has nicer one.

Re: Google details new 24-hour process to sideload unverified Android apps

#350
post #32
post #20

Earlier quoted context omitted.

You have to wait one day only once, when enabling the feature. I agree that enabling developer mode could be a problem but mostly because it's buried below screens and multiple touches. As a data point, I enabled developer mode on all my devices since 2011 and no banking app complained about it. But it could depend by the different banking systems of our countries.

You don't use the HSBC or Citibank app then I assume?

They don't operate in my county AFAIK. However that reinforces my idea that the endgame will be a pristine Android phone in a drawer at home with the banking apps required for accessing their sites with 2FA and another phone in my pocket for daily use.
Post reply on HN