Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

411–420 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#411
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

[flagged]

It's very obviously not irrelevant. Google is not going to let their main phone app product become associated with Grandma losing her savings! That's not going to help the free software folks... it's going to send everyone over to iOS.

Re: Google details new 24-hour process to sideload unverified Android apps

#413

Earlier quoted context omitted.

so Apple then? They require you to pay the $99 yearly fee to sideload for more than 7 days

Which increases the limit to whatever time is left on your current payment period. After which the app will stop working and need to be reinstalled by an authenticated developer who has a current Apple Developer Subscription. EDIT: Edited the above which previously said 90 days incorrectly. Not sure where my brain pulled that from but I posted the correct details here prior: https://news.ycombinator.com/item?id=45743…

> Which increases the limit to 90 days

It increases to 365 days, no? At least thats the longest I can sign my app and I use a personal but paid Apple Developer Account

Re: Google details new 24-hour process to sideload unverified Android apps

#414
post #28

Earlier quoted context omitted.

> some apps (e.g., banking apps) will refuse to operate and such when developer mode is on JFC. Why would an app be allowed to know this? Just another datapoint for fingerprinting.

Because estimates suggest Americans lose about $119 billion annually to financial scams, which is a not insignificant fraction of our entire military budget, or more than 5% of annual social security expenditures.

What do scams have to do with having developer options enabled?

This isn't a rhetorical question. There's no big red warning on the developer options screen saying it's dangerous. I haven't heard about real-world attacks leveraging developer settings. I suppose granting USB debug to an infected PC is dangerous, but if you're in that situation, you're already pwned.

Is there a real vulnerability nobody talks about?

Re: Google details new 24-hour process to sideload unverified Android apps

#415
post #203

Earlier quoted context omitted.

Developers, including non-US citizens, are forced to give Google their government ID to distribute apps. This enables Google to track and censor projects, like NewPipe, an alternative open source Youtube frontend, by revoking signing permissions for developers.

This is downright wrong.

Care to elaborate then? It's in line with the announcements I've heard

Re: Google details new 24-hour process to sideload unverified Android apps

#416
It'd be nice if they put a little sticker on the box or a flashing warning when you go to buy the phone noting that you'll be unable to use it as you desire for 24 hours if you are not willing to bend over to your corporate overlord.

Alternatives like GrapheneOS and Lineage are the way to go for right now, but I worry as things get more and more locked down that those options won't work with a lot of apps.

Re: Google details new 24-hour process to sideload unverified Android apps

#418

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

A minuscule amount of nerds being slightly annoyed is definitely worth when it hinders scammers from ruining a persons live.

Re: Google details new 24-hour process to sideload unverified Android apps

#419
post #292
post #194

Earlier quoted context omitted.

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

no way will they go back to coin-operated. That would mean they have to pay employees to walk up and down to collect coins.

The other problem, in the US at least, is that cash is very low value (inflation), and dollar coins never caught on. I'm not trying to carry around $6 in quarters to park for 2 hours. And that's a pretty inexpensive parking spot.

Re: Google details new 24-hour process to sideload unverified Android apps

#420

Earlier quoted context omitted.

[flagged]

I suppose the question is, who is actually willing to believe Google is going to deal in Good Faith. Why would anyone ever even begin to think that?

[flagged]
Post reply on HN