Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

451–460 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#451
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

(some) people are starting to understand why cash is so important. It's the neutrality that it provides. The fact that it can't be programmatically limited or censored and you can't be excluded from the economy. Cash is inclusive. Obviously cash becomes much harder to "use" online and in apps...

Re: Google details new 24-hour process to sideload unverified Android apps

#452
post #387

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

what's your solution to combat scammers?

Do you think regular desktop computer should be locked down like this too? Scammers can also tell people to run Windows programs. Should that be banned too?

I'm fine with an opt-in lock-down feature so people can do it for their parents/grandparents/children.

Also, just let people get used to it. People will get burned, then tell their friends and they will then know not to simply follow what a stranger guides them to do over the phone. Maybe they will actually have second thoughts about what personal data they enter on their phone and when and where and who it may be sent to.

Same as with emails telling you to buy gift cards at the gas station. Should the clerk tell people to come back tomorrow if they want to buy a gift card, just in case they are being "guided" by a Nigerian prince scammer?

Re: Google details new 24-hour process to sideload unverified Android apps

#453

Earlier quoted context omitted.

All apps should be open source and subject to verification by nonprofit repositories like F-Droid which have scary warnings on software that does undesirable things. For-profit appstores like Google and Apple that allow closed source software are too friendly to scams and malware.

I don't think that's a realistic suggestion as as the quantity of applications are huge who are going to spend time reviewing them one by one. And and even then it's not realistic to expect that that undesirable things can be detected as these things can be hidden externally for instance or obfuscated

F-Droid exists and they have a much better track record than Google. I'm not actually serious, I just think if there's a single app repo that should be allowed to install apps without a scary 24h verification cooldown, it's Google's proprietary closed-source app store that needs the scary process, not F-Droid.

Re: Google details new 24-hour process to sideload unverified Android apps

#454
post #100

I'd urge everyone here to seriously consider switching to GrapheneOS. It's a far simpler transition than e.g. switching from Windows or OSX to Linux, and many people find that it has basically no friction vs android. More people moving to GrapheneOS is the best tool we have against Google's continued and escalating hostility to user freedom and privacy and general anti-competitive conduct. (Of course, you could ditch…

This has really moved up my timeline of switching to Graphene.

Admittadly I was being lazy and not checking if Line works on it yet, but I'll be finding that out this weekend it seems.

Re: Google details new 24-hour process to sideload unverified Android apps

#455
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

'Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.' - Benjamin Franklin

'essential' means can't be bothered to wait 24 hours (once)?

Re: Google details new 24-hour process to sideload unverified Android apps

#456

Earlier quoted context omitted.

All apps should be open source and subject to verification by nonprofit repositories like F-Droid which have scary warnings on software that does undesirable things. For-profit appstores like Google and Apple that allow closed source software are too friendly to scams and malware.

I don't think that's a realistic suggestion as as the quantity of applications are huge who are going to spend time reviewing them one by one. And and even then it's not realistic to expect that that undesirable things can be detected as these things can be hidden externally for instance or obfuscated

I think compared to the alternatives, this is the best answer.

Even if you are a bank or whatever, you shouldn't store global secrets on the app itself, obfuscated or not. And once you have good engineering practices to not store global secrets (user specific secrets is ok), then there is no reason why the source code couldn't be public.

Re: Google details new 24-hour process to sideload unverified Android apps

#457

Earlier quoted context omitted.

'Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.' - Benjamin Franklin

'essential' means can't be bothered to wait 24 hours (once)?

Boiling the frog.

Re: Google details new 24-hour process to sideload unverified Android apps

#458
Since after doing this Google knows the user knows what they're doing (and officially they say they don't want to get in the way), why does this only enable installing unverified apps (still unprivileged), why is the system still insanely locked down? I thought the 24-hour delay solved the "security" problem?

Re: Google details new 24-hour process to sideload unverified Android apps

#459

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

Good luck installing things from anywhere you want on an iPhone.

Re: Google details new 24-hour process to sideload unverified Android apps

#460
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

Not the parent or agreeing/disagreeing with them, but to your question: if you get creative, there are a lot of things you could do, some more unorthodox than others. Tongue-in-cheek example, just to get the point across: instead of calling it Developer Mode, call it "Scam mode (dangerous)". Require pressing a button that says "Someone might be scamming me right now." Then require the user to type (not paste) in a lo…

The people falling for social engineering now won't be protected by this either. You could gate the functionality behind verification of an anti-scam awareness and education training and certification course, scammers would coach people through the entire course and the verification step, and people would still be victimized.
Post reply on HN