Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

501–510 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#501
post #150
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

[flagged]

Re: Google details new 24-hour process to sideload unverified Android apps

#502
post #193

Earlier quoted context omitted.

This has nothing to do with keeping people safe. ...and... some people are gullible enough to go into a hidden setting on their phone and enable that in order to install an app from a random Chinese website are kind of contradictory.

It's not a contradiction. Removing that setting solves that problem, but it's not the only solution.

It also only solves that very specific problem. You don't need to side-load an app to scam someone. There's plenty of malware on the play store you can use. And, you don't need malware. There's plenty of legitimate apps you can use for scamming.

And, you don't need an app, I would imagine most scamming is done without an app.

So, really, we're solving a subset of a subset of a subset of a subset of the problem.

Re: Google details new 24-hour process to sideload unverified Android apps

#503

It'd be nice if they put a little sticker on the box or a flashing warning when you go to buy the phone noting that you'll be unable to use it as you desire for 24 hours if you are not willing to bend over to your corporate overlord. Alternatives like GrapheneOS and Lineage are the way to go for right now, but I worry as things get more and more locked down that those options won't work with a lot of apps.

> I worry as things get more and more locked down that those options won't work with a lot of apps

I am increasingly interested in a dual-prong approach of building a parallel world of OSS apps, platforms, etc, plus an adversarial inter-op project for duping and wrapping apps/services from the commercial/normie world. We have some solid bases with Android/Graphene, Linux more broadly, wine, and Android VMs like Waydroid. Even if things don't get a lot of users, if the users it has are highly technical on average things can probably chug along.

Re: Google details new 24-hour process to sideload unverified Android apps

#504
post #193

Earlier quoted context omitted.

This has nothing to do with keeping people safe. If it did then power users could continue to install their own software by being given that ability as a developer setting. The fact that some people are gullible enough to go into a hidden setting on their phone and enable that in order to install an app from a random Chinese website is not a good reason to take away everyone's freedom. Consolidation of power is all t…

This has nothing to do with keeping people safe. ...and... some people are gullible enough to go into a hidden setting on their phone and enable that in order to install an app from a random Chinese website are kind of contradictory.

There's much easier ways for gullible people to be scammed than convincing them to install an android app.

Re: Google details new 24-hour process to sideload unverified Android apps

#505
post #394

Earlier quoted context omitted.

I don't think Google should be changing Android this way at all, and fear that it will later be used for evil. That said, I thought of an improvement: Allow a toggle with no waiting period during initial device setup. The user is almost certainly not being guided by a scammer when they're first setting up their device, so this addresses the concern Google claims is driving the verification requirement. I'll be pretty…

> Allow a toggle with no waiting period during initial device setup I like this idea in principle but I think it could become a workaround that the same malicious entities would be willing to exploit, by just coercing their victims to "reset" their phones to access that toggle.

That wipes all the data on the device and requires logging back in to accounts. It seems to me that's high enough friction to resist most coercion.

Re: Google details new 24-hour process to sideload unverified Android apps

#506

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I was so mad when they removed the fourth option. I can't remember which one was which, but one meant "open in a webview inside this app" and the other was "open in a new tab in your default browser". It was still terrible UX but I liked at least having that choice.

Re: Google details new 24-hour process to sideload unverified Android apps

#507
> “In that 24-hour period, we think it becomes much harder for attackers to persist their attack,” said Samat. “In that time, you can probably find out that your loved one isn’t really being held in jail or that your bank account isn’t really under attack.”

I wanted to be negative about the whole idea, as due to my age I'm resentful of not being allowed to use my own computer as I see fit.

On the other hand, in principle I see what they're going for here. The only decent argument for these user-hostile lockdowns is the malware issue.

Re: Google details new 24-hour process to sideload unverified Android apps

#508
post #417

SailfishOS / Jolla are unlikely to do this. Time to switch. Google's monopoly power over android is showing, badly.

Maybe if the Jolla folks were serious about making inroads in the market for personal mobile devices that they're ostensibly trying to compete in. But they're just as deluded and as doomed as their Meego/Maemo/Moblin predecessors about the value proposition that the SDKs and system software they ship has with the market segment they're targeting.

Re: Google details new 24-hour process to sideload unverified Android apps

#509
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

Let's say I'm sitting outside of your office with a bazooka and boxes of high explosives. You ask my why, and I say, "someone might try to rob this office." You say, "somehow, that does not persuade me that a stranger should loiter outside of my workplace with a massive stockpile of ordinance." I reply, "what's your solution to combat robberies?"

let's say I put a lock on an office door. You say "Why? Bazookas will get through the door anyways".

I don't know how I feel about this change but context does in fact matter about whether something is a good idea or not

Re: Google details new 24-hour process to sideload unverified Android apps

#510

Earlier quoted context omitted.

I suppose the question is, who is actually willing to believe Google is going to deal in Good Faith. Why would anyone ever even begin to think that?

[flagged]

Google has a fetish for controlling what I can install because they earn money by sitting on the brdige between me and the app developer. That is not a conspiracy theory like you try to portray it. That is basic economics.
Post reply on HN