Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

601–610 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#601

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

I'm genuinely interested in proposals for other ways to differentiate knowledgeable users enabling side loading for reasons like OSS, vs naive users enabling it at the instruction of scammers to install malware.

The one time per device (not per app/install) is annoying, but seems like a reasonable tradeoff between preventing bad installs and allowing legit installs. I can't think of any obviously better ways.

I realise some disagree with the entire premise. I think refusing to accept the reason given doesn't advance the discussion though and I am very interested in what a better experience that is trying to solve the same problems could look like.

Re: Google details new 24-hour process to sideload unverified Android apps

#602
post #206

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

I don't know. I've been silently outraged and disappointed by this whole forbidding of unverified apps, but also hopeful it wouldn't affect me much as a user of grapheneos. But this process seems pretty reasonable to me. I'd like to think it is due in part to the efforts of F-Droid and others. Waiting a day, once, to disable this protection doesn't seem like a big deal to me. I'd probably do it once when I got a phon…

It's not directly a big issue for us technical people and our own individual usage. Telling people about F-Droid, NewPipe (& forks) or secuso apps will be a pain. People will find free software / software not approved by Google complicated or suspicious. It is a huge issue, and even for us in the end because it hurts the software we love.

Re: Google details new 24-hour process to sideload unverified Android apps

#603

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

> not spam it on every website just for visiting?

It's the website that spamming that.

Either via google.accounts.id.prompt(), or options provided to loaded Google scripts.

Google is guilty only insofar as that feature is possible.

Re: Google details new 24-hour process to sideload unverified Android apps

#604
post #194

Earlier quoted context omitted.

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

Where I live, in the EU, we just have signs and the parking meters have been gone for several years

I found one parking lot in the EU where there were only signs, and the signs not only pointed to an Android+iOS only, attestation-protected app, rather than a website, but an app that, at least on Android, was region-locked to only allow installations from people with the local country set correctly in Play Store (something completely different than the country Google sets for your account, for some reason).

It was a public lot, and the only lot in the town, as far as we could tell.

Re: Google details new 24-hour process to sideload unverified Android apps

#605
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

Do you think regular desktop computer should be locked down like this too? Scammers can also tell people to run Windows programs. Should that be banned too? I'm fine with an opt-in lock-down feature so people can do it for their parents/grandparents/children. Also, just let people get used to it. People will get burned, then tell their friends and they will then know not to simply follow what a stranger guides them t…

Maybe? Let people form CAs, and if a CA gives out certs for malicious apps remove them. (Old apps continue to work, to publish new one get new cert.)

Yes, sad, but works.

People will learn about scams, but scammers are unfortunately a few steps ahead. (Lots of scammers, good techniques spread faster among them than among the general public.)

Re: Google details new 24-hour process to sideload unverified Android apps

#606

Earlier quoted context omitted.

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

> not spam it on every website just for visiting? It's the website that spamming that. Either via google.accounts.id.prompt(), or options provided to loaded Google scripts. Google is guilty only insofar as that feature is possible.

Google is guilty

Re: Google details new 24-hour process to sideload unverified Android apps

#607

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

It's OK. This is the dying, last gasp effort that a company makes when it has no way to innovate, no way to add any real value, no capacity to drive change internally, and has become completely non-user focused.

In short, it's what companies like IBM and Broadcom are now.

Shallow husks of their former self, mere holding companies for patents, with a complete lack of care and concern about any end-user retention.

Google search has turned completely into junk over the last two weeks. You may think "two weeks only?!", and you're right there, but this is a whole new level of stupid.

You may not be getting this where you are, but here searches are constantly prepended with human checks, searches can take up to 5+ seconds, you name it. They literally spend so little on maintaining and working on their search engine, that it's effectively unusable much of the time now. I don't care whether it's bot traffic, or what, and no it's not just me, or my ISP. This is wide-scale.

It takes so long I just click on an alternate search engine and search there. I don't have time to waste in their inanity.

Any sane and sensible company wouldn't entirely trash and destroy their mainline product, which is key to drive users to experience Google products. But this degree of sheer, unbridled arrogance is what topples empires. The thought that it really doesn't matter, flows off of google as a foul stench.

Look at Microsoft of old, the god of arrogance. Once the most dominant, powerful tech company in the world. They were king. Browser king. OS king. Everything king. Now they are barely noticed by large swaths of the market.

So goes Alphabet these days.

Re: Google details new 24-hour process to sideload unverified Android apps

#608

Earlier quoted context omitted.

Why are you even using the Gmail as your mail app?

The switching cost on a 20+ year old email address is high. It’s basically impossible to totally migrate away from. On top of that, since Google does their own thing, it doesn’t fit well into standard IMAP that most clients use. Sparrow made Gmail a great experience, but Google bought it and shut it down. I’m still rather bitter about that. It’s the only email client that actually made me enjoy email.

I've not had issues plugging Gmail into Thunderbird, aquamail, k-9 mail, maybe you could try one of those?

Re: Google details new 24-hour process to sideload unverified Android apps

#609

Earlier quoted context omitted.

There is immense pressure to stop online scams which are draining old people of their life savings. The whole flow from the article seems entirely based around letting power users install what they want while being able to break the flow of a scammer guiding a clueless person in to installing malware. It is promising that Google has avoided just turning off sideloading but still put measures in place to protect peopl…

Why is it on Google to stop this and not the banks?

Because they want to shake the image that the iPhone is for the average person while Android is for technical people who take the risk of malware and scams.

There are more grandmas who just want their banking secure than there are FOSS advocates wanting full system access.

Post reply on HN