Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

641–650 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#641

Earlier quoted context omitted.

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

> not spam it on every website just for visiting? It's the website that spamming that. Either via google.accounts.id.prompt(), or options provided to loaded Google scripts. Google is guilty only insofar as that feature is possible.

There is no way this many sites did it organically without Google pushing it in some way, not to mention they built the thing in the first place (as you mentioned). There also doesn’t seem to be any way to disable it (other than maybe an extension that I saw recently, but at $15 I needed to think about how much I want to spend just because Google is obnoxious).

I’m sure the real goal of this “feature” is to get people to sign-up for the site without them actually realizing they are signing up. They click OK just so the modal goes away and now the site has their email address. They can use that growing email list to seek higher prices from sponsors when they put an add in their newsletter the user will now be spammed with.

Imagine if the other auth providers followed suit. Open a news article and you need to close the Google auth, Apple auth, Facebook auth, Microsoft auth, GutHub auth, X auth… I’m sure I’m forgetting some. After closing those 6 modals, reject the cookie prompt, close the newsletter modal, and maybe now we can start reading the article if there is an auto-playing video ad covering some of the content.

All of this is really pushing me away from the internet in general and souring me on the tech industry as a whole. I’m at that point where I find myself casually browsing for jobs that won’t require I ever touch a computer again.

Re: Google details new 24-hour process to sideload unverified Android apps

#642

Earlier quoted context omitted.

This has nothing to do with keeping people safe. If it did then power users could continue to install their own software by being given that ability as a developer setting. The fact that some people are gullible enough to go into a hidden setting on their phone and enable that in order to install an app from a random Chinese website is not a good reason to take away everyone's freedom. Consolidation of power is all t…

There is immense pressure to stop online scams which are draining old people of their life savings. The whole flow from the article seems entirely based around letting power users install what they want while being able to break the flow of a scammer guiding a clueless person in to installing malware. It is promising that Google has avoided just turning off sideloading but still put measures in place to protect peopl…

I've never seen any news about such scams with actual malware that can break through Android's sandbox system - as we're still assuming a rootless systems. In most cases it's pig butchering, phishing, cold calls that make the person use the official app to transfer money to an account they're told to.

This stops nothing of the sort.

Re: Google details new 24-hour process to sideload unverified Android apps

#643

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

An annoying extension of this is opening a Google maps link on mobile. It always prompts to open Google Maps (the app) no matter what. If you click no, its bugs the fuck out and opens an App Store link. If you click yes, even if you have Google Maps installed, it bugs the fuck out and opens an app store link. In neither case will it properly show the location on a first attempt. It's been like this for years. I'd ask what they're thinking when they came up with this, but I remain unconvinced that any such activity happens inside any Google offices today.

Re: Google details new 24-hour process to sideload unverified Android apps

#644
post #607

Earlier quoted context omitted.

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

It's OK. This is the dying, last gasp effort that a company makes when it has no way to innovate, no way to add any real value, no capacity to drive change internally, and has become completely non-user focused. In short, it's what companies like IBM and Broadcom are now. Shallow husks of their former self, mere holding companies for patents, with a complete lack of care and concern about any end-user retention. Goog…

The problem is that these companies can remain on life support for decades, phoning it in and making things continuously worse as their desperation grows.

If they follow the path of IBM and Broadcom, they will move away from the consumer market and focus more on the enterprise. If Google fully realized that vision it would be extremely disruptive. Them shutting down Google Reader practically killed RSS for quite a while. Imagine that level of disruption with products that have mainstream appeal… mail, maps, docs, search, etc. It would be pandemonium.

Re: Google details new 24-hour process to sideload unverified Android apps

#646

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

I'm genuinely interested in proposals for other ways to differentiate knowledgeable users enabling side loading for reasons like OSS, vs naive users enabling it at the instruction of scammers to install malware. The one time per device (not per app/install) is annoying, but seems like a reasonable tradeoff between preventing bad installs and allowing legit installs. I can't think of any obviously better ways. I reali…

If you can get someone to do all these steps, you can get someone to wait 24 hours as well.

We use Android based devices internally with apps which aren't signed. I've had way too much trouble with Google flagging an internal app as problematic and then getting no where with Google "support" when we still used Google play.

The 24 hour wait is especially problematic because we often simply factory reset a device and preload it of there is any form of trouble.

This is just a power grab to lock down the ecosystem more. And ironically this seems to because of the Epic lawsuit. Google is now aligning with the absolute minimum they saw Apple needed to implement.

Re: Google details new 24-hour process to sideload unverified Android apps

#647
post #387

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

what's your solution to combat scammers?

China just executed couple of them that operated in Myanmar. Since we are hurling towards the bad parts in their dystopia anyway, why not also get the good ones?

Re: Google details new 24-hour process to sideload unverified Android apps

#648
Anytime I open the Play store it feels like I am getting hustled to install Scam Software I don't want. With Scam I mean either it is overblown with Ads or wants a subscription.

I really extremely rarely open the Play Store.

F-Droid is my place to. Even if the tools are simple, they are reliable.

Maybe Google is also scared, that with coding agents some OSS Tools improve that much that commercial alternatives don't matter.

Re: Google details new 24-hour process to sideload unverified Android apps

#649

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

I'm genuinely interested in proposals for other ways to differentiate knowledgeable users enabling side loading for reasons like OSS, vs naive users enabling it at the instruction of scammers to install malware. The one time per device (not per app/install) is annoying, but seems like a reasonable tradeoff between preventing bad installs and allowing legit installs. I can't think of any obviously better ways. I reali…

This was never about safety. It was all about control. Desktop OSes have always allow installing any softwares and the world is still spinning. Not even macos overreach this hard.

There's no solutions because they specifically crafted the problem to not be solvable. No amount of compromises will stop them from advancing further.

Re: Google details new 24-hour process to sideload unverified Android apps

#650

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

> I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too.

Alas, I don't think it's a bug. A PM or VP probably got a bonus for this.

> How about just giving the option to login with Google if so choose to login, and not spam it on every website just for visiting?

Yeah this is kinda weird. I don't know if it's browser specific though. I use Firefox on my main computer and I think I still see it. Which means that the website owner opted into this weird pattern. No other auth providers do this. Just Google.

Post reply on HN