Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

741–750 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#741
post #182

Earlier quoted context omitted.

3) And how can we keep on using F-Droid and other app stores? 4) How can we install apps made by devs who won't do the verification dance with Google?

Developers who distribute Android apps on other app stores are not strictly required to undergo verification and thus can remain anonymous, but if they choose not to, then later this year (when the enforcement of verification goes active) their apps can only be installed on certified Android devices via ADB and/or the new advanced flow. Thus, you can still install unregistered apps if they're distributed via F-Droid…

Mishall This sounds illegal.

Bad implementation. Like the SAVE act that requires you to bring your up to date passport just to vote. It's clearly user hostile.

Re: Google details new 24-hour process to sideload unverified Android apps

#742

The forced ID for developers outside the Play store is already killing open source projects you could get on F-Droid. The EU really needs to identify this platform gatekeeping as a threat. As an EU citizen I should not be forced to give government ID to a US company, which can blacklist me without recourse, in order to share apps with other EU citizens on devices we own.

[flagged]

stop spreading misinformation

Re: Google details new 24-hour process to sideload unverified Android apps

#743

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

If it helps, the 24-hour wait is a one-time process. You do it once, click the toggle to allow installing unregistered apps indefinitely, and then install whatever you want. You can even turn off developer options afterwards, per my understanding, and it won't impact your ability to install unregistered apps.

different strokes i suppose. normally i like being able to use something the same day i buy it

95% of the apps i use are ''side loaded''. that includes a web browser, file browser, all the fossify apps for things like messaging, phone/contacts -- so the phone would be basically be a paperweight until that restriction is removed

Re: Google details new 24-hour process to sideload unverified Android apps

#744
post #30

Earlier quoted context omitted.

> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.

Right, this friction makes it much harder for a scammer to get away with saying something like, "wire me $10,000 right now or you won't see your child ever again!" as the potential victim is forced to wait 24 hours before they can install the scammer's malicious app, thus giving them time to think about it and/or call their trusted contacts.

Goalposts moving, who says this on an official forum?

Re: Google details new 24-hour process to sideload unverified Android apps

#745

I can see that majority of response is negative, being mobile developer myself I can understand. What's the solution for 3rd world countries where 80% phones are android (and usually old/low spec) that balances freedom for knowledgeable users vs security/safety for the majority of users? you can roughly understand education level and tech literacy for the majority of people in 3rd world countries.

To be blunt: I don't care. Don't make their incompetence my problem.

Re: Google details new 24-hour process to sideload unverified Android apps

#746
post #418

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

A minuscule amount of nerds being slightly annoyed is definitely worth when it hinders scammers from ruining a persons live.

oh to be young and naive...

Re: Google details new 24-hour process to sideload unverified Android apps

#747

Earlier quoted context omitted.

> I remember when Google disabled call recording in Android, so you no longer could record scammers. Citation needed. My Pixel 7a with the latest updates has settings for call recording in the phone app. Since I never screwed around with it, I'd assume these are the defaults: Call recording is turned on, with "asks to record calls" set Automatically delete recordings is "never" Automatically record calls with non-con…

It was added recently to Google dialer app. If you want to use external one or aren't on pixel which received this update then bad luck for you.

Ah, I see. So still a dick move, then, even if I never use it in the first place.

Re: Google details new 24-hour process to sideload unverified Android apps

#748

I think most people here live too much in their tech bubble and don't realize how dumb the vast majority of people are when it comes to tech. I know that feeling myself that you lose the grip to "reality" when you are too much into tech, but after dealing a bit with "ordinary" people, I do understand why Google wants to do that. Most people have absolutely no idea about tech at all. So many people don't even know wha…

Scammers have no problem waiting 24 hours, so this doesn't protect incompetent people at all.

Re: Google details new 24-hour process to sideload unverified Android apps

#749
post #730

Even alternatives like GrapheneOS relies on AOSP. I wonder if it's possible for regulators in certain countries to pressure Google to kill it in the future. Even if that's not the case, I'd imagine attestation apps like banking apps would require some kind of identity verification in exchange for trusting Graphene's keys. In principle it doesn't make sense to leave any escape hatch, but I guess as always, it boils do…

> Even alternatives like GrapheneOS relies on AOSP

There are alternatives that don’t: Mobian, Ubuntu Touch, PureOS, postmarketOS, Sailfish OS.

Post reply on HN