Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

811–820 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#811
post #786

I've stuck with Android despite privacy concerns because of the control I have over the device. If they're going to do this I might as well go Apple.

Same here! I've traded some privacy for freedom, but if they take away freedom, I'm still paying the privacy price. In this scenario, there is nothing left for me here. So Apple beckons.

Re: Google details new 24-hour process to sideload unverified Android apps

#813
post #81

The goal seems to be breaking the real-time guidance scammers rely on. 24h probably works, but it feels like a heavy tradeoff for legit users.

They give no shit about safety. The real goal is to break NewPipe or YT Vanced and ads/subscription revenue. Google is advertising company foremost.

Re: Google details new 24-hour process to sideload unverified Android apps

#814

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

Another take: People are not getting scammed because of side-loading (or not knowing your demographics/biometrics). People are getting scammed because of ignorance & stupidity & lack of common sense. In a way, its just nature running its course. If I'm able to scam you successfully, don't you deserve it at that point? Doesn't matter what we do, if you are scammable, you will get scammed.

Have these companies sent out their people to old age homes to teach old people how to use their tech and how avoid scams? If you lock the system down at max level, scams will just move offline again or find another way. Same if they build backdoors into encryption or make chats data available to gov agents: all illicit comms will just move off the network or find another smarter way. Its just how nature works, we are seeing tech-evolution in realtime.

Re: Google details new 24-hour process to sideload unverified Android apps

#815

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

What I'm about to say is probably going to be contraversial: but I think this is (long term) a good thing for opensource/freedom. The whole idea of 'apps' on a device that sits in your pocket and has access to a whole range of personal information was from the start, a bad idea. We have seen countless cases of 'verified apps' from the Playstore which hoover up all your personal data without your consent. I believe Steve Job's original plan for the iPhone was for apps to be web-based. This is good as web browsers run all the potentially dangerous code within a sandbox, with very restricted access to the host system's resources (storage, cameras, etc). Web technology has come a long way and even allows for GPU accelerated content to be used, and it's only getting better.

Phones, by their nature, are always internet connected (obviously there are instances where that isn't the case)...so if 90% of my apps are actually just web apps then that's fine. The opensource aspect of this should be: I build and run my own infrastructure (on cloud servers or my own servers) that serves up the web apps.

Sure, this isn't something that 'normal' people would do...but they aren't side loading apps anyway.

The web is decentralised, as long as we choose it to be. We need to take advantage of this property.

Re: Google details new 24-hour process to sideload unverified Android apps

#816
post #607

Earlier quoted context omitted.

It's OK. This is the dying, last gasp effort that a company makes when it has no way to innovate, no way to add any real value, no capacity to drive change internally, and has become completely non-user focused. In short, it's what companies like IBM and Broadcom are now. Shallow husks of their former self, mere holding companies for patents, with a complete lack of care and concern about any end-user retention. Goog…

The problem is that these companies can remain on life support for decades, phoning it in and making things continuously worse as their desperation grows. If they follow the path of IBM and Broadcom, they will move away from the consumer market and focus more on the enterprise. If Google fully realized that vision it would be extremely disruptive. Them shutting down Google Reader practically killed RSS for quite a wh…

Pretty sure this would be the only way the rest of the world (except China) dumps US tech services, so it sounds great.

Re: Google details new 24-hour process to sideload unverified Android apps

#817

Earlier quoted context omitted.

The apps might not be available though. Many developers are simply stopping in the face of Google's invasive policies. I don't blame them. Say goodbye to useful apps like Newpipe.

Newpipe impedes revenue for an already free video hosting service. Google has less than zero obligation to them.

Sure, they have no obligation but the way you describe Newpipe to paint it as "obstructive" feels off to me.

When you offer a free service, by definition of it being free, you can't hold consumers of that service accountable for not furthering your revenue. They are impeding revenue only if it's not actually free (or only under false pretenses) which dismantles your first sentence here.

Re: Google details new 24-hour process to sideload unverified Android apps

#819

Earlier quoted context omitted.

May I use ADB or Developer mode to disable the one-day period?

Yes, ADB disables the 1-day period.

How do you know this? It's been confirmed that you can use adb to temporarily bypass verification on a per-app basis, yes, but from what I can see, there's no indication that sideloading one app over adb will also skip the 1-day period.

This matters if you're sideloading an app store like F-Droid, because sideloaded app stores still have to go through PackageInstaller [1], which probably still enforces verification checks for adb-sideloaded apps?

[1] https://developer.android.com/reference/android/content/pm/P...

Re: Google details new 24-hour process to sideload unverified Android apps

#820

Earlier quoted context omitted.

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

> I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. Alas, I don't think it's a bug. A PM or VP probably got a bonus for this. > How about just giving the option to login with Google if so choose to login, and not spam it on every website just for visiting? Yeah this is kinda weird. I don't know if it's browser specific though. I use Firefo…

I opt into it on my site it's just a login option you can ignore if you want to log in another way, but for those who use it it removes the friction of writing out a password and verifying the email
Post reply on HN