Live data from Hacker News

What we talk about when we talk about sideloading

f-droid.org

141–150 of 646 posts

Re: What we talk about when we talk about sideloading

#141

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

put a fork in it, it's done,almost! android that is. linux phones are comming up fast, and will be set up to run the droid apps we like. but big props to fdroid just used "etchdroid" to transfer a linux iso to a thumb drive and boot a new desk top, and if I get a few bucks ahead I will buy a dev board from these guys https://liberux.net/ flinuxoid?, flinux?

Google really knew what they were doing by hiring Marc Levoy. The Google camera is the only thing keeping me from getting something other than a pixel phone.

Re: What we talk about when we talk about sideloading

#142

After Google implements this, will I still be able to "side-load" (install any software) on Android-derivative OSes like GrapheneOS?

Yes (but see my comment about the permission system), however, the future of bootloader unlocking and AOSP is uncertain... :(

With one switch, one nasty update (disabling bootloader unlocking on Pixels), Google could kill GrapheneOS..

Re: What we talk about when we talk about sideloading

#143
post #112
post #77

Earlier quoted context omitted.

Debian has had a "first party store" since the early 90s, and the truth is the diametrical opposite of "they're sufficiently unpopular that people don't think of them as the primary source to get apps". It's been almost the only way I install software (that I didn't write) on my Debian and Ubuntu machines since I moved to Debian. This is true of most Debian and Ubuntu users.

>Debian has had a "first party store" since the early 90s, and the truth is the diametrical opposite of "they're sufficiently unpopular that people don't think of them as the primary source to get apps". Aren't those all considered first party apps? Sure, debian aren't the authors of nginx or whatever, but they're the people building, packaging it, and adding patches for it. It's a stretch to compare them to the play…

No, it's not a stretch at all. The user experience is the same, except that Debian and F-Droid apps don't come with antifeatures built in. The only friction is around who to report bugs to.

Re: What we talk about when we talk about sideloading

#144
post #132
post #49

Earlier quoted context omitted.

>Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. Can you corroborate this? At least for me, the whole idea that "sideloading" has negative connotations only came up as a result of this debacle, and the only evidence I've seen are some very careful readings of blog posts from Google. The word…

> The word itself hardly has any negative connotations aside from something like "not primary", which might be argued as negative, but is nonetheless correct. Android has an APK installer built in. Opening an APK file launches the installer and installs the application, just like opening an MSI file on Windows launches built-in Microsoft Installer and installs the application. Google have gradually added impediments…

>but calling the system's built-in application installation mechanism "not primary" is absurd.

So you're arguing that because play store installs and random .apk installs both goes through packageinstaller, the concept of a "primary" install method doesn't exist?

Re: What we talk about when we talk about sideloading

#145
Actually sideloading is not a made-up term. It's an existing term, that was (20yrs ago) used regarding to cracks and trainers software. Sideloaders loaded (mainly in DOS but Atari had it too) the main executable along with additional program, a routine or interrupt that would allow disabling of copy protection, cheat on the amount of lives, energy in games (trainers) or simply do something more like play demo music before the game's proper launching. One example - prehistorik game that was distributed by pirates with a "pretrain.com" which allowed to select unlimited lives and sideloaded this routine along with the main program, that would periodically check the counters and keep them up.

-- edit --

Apparently after checking this term in the internet, I am not so sure that this process had been called this way. Maybe I'll leave it here to provoke a correct answer according to the internet rule #1 - to learn what is the correct answer, just post an incorrect answer in the internet and wait

Re: What we talk about when we talk about sideloading

#146
post #87

Earlier quoted context omitted.

> 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices I would instead say that having a trustworthy channel for verified app loading is a valuable security tool. F-Droid is such a channel; the Google Play Store is not. So Google is trying to take this valuable security tool away from users.

Sure, but you'd probably also agree it should be up to the device owner (end user) which parties are to be considered 'trusted'

Yes, I think the end user is in a better position than Google to decide who to trust. Some end users will make bad decisions, but Google's interests are systematically misaligned with theirs.

Re: What we talk about when we talk about sideloading

#147

I think we could set the bar substantially higher. Don't even bother with discussion of sideloading. Talk about bounded transactions and device control. What is needed is: Once I have purchased a device, the transaction is over. I then have 100% control over that device and the hardware maker, the retailer, and the OS maker have a combined 0% control.

That bar would require infinitely good software on the hardware. Then it will be your device. Otherwise, they will constantly need to improve it. then it will be their software on your device.

Would you consider Microsoft Windows or Linux infinitely good software? The scenario described by the GP applies 100% to most personal desktop and laptop computers.

Re: What we talk about when we talk about sideloading

#148
post #87

I think this misses the forest for the trees here. The platforms behavior here is a symptom and not the core problem. I think the following are pretty clearly correct: 1. It's your damn phone and you should be able to install whatever the hell you want on it 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices Gi…

> 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices I would instead say that having a trustworthy channel for verified app loading is a valuable security tool. F-Droid is such a channel; the Google Play Store is not. So Google is trying to take this valuable security tool away from users.

I'm unclear on why F-Droid is any safer than the playstore and not possibly worse since using it tells potential malware purveyors that you're into sideloading in the first place.

Re: What we talk about when we talk about sideloading

#149
post #130
post #112

Earlier quoted context omitted.

>Debian has had a "first party store" since the early 90s, and the truth is the diametrical opposite of "they're sufficiently unpopular that people don't think of them as the primary source to get apps". Aren't those all considered first party apps? Sure, debian aren't the authors of nginx or whatever, but they're the people building, packaging it, and adding patches for it. It's a stretch to compare them to the play…

Apt has supported multiple sources since inception. Debian is not the only supplier.

Right, but those would hardly be considered first party. Just because it goes through apt, doesn't mean it's first party.

Re: What we talk about when we talk about sideloading

#150
post #20

As an iOS user who's been frustrated with Apple's approach to "self-loading" (i.e., running your own code on your own devices) and who's actually gone out and gotten Android devices to write PoC/PoV apps on instead, I really don't like Google's stance on this--even if I would not, at this time, choose to daily drive an Android device, I do rely on F-Droid for getting software on six or seven different devices _right…

This year, I discovered SideStore on iOS, and its wonderful auto-refresh feature. Since then, I have written two iOS apps and am happily using them daily with zero issues. This plus the new Google announcement mean no going back to Android for me any time soon.
Post reply on HN