Live data from Hacker News

Android’s new sideload settings will carry over to new devices

androidauthority.com

161–170 of 245 posts

Re: Android’s new sideload settings will carry over to new devices

#161
post #7

It's a very small concession. The high initial friction still means when someone comes to me with a problem and I tell them the solution is in F-Droid, they have to wait a day. Most give up and pick a different, less trustworthy solution from Google Play.

Given the Epic settlement means Google is allowing alternate app stores, and also the delay only applies for unregistered developers, I'm not certain it won't actually get easier to get folk set up on F-Droid. It still remains to be seen what the actual requirements are, and even if F-Droid could become "approved" that doesn't mean they want to. Time will tell.

"only applies for unregistered developers" but remember the whole point is to allow Google to pull your "registered developer" status on a whim. Something they've shown over and over again they cannot be trusted with

Re: Android’s new sideload settings will carry over to new devices

#162
post #78

None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes. If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the andr…

my bias former android and java dev....

Google choose an OS using a VM by design is insecure by default....

ITS NOT US USERS FAULT!

Re: Android’s new sideload settings will carry over to new devices

#163
post #122

Play store is the largest distributor of spyware and viruses for Android. Not even a small fraction of a percentage of scams come from installing software normally, but only from Google Play store.

Yeah. I had to remove malware from family phones because they installed the wrong "QR Code Scanner" out of the trillions of copies on the play store, which contained malware that somehow replaced the launcher on a Samsung phone and then showed ads all over the place. The Play store is fucking malware, Google services are malware, and the family member now uses a Pixel 9a with GrapheneOS which makes normie phone usage…

Stories like this is all my family members get iPhones. If Google wants to move to a walled garden too it should at least deliver on the walled garden benefits. No point otherwise.

Re: Android’s new sideload settings will carry over to new devices

#164
How is that setting supposed to carry over if I don't even have a Google account on my phone?

And even if I disregard that for a moment, what's up with the author being a mouthpiece for Google?

> Google's latest concession makes the sideloading controversy a big nothingburger

> Opting out is going to be even less of a problem than we thought

> This afternoon, Google’s Matthew Forsythe shares some answers to questions he’s gotten about the minutiae of how this process all works — and he’s got some very, *very* good news for us.

(emphasis theirs)

> Doing that once with every new phone already sounded perfectly manageable. But now Google clarifies that even that won’t be necessary, with the opt-out able to be transferred as we upgrade phones. That is maybe just the best news we could have gotten here, and hopefully it’s enough to calm everyone down about the sideloading-sky falling.

Re: Android’s new sideload settings will carry over to new devices

#165
post #78

None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes. If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the andr…

I don't find the assertion credible that people are getting scammed out of more money than the entire platform is worth. But given that Google does not make the revenue for Android public, what kind of numbers do you think you're talking about here?

Also, I think it's disingenuous to say that scams are predominantly powered by sideloading. I think the vast majority of the scams that are perpetrated use apps directly from the Play Store.

Re: Android’s new sideload settings will carry over to new devices

#166
post #104

Earlier quoted context omitted.

Google’s perspective is that they don’t want people to install NewPipe so that the CEO can buy more yachts.

I would bet the amount of people getting scammed is probably higher than those installing NewPipe.

Because we hear so many stories where the scammer directed their target to install an app so that their scam works

I know a lot more people that install newpipe than people that got scammed by any means, and have never heard of anyone being asked to install an app by a scammer

Re: Android’s new sideload settings will carry over to new devices

#167
post #103

Earlier quoted context omitted.

Why does nobody ever think of the poor megacorporation? I mean maybe you're even right and they care a little bit about people being scammed. But if you believe that the scamming thing is any more than a pretense for further establishing Google's absolute control over the Android ecosystem, that is just very naive. Their goal is to make money. Apps installed outside of Google mean less money for them. Ergo, consumer'…

I understand usually the megacorporation is simply being anti-consumer with these kinds of changes, and who knows maybe this is the same. But I think this might be an actual exception. They seem to be actually implementing a lot of high effort scam protection features recently in android so unless they did all of that just as an excuse to make side loading harder then they've fooled me. https://security.googleblog.co…

You don't need to side load a specific app with malware. All you do is tell the person to go to the Google Play Store and install any Anydesk. Heck, even the reviews for that app point out that people that are scamming you often tell you to install it. Kelly Walters' review from '23 has 215,000 upvotes for warning people about this.

Re: Android’s new sideload settings will carry over to new devices

#168

Earlier quoted context omitted.

First we need to understand what the root cause of the problem really is then we can discuss solutions. All we've been told is that "Android users are getting scammed, we are going to make side loading impossible". There is no clear cause and effect established, no data shared with the public on what percent of scams were caused by sideloaded apps and how the scams actually operate for us to be able to accept the sol…

> no data shared with the public on what percent of scams were caused by sideloaded apps and how the scams actually operate for us to be able to accept the solution. They will not share the data because the data goes against their public stance. Apks are already very annoying to install for your average user. The scams will target the web, the playstore and then as a very last resort, direct installs

What public stance do you mean? Did they say somewhere that sharing statistics about Android is against their morals or what do you mean?

Re: Android’s new sideload settings will carry over to new devices

#169
post #111

Earlier quoted context omitted.

Look at the attack vectors that are actually being used, and address them specifically, with minimally invasive measures. If the problem is apps that allow remote control of your device, that people can be socially engineered into installing, put up barriers to gaining just that permissions. That approach would actually help motivate the problem (as scammers can now just use Google-approved apps for such things). If…

I am quite genuinely curious what you think the best solution to prevent someone instructing a tech illiterate person over the phone to click through every permission warning about a malicious app they're installing is? No amount of scary menus will work. I feel like they only have 2 options, which is to limit some permissions without any exceptions (making their platform more closed), or make it harder to install ap…

If there is literally "No amount of scary menus will work." then those people cannot use computers. So long as they can transfer money with it, or do another action that a scammer may want to do, then the scammer can tell them to do it. They should not be allowed to install banking apps with that logic and need a legal guardian to manage their digital belongings

If the solution is that nobody has control of their digital life anymore (see also attempts to require client-side scanning and verify user age, which don't work if said user can override it) then we've lost sight of the bigger picture

Re: Android’s new sideload settings will carry over to new devices

#170
post #111

Earlier quoted context omitted.

Look at the attack vectors that are actually being used, and address them specifically, with minimally invasive measures. If the problem is apps that allow remote control of your device, that people can be socially engineered into installing, put up barriers to gaining just that permissions. That approach would actually help motivate the problem (as scammers can now just use Google-approved apps for such things). If…

I am quite genuinely curious what you think the best solution to prevent someone instructing a tech illiterate person over the phone to click through every permission warning about a malicious app they're installing is? No amount of scary menus will work. I feel like they only have 2 options, which is to limit some permissions without any exceptions (making their platform more closed), or make it harder to install ap…

It's not clear at all that a scammer is on the phone, instructing people to click through every warning that they see while sideloading a malicious app. As I stated up thread, the majority of these scams are happening through apps in the Play Store.

To address your question, there should be a straightforward option during device setup. If you're first attaching your account to the device, you simply check a box that says this is an advanced user's phone. You can put it behind the same kind of scary pop-ups that web browsers have when they're about to serve you an HTTP page, or when the HTTPS certificate is self-signed.

It's the most obvious, straightforward, user-friendly approach, and it was never even discussed.

Post reply on HN