Live data from Hacker News

Android’s new sideload settings will carry over to new devices

androidauthority.com

171–180 of 245 posts

Re: Android’s new sideload settings will carry over to new devices

#171
post #111

Earlier quoted context omitted.

I am quite genuinely curious what you think the best solution to prevent someone instructing a tech illiterate person over the phone to click through every permission warning about a malicious app they're installing is? No amount of scary menus will work. I feel like they only have 2 options, which is to limit some permissions without any exceptions (making their platform more closed), or make it harder to install ap…

It's not clear at all that a scammer is on the phone, instructing people to click through every warning that they see while sideloading a malicious app. As I stated up thread, the majority of these scams are happening through apps in the Play Store. To address your question, there should be a straightforward option during device setup. If you're first attaching your account to the device, you simply check a box that…

> the most obvious, straightforward, user-friendly approach, and it was never even discussed

Fwiw, it was "discussed" in the sense that the person we're arguing with meant upthread ("let's discuss a good solution instead of this boring repetitive outrage"), but it's not like Google listens to that so any such discussion is pointless anyway. It is indeed the obvious solution and it comes up in each of these threads, but believers like GP can always be new rationalizations of why Google doesn't implement one proposal or another

Re: Android’s new sideload settings will carry over to new devices

#172
post #38
post #25

What's the phone OS landscape now? What can someone who values their agency and wants FOSS choose? * iOS - walled garden, so no * Android: * * with a Google account and Play Services - a bit less of a walled garden, but still no * * Android without Google: * * * GrapheneOS - root or adb not supported, so no * * * LineageOS - (edit: root or adb not supported, so no - just learned) seems like a viable option although i…

> GrapheneOS - root or adb not supported, so no Like the other poster said, you can get root on GOS. However it's highly ill advised and severely breaks the security model of devices. 99% of the time nobody, especially the average person, needs root on their phone (imo). Allowing that easily just opens up the average person to getting duped into getting their phone rocked with exploits and possibly persistent malware…

You need root to get around all the stuff that Google won't let you do. There's tons of examples I've encountered over the last 20 years, but the one I encountered most recently is that without root, when I plug in an external display to my phone, I can't actually make the phone display go off. So it sits there powering the external display and its own display (that I'm not using) because of permissions.

Re: Android’s new sideload settings will carry over to new devices

#174

Earlier quoted context omitted.

Backing up all app data.

That breaks Android's security model and reduces overall security.

Ah yes, getting access to your own data would be a massive problem, can you imagine such a world?! /s

Such data should be put in (or encrypted by) the hardware-backed keystore. You get to have full access to what the OS does, including seeing what data gets passed into this secure element for encryption or signing (you retain visibility and control), and yet secrets can't be leaked to you or an attacker who tries to extract those secrets

See e.g. your bank card: it's yours, you can choose where to stick it and what transactions it authorizes, but you can't get at the token that serves as proof of possession nor reset the PIN attempts counter. Your phone('s banking app) could work in the same way and has the hardware on board that makes this possible. So you see, it's a choice that you don't get to see what apps are doing and people are scared into believing that access to their own phone is bad. It's a matter of conflicting incentives on the vendor side, not technical risk

Re: Android’s new sideload settings will carry over to new devices

#175
post #159

Earlier quoted context omitted.

Are Debian repos a viable grift target?

They absolutely are and that's why they're tightly curated by maintainers.

Exactly like... you guessed it... F-Droid. Not Google Play.

Re: Android’s new sideload settings will carry over to new devices

#176

Key point from the article: > ADB would be unaffected, and any power users who needed to install an app straight away could always connect their Android device to a computer and use ADB commands to manually install - no delay at all. So in practice this won't be an issue for anyone tech-savvy who uses their Android device with apps outside of the Play Store, as they can simply install through the ADB mechanism via a…

I would agree, but

- accepting that they take the finger now makes me worried about the rest of the hand

- it seems like a complete strawman argument: I have never heard of anyone getting scammed by being guided through system menus to enable app installations and then downloading and installing an apk from the scammer, as opposed to just going to the play store and installing e.g. teamviewer

- apps are already a pain about users with access to their own devices. If they can somehow detect that you're in "advanced flow" mode... that's going to be a real joy and further discourage/scare away people from using this

- my current understanding of the finger they've given us is that it does not include publishing apps via the play store and outside of the play store unless you change the app ID. One signing key is bound to one app ID when the developer does the verification to be in the Play Store and their code is not installable after compiling by an independent party. F-droid still can't exist in its current form

Re: Android’s new sideload settings will carry over to new devices

#177
post #122

Play store is the largest distributor of spyware and viruses for Android. Not even a small fraction of a percentage of scams come from installing software normally, but only from Google Play store.

> Not even a small fraction of a percentage of scams come from installing software normally, but only from Google Play store.

This change is not about stopping malware/scams. Malware/scams is just the gaslighting excuse for the change.

The actual reason for the change is to try to protect playstore profits. With the lawsuit that forced them to allow alternate "stores" they saw the money stream shrinking, and this is their attempt at propping up the money flow for as long as possible.

Re: Android’s new sideload settings will carry over to new devices

#178
post #134

Earlier quoted context omitted.

It's pretty easy to make up a reasonable sounding excuse for something you do for your own profit as a company. If they don't even provide any statistic on how frequent these scams are, it can be just words Also, if your bank 2fa code is in your notifications, you should switch 2fa methods to something other than sms, or switch banks.

So we should just accept that all apps must treat android notifications as a compromised communication channel? The scammers will find some other way to abuse the very generous permissions allowed by an android app if you prevent the notification attack.

> So we should just accept that all apps must treat android notifications as a compromised communication channel?

Look, that's an OS issue, not an app distribution issue. If I could use the trusted, vetted software from F-Droid I wouldn't need to worry about this sort of attack.

Re: Android’s new sideload settings will carry over to new devices

#179
post #103

Earlier quoted context omitted.

Why does nobody ever think of the poor megacorporation? I mean maybe you're even right and they care a little bit about people being scammed. But if you believe that the scamming thing is any more than a pretense for further establishing Google's absolute control over the Android ecosystem, that is just very naive. Their goal is to make money. Apps installed outside of Google mean less money for them. Ergo, consumer'…

I understand usually the megacorporation is simply being anti-consumer with these kinds of changes, and who knows maybe this is the same. But I think this might be an actual exception. They seem to be actually implementing a lot of high effort scam protection features recently in android so unless they did all of that just as an excuse to make side loading harder then they've fooled me. https://security.googleblog.co…

> They seem to be actually implementing a lot of high effort scam protection features recently in android

This all happened recently because a court case was recently decided that broke Google's monopoly on play store money flows (Google must now allow alternate play stores). These recent changes are simply to try to prop up as much of their play store profit center as they can by restricting what you can do with the computer you purchased.

Post reply on HN