Live data from Hacker News

Android’s new sideload settings will carry over to new devices

androidauthority.com

211–220 of 245 posts

Re: Android’s new sideload settings will carry over to new devices

#211

Earlier quoted context omitted.

If you don't want Play Store, don't use it?

"Google is slowly removing such option "for your safety", and "hackers" on this website really believe them.

You can still install any ROM you want. Not having Play Store has some downsides, but those trades offs should be familiar to a free software enthusiast.

Re: Android’s new sideload settings will carry over to new devices

#212

Earlier quoted context omitted.

"Google is slowly removing such option "for your safety", and "hackers" on this website really believe them.

You can still install any ROM you want. Not having Play Store has some downsides, but those trades offs should be familiar to a free software enthusiast.

You can only do this on a tiny number of devices supporting free drivers (and mainline kernel), otherwise you are tied to an ancient Linux kernel. I'm using Librem 5 btw and don't believe that Android, whose development completely depends on Google, is a viable long-term solution.

Re: Android’s new sideload settings will carry over to new devices

#213
post #205

Earlier quoted context omitted.

FDroid has 0.2% of app volume of Play Store. Don't mistake obscurity for security. FDroid isn't the size to even be noticed by problems that Play Store and AppStore are dealing with.

This is exactly why I gave the example of Debian repos.

Which again work on a model of a single entity having all the curation power.

Re: Android’s new sideload settings will carry over to new devices

#214
post #213

Earlier quoted context omitted.

This is exactly why I gave the example of Debian repos.

Which again work on a model of a single entity having all the curation power.

My point is that Google does not want to protect users by restricting "side loading". If they actually wanted that, they would remove all the malware in their store. They are just building higher walls in the walled garden to lock you in.

Re: Android’s new sideload settings will carry over to new devices

#215
post #174

Earlier quoted context omitted.

Ah yes, getting access to your own data would be a massive problem, can you imagine such a world?! /s Such data should be put in (or encrypted by) the hardware-backed keystore. You get to have full access to what the OS does, including seeing what data gets passed into this secure element for encryption or signing (you retain visibility and control), and yet secrets can't be leaked to you or an attacker who tries to…

There is an API for backing up all app data that requires authorization. This is different from giving the user root, so any malicious can back up all app data at any time.

Which API do you mean?

Re: Android’s new sideload settings will carry over to new devices

#216
post #78

None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes. If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the andr…

I don't find the assertion credible that people are getting scammed out of more money than the entire platform is worth. But given that Google does not make the revenue for Android public, what kind of numbers do you think you're talking about here? Also, I think it's disingenuous to say that scams are predominantly powered by sideloading. I think the vast majority of the scams that are perpetrated use apps directly…

Googles total revenue in 2025 was about $400 billion across their entire company. It's hard to estimate how much money scammers steal in general but if you take an estimate[1] that each of the 300,000 forced laborers generates $300-400/day then you end up at a figure of 40 billion in scams, and considering android has most of the market in the regions the scammers target you can be pretty sure those are android owners being scammed through android devices.

They're also growing rapidly, so those numbers might already be double in 2026

1. https://www.theguardian.com/technology/2025/dec/02/scam-stat...

Re: Android’s new sideload settings will carry over to new devices

#217
post #78

None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes. If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the andr…

I don't find the assertion credible that people are getting scammed out of more money than the entire platform is worth. But given that Google does not make the revenue for Android public, what kind of numbers do you think you're talking about here? Also, I think it's disingenuous to say that scams are predominantly powered by sideloading. I think the vast majority of the scams that are perpetrated use apps directly…

They've been claiming since 2023 that sideloading has been a favored attack vector.

"The Global Scam Report also found that scams were most often initiated by sending scam links via various messaging platforms to get users to install malicious apps and very often paired with a phone call posing to be from a valid entity."

https://security.googleblog.com/2023/10/enhanced-google-play... https://security.googleblog.com/2024/02/piloting-new-ways-to... https://blog.google/intl/en-in/products/launching-enhanced-f...

Re: Android’s new sideload settings will carry over to new devices

#218
post #111

Earlier quoted context omitted.

I am quite genuinely curious what you think the best solution to prevent someone instructing a tech illiterate person over the phone to click through every permission warning about a malicious app they're installing is? No amount of scary menus will work. I feel like they only have 2 options, which is to limit some permissions without any exceptions (making their platform more closed), or make it harder to install ap…

It's not clear at all that a scammer is on the phone, instructing people to click through every warning that they see while sideloading a malicious app. As I stated up thread, the majority of these scams are happening through apps in the Play Store. To address your question, there should be a straightforward option during device setup. If you're first attaching your account to the device, you simply check a box that…

> It's not clear at all that a scammer is on the phone, instructing people to click through every warning that they see while sideloading a malicious app.

Google claims this to be a very common or majority attack vector.

"The Global Scam Report also found that scams were most often initiated by sending scam links via various messaging platforms to get users to install malicious apps and very often paired with a phone call posing to be from a valid entity."

https://security.googleblog.com/2024/02/piloting-new-ways-to...

> If you're first attaching your account to the device, you simply check a box that says this is an advanced user's phone.

I completely agree this is a perfectly valid solution but what about those who already setup their device? The security of the checkbox only works if you click it before someone attempts to scam you.

Re: Android’s new sideload settings will carry over to new devices

#219
post #205

Earlier quoted context omitted.

Exactly like... you guessed it... F-Droid. Not Google Play.

FDroid has 0.2% of app volume of Play Store. Don't mistake obscurity for security. FDroid isn't the size to even be noticed by problems that Play Store and AppStore are dealing with.

F-Droid at least does a quick review to make sure there's nothing malicious in the app before adding it. Since we know Google does something similar and there is still malware on the Play Store one might reasonably conclude that Google doesn't actually care about malware.

Now, it might be a problem of vetting at scale or malware being really subtle, but if that's the case Google should focus on improving their process before locking down Android for "security".

Re: Android’s new sideload settings will carry over to new devices

#220
post #67

Earlier quoted context omitted.

I'm biased, but I don't think less trustworthy is a fair assessment. I think you can suggest that open source software provides a different trust model than closed source and distributed by Play, but to conclude it's less trustworthy is a real stretch.

The vast majority of software on Google Play is absolute spyware-laden slop. There are turstworthy apps, sure, but they are drops in an ocean. F-Droid’s trustworthy-to-ad-ridden-slop ratio is pretty much definitionally lower than Google’s, by virtue of it being actually curated. That everything on it is libre and they are working hard on reproducible builds just makes it all the better.

This is a bunch of opinion though. I'm not saying I disagree, but I do think it's bad faith to state as fact what is opinion. Is Play a "walled garden" or is it not curated? It can't be both depending on what suits the argument. You may disagree with the policies, but suggesting there are no policies in favour user privacy is just false. You may think they aren't enforced sufficiently, but again this is opinion. The policies are there.

F-Droid has the benefit that it essentially doesn't have to deal with malicious actors. It's very easy to have a high quality library when there are no malicious actors.

Post reply on HN