Earlier quoted context omitted.
If you don't want Play Store, don't use it?
"Google is slowly removing such option "for your safety", and "hackers" on this website really believe them.
Android’s new sideload settings will carry over to new devices
211–220 of 245 posts
Re: Android’s new sideload settings will carry over to new devices
#212Earlier quoted context omitted.
"Google is slowly removing such option "for your safety", and "hackers" on this website really believe them.
You can still install any ROM you want. Not having Play Store has some downsides, but those trades offs should be familiar to a free software enthusiast.
Re: Android’s new sideload settings will carry over to new devices
#213Earlier quoted context omitted.
FDroid has 0.2% of app volume of Play Store. Don't mistake obscurity for security. FDroid isn't the size to even be noticed by problems that Play Store and AppStore are dealing with.
This is exactly why I gave the example of Debian repos.
Re: Android’s new sideload settings will carry over to new devices
#214Earlier quoted context omitted.
This is exactly why I gave the example of Debian repos.
Which again work on a model of a single entity having all the curation power.
Re: Android’s new sideload settings will carry over to new devices
#215Earlier quoted context omitted.
Ah yes, getting access to your own data would be a massive problem, can you imagine such a world?! /s Such data should be put in (or encrypted by) the hardware-backed keystore. You get to have full access to what the OS does, including seeing what data gets passed into this secure element for encryption or signing (you retain visibility and control), and yet secrets can't be leaked to you or an attacker who tries to…
There is an API for backing up all app data that requires authorization. This is different from giving the user root, so any malicious can back up all app data at any time.
Re: Android’s new sideload settings will carry over to new devices
#216None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes. If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the andr…
I don't find the assertion credible that people are getting scammed out of more money than the entire platform is worth. But given that Google does not make the revenue for Android public, what kind of numbers do you think you're talking about here? Also, I think it's disingenuous to say that scams are predominantly powered by sideloading. I think the vast majority of the scams that are perpetrated use apps directly…
They're also growing rapidly, so those numbers might already be double in 2026
1. https://www.theguardian.com/technology/2025/dec/02/scam-stat...
Re: Android’s new sideload settings will carry over to new devices
#217None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes. If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the andr…
I don't find the assertion credible that people are getting scammed out of more money than the entire platform is worth. But given that Google does not make the revenue for Android public, what kind of numbers do you think you're talking about here? Also, I think it's disingenuous to say that scams are predominantly powered by sideloading. I think the vast majority of the scams that are perpetrated use apps directly…
"The Global Scam Report also found that scams were most often initiated by sending scam links via various messaging platforms to get users to install malicious apps and very often paired with a phone call posing to be from a valid entity."
https://security.googleblog.com/2023/10/enhanced-google-play... https://security.googleblog.com/2024/02/piloting-new-ways-to... https://blog.google/intl/en-in/products/launching-enhanced-f...
Re: Android’s new sideload settings will carry over to new devices
#218Earlier quoted context omitted.
I am quite genuinely curious what you think the best solution to prevent someone instructing a tech illiterate person over the phone to click through every permission warning about a malicious app they're installing is? No amount of scary menus will work. I feel like they only have 2 options, which is to limit some permissions without any exceptions (making their platform more closed), or make it harder to install ap…
It's not clear at all that a scammer is on the phone, instructing people to click through every warning that they see while sideloading a malicious app. As I stated up thread, the majority of these scams are happening through apps in the Play Store. To address your question, there should be a straightforward option during device setup. If you're first attaching your account to the device, you simply check a box that…
Google claims this to be a very common or majority attack vector.
"The Global Scam Report also found that scams were most often initiated by sending scam links via various messaging platforms to get users to install malicious apps and very often paired with a phone call posing to be from a valid entity."
https://security.googleblog.com/2024/02/piloting-new-ways-to...
> If you're first attaching your account to the device, you simply check a box that says this is an advanced user's phone.
I completely agree this is a perfectly valid solution but what about those who already setup their device? The security of the checkbox only works if you click it before someone attempts to scam you.
Re: Android’s new sideload settings will carry over to new devices
#219Earlier quoted context omitted.
Exactly like... you guessed it... F-Droid. Not Google Play.
FDroid has 0.2% of app volume of Play Store. Don't mistake obscurity for security. FDroid isn't the size to even be noticed by problems that Play Store and AppStore are dealing with.
Now, it might be a problem of vetting at scale or malware being really subtle, but if that's the case Google should focus on improving their process before locking down Android for "security".
Re: Android’s new sideload settings will carry over to new devices
#220Earlier quoted context omitted.
I'm biased, but I don't think less trustworthy is a fair assessment. I think you can suggest that open source software provides a different trust model than closed source and distributed by Play, but to conclude it's less trustworthy is a real stretch.
The vast majority of software on Google Play is absolute spyware-laden slop. There are turstworthy apps, sure, but they are drops in an ocean. F-Droid’s trustworthy-to-ad-ridden-slop ratio is pretty much definitionally lower than Google’s, by virtue of it being actually curated. That everything on it is libre and they are working hard on reproducible builds just makes it all the better.
F-Droid has the benefit that it essentially doesn't have to deal with malicious actors. It's very easy to have a high quality library when there are no malicious actors.