Live data from Hacker News

What we talk about when we talk about sideloading

f-droid.org

221–230 of 646 posts

Re: What we talk about when we talk about sideloading

#221
post #137

Earlier quoted context omitted.

No, that is not the definition I was using. "Sideloading" is a subset of installing, not disjoint from it. If Google were to prevent installing, it would prevent sideloading, but it would also prevent installing from the Play Store, which clearly they don't want. It's a very dangerous precedent, but one that's difficult to discuss without having a name for the kind of installing that Google is trying to prevent.

I feel like although sideloading could be correct term maybe but at the same time as the author stated, people might refer something shady to something which is a genuinely normal part, maybe even more safer when you download from f-droid compared to play-store I feel like you are having this discussion in good faith which is really nice but I just feel like saying that google is oppressing other open source appstore…

Ultimately the only escape hatch is to build hardware that isn't dependent on Google, then stop being dependent on Android, which is what Huawei has done. https://news.ycombinator.com/item?id=45721022 goes into more detail.

Re: What we talk about when we talk about sideloading

#222
post #159

Earlier quoted context omitted.

"resistance level trivial" Could literally replace the control software with a potentiometer (a resistor)! :)

I mentioned a knob - it did the trick with literal mechanical friction { instead of electrical friction = potentiometer :-) }.

I know I'm on a tech website but so much consumer stuff is entirely too complicated for relatively spare benefits to the consumer.

Re: What we talk about when we talk about sideloading

#223
post #183

Earlier quoted context omitted.

Hey, question. While I'm also miffed about Google's decision and see your point about the term sideloading, there is another elephant in the room you seem to not be addressing here. You write: > “Sideloading is Not Going Away” is clear, concise, and false_ But isn't Google saying that you will still be able to sideload via ADB ? Which would mean their statement is true, and that your claim that Google's statement is…

Not only will sideloading via ADB continue to work, installing from most other third-party app stores will continue to work. The developers on the Amazon, Samsung, and Epic app stores won't have a hard time with the developer verification process. F-Droid is in a uniquely inconvenient position that they have a legitimate app store, but its design causes them to have a hard time with developer verification.

F-Droid is also the only one that does reproducible builds which is a big security feature. One that is precisely the cause of making this hard. But it also makes it safer than even the play store. It should really be accommodated.

Re: What we talk about when we talk about sideloading

#224
post #148
post #87

Earlier quoted context omitted.

> 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices I would instead say that having a trustworthy channel for verified app loading is a valuable security tool. F-Droid is such a channel; the Google Play Store is not. So Google is trying to take this valuable security tool away from users.

I'm unclear on why F-Droid is any safer than the playstore and not possibly worse since using it tells potential malware purveyors that you're into sideloading in the first place.

If I had to install a random app from the play store or from F-droid, I would pick F-droid every time. The level of vetting they apply is miles ahead of Google.

Re: What we talk about when we talk about sideloading

#225

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

Regardless of its origin, its usage in context clearly implies it's supposed to be understood as a non-standard, non-default process. Making preferred software design choices feel like defaults, or making preferred app or distribution ecosystems feel like default is the product of extraordinary and intentional effort to set expectations, and so I don't see it as an accident that the nomenclature would be used for the purposes you describe.

I did make a comment in this thread about the historical usage of the term sideload, although for my purposes, I was noting a historical quirk frim a unique time in the history of the internet rather than disputing any premise in your post. It was the first and only comment at the time I posted it and I was not anticipating such an unfortunate backlash that seized on terminology for the purpose of disputing your point, or for otherwise missing your point.

But it is indeed missing the point. Requiring developer registration to install is exercising a degree of control over the software ecosystem that's fundamentally out of step with something I regard as a pretty important and fundamental ideal in how software is able to be accessed and used.

Re: What we talk about when we talk about sideloading

#226

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

Hey, question. While I'm also miffed about Google's decision and see your point about the term sideloading, there is another elephant in the room you seem to not be addressing here. You write: > “Sideloading is Not Going Away” is clear, concise, and false_ But isn't Google saying that you will still be able to sideload via ADB ? Which would mean their statement is true, and that your claim that Google's statement is…

>But isn't Google saying that you will still be able to sideload via ADB?

No, it will not. Nothing will install an application without a Google approved signature on it. They will remove ad blocks from your Android and you will like it. "The beatings will continue until morale improves" sort of behavior.

I'm hopeful that the mystery OEM that GrapheneOS is targeting is in fact Sony Xperia. If it isn't, I'm just going to stop carrying a smartphone when all my installed apps stop working on it.

Re: What we talk about when we talk about sideloading

#227
post #125

Earlier quoted context omitted.

On the other hand, it used to be very common for malware on Windows to email itself to all your contacts using your real email client. It's probably reasonable for an OS to add a little friction to the process in the modern era, though it probably shouldn't lie and claim the binary is damaged when that's not the problem.

chmod to dequarantine doesn't sound like "a little friction" to me. On your point about security, this kind of aggressivity from the platform owner tend to backfire. The user was already convinced to open that mail, download that file, and try to run it. Pushing the process to the terminal just means your clueless users now run the provided incantations in the shell instead, and the attack vector now becomes huge (th…

I agree having to go to the command line is too much friction. Just clicking `overdue-invoice.doc.pif` is too little. About right is somewhere between a prompt and setting the file executable in the GUI.

Re: What we talk about when we talk about sideloading

#228
post #52

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

I would say the situation is worse as this "subscription-esque" model is "spreading" to areas beyond software. Exercise equipment like ellipticals and bicycles - whose software is/could be borderline +/- resistance level trivial - has been moving to "only works with an online subscription" business models for a long time. I mean, I have had instances that controlled resistance with like a manual knob , but these new…

Anyone buying internet-connected exercise equipment is getting exactly what they deserve.

Re: What we talk about when we talk about sideloading

#229
post #47
post #36

Earlier quoted context omitted.

What does this even mean? You don't want software updates? Or strictly only software updates that are 100% aligned with your wishes whatever they may be at the time?

Maybe I do, maybe I don't. It's for me to decide what updates I want, if any. Apple and Microsoft do not give you a choice. Precisely zero people wanted Copilot on their computers, but it's there anyway whether you want it or not.

You can choose not to update in both Android and iOS. Same with running Windows.

Re: What we talk about when we talk about sideloading

#230

The fact that we don't have root access to our phones is insane. This "sideloading" part is just the cherry on top of the dystopia we live in.

The result of this is very deep. Apple/Google effectively control what consumer technologies and services are allowed to gain traction.
Post reply on HN