Live data from Hacker News

What we talk about when we talk about sideloading

f-droid.org

261–270 of 646 posts

Re: What we talk about when we talk about sideloading

#261
post #158

I think this misses the forest for the trees here. The platforms behavior here is a symptom and not the core problem. I think the following are pretty clearly correct: 1. It's your damn phone and you should be able to install whatever the hell you want on it 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices Gi…

This comment is very uninformed and misleading. > Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices These are claims that Apple and Google make to justify their distribution monopolies, and you are repeating them as fact. I don't think it's true, and cite as evidence both major app stores and the massive amount o…

> both major app stores and the massive amount of malware in them

This is true, but it's also not the main vector of attack. The primary threat is that the user is intending to download $WELL_KNOWN_APP and instead downloads a compromised binary from a malicious third party and is instantly compromised. The app stores make the probability of this essentially zero.

Re: What we talk about when we talk about sideloading

#262

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

Could you make the claim that F-Droid is actually safer than "Google Play Store" The plea Google makes against so-called "sideloading" always refers to "malware" But how much malware has been distributed via F-Droid versus "Google Play Store" It could be that smaller, independent "app store" might be better managed than Google's

Yes, software on F-droid is free and reviewed for anti-features before publishing. Google Play has the worst, ad ridden, dark pattern filled, data guzzling, subscription packed, commercial slop with no real oversight on what gets published. Malware frequently gets on the Play Store, never heard of it being a problem on F-Droid.

Re: What we talk about when we talk about sideloading

#263
post #254
post #242

Earlier quoted context omitted.

Yes, you absolutely should have the right to install (or uninstall) whatever software you want on any of those, assuming it contains writable program memory. The alternative is a nightmarish dystopian future where your washing machine company is selling its estimate of your political inclinations, sexual activities, and risk aversion to your car insurance company, your ex-husband, your trade union representative, and…

Why? My washing machine could be programmed to do all of those things you're worried about without any writeable memory. Why does the parts the manufacturer puts into it turn it from an appliance that washes my clothes to a computer that I have a right to install custom code on?

The principle is that the owner should have full control of their own device, because that's what defines private property. In particular, everything that the maker can make the device do must be something that the owner can make the device do. If the device is simply incapable of doing a certain thing, that might be bad for the owner, but it's not an abrogation of their right to their own property, and it doesn't create an ongoing opportunity for exploitation by the maker.

Maybe in theory your washing machine could be programmed to do those things without writable program memory. Like, if you fabricated custom large ROM chips with the malicious code? And custom Harvard-architecture microcontrollers with separate off-chip program and data buses? But then the functionality would be in theory detectable at purchase time (unlike, for example, Samsung's new advertising functionality: https://news.ycombinator.com/item?id=45737338) and you could avoid it by buying an older model that didn't have the malicious code. This would greatly reduce the maker's incentives to incorporate such features, even if it were possible. In practice, I don't think you could implement those features at all without writable program memory, even with the custom silicon designs I've posited here.

If you insist that manufacturers must not prevent owners from changing the code on their devices, you're insisting that they must not use any ROM, for any purpose, including things like the PLA that the 6502 used to decode instructions. It's far more viable, and probably sufficient, to insist that owners must be able to change any code on their devices that manufacturers could change.

Re: What we talk about when we talk about sideloading

#264
post #161

Earlier quoted context omitted.

It's a proper argument on its surface, complete with claim, warrant, and impact. "Features aren't rights" > see: Consumer Rights. "Force of the state making sideloading mandatory is bad" > ...Except we have antitrust laws? The Play Store becomes the only source of apps, all transactions are routed through Google Billing? Not a problem for you? "99% users won't use" > Except for when Google demands that transactions h…

> "Features aren't rights" > see: Consumer Rights. Consumer rights aren’t features, and they’re very intentionally written to not be. > "Force of the state making sideloading mandatory is bad" > ...Except we have antitrust laws? Then sue them over those. > Listen, either it's the case that "sideloading" is a threat to normies or it's not. Are normies your 1% or 99% of users? I thought according to you 99% of users wo…

"Consumer rights aren’t features" > Any attempt to weasel out of a marketed feature set is generally and colloquially known as "false advertising"; consumers have a right to the features of a product they purchase under the original conditions of the purchase agreement.

"Then sue them" > My point was that the force of the state is a necessary evil to ensure fair competition. Yours implied that the force of the state is overreach, but if you warrant that, then you wouldn't enjoy protections against corporations afforded to us by antitrust law.

"That you're not using something..." > For you to claim that sideloading presents additional threat surface to the normie consumer, you need to also claim that normie users are sideloading. This means that if 99 percent of users are not sideloading, there is no threat surface.

"Because corporations tend to die when they do anti-consumer things, but governments keep doing anti-citizen things without much trouble." > Absolutely not. The paradigm has changed from the time when you could vote with your dollar. You and I are economically and legally irrelevant (where is Congress, anyway?), and corporations like the Big G are too big to fail. They are -already- colluding with government to do both anti-consumer and anti-citizen things.

Nominatively, this is why both the government AND google do not want you to side-load software outside of their control.

Re: What we talk about when we talk about sideloading

#265
I know that this is a controversial take here, but this sideloading crackdown is just fallout from the inevitable disaster that is mixing general purpose computing with high security and reliability requirements.

There's just no way at this time in which a single computing device can run software with high reliability expectations (emergency calls), high security expectations (controlled calling/texting, banking, money transactions) at the same time as random crap from the internet and keep the user safe and secure.

The HN community is far to fixated on their own use cases to properly understand this issue and its implications which can potentially upset a person's entire existence.

Re: What we talk about when we talk about sideloading

#266
post #36

I think we could set the bar substantially higher. Don't even bother with discussion of sideloading. Talk about bounded transactions and device control. What is needed is: Once I have purchased a device, the transaction is over. I then have 100% control over that device and the hardware maker, the retailer, and the OS maker have a combined 0% control.

What does this even mean? You don't want software updates? Or strictly only software updates that are 100% aligned with your wishes whatever they may be at the time?

Pure security updates are often better than the status quo, but yes I'd prefer to have zero updates instead of the current mess.

Re: What we talk about when we talk about sideloading

#267
post #137

Earlier quoted context omitted.

This comment is funny because you have defined these words to be as such You have defined installing to be specifically from play store and sideloading as everything except it. Google isn't trying to prevent installing, just sideloading works in this sentence because of what you have already defined but you are using this sentence in defense of that.... As OP stated, installing can mean on debian as an example, insta…

No, that is not the definition I was using. "Sideloading" is a subset of installing, not disjoint from it. If Google were to prevent installing, it would prevent sideloading, but it would also prevent installing from the Play Store, which clearly they don't want. It's a very dangerous precedent, but one that's difficult to discuss without having a name for the kind of installing that Google is trying to prevent.

This is why this specific definition is problematic: both "sideloading" and "install from Play store" are subsets of "installing".

If one limited the ability to "install from Play store", while keeping the ability to "sideload", would you say it's fair to say "installing is restricted"?

Re: What we talk about when we talk about sideloading

#268
post #189
post #172

Earlier quoted context omitted.

>No, it's not a stretch at all. For one, it doesn't contain non-free software, and therefore can't be the primary source of software. Maybe you're a Stallman acolyte who only runs free software, but that's not feasible for the average user.

If you are running Linux non free software in the exception, not the rule. I myself can’t think of any that I run.

Try

    sudo apt install vrms

Re: What we talk about when we talk about sideloading

#269
post #191

I think this misses the forest for the trees here. The platforms behavior here is a symptom and not the core problem. I think the following are pretty clearly correct: 1. It's your damn phone and you should be able to install whatever the hell you want on it 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices Gi…

> Given that both of these things are obviously true, it seems like a pretty obvious solution is to just have a pop up that has a install at your own risk warning whenever you install something outside of the official app store. It is an obvious solution, and it's a good first solution. This popup already exists. A problem in security engineering is that when people are motivated (which is easy to achieve), they will…

[deleted]

Re: What we talk about when we talk about sideloading

#270

Earlier quoted context omitted.

Could you make the claim that F-Droid is actually safer than "Google Play Store" The plea Google makes against so-called "sideloading" always refers to "malware" But how much malware has been distributed via F-Droid versus "Google Play Store" It could be that smaller, independent "app store" might be better managed than Google's

Yes, software on F-droid is free and reviewed for anti-features before publishing. Google Play has the worst, ad ridden, dark pattern filled, data guzzling, subscription packed, commercial slop with no real oversight on what gets published. Malware frequently gets on the Play Store, never heard of it being a problem on F-Droid.

Google is a malware services company. They profit when malware OBS is the first search result when you search for OBS.
Post reply on HN