Live data from Hacker News

What we talk about when we talk about sideloading

f-droid.org

271–280 of 646 posts

Re: What we talk about when we talk about sideloading

#271
post #69
post #52

Earlier quoted context omitted.

I would say the situation is worse as this "subscription-esque" model is "spreading" to areas beyond software. Exercise equipment like ellipticals and bicycles - whose software is/could be borderline +/- resistance level trivial - has been moving to "only works with an online subscription" business models for a long time. I mean, I have had instances that controlled resistance with like a manual knob , but these new…

That planned obsolescence thing on light bulbs isn't the entire story. Light bulbs will last longer if driven less hard, due to the lower temperature. But that lower temperature also means much lower efficiency because the blackbody spectrum shifts even further into the infrared. So some compromise had to be picked between having a reasonable amount of light and a reasonable life span. But yeah agree, this subscripti…

They will also last longer if the metal filament is thicker. Which is the way they artificially limited the lifespan.

Re: What we talk about when we talk about sideloading

#272
post #227

Earlier quoted context omitted.

chmod to dequarantine doesn't sound like "a little friction" to me. On your point about security, this kind of aggressivity from the platform owner tend to backfire. The user was already convinced to open that mail, download that file, and try to run it. Pushing the process to the terminal just means your clueless users now run the provided incantations in the shell instead, and the attack vector now becomes huge (th…

I agree having to go to the command line is too much friction. Just clicking `overdue-invoice.doc.pif` is too little. About right is somewhere between a prompt and setting the file executable in the GUI.

I wish it would run in a stricter sandboxed mode and prompt the user on the first network requests and file writes outside of it's directory.

That wouldn't be perfect, but at least the user could be prompted for a concrete action instead of a vague "this script is scary" warning.

Re: What we talk about when we talk about sideloading

#273

Earlier quoted context omitted.

> You don’t get to decide how others people’s devices work. Perfectly reasonable. It's important that people can decide how their devices work for themselves. No one else should decide for them. But I'm genuinely curious how you see this principle working in practice when there's effectively a duopoly. What's the path for someone who wants to still have any choices for their device? I'm not seeing an obvious answer,…

There isn’t a duopoly, it’s just that the two top contenders are way ahead of the rest, so wanting that niche feature requires a big sacrifices. Nowadays it’s not even that hard to build your own phone, but it’s not going to be a slick smartphone for sure

It's not possible to build your own phone in most markets anymore. Without iOS or Google Play Integrity you won't be able to install or run essential apps required for banking, taxes, healthcare, public transport, etc. This makes it impossible to compete because anyone who buys your phone are required to also buy a secondary Google approved Android or iPhone to lug around in order to function in society.

Re: What we talk about when we talk about sideloading

#274
post #87

I think this misses the forest for the trees here. The platforms behavior here is a symptom and not the core problem. I think the following are pretty clearly correct: 1. It's your damn phone and you should be able to install whatever the hell you want on it 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices Gi…

> 2. Having an approved channel for verified app loading is a valuable security tool and greatly reduces the number of malicious apps installed on users devices I would instead say that having a trustworthy channel for verified app loading is a valuable security tool. F-Droid is such a channel; the Google Play Store is not. So Google is trying to take this valuable security tool away from users.

"Trustworthy" requires a qualifier of "for what" and I do trust Google to not intentionally install malware on my device and to take reasonable steps to prevent other people from doing it. I will admit that I don't know the details of how the app stores work, but they are at least checking the hashes of the binaries right? The probability of trying to install Instagram from Meta, but actually installing Instapwned from some malicious third party is zero when you go through the app store, right?

Re: What we talk about when we talk about sideloading

#275
post #69

Earlier quoted context omitted.

That planned obsolescence thing on light bulbs isn't the entire story. Light bulbs will last longer if driven less hard, due to the lower temperature. But that lower temperature also means much lower efficiency because the blackbody spectrum shifts even further into the infrared. So some compromise had to be picked between having a reasonable amount of light and a reasonable life span. But yeah agree, this subscripti…

They will also last longer if the metal filament is thicker. Which is the way they artificially limited the lifespan.

That changes the resistance and thus efficiency

Re: What we talk about when we talk about sideloading

#276

I know that this is a controversial take here, but this sideloading crackdown is just fallout from the inevitable disaster that is mixing general purpose computing with high security and reliability requirements. There's just no way at this time in which a single computing device can run software with high reliability expectations (emergency calls), high security expectations (controlled calling/texting, banking, mon…

I always buy this argument....to the extent that the more powerful, dangerous capabilities are still allowed but locked behind some (one time) process that indicates you have a base level of knowledge and understanding. If you want to make it default safe for normies, fine, but let me turn my own device into the dangerous thing it is capable of being.

The version of the your view that we are actually getting is _incredibly_ paternalistic and condescending to the general populace. The kind of society that is capable of protecting everyone from every conceivable harm comes with the kinds of tradeoffs that no one, not even the people who actually need the protection, are going to want.

Re: What we talk about when we talk about sideloading

#277
post #69

Earlier quoted context omitted.

That planned obsolescence thing on light bulbs isn't the entire story. Light bulbs will last longer if driven less hard, due to the lower temperature. But that lower temperature also means much lower efficiency because the blackbody spectrum shifts even further into the infrared. So some compromise had to be picked between having a reasonable amount of light and a reasonable life span. But yeah agree, this subscripti…

They will also last longer if the metal filament is thicker. Which is the way they artificially limited the lifespan.

But if the filament is thicker you need much more current to get the same level of light, hence much lower efficiency, like your parent comment said.

Re: What we talk about when we talk about sideloading

#278

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

Could you make the claim that F-Droid is actually safer than "Google Play Store" The plea Google makes against so-called "sideloading" always refers to "malware" But how much malware has been distributed via F-Droid versus "Google Play Store" It could be that smaller, independent "app store" might be better managed than Google's

Google themselves have mentioned that about half of all malware is installed through their Play Store.

Re: What we talk about when we talk about sideloading

#279
post #91

Earlier quoted context omitted.

I'm not an expert on the case law, but supposedly United States v. General Electric Co. et al., 82 F.Supp. 753 (D.N.J. 1949) indicates that whatever design trade-offs might have existed, corporate policy makers were really just trying to screw consumers [1] (which is why they probably had to agree on short lifespans as a cartel rather than just market "this line of bulbs for these preferences" vs. "this other line fo…

Leds are already awful. I already lost 4 of 10 led light bulbs I boughtast year. I hope they will be replaced. It's because every led bulb has a small transformer inside and it fails quite quickly

It depends a lot on the bulbs. When we moved into our current house 11 years ago, we replaced everything with LEDs. Many of those original bulbs are still going strong, including all of the 20 or so integrated pot lights we put in to replace the old-school halogen ones. Others died within a year, and replacements have been similarly hit and miss. To some extent you get what you pay for; most of the random-Chinese-brand LEDs I've picked up off of Amazon have failed pretty quickly. Most of the Philips and similarly expensive ones have lasted. Also the incandescent-looking ones that stuff all the electronics into the base of the bulb tend to fail quickly, as do anything installed in an enclosed overhead light fixture, due to heat buildup.

Re: What we talk about when we talk about sideloading

#280

Is this seeking Google’s approval for the app? Or is the condition app be signed by a verified user? The latter means side loading is still viable for apps from known developers . This way anyone who is known who may create malware and will not be free from prosecution

> The latter means side loading is still viable for apps from known developers. This way anyone who is known who may create malware and will not be free from prosecution

Important corrections:

This way anyone who is known to create malware or any software which interferes with Google's current or potential future revenue, strategic interests, and unpredictable whims will not be free from prosecution in the case of distributing malware, nor from digital exile and unpersoning in the case of causing inconvenience to Google.

Post reply on HN