I think we could set the bar substantially higher. Don't even bother with discussion of sideloading. Talk about bounded transactions and device control. What is needed is: Once I have purchased a device, the transaction is over. I then have 100% control over that device and the hardware maker, the retailer, and the OS maker have a combined 0% control.
That bar would require infinitely good software on the hardware. Then it will be your device. Otherwise, they will constantly need to improve it. then it will be their software on your device.
What we talk about when we talk about sideloading
331–340 of 646 posts
Re: What we talk about when we talk about sideloading
#332Earlier quoted context omitted.
Is there no line, in your opinion? At this point, there are computers (many of which run variants of Linux in many cases) in my: 1. Laptop 2. Phone 3. Car 4. Washing machine 5. Handheld GPS 6. E-reader 7. TV Is there some intrinsic different between a device where the manufacturer has programmed it using an ARM/x86-based chip vs a microcontroller vs some other method that means in the 1st case I have the right to ins…
Yes, you absolutely should have the right to install (or uninstall) whatever software you want on any of those, assuming it contains writable program memory. The alternative is a nightmarish dystopian future where your washing machine company is selling its estimate of your political inclinations, sexual activities, and risk aversion to your car insurance company, your ex-husband, your trade union representative, and…
Likewise, I'd be fine with banking apps on phones requiring some level of trust, but it shouldn't affect how the rest of my phone works so drastically.
Re: What we talk about when we talk about sideloading
#333Earlier quoted context omitted.
> Given that both of these things are obviously true, it seems like a pretty obvious solution is to just have a pop up that has a install at your own risk warning whenever you install something outside of the official app store. It is an obvious solution, and it's a good first solution. This popup already exists. A problem in security engineering is that when people are motivated (which is easy to achieve), they will…
I guess this is a difference in philosophy then, but I think that the goal of security engineering should be to protect users from malicious actors, not to protect them from their own bad choices. If I give you a safety feature, and you turn it off, that's not my problem. There is a special level of hatred that I have reserved only for the busybodies who limit my choices and justify it as protecting me. That said, yo…
However, we need a better solution than pop-up warnings. I guarantee that you have clicked through a pop-up warning that was standing between you and the thing that you wanted to do (as have I, and everyone else who has used a computer for more than a day). We very quickly learn that most warnings aren't going to affect us, and that they're just saying "are you sure" to things that we're already sure of.
We've all selected a file, hit the delete key, got the pop-up saying "are you sure you want to delete wrong_file.txt", hit "yes" (because we always have to hit yes after hitting delete), then looked at the outcome and thought "oh, that was the wrong file" too late...
Re: What we talk about when we talk about sideloading
#334Earlier quoted context omitted.
I would say the situation is worse as this "subscription-esque" model is "spreading" to areas beyond software. Exercise equipment like ellipticals and bicycles - whose software is/could be borderline +/- resistance level trivial - has been moving to "only works with an online subscription" business models for a long time. I mean, I have had instances that controlled resistance with like a manual knob , but these new…
An even more grotesque practice is to charge a stratosphere level premium for the product itself AND put its control behind a subscription e.g. 8sleep
Re: What we talk about when we talk about sideloading
#335Why are OEMs like Samsung just letting this happen? A lot of power users who buy flagships will leave for iPhones if Android ceases to be an open platform. (This segment is what is preventing the “green bubbles = poor” narrative from taking over.)
> A lot of power users who buy flagships will leave for iPhones if Android ceases to be an open platform. 99.9% of people who use Android have never, and never will, install apps outside the Play Store, and aren't even aware that they can do so.
I'd guesstimate that close to 50% of Android users know how to install an apk.
Re: What we talk about when we talk about sideloading
#336They wanted to call it freeloading, but showed a bit of self-restraint. Whenever you side load anything, you are robbing someone's app store of income. You are not visiting their portal to be exposed to ads, you are not seeing ads in the middle of an application, you are not paying for anything. Or at least, not paying to them. The only streaming service I pay for in my household is Japanese TV, which uses a side-loa…
I'm not sure if your comment is satire. So I'll respond as is.
"Not providing potential further income" is not "robbing"... what is being stolen from them? Something they never had in the first place? When I lose a bet I willingly entered, am I being "robbed" of the gains?
Furthermore, who is losing if I go to F-Droid to install an open source app people wrote with no expectation of income? If Google had a better app, I would have installed it from there. Too bad everything is riddled with ads detracting from the core purpose.
Re: What we talk about when we talk about sideloading
#337Note that the Android permission system is designed so that you are not in control by design, some permissions are "not for you" and only for "system apps" which you can't control. This gives Google and device manufacturers advantage over third party software developers in the name of security... I think we should focus on defending the slowly-vanishing ability to unlock the bootloader and fight for the core parts of…
A great example of this is the 'networking' permission. Being able to control which app can speak to the WAN/LAN is a very important security consideration. Instead, every Android app can send any data it wants without the user being able to have a say in the matter. A lot of apps work just fine without being able to 'phone home'. Thankfully there's the likes of GrapheneOS, however, with Google's recent changes, unle…
I guess if it was, people would be turning off the network permission of all the "apps that perform a trivial function, but with ads", like I always do.
Re: What we talk about when we talk about sideloading
#338Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…
Could you make the claim that F-Droid is actually safer than "Google Play Store" The plea Google makes against so-called "sideloading" always refers to "malware" But how much malware has been distributed via F-Droid versus "Google Play Store" It could be that smaller, independent "app store" might be better managed than Google's
It's not about immediate safety, it's about safety in the long run.
Re: What we talk about when we talk about sideloading
#339Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…
Re: What we talk about when we talk about sideloading
#340Earlier quoted context omitted.
Hey, question. While I'm also miffed about Google's decision and see your point about the term sideloading, there is another elephant in the room you seem to not be addressing here. You write: > “Sideloading is Not Going Away” is clear, concise, and false_ But isn't Google saying that you will still be able to sideload via ADB ? Which would mean their statement is true, and that your claim that Google's statement is…
>But isn't Google saying that you will still be able to sideload via ADB? No, it will not. Nothing will install an application without a Google approved signature on it. They will remove ad blocks from your Android and you will like it. "The beatings will continue until morale improves" sort of behavior. I'm hopeful that the mystery OEM that GrapheneOS is targeting is in fact Sony Xperia. If it isn't, I'm just going…