Live data from Hacker News

What we talk about when we talk about sideloading

f-droid.org

401–410 of 646 posts

Re: What we talk about when we talk about sideloading

#401

Earlier quoted context omitted.

This community has pockets of people who like authoritarian control, and genuinely believe in Apple or Google Play as some kind of superego that they need to defend, that they believe is protecting us. This surfaces in many types of discussions, including discussions where they may be prompted to defend the locked down nature of mobile devices. I say it's just pockets. A vocal pocket. It's not everyone here. But it e…

> This community has pockets of people who like authoritarian control, Alternatively, we've spent our lives helping our parents out. Last year my mom just got completely owned, total taken over of all her financial accounts. The most likely vector was that her phone was out of date and not receiving security patches anymore. Luckily her bank's anti fraud systems kicked in before too much damage was done. Prior to sma…

  > The most likely vector was that her phone was out of date
No one is talking about stopping security patches. Your computer works fine, gets security patches, and you aren't restricted from installing any software on it.

Perhaps, as a fellow developer and a HACKER News user, you can understand that the underlying problem is the device security. Amplifying the problem is the surveillance capitalism ecosystem. Your data is valuable, to the trillion dollar companies and to hackers. Which means they need to collect that data and try to drive a fine line of giving them access but no one else. I thought we were all aware that trying to make backdoors is a foolish endeavor.

  > Prior to smart phones ... to remove malware and viruses from personal computers.
Your desktop computer is still a desktop computer. The smart phone didn't change anything there. If you're getting fewer viruses it is because either 1) the user is becoming more proficient, 2) the hackers are becoming less proficient, or 3) (the actual answer) security is getting stronger. Critical to #3 is noting that this has happened without the requirement of app stores.

I also want to stress, the enforcement of app stores is the death of phones and general purpose computers.

What makes computers (phones included) so great is that they are an ecosystem. You can't make a product for everyone, but you can make an ecosystem that can be adapted to anyone. Without programs these things aren't very useful. We're back in the old days like with the IBMs. Just remember, it took Google and Apple years before they put a flashlight app on their phones, but it only took weeks for developers. If we wait for them to build everything we're going to wait forever and won't get half the stuff we need.

  >>> You have the right to install whatever you want on your computer, regardless of whether that computer is on your desk or in your pocket. That's a hill I'll die on
It is a hill I'll die on too

Re: What we talk about when we talk about sideloading

#402

Earlier quoted context omitted.

When that happens we'll abandon the web as you described it and build a new one that better resists the cancer. Honestly there are a lot of bad decisions baked into out default stack that it's gonna be refreshing to be rid of. Not just malware and corporate overreach, but 1980s thinking that seemed fine at the time and turned out to not be. So to answer your question: Ubuntu will let you access the next web, and Andr…

Why the assumption that there will be a new web? If you're talking about developing some brand new means of worldwide communications, this seems extremely improbable if done by the 1% of the rest of us (basically, hobbyists and techy people). The internet required tens of billions of dollars worth of development and infrastructure to get to this point, how will it ever happen without the sponsorship of large centrali…

Its just a pattern I see repeated. The innovators find a playground, its cool for a while, then it succumbs to grift of some kind or another, and the innovators move on.

There was a time when "pamphlets" were an edgy new social medium, now its just a certain kind of ad. Same thing happened with radio. And now it has happened to the web also.

Why should this be the last time?

As for threatening the existing powers... I don't see what power they have if all they're guarding is a pile of stuff that nobody wants anymore.

It may be a bit inconvenient, but if you really need a device with radios that you can run arbitrary code on, you can get one for something like $4 and you can use your existing phone to drive it over something generic like http (There are plenty of people on meshtastic doing this).

I don't have the answers re: next steps but I know that its far more difficult to prevent people from communicating in novel ways than it is to come up with novel ways to communicate. I figure we've been playing this cat and mouse game with authority for millennia: they always win eventually and we always find a new way to make that victory irrelevant.

We lost. OK. What's left to do but invent the next battleground? We're hackers, its what we do.

Re: What we talk about when we talk about sideloading

#403

After Google implements this, will I still be able to "side-load" (install any software) on Android-derivative OSes like GrapheneOS?

Currently it seems that Google is pushing for hardware attestation, so you might be able to install Graphene/Lineage if your phone manufacturer allows you to unlock your bootloader, but many Play Store apps won't work as they'll detect your root. It's actually gotten pretty insane how every low-value app considers themselves the centre of the world and unable to run on a rooted device. Example: the loyalty card app f…

> as they'll detect your root

A small clarification, neither GrapheneOS or LineageOS runs as root. Rooting is different from "installing an alternate OS".

Re: What we talk about when we talk about sideloading

#404

Earlier quoted context omitted.

This community has pockets of people who like authoritarian control, and genuinely believe in Apple or Google Play as some kind of superego that they need to defend, that they believe is protecting us. This surfaces in many types of discussions, including discussions where they may be prompted to defend the locked down nature of mobile devices. I say it's just pockets. A vocal pocket. It's not everyone here. But it e…

> This community has pockets of people who like authoritarian control, Alternatively, we've spent our lives helping our parents out. Last year my mom just got completely owned, total taken over of all her financial accounts. The most likely vector was that her phone was out of date and not receiving security patches anymore. Luckily her bank's anti fraud systems kicked in before too much damage was done. Prior to sma…

You're assuming that the drawbacks of Google's peddled response are worth the alleged fix. Given that the primary malware vector for your mom's phone is the play store, this has all the hallmarks of a nonsolution: no benefit, only drawbacks.

It is the equivalent of restricting car use to paved roads only as a "solution" to car crashes.

Re: What we talk about when we talk about sideloading

#405

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

Sorry about this. This hairsplitting is common on HN comment threads. We lose track of the main theme and nitpick at great length on some word. .. A grateful F-Droid supporter and user.

Have to constantly remind others (and myself!) at work that "we aren't focusing on that right now, that's not what this conversation is about". Technical minded people seem to have a real problem of missing the forest for the trees.

Re: What we talk about when we talk about sideloading

#406

Earlier quoted context omitted.

This community has pockets of people who like authoritarian control, and genuinely believe in Apple or Google Play as some kind of superego that they need to defend, that they believe is protecting us. This surfaces in many types of discussions, including discussions where they may be prompted to defend the locked down nature of mobile devices. I say it's just pockets. A vocal pocket. It's not everyone here. But it e…

> This community has pockets of people who like authoritarian control, Alternatively, we've spent our lives helping our parents out. Last year my mom just got completely owned, total taken over of all her financial accounts. The most likely vector was that her phone was out of date and not receiving security patches anymore. Luckily her bank's anti fraud systems kicked in before too much damage was done. Prior to sma…

> my mom just got completely owned

Any evidence this was caused by "sideloading"?

Re: What we talk about when we talk about sideloading

#407
I have coded some apps that are customized for my mother's usage and accessibility. I plan on coding some more. I need to install them on just 2 phones - my own for testing and my mother's.

As of now, I can create APKs of my apps and install them on my mother's phone by unchecking the "prevent apps from other sources" option.

Even after going through so many articles, I still don't know unambiguously whether I can continue this workflow in future, or I'll need Google's approval to install on just our own 2 family phones.

There's a failure in communications here from both sides.

Ambiguity suits Google perfectly fine.

But it's counterproductive to its opponents because every dev who's confused will remain a fence-sitter rather than an ally, even if only motivated by personal inconvenience rather than any principled stand.

I doubt I'm the only Android dev who's confused. I hope at least f-droid communicates more clearly the consequences of this policy to all types of developers and deployment scenarios.

Re: What we talk about when we talk about sideloading

#408

Author here. I admit I am rather startled by the tone of many comments here and the accusations of disingenuity. Splitting hairs about the origin of the term "sideload" does not change the fact that those who promote the term tend to do so in order to make it feel deviant and hacker-ish. You don't "sideload" software on your Linux, Windows, or macOS computer: you install it. You have the right to install whatever you…

FWIW, thank you and the team for all the hard work. Me and my family use it to install, discover, and try out many of the genuinely useful and really cool, high-quality Apps on our de-Googled devices and truly appreciate it. I could never imagine using that ad-ridden, user-tracking, scam-infested, filth-flinging abomination they call Play "Store". The only thing that's worse is GCM - you don't even see it's there as a regular user.

Re: What we talk about when we talk about sideloading

#410

Earlier quoted context omitted.

This is what they say in their blog post: You will continue to be able to build and run an app even if your identity is not verified. Android Studio is unaffected because deployments performed with adb, which Android Studio uses behind the scenes to push builds to devices, is unaffected . You can continue to develop, debug, and test your app locally by deploying to both emulators and physical devices, just as you do…

I'm just not sure people have been referring to that method when saying 'sideloading' and Google didn't mention sideloading specifically there. This is what they say in the quote this article is about: "Does this mean sideloading is going away on Android? Absolutely not. Sideloading is fundamental to Android and it is not going away. Our new developer identity requirements are designed to protect users and developers…

I see, wow. That's such a frustrating lack of clarity on Google's part and (consequently?) those responding to the blog post...

As far as I now, historically, "sideloading" has always meant "installing from some mechanism other than the Play Store", and everyone has been referring to adb-based installations as "sideloading" as long as I can remember (example [1]). If Google or others don't call using adb sideloading, then I have no idea what they would call it, and I'm thoroughly confused.

[1] https://www.xda-developers.com/how-to-sideload-apps-android-...

Post reply on HN