Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

421–430 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#421

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

Probably f droid will become an official app store recognized by Google, and then you won't have to go through this flow to install f droid or its apps.

As I understand it, that would not bypass Google's requirement that the developer of each app be verified by Google.

Re: Google details new 24-hour process to sideload unverified Android apps

#422
post #194

Earlier quoted context omitted.

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

Place where I park my car for work (Gosford, Australia) just got rid of cash payment, they now take card payment only (apparently there is also going to be an app, but they haven’t launched it yet). I think the number one reason is they are upgrading to a new system, and the parking technology vendor doesn’t provide cash payments as a standard option-probably they could implement a custom integration to enable it if…

It’s kinda easy to justify though from a financial standpoint. If the parking meters take cash, you need all the hardware to accept and secure the cash. Then you need somebody to go around at some point and actually physically collect the cash. Then someone has to reconcile the cash, etc.

So at least from that angle I see it as an easy “government is actually trying to be more efficient” argument.

As a user cash is a pain in the ass. I have to count it out, keep it in my pockets, etc. So much easier to just tap my phone or my card. But yeah that’s a tradeoff in the classic “You’re trading X for convenience”.

Re: Google details new 24-hour process to sideload unverified Android apps

#423
post #387

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

what's your solution to combat scammers?

Not the parent or agreeing/disagreeing with them, but to your question: if you get creative, there are a lot of things you could do, some more unorthodox than others.

Tongue-in-cheek example, just to get the point across: instead of calling it Developer Mode, call it "Scam mode (dangerous)". Require pressing a button that says "Someone might be scamming me right now." Then require the user to type (not paste) in a long sentence like "STOP! DO NOT CONTINUE IF SOMEONE IS TELLING YOU TO DO THIS! THIS IS A SCAM!"... you get the idea. Maybe ask them to type in some Linux command with special symbols to find the contents of some file with a random name. Then require a reboot for good measure and maybe require typing in another bit of text like "If a stranger told me to do this, it's a scam." Basically, make it as ridiculous and obnoxious as possible so that the message gets across loud and clear to anybody who doesn't know what they're doing.

Re: Google details new 24-hour process to sideload unverified Android apps

#424
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

[flagged]

You didn't even slightly research the topic of phone malware, browse /r/isthisascam for starters. I don't say the problem is an "epidemic" and it doesn't have to be an epidemic to be addressed.

Re: Google details new 24-hour process to sideload unverified Android apps

#425
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

I fully agree. Similar to killing bacteria with antibiotics, Attempting to idiot-proof machinery only leads to the creation of idiot-proofing-resistant idiots.

We need to move back to putting users back into full control. Machines (including computers) should ALWAYS respect the input of the user, even if the user is wrong.

If a person shoots themself with a gun as a result of their incompetence, we don't fault the gun manufacturer for not designing the gun to prevent auto-execution. If you can't operate a firearm safely, you shouldn't attempt to operate a firearm.

Similarly, if a person deliberately points their car a solid object and accelerates into it, the actions of the operator shouldn't be the car manufacturer's responsibility. We need to get rid of ESC, ABS, AEB, etc. These features have created a whole slew of drivers who speed headfirst into the back of stationary drivers and expect their car to stop itself. This works right up until a sensor fails and the operator flies through the windshield (usually people like this don't wear seat-belts). If you can't drive, you shouldn't be driving until you rectify your incompetence.

Similarly, phones and computers should respect user input. If a users wants root access to their personal device, they should be able to get root access. If a user runs "rm -rf --no-preserve-root /" as root, the device should oblige and delete everything, since that is what the operator instructed it to do. If you can't be trusted to use a computer, you shouldn't be using a computer until you rectify your incompetence.

The lack of accountability in modern society is disgusting, and it leads to much deeper societal problems when people refuse to better themselves and instead expect the world to shield them from their willful ignorance.

Re: Google details new 24-hour process to sideload unverified Android apps

#426

Earlier quoted context omitted.

You can do that, there are custom roms and open source phones. The problem is banks are legally obligated a lot of the time to pay out for fraud and scams. So in response they won't allow you to run their software unless they can verify the compute environment.

So why can I access my bank account just fine via the website on my phone, but shouldn't be able to do the same via the app? Can't they offer at least a PWA version of the website for custom ROM users?

People tend to distrust websites. URLs are also an immutable ledger that guarantees you’re in the right spot. The web is surprisingly robust for security.

What guarantees your banking app is the right one? A PNG and an app name with no security whatsoever.

Re: Google details new 24-hour process to sideload unverified Android apps

#427
post #30

Earlier quoted context omitted.

> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.

I think the more important aspect is that people will have 24h to slow down, think, and realize that they are being scammed. Urgency and pressure is one of the top tactics used by scammers. Scammers will definitely call back the next day to continue. But it is quite possible that by then the victim has realized, or talked to someone who helped them realize that they are being scammed.

There's been some reporting recently where I live about a case of some woman being scammed.

She went to a bank to transfer the scammer money. They told her no. She came back the next day. The police got involved and explained everything to her. Then she came back the next day. After that, she apparently found another location which let her transfer the money.

There's basically zero chance a 24 hour (or any amount of a) cool off period will help these people.

Re: Google details new 24-hour process to sideload unverified Android apps

#428

Earlier quoted context omitted.

We'll see when this rolls out, but I don't foresee the package manager checking for developer mode when launching "unverified" apps, just when installing them. AFAICT the verification service is only queried on install currently.

Googler here (community engagement for Android) - I looked into the developer options question, and it's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you turn off developer options, then to turn off the advanced flow, you would first have to turn developer options back on.

If I understand correctly, the F-Droid store itself would be possible to install without waiting period, as it's an app from a verified developer.

Would apps installed from F-Droid be subject to this process, or would they also be exempt? Could that be a solution that makes everyone happy? Android already tracks which app store an app originates from re: autoupdating.

Also: Can I skip the 24h by changing the my phone's clock?

Re: Google details new 24-hour process to sideload unverified Android apps

#429
post #387

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

what's your solution to combat scammers?

I suppose you could make the cooldown apply to the actual installed app. Like... when it's first installed it won't work for 24 hours and the clock doesn't start until you reboot. And then on boot it scares you again before starting the clock. And then "scares" you again after the cooldown.
Post reply on HN