Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

471–480 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#471
People already have the choice between an ecosystem that offers the safety of a walled garden and one that allows the freedom to do anything you like, including shooting yourself in the foot.

Google's decision to walk back the supposed freedom to run anything you like removes user choice from the marketplace and harms consumers.

Re: Google details new 24-hour process to sideload unverified Android apps

#472
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

open source alternative, at first it's going to suck. but over time it will win. imagine how miserable we would be if all we had was windows and osx. but we have linux. we are now at such crossroads were the choice is android and apple, we need a free alternative. much sooner than most realize the threat to freedom from big corps, govt and others will be so big that we would wish to have a free mobile OS. mobile is now the main computing platform and needs a free big corp alternative. it's true that some big corps would refuse to allow there apps to run on there like a bank, but that's okay! there will be alternatives ...

Re: Google details new 24-hour process to sideload unverified Android apps

#473
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

Tell the unsophisticated users that they would be safer inside the ecosystem that has always been a walled garden. Why destroy the ecosystem that gives you the freedom to shoot yourself in the foot? Turning Android into another walled garden removes user choice from the equation.

[deleted]

Re: Google details new 24-hour process to sideload unverified Android apps

#474

Earlier quoted context omitted.

Googler here (community engagement for Android) - I looked into the developer options question, and it's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you turn off developer options, then to turn off the advanced flow, you would first have to turn developer options back on.

If I understand correctly, the F-Droid store itself would be possible to install without waiting period, as it's an app from a verified developer. Would apps installed from F-Droid be subject to this process, or would they also be exempt? Could that be a solution that makes everyone happy? Android already tracks which app store an app originates from re: autoupdating. Also: Can I skip the 24h by changing the my phone…

> as it's an app from a verified developer.

Well that's if they go through the verification process, which does not seem like a thing they'd want to do - https://f-droid.org/en/2026/02/24/open-letter-opposing-devel...

Re: Google details new 24-hour process to sideload unverified Android apps

#475

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

[flagged]

> "That's just FURTHER PROOF that you're secretly trying to destroy my phone."

What a ridiculous strawman. I outlined a specific issue with what they introduced. To make it even more clear - the new flow Google created would work just the same with just the 24 hour delay, but the way how they introduced the "For how long should you be able to install apps?" question comes out of left field and suddenly makes you think about timing. Why would they ask you that? After all, you jumped through a sufficient number of hoops for Google, they probably estimated that anyone who has gone that far out of their way should know what they're doing. So why ask a developer or power user about the duration when this feature works? The very unsubtle hint here is that the question is asked because soon enough, 'Forever' will not be an option anymore. It's a very common tactic - restrictions start light, and then are ratcheted up into a nagging reminder that works to dissuade everyone but the most dedicated.

> You understand there's a real goal being pursued here, right? Suppose Google is dealing in good faith.

I do. But why are you so implicitly adamant that the only goals here are good, noble, moral goals? Google will do everything in its interests, regardless of how good or bad it is for people. Decreasing the vectors of attack on their platform is profitable for them, and it also coincides with the public interest of not getting hacked. But ensuring that other brands, OEMs or developers can't interfere with them building an app distribution monopoly is also good for them. Being the sole arbiters of what goes on the devices that have now become mandatory for participating in society is extremely good for them. Do you think they're only pursuing the first one of the three?

> How should they solve it differently?

You're not going to like the answer, but there's no clean, perfect solution that balances everyone's interests. Companies are pushing the safety angle in pursuit of the three interests I listed above. You can see just how much it ramped up in the last few years, even though we've been living under this status quo for decades. But it's not as simple as turning devices into grandma-phones with approved functionality only, because both extremes have big drawbacks. If you have 90s-style insecure fully-privileged computing for everyone, that's a path towards extremely unsafe and vulnerable systems, worked on by people who don't know what they're doing. If you have full lock-down, you're awarding current market leaders with an endless reign of power by insulating them from competition and giving them more control over users. The way we were doing things before this crackdown was striking a good balance of keeping most grandmas out while not choking the abilities of the hobbyists or third-party app distributors too much. If you want an alternative, an ADB flag that you have to change once through a command prompt would've been good too.

Re: Google details new 24-hour process to sideload unverified Android apps

#476
post #100

I'd urge everyone here to seriously consider switching to GrapheneOS. It's a far simpler transition than e.g. switching from Windows or OSX to Linux, and many people find that it has basically no friction vs android. More people moving to GrapheneOS is the best tool we have against Google's continued and escalating hostility to user freedom and privacy and general anti-competitive conduct. (Of course, you could ditch…

Would but unfortunately I got screwed with a locked bootloader, either going to go the dumbphone or the (much less practical) cyberdeck + SIM card route.

Re: Google details new 24-hour process to sideload unverified Android apps

#477
post #194
post #150

Earlier quoted context omitted.

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

> Where I live, in EU, parking meters even take cards.

Unfortunately, a more accurate way of putting it is: stuff takes cards in lieu of coins. Like, where I live (also EU), ticket machines in buses and trams have gradually been upgraded over the past decade to accept cards, and then to accept only cards.

It's a ratchet. Hidden inflation striking again. Cashless is cheaper to maintain than cash-enabled, so it pretends to be a value-add at first, but quickly displaces the more expensive option. Same with apps, which again, are cheaper to maintain than actual payment-safe hardware.

It's near impossible to reverse this, because to do that, you have to successfully argue for increasing costs - especially that inflation quickly eats all the savings from the original change, so you'd be essentially arguing to make things more expensive than the baseline.

Re: Google details new 24-hour process to sideload unverified Android apps

#478
post #418

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

A minuscule amount of nerds being slightly annoyed is definitely worth when it hinders scammers from ruining a persons live.

It won't make a dent in scammers' revenue.

Re: Google details new 24-hour process to sideload unverified Android apps

#479

Earlier quoted context omitted.

I suppose the question is, who is actually willing to believe Google is going to deal in Good Faith. Why would anyone ever even begin to think that?

[flagged]

Alex Jones is a bit much, yathink?

They're an amoral monopolistic megacorp that should have been broken up a year ago.

They are performing the ritual of maximalist offensive position -> half-hearted walk back to a worse status quo.

Is the problem they claim to want to solve real? Maybe. I haven't seen a convincing breakdown that doesn't lump a lot of unrelated fraud in the unvetted APK bucket.

That's beside the point though. No one should applaud this utterly predictable and disgusting behavior.

I don't accept it when Unity does it. I don't accept it when Hasbro does it. I won't accept it here either.

Re: Google details new 24-hour process to sideload unverified Android apps

#480
I'm not sure if I've heard this discussion from somewhere else and took it as my owm thought. Anyways, I consider this era the beginning of tech feudalism. I honestly don't think we'll be able to escape it. Please note I use Linux and GapheneOS as my two main daily drivers. Most normal people do not care and they think it's crazy I'd make my life so inconvenient. It's my perspective, but I believe users in general don't care, understand, and prefer convenience over choice. Which gives a lot of power to this push for max control. Wether we like it or not I think we won't be able to stop it. I'm not being negative about it or trying to demoralize anyone. We already have at least four basic tech-feudal states, Microsoft, Android, Apple, and Freedom-Software. Each one somewhat has a used base that reflects it's ideology.
Post reply on HN