Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

581–590 of 694 posts

Re: Android developer verification: Early access starts

#581
post #111
post #102

Earlier quoted context omitted.

> > intercepts the victim's notifications > And who controls these notifications and forces application developers to use a specific service? Am I alone in being alarmed by this? Are they admitting that their app sandboxing is so weak that a malicious app can exfil data from other unaffiliated apps? And they must instead rely on centralized control to disable those apps after the crime? So.. what’s the point of the s…

> Are they admitting that their app sandboxing is so weak that a malicious app can exfil data from other unaffiliated apps? An app can read the content of notifications if the appropriate permissions are granted, which includes 2FA codes sent by SMS or email. That those are bad ways to provide 2FA codes is its own issue. I want that permission to exist. I use KDE Connect to display notifications on my laptop, for exa…

> An app can read the content of notifications if the appropriate permissions are granted, which includes 2FA codes sent by SMS or email.

Do apps generally do this? I've never run into one that doesn't expect me to type in the number sent via SMS or email, rather than grabbing it themselves.

I don't use a lot of apps on my android phone, though, so maybe this is a dumb question to those who do.

Re: Android developer verification: Early access starts

#582

"Allow". This is the entirety of the problem. They are allowing things on my machine that I purchased with monies that I leased my soul for. Anyway, I am already planning for a future in which Google does not feature as prominently as did until now. Small steps so far ( grapheneOS ), but to me the writing the wall is unmistakable. Google got cold feet over feedback and now they can allow things. When negative publici…

Consider UbuntuTouch, really nice ecosystem and community, you can run many Android apks.

Re: Android developer verification: Early access starts

#583

Earlier quoted context omitted.

> In most cases, F-Droid couldn't know either. F-Droid is quite restrictive about what kinds of app they accept, they build the app from source code themselves, and the source code must be published under a FLOSS license. They have some checks that have to pass for each new version of an app. Although it's possible for a developer to transfer their accounts and private keys to someone shady, F-Droid's checks and open…

One thing worth noting, these checks and restrictions only apply if you're using the original F-Droid repository. Many times I've seen the IzzyOnDroid repository recommended, but that repo explicitly gives you the APKs from the original developers, so you don't get these benefits.

That's true. The whole point of an open ecosystem is that you get to decide who you get your software from. You can decide on the official F-Droid repository and get the benefits and drawbacks of a strict open source rule with the F-Droid organization's curation if that's your preference. You can add other repositories with different curation if you prefer that.

Re: Android developer verification: Early access starts

#584

Earlier quoted context omitted.

It's the JUDGE that came up with that reasoning.

Yeah it's the judge.

I think you missed the point that judges aren't part of the legislative branch. They're in the judicial branch.

Re: Android developer verification: Early access starts

#585
post #499

Excuse me, what exactly is "sideloading"? If I wanted to run third-party code on a system through the means that's supported by the system, then it should be called "running", it's a part of normal operation. The word "sideload" made it sound like you're smuggle something you shouldn't onto the system. Subtle word tricks like this could sneak poisons into your mind, be watchful.

You can't make people just stop using a word. The best course of action is to reclaim it. Look at us, we're posting on Hacker News. With a sideloaded browser.

They already did! The word was install. Or as GP noted, run. They're actually even now much more conventional and widely understood uses, and if anything it's Google attempting to swim against the stream and normalize sideload as language for software installation. Theirs is an object lesson, I think, in appropriately registering the objection and pushing us back to normal language.

Re: Android developer verification: Early access starts

#586
post #111

Earlier quoted context omitted.

> Are they admitting that their app sandboxing is so weak that a malicious app can exfil data from other unaffiliated apps? An app can read the content of notifications if the appropriate permissions are granted, which includes 2FA codes sent by SMS or email. That those are bad ways to provide 2FA codes is its own issue. I want that permission to exist. I use KDE Connect to display notifications on my laptop, for exa…

> An app can read the content of notifications if the appropriate permissions are granted, which includes 2FA codes sent by SMS or email. Do apps generally do this? I've never run into one that doesn't expect me to type in the number sent via SMS or email, rather than grabbing it themselves. I don't use a lot of apps on my android phone, though, so maybe this is a dumb question to those who do.

Most apps don't read notifications for that purpose, and I'm not sure they'd be allowed in the Play Store if they wanted the permission just for that. It's mainly used for automation and sending notifications to other devices like PCs and maybe smartwatches.

Re: Android developer verification: Early access starts

#587
post #536
post #499

Excuse me, what exactly is "sideloading"? If I wanted to run third-party code on a system through the means that's supported by the system, then it should be called "running", it's a part of normal operation. The word "sideload" made it sound like you're smuggle something you shouldn't onto the system. Subtle word tricks like this could sneak poisons into your mind, be watchful.

You're about two decades late to the complaint party in this context at least. I can find references on google books back in 2006 referencing sideloading. https://www.google.com/books/edition/CNET_Do_It_Yourself_IPo...

I'm ready to grant that you found an occurrence in the wild but it takes more than that to demonstrate prevalence, conventional usage, or semantic fidelity to originally intended meanings. Also they are appealing to a usage that's practically as old as the paradigm of personal computing itself, so I don't think they're the one that's out of date.

I happen to remember "sideload" as a term of art for some online file locker sites to mean saving it to your cloud drive instead of downloading it to your computer. A cool usage, but it never caught on.

I think nomenclature as it exists in the PC software universe is closest in spirit on all fronts, in describing running software as, well, running software, and describing installing as installing. While a little conspiratorial in tone they're not wrong that "sideload" pushes the impression that controlling what software you run on your phone should be understood as non-default.

Re: Android developer verification: Early access starts

#588
post #499

Excuse me, what exactly is "sideloading"? If I wanted to run third-party code on a system through the means that's supported by the system, then it should be called "running", it's a part of normal operation. The word "sideload" made it sound like you're smuggle something you shouldn't onto the system. Subtle word tricks like this could sneak poisons into your mind, be watchful.

I keep hearing that here, and people have good reasons why they think of that but to me sideloading always meant having your phone physically next to the device you're pulling an apk from, in other words loading the app from the side.

Yeah, that strikes me as a familiar use also. They seem to be using it to mean not only that but any software installation that doesn't happen via the Play Store, so it's rooted in real history but also conveniently re-appropriated to imply it's veering outside of typically intended use cases.

Re: Android developer verification: Early access starts

#589
post #540

Earlier quoted context omitted.

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

> In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected. 1. The Android OS does not allow installing app updates if the new APK uses a different signing key than the existing one. It will outright refuse, and this works locally on device. There's no need to ask some third party server to verify anything. It's a fundamental part of…

Android also has the feature of warning the user if an update is coming from a different source than what is installed. This will happen even if they have the same key. This reply isn't trying to argue against anything you've said. I am just adding to the list of how Android handles updates.

Re: Android developer verification: Early access starts

#590
post #536

Earlier quoted context omitted.

You're about two decades late to the complaint party in this context at least. I can find references on google books back in 2006 referencing sideloading. https://www.google.com/books/edition/CNET_Do_It_Yourself_IPo...

I'm ready to grant that you found an occurrence in the wild but it takes more than that to demonstrate prevalence, conventional usage, or semantic fidelity to originally intended meanings. Also they are appealing to a usage that's practically as old as the paradigm of personal computing itself, so I don't think they're the one that's out of date. I happen to remember "sideload" as a term of art for some online file l…

This is an instance of an on target usage though relating to the unofficial loading of software onto the device. And in my eyes finding it in a published work by a major publication means it was likely in wider usage in the same context, at the very least it can be an indicator of the start of that particular usage.
Post reply on HN