Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

611–620 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#612
post #18

Can you set your clock forward or does this also require phoning home to a central server to install an app on your computer?

It requires an internet connection to adjust the toggle.

I think it would be a bad idea to require an internet connection (for one thing, you might want to write your own app that does not require a internet connection); but, even if it doesn't, would not mean you can set the clock to avoid the delay, because it could be made to reset the delay if the clock is set.

Re: Google details new 24-hour process to sideload unverified Android apps

#613
post #522
post #447

Earlier quoted context omitted.

There's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. Would welcome evidence to the contrary. Is this truly a threat model that's seen in the wild? My gut says no because social engineering is about hijacking legitimate, first-party processes. Scammers attack login credentials, MFA flows, and use first-party apps to m…

>There's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. I also never got targeted by pig butchering scams[1], and neither did my immediate friends/family, so I guess those must not exist either? [1] https://en.wikipedia.org/wiki/Pig_butchering_scam

You don’t need malicious apps for this, it’s common to use real crypto exchanges and get them to send you money. How does google’s approach solve that?

And here are apps straight from the App Store [0] that are outright scams. How dos this protect people from these?

[0]: https://arstechnica.com/information-technology/2023/02/pig-b...

Re: Google details new 24-hour process to sideload unverified Android apps

#614

Judging by the comments sideloading plays a major part in everyone's life. What apps do you sideload guys? Why those apps are not in a store?

Apart from why "those apps are not in a store", there's very good reason to want to use an alternative source for your applications. F-droid is a far safer source than google play is, because they actually vet the source code and project and build it themselves. You are far more likely to download malware from google's official 'safe' sources than from F-droid, and hence it's my first option when searching for simple utility applications because the top results on google play will be utterly infested with ads and tracking at minimum.

Re: Google details new 24-hour process to sideload unverified Android apps

#615

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

Gatekeepers have to gatekeeper. Sigh.

Re: Google details new 24-hour process to sideload unverified Android apps

#616

Earlier quoted context omitted.

Why do you keep harping on about ADB installs. That's not helpful. It doesn't help me install open source apps from FDroid. It's ridiculous that you think booting up a computer and using ADB is a reasonable workaround. It isn't.

You would be able to install f droid and it's apps without going through this flow.

How? Reading this it seems like only verified developers can skip this process. Most Fdroid developers won't be verified. I don't see where it says Fdroid would be exempt from this requirement. Would Fdroid be a verified developer?

Re: Google details new 24-hour process to sideload unverified Android apps

#617

Tbh, I love this flow. They truely think for users, all users not just advanced users. Unlike Apple, Apple just think for its ecosystem, its money. How the advanced flow works for users Enable developer mode in system settings: Activating this is simple. This prevents accidental triggers or "one-tap" bypasses often used in high-pressure scams. Confirm you aren't being coached: There is a quick check to make sure that…

Do you also like Dictators that decide and think for you?

Re: Google details new 24-hour process to sideload unverified Android apps

#618

Earlier quoted context omitted.

>Having to wait a day for a one off isn't a big deal It's my phone. It's my software. Period. The general population is deterred by burying a setting deep. Waiting is a dark pattern and we're not idiots.

Scammers can coerce people into ignoring warnings if they convince them their entire life savings are on the line. It's hard to do if you need to wait 24 hours before the setting unlocks.

Are these scammers in the room with us?

Re: Google details new 24-hour process to sideload unverified Android apps

#619

Earlier quoted context omitted.

so Apple then? They require you to pay the $99 yearly fee to sideload for more than 7 days

Apple was clear that they were offering the safety of a walled garden from the start. Apple didn't lie about supporting a user's freedom to run anything they like, only to execute a rug pull after they successfully drove the other open options out of the marketplace.

> Apple didn't lie about supporting a user's freedom to run anything they like, only to execute a rug pull after they successfully drove the other open options out of the marketplace.

They did execute a rugpull, and they aren't offering safety anymore.

The rug pull is ads in the app store. If I go to the app store now and search for my bank's name, the first result is a different bank. If I search for 'anki', the first 3 results are spam ad-ware tracking-cookie trash.

If I search "password store" I get 4 results before the "password store" app. I had a family member try to install one of the google-docs suite of apps, and the first result was some spamware that opened a full-screen ad, which on click resulted in a phishing site.

My family can't safely use the app store anymore because they click the first result, and the first result for most searches is now adware infested crap because of apple's "sponsored results".

What's the point of charging huge overhead on the hardware, and then an astounding 30% tax, and also a $100/year developer fee, if you then double-dip and screw over the users who want your app by selling user's clicks to the highest bidder?

Re: Google details new 24-hour process to sideload unverified Android apps

#620

Earlier quoted context omitted.

Why are you even using the Gmail as your mail app?

The switching cost on a 20+ year old email address is high. It’s basically impossible to totally migrate away from. On top of that, since Google does their own thing, it doesn’t fit well into standard IMAP that most clients use. Sparrow made Gmail a great experience, but Google bought it and shut it down. I’m still rather bitter about that. It’s the only email client that actually made me enjoy email.

>The switching cost on a 20+ year old email address is high. It’s basically impossible

You can use mobile Thunderbird with a Gmail account.

Post reply on HN