Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

621–630 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#621

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

Switching to an iPhone will put you in an even worse walled garden that respects you even less. Even simple things like setting your default navigation app in iOS are gated behind moving to the EU.

Re: Google details new 24-hour process to sideload unverified Android apps

#622

Earlier quoted context omitted.

Why are you even using the Gmail as your mail app?

The switching cost on a 20+ year old email address is high. It’s basically impossible to totally migrate away from. On top of that, since Google does their own thing, it doesn’t fit well into standard IMAP that most clients use. Sparrow made Gmail a great experience, but Google bought it and shut it down. I’m still rather bitter about that. It’s the only email client that actually made me enjoy email.

[deleted]

Re: Google details new 24-hour process to sideload unverified Android apps

#623
post #81

The goal seems to be breaking the real-time guidance scammers rely on. 24h probably works, but it feels like a heavy tradeoff for legit users.

iOS was supposed to prevent phone theft by making phones brickable through iCloud. Now, phone thieves just ask you at knifepoint or gunpoint to log out of iCloud

Unfortunately that's your own misunderstanding. iOS (as well as modern android) quite effectively prevent phone theft while the electronics are in transit along the last mile of the supply chain. Anything beyond that is a happy accident.

(I'm being a bit overly cynical there but IMO only the tiniest bit.)

Re: Google details new 24-hour process to sideload unverified Android apps

#624
I feel like loading sideloaded applications it's locked enough, google created google protect (which I have disable) but it if you have it enabled you are unable to instal sideloaded apps, also you have to accept the prompt to accept the app you're installing from and the prompt from your android to let you install sideloaded apps, like how many prompts is enough? now also a fee and verification. Most of the apps I enjoy the most are in alternatives stores. Ankidroid,keeepassxc,revanced, newpipe,tubular.

Re: Google details new 24-hour process to sideload unverified Android apps

#625
post #509

Earlier quoted context omitted.

Let's say I'm sitting outside of your office with a bazooka and boxes of high explosives. You ask my why, and I say, "someone might try to rob this office." You say, "somehow, that does not persuade me that a stranger should loiter outside of my workplace with a massive stockpile of ordinance." I reply, "what's your solution to combat robberies?"

let's say I put a lock on an office door. You say "Why? Bazookas will get through the door anyways". I don't know how I feel about this change but context does in fact matter about whether something is a good idea or not

it already has a lock, by default you're not allowed to install apps in android you have to accepts a bunch of prompts and configurations (the key) and now you won't even have the key

Re: Google details new 24-hour process to sideload unverified Android apps

#626

Earlier quoted context omitted.

Developers, including non-US citizens, are forced to give Google their government ID to distribute apps. This enables Google to track and censor projects, like NewPipe, an alternative open source Youtube frontend, by revoking signing permissions for developers.

>Developers, including non-US citizens, are forced to give Google their government ID to distribute apps. Developers can choose to not undergo verification, thereby remaining anonymous. The only change is that their applications will need to be installed via ADB and/or this new advanced flow on certified Android devices. Either way, you can still distribute your apps wherever you want. If you verify your identity, th…

> Developers can choose to not undergo verification, thereby remaining anonymous. The only change is […]

"The only change" – with all due respect, are you even listening to yourself? The "only change" is that you, as a developer, will be completely excluded from publishing apps in the Play Store and that people effectively won't be able to install your app anymore! (Unless you were targeting only e.g. F-Droid users to begin with, which very few apps do.)

In essence, you are cutting down on the privacy of tens of thousands of honest developers around the world in the name of protecting users from scammers and you're pretending that 1) it's a nothingburger and 2) developers have a choice.

Re: Google details new 24-hour process to sideload unverified Android apps

#627

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

> some apps (e.g., banking apps) will refuse to operate and such when developer mode is on

And you blame Google for this? First of all, banks chose to make apps work this way, not Google. Moreover, they chose this likely due to scams. That proves scamming on android IS an issue that needs some technical solution.

Re: Google details new 24-hour process to sideload unverified Android apps

#628
post #228

Earlier quoted context omitted.

There's quite a gap between this sort of opportunistic scamming that's happening all over the world and targeted multi-year campaigns that probably require the resources of a nation state.

True, but that kinda misses the point. One way to look at it: there are many open source projects targeting Android, projects that gain some sense of legitimacy over being open source yet have few (if any) eyes vetting them. Or, perhaps, the project is legitimate but people are getting third-party builds. That is what F-Droid does. That is what the developer of a third-party ROM does. It would not require the resourc…

F-Droid has a build farm, they don't just host apks uploaded by developers, so it can't be attacked in that way. https://f-droid.org/en/docs/FAQ_-_App_Developers/#will-my-ap...

Re: Google details new 24-hour process to sideload unverified Android apps

#629
Supported Android since the beta m3 SDK in 2008 (ok, I was in high school, but I still downloaded it!) Never considered abandoning it before now.

It's time to leave Android.

Call me naive, but despite the feeling in my gut I was holding out for Google's answer. Reading what it is, this is still going way too far. You essentially need to be a developer in order to sideload, which brings Android down to parity with iOS.

No, being able to sideload (on my phones, AND friends and family as-needed) is a fundamental computing right. This is my personal belief. And this move by Google is a step too far.

The search begins...

Re: Google details new 24-hour process to sideload unverified Android apps

#630

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

> some apps (e.g., banking apps) will refuse to operate and such when developer mode is on And you blame Google for this? First of all, banks chose to make apps work this way, not Google. Moreover, they chose this likely due to scams. That proves scamming on android IS an issue that needs some technical solution.

>And you blame Google for this

Why does google allow apps to access this info?

Post reply on HN