Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

671–680 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#671

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I’m in the UK and use the Gmail app, I don’t ever see this sheet. Is this US-only?

I don’t see the sheet for imgur.com either because, well, they’ve blocked access completely for UK users. :shrug:

Re: Google details new 24-hour process to sideload unverified Android apps

#673
post #652
post #607

Earlier quoted context omitted.

It's OK. This is the dying, last gasp effort that a company makes when it has no way to innovate, no way to add any real value, no capacity to drive change internally, and has become completely non-user focused. In short, it's what companies like IBM and Broadcom are now. Shallow husks of their former self, mere holding companies for patents, with a complete lack of care and concern about any end-user retention. Goog…

>Look at Microsoft of old, the god of arrogance. Once the most dominant, powerful tech company in the world. They were king. Browser king. OS king. Everything king. Now they are barely noticed by large swaths of the market. Have they ever been more valuable than now?

I think if, 10 years ago, you spun Microsoft into several different companies with everything playing out exactly as it has today in the product management side, the most direct consumer-facing sections like Windows Desktop and Xbox would have cratered and most analysts would say that they have bleak futures, while Azure and 365 would have grossly overperformed and would have been titans.

MS has been successful despite fucking up the monolithic position they held in desktop and gaming, because they managed to find a particularly valuable golden goose. It's just that in doing so they allowed the other golden geese they have to become quite sick.

If you took out cloud rev MS would have been much more motivated to not let the rest of the company's products turn in to the sorry state they're in.

Re: Google details new 24-hour process to sideload unverified Android apps

#674
post #671

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I’m in the UK and use the Gmail app, I don’t ever see this sheet. Is this US-only? I don’t see the sheet for imgur.com either because, well, they’ve blocked access completely for UK users. :shrug:

I see it in the UK.

Re: Google details new 24-hour process to sideload unverified Android apps

#675
post #222

Earlier quoted context omitted.

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

Then don't issue an app. Issue people cards to pay with and let them come to the bank for weird transactions.

You can even use the chip on the card together with some cheap HW device to authorize the transactions made with the app. This actually exists [1] for quite some time but seems to be mostly limited to Germany. But this and the use of other HW tokens systems is on decline. Banks increasingly use apps now, increasingly without any meaningful second factor, not even offering better options. They want this and are fully to blame.

[1] https://en.wikipedia.org/wiki/Transaction_authentication_num... (This is a bit outdated, nowadays it works via QR codes instead of those flickering barcodes but the concept stays the same)

Re: Google details new 24-hour process to sideload unverified Android apps

#676
post #150
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

>how to pay with the app.

Or by phone.

Re: Google details new 24-hour process to sideload unverified Android apps

#677

Earlier quoted context omitted.

Do I need to be signed in to Google play to get the sideloading exception turned on? I don't sign in to it because I don't want to have my phone associated with a Google account. But I can't uninstall play completely on the devices I have. It says something about 'restart your phone and reauthenticate' that's why I'm asking. What do you autenticate? > ADB installs are not impacted by the waiting period, so that is an…

>It says something about 'restart your phone and reauthenticate' that's why I'm asking. What do you autenticate? You're authenticating that you're the device owner (via your device's saved biometrics or PIN/pattern/password). >Um yeah but then do I have to install every update via adb? I want to just use F-Droid. No, once you go through the advanced flow and choose the option to allow installing unregistered apps ind…

This part I don't understand. I want to allow for a couple minutes, the time to install a unregistered app, and then go back to deny. I don't want to allow "for 7 days" or "indefinitely". In the text and screenshot of the announcement I see that you can switch these feature "on", but can they be switched "off"?

Re: Google details new 24-hour process to sideload unverified Android apps

#678
post #607

Earlier quoted context omitted.

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

It's OK. This is the dying, last gasp effort that a company makes when it has no way to innovate, no way to add any real value, no capacity to drive change internally, and has become completely non-user focused. In short, it's what companies like IBM and Broadcom are now. Shallow husks of their former self, mere holding companies for patents, with a complete lack of care and concern about any end-user retention. Goog…

I'm not sure where you are but at least here Microslop is still ruling more or less everywhere besides the online ad market.

They are big in everything that is mass scale developer oriented with things like GitHub, VSCode, or all their libs, tools, and integrations (they "own" in large parts for example Python, TS, and Rust). Governments and public services are all running on Azure. So do a lot of companies; more or less all small and mid sized. They are still dominant in the gaming market, and get stronger there with every year.

Microslop was always, and still is the same Microslop. They are very successful with what they do since decades. Whether one likes that or not.

Re: Google details new 24-hour process to sideload unverified Android apps

#679
I think most people here live too much in their tech bubble and don't realize how dumb the vast majority of people are when it comes to tech. I know that feeling myself that you lose the grip to "reality" when you are too much into tech, but after dealing a bit with "ordinary" people, I do understand why Google wants to do that. Most people have absolutely no idea about tech at all. So many people don't even know what exactly a browser is, what a "tab" means or can't even get to install an iPad. Google mainly has to take care of these people, not people who install apps using F-Droid. Go to the streets and ask strangers if they know what F-Droid is, and if they don't, try to explain it to them. The 24 hour wait period looks like a good trade off to me. Still allowing experienced users to install apps, but the majority of people will be protected, and it won't even affect most people.

And no, I'm not a bot or some pro Google activist, check my github account, I even use GrapheneOS myself.

Post reply on HN