The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…
what's your solution to combat scammers?
Google details new 24-hour process to sideload unverified Android apps
701–710 of 1001 posts
Re: Google details new 24-hour process to sideload unverified Android apps
#702Earlier quoted context omitted.
I don't know if Google is making the right choice here, but I do believe that technology should be for anyone (anyone who wants it, at least). How do you plan to decide who gets to use internet banking and who doesn't? That doesn't seem like a good road to be going down, either.
People themselves will decide. Same way they decided whether they wanted to buy a computer in the 00s. It's just that those who decide to not have internet banking should not be disadvantaged by the society compared to those who have it.
Re: Google details new 24-hour process to sideload unverified Android apps
#703Let's be realistic, there IS a problem with sideloaded apps being downloaded by ignorant people, and they do get scammed/hacked or whatever.
This leads to unhappy people complaining to their banks, politicians and media, these in turn starts lighting a fire under Googles bottom.
So, my point being, how do we solve the ACTUAL problem with rogue apps then?
Re: Google details new 24-hour process to sideload unverified Android apps
#704In addition to a enabling it in this onerous way, this should be a thing you can set when you first set up the phone after factory default: "I am technologically literate and I accept the risks of side loading indefinitely." If it's set once during set up then none of the vulnerable people will have it set for the lifetime of their phone. A scammer would have to factory reset their phone which would defeat the purpos…
Re: Google details new 24-hour process to sideload unverified Android apps
#705As for the IDs, I think what happens is that Google sees no need to have hobbyists anymore in the ecosystem. Companies are easier to deal with, easier to change ecosystem to what's needed for Google. While for app development companies, there will be a single enterprise account with some ID used for many developers. And companies just shut up and follow almost any non-financial requirements Google wants to add.
In contrast, opensource developers frequently go public advocating for user privacy and data prorection, while companies tend to be on the same side as Google squeezing any bit of personal user data to sell it for any margin possible.
Is any open mobile device and OS ecosystem possible at this point of time, other than the hobbyist one? With closed gates of LTE/5G ecosystem it seems there's no such possible at all.
Re: Google details new 24-hour process to sideload unverified Android apps
#706Earlier quoted context omitted.
Being able to decide yourself the software that is allowed to run on the hardware you own.
But you have that ability. There's a one-off 24 hour wait. You have a similar wait if you get it shipped to you from Amazon. Is the instant gratification essential ?
Re: Google details new 24-hour process to sideload unverified Android apps
#707Earlier quoted context omitted.
They have terrible support for banking apps and any app that needs play integrity
You are badly informed. GrapheneOS has full support for Play Integrity[0]. [0]: https://grapheneos.org/articles/attestation-compatibility-gu...
Re: Google details new 24-hour process to sideload unverified Android apps
#708This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…
>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…
If you go forward with this, I am not coming back. I will never again in my life trust you. And believe me - I still have boycotts on-going 20 years later. Including microsoft. It is surprisingly easy to avoid you "Ubiquitous" companies once you get your mind into it.
Re: Google details new 24-hour process to sideload unverified Android apps
#709Earlier quoted context omitted.
The one-day waiting period is so arbitrary. Have they demonstrated any supporting data? We know google loves to flaunt data. Something like Github's approach of forcing users to type the name of the repo they wish to delete would seem to be more than sufficient to protect technically disinclined users while still allowing technically aware users to do what they please with their own device.
> The one-day waiting period is so arbitrary. Scammers aren't going to wait on the phone for a day with your elderly parent.
Re: Google details new 24-hour process to sideload unverified Android apps
#710Earlier quoted context omitted.
Do you think regular desktop computer should be locked down like this too? Scammers can also tell people to run Windows programs. Should that be banned too? I'm fine with an opt-in lock-down feature so people can do it for their parents/grandparents/children. Also, just let people get used to it. People will get burned, then tell their friends and they will then know not to simply follow what a stranger guides them t…
Maybe? Let people form CAs, and if a CA gives out certs for malicious apps remove them. (Old apps continue to work, to publish new one get new cert.) Yes, sad, but works. People will learn about scams, but scammers are unfortunately a few steps ahead. (Lots of scammers, good techniques spread faster among them than among the general public.)
Also Chrome trusts like 300 CAs. Does that work? Probably not if you live in 200 of those countries.