Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

751–760 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#751
* enable developer options

* confirm that you are not tricked

* restart phone and re-authenticate

* wait one day

* confirm with biometrics that you know what you are doing

* decide if you only want unrestricted installs for 1 week or forever

* confirm that you accept the risks

* enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this

Re: Google details new 24-hour process to sideload unverified Android apps

#752
post #500

Earlier quoted context omitted.

GrapheneOS phones are still an option, it’s unaffected by these rules.

They have terrible support for banking apps and any app that needs play integrity

"Terrible" is incorrect. Yes quite a few don't work but many many do . See:

https://privsec.dev/posts/android/banking-applications-compa...

Re: Google details new 24-hour process to sideload unverified Android apps

#753
post #729

> Flip the toggle and tap to confirm you are not being coerced This is just spreading fear. If you're being coerced to do this, then you're in a much bigger danger than what a rogue application sideloaded to your phone represents.

“Being coerced” typically means “you’re on the phone with a person who claims to be a bank representative and who is trying to push you into flipping the toggle.”

Re: Google details new 24-hour process to sideload unverified Android apps

#754

Earlier quoted context omitted.

Your mistake is taking Google's argument at face value. Protecting users is an outright lie, this is purely about control. Google doesn't give one single shit if users download malware from the Play Store, but hypothetical malware from third party sources is so much worse that we need to ruin the whole OS? That doesn't pass the sniff test. Google wants to make sure you can only download malware from developers who gi…

I'm assuming good faith and giving them the benefit of the doubt. Of course it might be that they want more control. In addition to controlling the world's most popular web browser and the world's most popular search engine and the world's most popular online advertising network and the world's most popular online video service.

Assuming good faith and giving the benefit of the doubt to google is just naivety.

They have shown time and time again that they will take as much control from you as they can.

Re: Google details new 24-hour process to sideload unverified Android apps

#755

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

I wouldn’t be fully optimistic about the one-day waiting period. Almost certain there will be a pop up showing up with: Process failed try again in 23:59:59.

Re: Google details new 24-hour process to sideload unverified Android apps

#757
So this means one can't just copy over unsigned apps from previous phone when transferring.

As others have suggested, there should be an option skip the 24hr wait when activating at setup time. Or, alternatively, when the previous phone one is transferring from has it enabled it should be without wait time on the new one.

Re: Google details new 24-hour process to sideload unverified Android apps

#758
post #636

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

The darkest UX pattern I have ever hit is trying to cancel Google Workspace; whereby they disable the scrollbar on the page so you cannot actually get to the cancel button.

Welcome to the future :)

Re: Google details new 24-hour process to sideload unverified Android apps

#759

The "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.

I'm genuinely interested in proposals for other ways to differentiate knowledgeable users enabling side loading for reasons like OSS, vs naive users enabling it at the instruction of scammers to install malware. The one time per device (not per app/install) is annoying, but seems like a reasonable tradeoff between preventing bad installs and allowing legit installs. I can't think of any obviously better ways. I reali…

I think Google is trying to solve the problem at the wrong level - people do not really understand their computing devices enough to understand the risks, they never had to learn or were taught how to use such devices, they were only told it's easy and to not ask questions. The interfaces are designed in a way that allows them to get by with almost no understanding of anything. Which is why such solutions may also be bypassed by a determined attacker. Such scams only really expose this fact. So there is no good way to differentiate between the two groups.

My solution is educating about smartphones and computers first. Not in an in-depth way, but people need to understand what "application", "verified" means and what are the risks. I think android cleaned up the abstraction enough to make this possible.

Being able to tell if an app came from a trusted company or not is a good thing, but I would rather such a solution be managed in an OS-independent way, not controlled by Google. Applications not authenticated by a company should not be second-tier citizens, but there should be a clear warning (and the users should already know the difference before even seeing this warning).

I think the scams and phishing also expose another important problem that nobody tried to tackle yet - you can't authenticate calls, sms messages or emails. There is no good way of telling if it's actually your bank calling you, or if it's just a scammer.

In the end, we also need to accept that not all scams can be prevented, at some point if someone is calling as a friend of your family member, and is asking to urgently transfer money to an unknown account, and you fall for this... I really can't think of a technological measure that would've helped, it's only you and your common sense.

Re: Google details new 24-hour process to sideload unverified Android apps

#760
"Sideload", "unverified"!!! Woaa, careful now, we can't guarantee for anything!! Danger, danger!

How much can you twist words and language to engage in fear mongering? The headline could just as well have been "install", and "free choice" and "Google gatekeeps".

Post reply on HN