Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

771–780 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#771
post #737
post #631

Earlier quoted context omitted.

Used Graphene as a daily driver for a year. It’s an unserious toy.

Can you elaborate? Why? I think many of us were hoping we could switch to it if/when Android becomes intolerable.

I have no idea what they are talking about. I have been daily driving GrapheneOS for almost two months now (coming from iPhone, but I have tested Pixels and Samsung phones on the side for a while) and there is no material difference in daily use from running the stock Pixel OS in daily use if you install Play (Services) and a bunch of apps. Of course, it is more secure and comes with no crap pre-installed, which is nice.

The only thing I have really found missing is Google Pay support for contactless payment (because Google doesn't want to allow GrapheneOS, but there are alternatives like Curve).

Re: Google details new 24-hour process to sideload unverified Android apps

#772
Newspeak is the trademark of oppressive regimes. Can we please not overexert ourselves in trying to please the global tech companies by pre-emptively changing our language?

Google details new process to install unverified Android apps. The sentence is much more clear using established language. Not "side-load", whatever that means.

Re: Google details new 24-hour process to sideload unverified Android apps

#773
post #2

tl;dr: - You need to enable developer mode - You need to click through a few scare dialogs - You need to wait 24h once I wonder how long this will last before they lock it down further. There was a lot of pushback this time around and they still ended up increasing the temperature of the metaphorical boiling frog. It still seems like they're pushing towards the Apple model where those who don't want to self-dox and/o…

its so obvious what the real goal is. No sideloading. Period. But nice of them to show their intentions while still giving time to leave.

Leaving where though?

Re: Google details new 24-hour process to sideload unverified Android apps

#774
Imagine if Microsoft did that with Windows. Absurd. The difference between Microsoft and Google seems to be that Microsoft accepts a small fraction of not-so-bright users getting scammed, because this is obviously much less bad than locking down the OS for everyone. (I say this as someone who is usually much more positive about Google than about Microsoft.)

Re: Google details new 24-hour process to sideload unverified Android apps

#775

How exactly is this going to stop scammers from simply modifying their scam runbook to say "Turn this thing on, and get back to me in 24 hours.", and then continue on from the next step? We know from Nigerian email scams that these things can stretch out days, weeks, months, all to get the victim to do the thing.

The Nigerian type scams typically prey on greed; time pressure isn't part of the draw.

There's another class of scams where the draw is fear - "your son is in jail", "your bank account is under investigation and will be closed in 24 hours if you don't act now", &c. They rely on time pressure to prevent the victim from reaching out directly to the parties they're lying about and disproving the scam.

This is aimed at that particular type of scam and that particular type of victim.

Re: Google details new 24-hour process to sideload unverified Android apps

#776
post #631

Earlier quoted context omitted.

GrapheneOS phones are still an option, it’s unaffected by these rules.

Used Graphene as a daily driver for a year. It’s an unserious toy.

I'm using GrapheneOS as my daily driver you couldn't be more wrong.

Re: Google details new 24-hour process to sideload unverified Android apps

#777
post #500

Earlier quoted context omitted.

GrapheneOS phones are still an option, it’s unaffected by these rules.

They have terrible support for banking apps and any app that needs play integrity

All Swedish banking apps work without issue and many apps that use play integrity works well regardless. It's just some apps that use play integrity that in a certain way that doesn't work.

Re: Google details new 24-hour process to sideload unverified Android apps

#778
post #100

I'd urge everyone here to seriously consider switching to GrapheneOS. It's a far simpler transition than e.g. switching from Windows or OSX to Linux, and many people find that it has basically no friction vs android. More people moving to GrapheneOS is the best tool we have against Google's continued and escalating hostility to user freedom and privacy and general anti-competitive conduct. (Of course, you could ditch…

I'd like to add that you can start in a really affordable way. E.g. the Pixel 9a is typically 350 Euro here and a perfectly fine way to start out with GrapheneOS - it still has years of support in it.

Re: Google details new 24-hour process to sideload unverified Android apps

#779

> Restart your phone and reauthenticate: This cuts off any remote access or active phone calls a scammer might be using to watch what you’re doing. This is smart. But putting my design hat on here: couldn't this be the whole approach? When enabling the "unverified apps" setting, the phone could terminate all running apps and calls before walking the user through the process. Why do you even need the rest of the compl…

> But putting my design hat on here: couldn't this be the whole approach? No, because protecting users is just an excuse. The overreach is the goal.

Having worked in big tech, my money would be on Hanlon's Razor here -- "Never attribute to malice that which is adequately explained by incompetence"

Re: Google details new 24-hour process to sideload unverified Android apps

#780

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

If you use iPhone, you can use iOS Mail app (and with iCloud mail) if you really care. Apple dark UX pattern is that there always has badges on Settings app if you do not subscribe to iCloud even if you have manual backup. You cannot dismiss it.

This has tripped up non-technical family members who ask for help and aren't sure if they are required to pay for these things.

"What is Arcade, am I supposed to be paying for it?"

Sigh. Apple used to be better than this.

Post reply on HN