Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

801–810 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#801

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

Can apps detect whether the advanced flow for sideloading is enabled or not?

Re: Google details new 24-hour process to sideload unverified Android apps

#803
post #759

Earlier quoted context omitted.

I'm genuinely interested in proposals for other ways to differentiate knowledgeable users enabling side loading for reasons like OSS, vs naive users enabling it at the instruction of scammers to install malware. The one time per device (not per app/install) is annoying, but seems like a reasonable tradeoff between preventing bad installs and allowing legit installs. I can't think of any obviously better ways. I reali…

I think Google is trying to solve the problem at the wrong level - people do not really understand their computing devices enough to understand the risks, they never had to learn or were taught how to use such devices, they were only told it's easy and to not ask questions. The interfaces are designed in a way that allows them to get by with almost no understanding of anything. Which is why such solutions may also be…

> My solution is educating about smartphones and computers first.

98% of people literally do not care and/or are too dumb to understand. You could force them at gunpoint to sit in the education class, and give them a simple basic quiz afterwards, and they'd get half the answers wrong. They will continue to not even read what's on their screen, and just click the big highlighted button every time they see one.

Re: Google details new 24-hour process to sideload unverified Android apps

#804

Welp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably…

GrapheneOS phones are still an option, it’s unaffected by these rules.

It's pretty crazy to trust such project to run your phone.

Re: Google details new 24-hour process to sideload unverified Android apps

#805

As an idea, what about allowing the 24 hours to be bypassed using adb (edit: bypass to allow indefinitely, not just install a single app)? I understand there is some problem trying to be solved here, but honestly this is still quite frustrating for legitimate uses. If this is the direction that computing is moving, I'd really rather there were separate products available for power users/devs that reflected our differ…

This is already how it works.

[deleted]

Re: Google details new 24-hour process to sideload unverified Android apps

#806

Earlier quoted context omitted.

Pay verification fee to continue

so Apple then? They require you to pay the $99 yearly fee to sideload for more than 7 days

You can refresh them. SideStore[1] does that automatically out of the box (no computer needed) but there are Shortcuts to do that too.

[1] https://docs.sidestore.io/docs/faq#what-is-sidestore

Re: Google details new 24-hour process to sideload unverified Android apps

#807
post #194
post #150

Earlier quoted context omitted.

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

Of course it's not impossible; but very incompatible with the agenda per which everyone must become a digital slave, guilty by default, surveilled 24/7, deprived of all privacy, freedom and rights, with TOSes replacing the charade that there is for law now, and impenetrable screens instead of human interaction.

Re: Google details new 24-hour process to sideload unverified Android apps

#808
post #759

Earlier quoted context omitted.

I think Google is trying to solve the problem at the wrong level - people do not really understand their computing devices enough to understand the risks, they never had to learn or were taught how to use such devices, they were only told it's easy and to not ask questions. The interfaces are designed in a way that allows them to get by with almost no understanding of anything. Which is why such solutions may also be…

> My solution is educating about smartphones and computers first. 98% of people literally do not care and/or are too dumb to understand. You could force them at gunpoint to sit in the education class, and give them a simple basic quiz afterwards, and they'd get half the answers wrong. They will continue to not even read what's on their screen, and just click the big highlighted button every time they see one.

Yet somehow they are not too dumb to get a driving license or operate a gas stove. I would argue that operating a car is much more complicated than operating a smartphone.

At some point, if you are unwilling to learn basic facts about your environment, and you don't have a guardian, then you will get hurt. I don't necessarily mean by a computer. I think that's fine and I don't think a patronizing solution by a corporation that clearly wants more control over society is a necessary help.

Re: Google details new 24-hour process to sideload unverified Android apps

#809
post #764
post #447

Earlier quoted context omitted.

There's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. Would welcome evidence to the contrary. Is this truly a threat model that's seen in the wild? My gut says no because social engineering is about hijacking legitimate, first-party processes. Scammers attack login credentials, MFA flows, and use first-party apps to m…

> I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. Maybe not scammers, but an abusive partner could sideload an application on your phone to spy on you. I've seen that before within my relatives.

I doubt a one-day wait will solve this though. Abusers have persistent physical access to the device, often over a span of years :(

Re: Google details new 24-hour process to sideload unverified Android apps

#810
post #522
post #447

Earlier quoted context omitted.

There's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. Would welcome evidence to the contrary. Is this truly a threat model that's seen in the wild? My gut says no because social engineering is about hijacking legitimate, first-party processes. Scammers attack login credentials, MFA flows, and use first-party apps to m…

>There's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. I also never got targeted by pig butchering scams[1], and neither did my immediate friends/family, so I guess those must not exist either? [1] https://en.wikipedia.org/wiki/Pig_butchering_scam

I didn't say the scams don't exist. I am of course aware of these types of scams.

But again, I've never heard of sideloading being used as an attack vector here. Nor have I ever seen reporting on it.

I figure Krebs or somebody would have written about this if it was an issue.

Post reply on HN