Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

821–830 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#822

Earlier quoted context omitted.

One of my banking apps didn't even run if I had accessibility settings turned on. I've since closed my account with them, just because of that. The amount of control we've given corporations over our computers is incredibly disappointing.

Was this in EU/US? This sure has to break some disability act to discriminate visually imparied in such way.

It was in Moldova. Probably illegal there too if someone bothered to challenge it. I just downloaded it again, still won't work.

https://i.ibb.co/6c1MgkJQ/Screenshot-20260320-115310.png

Re: Google details new 24-hour process to sideload unverified Android apps

#824

Earlier quoted context omitted.

This has nothing to do with keeping people safe. If it did then power users could continue to install their own software by being given that ability as a developer setting. The fact that some people are gullible enough to go into a hidden setting on their phone and enable that in order to install an app from a random Chinese website is not a good reason to take away everyone's freedom. Consolidation of power is all t…

It absolutely has to do with keeping people safe. You not caring isn't relevant.

If Google cared just the slightest bit about keeping people safe, they would stop hosting scam ads as core part of their business model.

Google is on the side of the scammers.

Re: Google details new 24-hour process to sideload unverified Android apps

#825
post #500

Earlier quoted context omitted.

GrapheneOS phones are still an option, it’s unaffected by these rules.

They have terrible support for banking apps and any app that needs play integrity

Then keep Google crapphone for banking purposes in your drawer, like auth scratch code cards in the past. I don't get that idea of carrying device with bank access in your pocket constantly. Moreover, at least in EU, there is more and more banks which publish their apps in non Google app stores too.

Re: Google details new 24-hour process to sideload unverified Android apps

#827
If this was truthful about security...

Google could make a mobile website to take an app apk and verify it if its secure and offer to install it back to android users ...

My bias, former Android app developer.

This is using the increase in attacks to do a business monopoly goal instead...

Re: Google details new 24-hour process to sideload unverified Android apps

#828
post #156

Earlier quoted context omitted.

I was always under the impression security was a red herring and the real reason was control. Google wants to own the device and rent it to users with revocable terms the same way SaaS subscription software works. Locking down what can run is a key step in that process

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

How does preventing people from running software of their choice on their own device (what you call jailbreaking) prevent fraud in practice? It's a pretty strong claim you're making there. And it's being made frequently by institutions, yet I have never seen it actually explained and backed up with any real security model.

All the information and experience I ever got tells me this is security theater by institutions who try to distract from their atrocious security with some snake oil. But I'm willing to be convinced that there is more to it if presented with contraindicating information. So I'm interested in your case.

How did demanding control over your customers' devices and taking away their ability to run software of their choice in practice in quantifiable and attributable terms reduce fraud?

Re: Google details new 24-hour process to sideload unverified Android apps

#830

How does it track time? Is it possible that user will just change current time to the future to instantly process the request? Is it possible to track time "safely"?

idk if they'll use it for this, but Pixel phones have "secure" clocks used for image attestation, among other things.

https://security.googleblog.com/2025/09/pixel-android-truste...

Post reply on HN