Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

861–870 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#861

> Restart your phone and reauthenticate: This cuts off any remote access or active phone calls a scammer might be using to watch what you’re doing. This is smart. But putting my design hat on here: couldn't this be the whole approach? When enabling the "unverified apps" setting, the phone could terminate all running apps and calls before walking the user through the process. Why do you even need the rest of the compl…

I don't understand how it makes any difference.

A scammer is going to be familiar with the flow and can also just... call again?

"Just follow x, y, z and I will call back to help you"

Re: Google details new 24-hour process to sideload unverified Android apps

#862

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

Can you explain what open society means?

Re: Google details new 24-hour process to sideload unverified Android apps

#863
This is getting a ton of hate here, but I think it feels like a pretty reasonably balanced response to competing concerns: protecting literally billions of non-tech-savvy users from potentially malicious social-engineering attacks while allowing devs and tech-savvy a path to bypass that protection if they’re sure they want to.

What concrete change to the policy would be a strict Pareto improvement keeping just those two concerns in mind?

Re: Google details new 24-hour process to sideload unverified Android apps

#864
post #856

Earlier quoted context omitted.

> Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services). First phones, then lobbying. As citizens of an open society, government exists to serve us, not the other way around. With enough users, they will have to respond. As I said, there are a number of areas that need attention…

it also makes it urgent to have a platform with leverage under 3-5 years, with a whole lot of countries pushing for digital ID globally.

It's almost as if there is a global plan to deanonymise everyone online, and for governments and corporations to have total awareness and control of everyone's actions.

Re: Google details new 24-hour process to sideload unverified Android apps

#865
post #636

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

The darkest UX pattern I have ever hit is trying to cancel Google Workspace; whereby they disable the scrollbar on the page so you cannot actually get to the cancel button.

Hanlon's razor applies.

Re: Google details new 24-hour process to sideload unverified Android apps

#866

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).

Carry an old used iPhone, powered off with no SIM, and treat it as a black box hardware token that you turn on only for these uses. You can tether it via wifi through your “real” freedom phone.

Re: Google details new 24-hour process to sideload unverified Android apps

#867
post #847

Earlier quoted context omitted.

I hope the EU cracks down on them like they did with Apple.

Fast forward, and a few years from now, developers will have to sign their app with some EU bureau, otherwise it won't install anywhere. It's a choice about from whom come the restrictions. I don't like how much EU mandates and regulates hardware and software. It is about 20% helpful and 80% garbage regulations so far.

I voted for the EU representatives more directly than I voted for Google.

Re: Google details new 24-hour process to sideload unverified Android apps

#868

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).

convince people to use them and banks can suck it up

Re: Google details new 24-hour process to sideload unverified Android apps

#869
post #631

Earlier quoted context omitted.

GrapheneOS phones are still an option, it’s unaffected by these rules.

Used Graphene as a daily driver for a year. It’s an unserious toy.

If it really was, you wouldn't have used it for a year

Re: Google details new 24-hour process to sideload unverified Android apps

#870

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

At what point will you draw the line between "the user wants to do this because of his/her free will" and "the user wants to do this because someone else told them to"? Where will you stop?

All of this is just a bandaid, so why not stop at the state we are at _right now_, without some kind of 24h-long process to enable sideloading and let people be people? Yes, people make mistakes. But that is not your responsibility, especially if it comes at the cost of freedom. The most secure android device would probably be a brick, but you won't sell these, right?

Please instead take these resources and invest them into the app verification process in the play store. Way too many scams are right under your nose, no need to search in places where people are happy with the status quo.

Post reply on HN