Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

881–890 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#881
To their credit, the 24hr hold would actually serve an important, legitimate purpose if the same malware weren't going to be on the PlayStore anyway. I was expecting to disagree with their public statements more than I actually did on this topic.

This still isn't a good idea. It's not going to materially improve security for anyone, so all the negatives (beaten to death here and elsewhere) are still top-of-mind.

Re: Google details new 24-hour process to sideload unverified Android apps

#882

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).

[dead]

Re: Google details new 24-hour process to sideload unverified Android apps

#883
If this becomes widely successful and side-loaded crapware apps and Android phone scammers drop off a cliff, we will still be upset because we want a perfect world where everyone is above average in their digital security. Time boxing is a great compromise and you've lost none of your previous freedoms. Guaranteed convenience of side-loaded software was never in the Android terms of use.

Re: Google details new 24-hour process to sideload unverified Android apps

#885
post #35

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

> - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? What apps are those? I've yet to run into any of my banking apps that refuse to run with developer mode enabled. I've seen a few that do that for rooted phones but that's a different story. I've been running android for a decade…

Just summarizing the apps below it seems to mostly be banking/payment and government apps specifically outside the US that break under developer mode and sometimes even accessibility access.

I wonder what makes them less trustful of Android security. AFAIK there are still pretty hard limits to what you can do inside apps you did not create. US companies at least seem comfortable with their security even with Developer or accessibility apps enabled.

Re: Google details new 24-hour process to sideload unverified Android apps

#886

Earlier quoted context omitted.

so Apple then? They require you to pay the $99 yearly fee to sideload for more than 7 days

Apple was clear that they were offering the safety of a walled garden from the start. Apple didn't lie about supporting a user's freedom to run anything they like, only to execute a rug pull after they successfully drove the other open options out of the marketplace.

hahahahaha 'walled garden'

repeating marketing speak.

Apple got you.

Walled Prison. Look at all those people suffering with iMessage trying to use openclaw.

Re: Google details new 24-hour process to sideload unverified Android apps

#887

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

The funny thing is that until like 2024 iOS actually HAD no default browser control, so this kind of thing was a huge help for people who wanted to use Chrome against Apple’s monopolistic wishes. Of course it’s fair to argue that it should be eliminated now. The commenter who mourned the web view option also has a good point, but tbh that ought to just be asked once and then live in settings.

Re: Google details new 24-hour process to sideload unverified Android apps

#888

Earlier quoted context omitted.

Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).

Carry an old used iPhone, powered off with no SIM, and treat it as a black box hardware token that you turn on only for these uses. You can tether it via wifi through your “real” freedom phone.

Your freedom phone will not be on your carrier's device allowlist.

Re: Google details new 24-hour process to sideload unverified Android apps

#889

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).

there is a power that could help with this. And I know quite a few people do not like this. But this would be prime EU real estate.

Re: Google details new 24-hour process to sideload unverified Android apps

#890
Coming soon:

- New toaster requires permission from manufacturer to toast bread from a local bakery.

- Car manufacturer to vet all passengers. Any unidentified and unvetted passengers will disable the vehicle.

- TV manufacturer requires 7 days advance notice of what you want to watch.

Post reply on HN