Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

901–910 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#901

Earlier quoted context omitted.

I “get” technology so I understand how you got here. But this is the wrong take. I expect to go to a restaurant and not die from the food… and I want nothing to do with the inner workings of the kitchen. I just want to know any restaurant I go into will be safe. Society has made restaurants safe, either because of government pressure or it’s good for business. How is that not a fair ask for technology, too? We all ha…

Your analogy doesn't work here. Going to a restaurant is like using an app store. Installing apks is like cooking at home. Nothing stops you from cooking a meal that will get you sick. Now imagine that every restaurant in your city is owned by one of two megacorporations and they really don't want you to have a microwave at home, let alone a stove. They expect that you will get all your food from them. This is where…

It works fine for the point that they were making.

Which is that the fact that restaurants have to certify for food safety training and pass regular inspection is perfectly reasonable, and allows those who aren't experts in those areas, or want to continually inspect kitchens to dine out in confidence & conveinience. (or at least vastly reduced risk).

There should be some equivalent, safe, experience in the technology space. Especially given how powerful a tool of liberation it is.

Of course, who controls that, and the ability to turn off those safeguards is important for many many other reasons and... also a question of liberty. And so I think it is a difficult conflict to resolve elegantly.

Re: Google details new 24-hour process to sideload unverified Android apps

#902
post #387

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

what's your solution to combat scammers?

> what's your solution to combat scammers?

I'd wipe the Play Store off the face of the earth. Have you looked at the garbage on there that Google considers legit?

This: https://news.ycombinator.com/item?id=47447600

is is the shit people are exposed to when they go through the Play Store. You don't find that on F-droid.

The second thing I'd do to combat scammers is the same thing I'd do to combat child porn and disinformation: educate people. This silly process is a technical answer to a social problem, and those rarely work well.

Re: Google details new 24-hour process to sideload unverified Android apps

#903

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

I think you are 2-4 orders of magnitude off if you think donation could be enough for a project as important as Android where 1 day delay in fixing security issue is just disasterous.

> where 1 day delay in fixing security issue is just disasterous.

looking at the current reality of patches is that you are lucky if there is a patch next month

Re: Google details new 24-hour process to sideload unverified Android apps

#904
post #150
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

> People who are unwilling to figure out the risks just should not use smartphones and the internet. Sounds great in theory, but just today I was reminded how impossible this is when walking back from lunch, I noticed all the parking meters covered with a hood, labelled with instructions on how to pay with the app. https://www.cbc.ca/news/canada/saskatchewan/city-of-regina-r...

Right, and builders now build homes with Ring cameras pre-installed. Surveillance chills aside it's about building rent-seeking into every corner of the economy, and that's a top-down goal of modern capitalism. Requiring a smart-phone to park is just part of it, and it goes back to the parent comment that there is something deeply wrong with how our society treats technology.

To me it proves that Google's steps to lock down phones isn't really about security. To them the scams that happen are acceptable losses. The scammed will still use Android and still click on ads and still let themselves be tracked and marketed to as before. But if Google can use the excuse of security to edge out alternative apps and app stores they will spend plenty of money and time to do it.

This isn't security, it's sealing a hole in the sales funnel.

Re: Google details new 24-hour process to sideload unverified Android apps

#905
post #900

Could this be worked around by installing a single shell app which then loads other apps internally? I think it's possible to dynamically load Dalvik byte code in ART these days, right? Obviously permissions would be a problem, as you can't update the app manifest, so there would either have to be one shell app per publisher (which would at least solve the problem of installing updates for their apps) or the shell wo…

That would be very similar to LiveContainer for iOS [1]. I think that unsandboxed JIT is still possible as of Android 16, but Google has been cracking down on it.

[1] https://github.com/LiveContainer/LiveContainer

Re: Google details new 24-hour process to sideload unverified Android apps

#906

This is getting a ton of hate here, but I think it feels like a pretty reasonably balanced response to competing concerns: protecting literally billions of non-tech-savvy users from potentially malicious social-engineering attacks while allowing devs and tech-savvy a path to bypass that protection if they’re sure they want to. What concrete change to the policy would be a strict Pareto improvement keeping just those…

I'm pretty surprised at the amount of hate here. All the "just build it ourselves!" and "Google wants your data", and almost no top-level comments even discussing the difficulty of dealing with malware and social engineering. There are at least three moral arguments that can be made: - Google, as a capitalist company, is ignoring the privacy and FOSS implications, and is guilty of screwing the customer due to greed -…

It’s pretty common for techies to overestimate how widely their opinions and desires are shared. If you think a good chunk of the population wants to sideload apps, then this feels like an attack. But it’s really just a decision not to cater to a tiny fraction of the market. It’s the same thing in discussions about headphone jacks or small phones. People act like it’s nefarious, when really it’s just that their desire for those things is pretty uncommon.

Personally I think there should be a lot more work done on how to secure arbitrary apps from arbitrary sources so that they are unable to hurt people, rather than focusing so much on on preventing random apps from being installed in the first place. This would help the average person as well, since these walled gardens still make mistakes. But it’s not realistic to put a box in everyone’s pockets that’s three taps away from sending all their money to some dude in Laos.

Re: Google details new 24-hour process to sideload unverified Android apps

#907
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

Consider that you, and most of the community here, wouldn't have jobs if that were the case. XD

Re: Google details new 24-hour process to sideload unverified Android apps

#908
post #194

Earlier quoted context omitted.

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards. EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree…

> Where I live, in EU, parking meters even take cards. Unfortunately, a more accurate way of putting it is: stuff takes cards in lieu of coins . Like, where I live (also EU), ticket machines in buses and trams have gradually been upgraded over the past decade to accept cards, and then to accept only cards. It's a ratchet. Hidden inflation striking again. Cashless is cheaper to maintain than cash-enabled, so it preten…

I feel like this kind of glosses over the fact that a lot of people (I'd say an overwhelming majority) prefer the cashless options anyway.

I don't know if I have any friends who miss carrying coins and cash, or who miss carrying individual bus/subway tickets, but if they do, they're awfully quiet about it compared to the friends who happily say they can't remember using cash.

I'd say that if anything, cashless things are catching up to the general public.

Personally, I'm in favor of keeping things cash-friendly because people shouldn't be forced to be cash-free, but that's only to support a small minority of people.

Re: Google details new 24-hour process to sideload unverified Android apps

#909

Earlier quoted context omitted.

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

You can set a personal rule in Ublock origin to block these sign in with Google pop-ups.

https://www.reddit.com/r/uBlockOrigin/wiki/solutions/#wiki_g...

Re: Google details new 24-hour process to sideload unverified Android apps

#910
post #440

And now we see why Android never really was Linux. Does it have a Linux kernel? Of course. But this isn't a free operating system.

RHEL isn't Linux either then?

It's more complex than that.

RHEL has Fedora upstream. There's a group of people who regularly contribute to those projects on their own time and the userland for Fedora is made up primarily of FOSS where people routinely try to consolidate popular features into main code branches. There's a truly free software project that is the main project that someone provides paid support for. Fedora drives the evolution of the system; RHEL just gives a way to make that evolution palatable to the suits.

Android has the AOSP but it's not the driver of Android as a platform. For the most part, the evolution is driven by a bunch of closed-source applications that Google and OEMs happen to run on Android. Those parties derive competitive advantage and brand identity from the proprietary code that runs on top of the Android OS, and don't make a habit of merging much of that into the project. There are the system-wide improvements that get updated, sure, but the ethos is not to keep the code moving up the chain into the project so that anyone can take it and do what they want with it for free.

It's a hard difference to describe but it's there.

Post reply on HN