Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

931–940 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#931

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

Can you answer this question:

If you install F-Droid via ADB, can F-Droid then install the apps from its catalog?

Re: Google details new 24-hour process to sideload unverified Android apps

#932
post #865
post #636

Earlier quoted context omitted.

The darkest UX pattern I have ever hit is trying to cancel Google Workspace; whereby they disable the scrollbar on the page so you cannot actually get to the cancel button.

Hanlon's razor applies.

I think there needs to be a new kind of 'razor': 'Never attribute mistakes to stupidity that benefit the ones making them'

The dressing up of purely malicious or greedy actions as merely resonable ones, that were executed poorly has become incredibly prevalent in the modern world.

Re: Google details new 24-hour process to sideload unverified Android apps

#933
post #607

Earlier quoted context omitted.

I hate this pop-up so much. I don’t even have Chrome installed on my phone. How about open up on the only browser I have installed… This kind of thing should be illegal. The default browser is the default for a reason, to avoid this kind of stuff. I think I’ve reported this as a bug to Google a couple times, in a couple different apps… as they do it in their other apps too. The only thing that bothers me more are the…

It's OK. This is the dying, last gasp effort that a company makes when it has no way to innovate, no way to add any real value, no capacity to drive change internally, and has become completely non-user focused. In short, it's what companies like IBM and Broadcom are now. Shallow husks of their former self, mere holding companies for patents, with a complete lack of care and concern about any end-user retention. Goog…

Just to illustrate how bad Google has gotten, I've had the boomer habit of searching for a website name and then clicking the link in Google.

In the past 1-2 years I had to stop that, as there's a good chance I will be taken to some ad-sponsored link that has hijacked the search results.

For example, if I search 'Claude' the actual link to claude.ai will not even fit on a 1080p screen.

Re: Google details new 24-hour process to sideload unverified Android apps

#934

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

> ADB installs are not impacted by the waiting period

"If you don't like the food we're serving, you can always buy a farm"

Re: Google details new 24-hour process to sideload unverified Android apps

#935

It is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generatio…

Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).

In my country, government applications are required to be interoperable, use open APIs and work with open formats (XML, PDF, etc.). There should be no problem there. I've already used some FOSS applications to interact with government services.

Banks are required to interoperate using open API in the EU. EU managed to cripple this requirement, by not requiring open api access to regular customers, but only to accredited organizations. There's more work to be done on this front.

Re: Google details new 24-hour process to sideload unverified Android apps

#936

Earlier quoted context omitted.

Carry an old used iPhone, powered off with no SIM, and treat it as a black box hardware token that you turn on only for these uses. You can tether it via wifi through your “real” freedom phone.

Your freedom phone will not be on your carrier's device allowlist.

My MVNO has no allowlist.

Re: Google details new 24-hour process to sideload unverified Android apps

#937

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

An actual example of this lives in the Gmail iOS app. Click a link in an email and every x days, a sheet appears: https://imgur.com/a/nlGS4Yk 1. Chrome 2. Google 3. Default browser app (w/unfamiliar generic logo) They removed the option for Safari some time in the last two years; here's how it looked in 2024: https://imgur.com/1iBVFfc And the cherry on top of dark UX patterns: an unchecked toggle rests at the bottom.…

This would drive me insane! I'm glad I ditched Gmail altogether.

Re: Google details new 24-hour process to sideload unverified Android apps

#938
post #387

Earlier quoted context omitted.

what's your solution to combat scammers?

Do you think regular desktop computer should be locked down like this too? Scammers can also tell people to run Windows programs. Should that be banned too? I'm fine with an opt-in lock-down feature so people can do it for their parents/grandparents/children. Also, just let people get used to it. People will get burned, then tell their friends and they will then know not to simply follow what a stranger guides them t…

The scams are more sophisticated than getting gift cards to pay the IRS. A number saying that it’s from the bank will say they need to verify some account information.

I have had to actually verify my “investment profile” with a major broker in order to unfreeze some trades, in a high friction process. To the extent that a sideloaded app that looks exactly like the bank app has a low friction install, then people can get fooled and irrevocably lose savings.

If the lock-down is opt-in, almost nobody will opt in to it. If the lockdown is opt-out, then whether scams still happen depends on how much friction there is in opting out.

Freedom to install other unsigned sandboxed apps has a solution: Banks could use passkeys and other non-phishable methods. Sideloaded apps in Android can’t get to the bank app’s passkey.

Passkeys or hardware tokens get worries about the enshittification of the theoretical recovery process. Which, if that’s the case, I guess we should hope for/pay a better world, at least with banks and brokers. For them specifically, for account recovery allow either showing up in person or using ID checks.

Both for personal accounts and business accounts (i.e. with Business Email Compromise), I believe the onus should be on the bank to use non-phishable methods to show the human-readable payee from their app for irrevocable transfers.

Re: Google details new 24-hour process to sideload unverified Android apps

#939
post #387

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give us…

what's your solution to combat scammers?

If I proposed putting mandatory cameras in all homes and you objected, would it then be fair for me to demand that you justify your position by proposing a better alternative to combat domestic violence?

Locking down computing is just fundamentally wrong and leads to an unfree society.

Re: Google details new 24-hour process to sideload unverified Android apps

#940

I'm not in agreement with most of you, hn. They've found a decent compromise that works for power users and the general population. Your status as a power user does not invalidate the need to help the more vulnerable. Having to wait a day for a one off isn't a big deal, if they kept it looser then you'd be shouting about the amount of scams that propagate on the platform.

Sure, I believe that the likes of Meta, Google, and god damn Microsoft who enabled mass brutal persecution of millions of people for money (engaged in recording and analysis of phone calls of Palestinians), care about vulnerable individuals, and not just about stuffing their pockets with more and more money by the means of increased control over "their" platforms.

They sure spend billions to "help the vulnerable". Right. Like Meta here: https://github.com/upper-up/meta-lobbying-and-other-findings

Post reply on HN