Live data from Hacker News

Google details new 24-hour process to sideload unverified Android apps

arstechnica.com

991–1000 of 1001 posts

Re: Google details new 24-hour process to sideload unverified Android apps

#992
post #865

Earlier quoted context omitted.

Hanlon's razor applies.

I think there needs to be a new kind of 'razor': 'Never attribute mistakes to stupidity that benefit the ones making them' The dressing up of purely malicious or greedy actions as merely resonable ones, that were executed poorly has become incredibly prevalent in the modern world.

It’s Grey’s law: any sufficiently advanced incompetence is indistinguishable from malice.

https://en.wikipedia.org/wiki/Clarke's_three_laws

Re: Google details new 24-hour process to sideload unverified Android apps

#993

This is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably no…

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

> ADB installs are not impacted by the waiting period, so that is an option if you need to install certain unregistered applications immediately.

if that's the case, why would the new flow help reduce fraud and scams? These are meant to be roadblocks, which the ADB bypass will just...you know, by pass it? Why can't the scammer coach the victim to use this instead then?

Re: Google details new 24-hour process to sideload unverified Android apps

#994
post #874
post #794

Earlier quoted context omitted.

Yes, I want through this last year and documented it in a screencast. This is how it looks https://mstdn.social/@can/115243851196253381 How is this legal?

Don't assign to malice what can be explained by incompetence: * new automated UX experiments starts * the UI bot made a change that made the page unscrollable * the experiment has a much higher rate of retention then the control (because people can't scroll) * the experiment is deemed a success by results analysis (no one looks at the page to see WHY) * the experiment is blessed as the new pipeline Such an obvious bu…

How about "don't assign to incompetence the malice that can result in big bucks"

Re: Google details new 24-hour process to sideload unverified Android apps

#995

Earlier quoted context omitted.

I worked at a bank on the backend for architecture and security.. and I've posted this attestation here before, but the sheer volume of fraud and fraud attempts in the whole network is astonishing. Our device fingerprinting and no-jailbreak-rules weren't even close to an attempt at control. It was defense, based on network volume and hard losses. Should we ever suffer a significant loss of customer identity data and/…

I wish we had technical solutions that offered both. For example, a kernel like SeL4, which could directly run sandboxed applications, like banking apps. Apps run in this way could prove they are running in a sandbox. Then also allow the kernel to run linux as a process, and run whatever you like there, however you want. Its technically possible at the device level. The hard part seems to be UX. Do you show trusted a…

The banking app has no password or 2FA prompt before opening? Even if the 2FA has to come from Authenticator/Authy/etc , that should atleast have a password on it. What am I missing here?

Re: Google details new 24-hour process to sideload unverified Android apps

#996

Earlier quoted context omitted.

>- Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? Hi, I'm the community engagement manager @ Android. It's my understanding that you don't have to keep developer options enabled after you enable the advanced flow. Once you make the change on your device, it's enabled. If you tur…

The only reason I run android over iOS is the freedom to install things I want on it. A waiting period is unacceptable as Android has proven that it can't be trusted not to tighten the grip further. Reconsider.

If you prefer to keep your freedom when Android removes it, you may want to try GNU/Linux phones. Sent from my Librem 5.

Re: Google details new 24-hour process to sideload unverified Android apps

#997

Earlier quoted context omitted.

I fully agree. Similar to killing bacteria with antibiotics, Attempting to idiot-proof machinery only leads to the creation of idiot-proofing-resistant idiots. We need to move back to putting users back into full control. Machines (including computers) should ALWAYS respect the input of the user, even if the user is wrong. If a person shoots themself with a gun as a result of their incompetence, we don't fault the gu…

I was with you right up until "We need to get rid of ESC, ABS, AEB, etc.". That is unreasonable. ABS, ESC, and AEB all exist to interpret what the driver intends. The driver does not intend for their wheels to lock up, that's why ABS exists, nor does the driver intend to skid. You can argue that AEB does not reflect the will of the driver, but it can also be disabled.

I was admittedly a bit hot-headed when I wrote the original comment, but the critical qualifier in all of this is that these driver assist technologies should be optional and easily disable-able in a persistent manner, with a dashboard warning light to remind you that they're disabled.

In a lot of modern cars, there's no straightforward way of fully disabling ABS, traction control, electronic stability control, etc. There are certainly situations where they may be helpful, such as in a top-heavy truck with an open differential, but ABS and traction control systems can pose problems in other situations, such as in snow. Especially in the case of RWD coupes with limited-slip differentials, a bit of skidding may be an asset, provided the driver knows how to correct for oversteer. Even in FWD cars, ABS can sometimes be a detriment when stopping in snow, as the rapid automated brake-pumping can dislodge the snow you were otherwise going to be holding steady on.

Ultimately, I'm opposed to driver assist features being forced onto drivers who don't want to use them. I'm also opposed to teaching people how to drive with these assistance features. It's a lot like teaching students to use AI chatbots to do their work instead of teaching them to do their work themselves.

Re: Google details new 24-hour process to sideload unverified Android apps

#1000
post #87

At this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling…

This has nothing to do with keeping people safe. If it did then power users could continue to install their own software by being given that ability as a developer setting. The fact that some people are gullible enough to go into a hidden setting on their phone and enable that in order to install an app from a random Chinese website is not a good reason to take away everyone's freedom. Consolidation of power is all t…

> then power users could continue to install their own software by being given that ability as a developer setting

That exact setting is literally what this entire article is about.

Post reply on HN