Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
If the issue Google has with sideloading is really just the rampant app piracy (and the malware that comes with cracked apps) that might be something F-Droid can accomodate.
I don't think malware is the problem, as most malware comes directly via Google's ecosystem carried by ads. Just recently I had to uninstall some app from the play store since it tried to distribute malware through scary pop-ups and had it replaced with something from f-droid for someone I know.
> most malware comes directly via Google's ecosystem carried by ads.
Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google.
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
The world may not of ended but to of people have been hurt by malware ruining their computer, cryptolocking all of their company's files for ransom, stealing all of your login credentials, stealing cryptocurrency, taking secret photos with your webcam, screen recording what you are doing on your computer, etc.
The "personal computer" has a terrible track record.
It is much rarer since it needs 0 day to do these at the same level as possible on a pc. The play store scanning apps for malware is an important safety mechanism against this. Further more imposter apps like YouTube but with no ads that are Trojans that steal people's accounts.
Or the accessibility permission, or to some degree the access all files ones; but it's also enough for the app to pilfer the data you trust it with.
The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs.
Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google
For many decades, people have been mistakenly putting diesel fuel into their gasoline cars, yet we never outlawed diesel vehicles. You can only do so much to protect people without destroying their rights to their property.
> And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
> The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use.
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
Yeah, compared to separate hardware HSMs mobile banking is a massive downgrade in both security as well as user being in control of the hardware they own (by forcing locked down closer source OS & forcing hardware updates).
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.
Today people get in debt to have the latest orange iPhone, for a long time before that most people in, ok, developed countries somehow got hold of a computer.
It was true then and it is true now. Outside businesspeople and students and the middle class of OECD countries (all amounting to a low single-digit percentage of the world population), ordinary people never bought desktop or laptop computers. By contrast, everyone has a mobile one in their pocket today.
More likely you're living in a bubble unrepresentative of the rest of the world. I just did some research, inconclusive because nobody is tracking this data. Personal-computer ownership in rich countries (i.e. "OECD") is indeed high. But only 12% of the world's population lives in Europe and North America combined. The figure is much much lower elsewhere in the world, where everyone lives. For example, 16 computers per 100 people in Brazil in the 2010s. [1] Most people in the world have never touched a laptop or desktop. Now that computing has gone mobile-first, the figure is only going to keep dropping.
> a device that holds your entire life, bank info, photos, etc.
I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc.
How do you get around this? Literally every bank, brokerage, etc... is hell bent on you using your phone for everything from 2FA to passkeys, etc... They dont even imagine people have computers anymore or want two+ physical devices/controls on what can be done with which factors
It requires collective action. Ideally with laws to force interoperability, so folks can move among platforms with ease. Then standards will arise to keep that feasible for app makers.
Without regulation markets coalesce as the winners eat each other like a game of snake. It's a miracle Apple hasn't yet eliminated Android. Although I suppose for some institutions there is only iPhone.
Certainly you can use those, but they're not mandatory (here in Canada at least). Can easily get a card and use physical bank and ATM to do everything, and website logins use email as 2fa.
Not sure why you waited 8 days to respond to a comment, and your response is a bit of a non-sequitur. That said..
I was simply stating you can perform banking without a phone. You can check your email (or do your banking) on a phone... But you can do it on a desktop computer just as easily.
Lol, like it's some sort of psy-op. I dont check hackernews that often. My point was that banks are pushing one factor, just the phone, by requiring you to use your phone number or their app as the 'second factor'. I don't know which banks you can use without a phone number in the US.
What you can do is create a second email that is not at all accessible on your phone, but this is not what 99.9% of people do.
I'm not sure the situations are comparable when Windows doesn't have this permission system where the apps are still very limited in what they can access unless you grant specific directory access or access to the contact list or such
It does, but approximately nobody uses it, because Microsoft also tried to apply loads of constraints on what kinds of program could exist when they rolled it out, as part of their "all Windows software should also work on Windows Phone and Xbox" campaign.
Have you ever tried to educate a 70+ year old person on this kind of stuff? Their eyes gloss over and they don't care. I've told my mother not to install random apps on her phone several times yet she still does it. I could probably send her a phishing e-mail right now that 'looks like' it's from me (so long as my name is in the from: field that's enough) and she'd follow the instructions to install a malicious apk too.
"Everyone should just be smarter/more educated" is what I used to think as well. I now fully understand some people have no desire to be educated in any way and it's a net good for society to not have a large % of devices compromised.
yes, got my father on linux a decade (or more) ago. He's 84. No problem. Most recently we discussed being vigilant against vishing.
Now my in-laws (similar age) one very demented, the other thinks he knows best because he was a chemical engineer...they could use some built in protections
so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch
>so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch
Which is really exactly what google is implementing here and why I'm so perplexed so many people are upset. You or I or smart parents (my mother has never used a computer in her life and wouldn't want to) will have absolutely no issue sideloading apps after the proposed changes.
Given Google's track record, I don't think it's just "being upset" to have serious doubts about the probability of this escape hatch staying indefinitely.
But that's just a completely different discussion that we could've had a long time ago when they introduced it as a on/off security setting ~15-20 years ago too (and I bet people did). IMO nothing has changed except I bet more people will take going into developer options, being sternly warned, then having to wait 24 hours as a sign this is something maybe they shouldn't be doing. And I'd argue if you come to that conclusion and don't look into it further you're probably right,
Given that google is now forced to have competing app stores due to Epic v. Google and the ninth circuit courts went into long and arduous detail in that anti-trust case about sideloading restrictions I don't think they have a leg to stand on if they get rid of sideloading completely. Oddly Apple continues to get away with it no problem.
This description is downplaying what's changing by a lot. The way you present it, they're merely adding a 24h wait time to the existing local "unknown sources" toggle.
They've been chipping away at AOSP for years, pulling more and more parts of the Android experience into their proprietary Google Play Services. In this case, they're doubling down in the same direction. Sure, it may be more or less transparent from a user-facing perspective, but it's a fundamental change to the model.
Previously, it was ultimately a local decision: Android warned you, you enabled the permission, and you installed the APK. It now becomes dependent on a Google-controlled verification/authorization mechanism. That's fundamentally different from making the existing "unknown sources" toggle more annoying.
Google is the one peddling the malware. Any changes to 'security' that don't start with them removing the oodles of malware from their store are not security but profit driven.
The answer to people refusing to care about important things in life is not to put restrictions upon everyone's freedom. Ultimately, being an adult means you have to take responsibility for your actions (or lack thereof). It isn't hard to learn how to use a computer responsibly, and I've known plenty of older people who did so just fine. There's no excuse here.
You do understand we've broadly come to the conclusion that this isn't how society should work though, correct? It's why there's warning labels on everything, liability for not warning people for even the dumbest of things they might do with your product or in your establishment, extremely strict laws for things like driving a car, flying an airplane, or using any kind of heavy machinery, responsibility of servers to cut people off if they've had too much alcohol, the list goes on. I find intelligent people often have this mindset that all "real adults" are just as responsible as they are. It's just not the case.
And I generally wouldn't care "have at it" if their phone/computer being compromised only harmed them. But a bulk amount of compromised devices harms us all.
"Think of how stupid the average person is and then realize half of them are stupider than that!" -George Carlin
It is like saying that you should not have free speech because someone might influence 70+ to say stupid stuff (well, that is already happening...).
Family should be responsible on education or making phone of people that are not educated enough (minors, elderly, etc.) limited - I do that using Family Link. I have there my child and also my in-laws - both of them can't install new apps without my permission.
So the tech is already there, one just needs to use it.
What about an entire family of people who have no interest in learning technology they just want the shady ad-free youtube on their phone? I find it perplexing you've never met people like this. I'd wager it's more common than not in our world.
There is no way to have no "shady ad-free" on Google play. Have you tried installing anything that is free? Games for example? There are ads every few minutes that you either wait or accidentally click on them and you install another approved google play app, that has similar ads.
Look at apps on fdroid, no such thing.
So the solution is simple - ban google play and allow only fdroid if one wants good apps.
You can't protect everyone. Just like there are people oblivious to bad eating habits - it is a tax on ignorance.
That would be like requiring people taking driving lessons before driving cars - what nonsense! Just let them behind the wheel & they will figure it out just fine!
The Emacs version for Android makes uses of something like this IIRC by signing a version of Termux with the same key and distributing it in the same SourceForge repo such that Emacs on Android can access CLI tooling like git for example.
Isn't it possible, however complicated, for users to undo the lockdown to install an app? The required 9 steps are noted at <a href="https://keepandroidopen.org/" rel="nofollow">https://keepandroidopen.org/ for devices that use Google Play Services.
Irrespective, people should probably be migrating to a GrapheneOS or similar OS asap once the OS ships with a device.
Honestly not as bad as I feared it would be. Still not great and it's moving us farther from the idea that people who paid for the device should be allowed to install what they want on it, but as it stands it's a workable process. We'll see how quickly it takes Google to make it worse
Currently, switching to GrapheneOS means giving Google money. Next year's Motorola-based alternative is also likely going to be several price classes above the Pixels you can currently put GrapheneOS on.
Then buy a Pixel second-hand or when they hit rock-bottom prices, which usually happens after 6 months or so. At some point Google is probably not making a lot of profit from the devices anymore and they want to sell it to you for tracking and to sell Google One subscriptions, which are mostly irrelevant if you use GrapheneOS.
I followed Pixel prices for the last year, and rock-bottom for a 256gb version (the current absolute minimum for a device without an sd, to my eyes) meant 450€.
There are occasional good deals for (unused) older models on eBay, but they're surprisingly rare.
I wonder if Google demands stores to give the old models back, after the release of newer ones; they disappear from every store extremely quickly.
Interesting, here you can still buy the P10 and P10P for hundreds of Euros off and the prices are still trending down. Also many stores still have them. This is not surprising, because Google still sells them themselves, just in fewer colors and storage tiers.
I've tried $1000 phones before and found that they don't do anything different than my cheap phone, other than taking better quality pictures. But at least my cheap phone has an SD card slot and a headphone jack.
The latest pixels are a complete downgrade from the previous year (worse components). That's one huge reason to buy a last year phone (as opposed to a current one).
Yes, but the ability to install any software isn't. goggle can still decide to allow only "official" apps in """3rd party""" stores.
Updates on this have been slowly trickling out and the best I can discern is you will be able to still install apps from stores like F-Droid, but you have to go through a manual "advanced flow" which will most likely make you wait 24 hours before installing it and make you go through other hoops.
In short, google has referred to this as "increased user friction" to try and deter people from doing this. Essentially not making it impossible; just really frustrating for users so they get sick of the process and just install verified apps through them.
The only way I know around this is to install a custom rom like GrapheneOS or Lineage OS since this change targets Because the policy targets the Google Mobile Services (GMS) framework rather than the foundational Android Open Source Project (AOSP).
Wait, it's not 24 hours per app though, is it? Isn't it 24 hours before the "allow installing apps from .apks" setting turns on once and for all?
Pushing it with ADB isn't subject to the limitation:
Will Android Debug Bridge (ADB) install work without registration?
<a href="https://developer.android.com/developer-verification/guides/faq" rel="nofollow">https://developer.android.com/developer-verification/guides/...
It seems google is going to allow an "advanced flow" that is scam resistant by requiring the user to wait 24 hours before they can start installing their own apps. It sucks, but assuming they don't change the plan again, F-Droid should be able to continue working.
It's already live, I had to go through it last week. It's in developer options, then it asks if you're moving the selector to allow the installation of non-play store apps because you're being asked to by someone.
Then it starts a 24 hour timer. When that hits zero, you have 1 hour to go back in and select that you want to install apps on a device you own and paid money to own.
It's not scam-resistant at all. Any scammer will gladly work around this and send someone to one of many malicious apps in the play store, or a malicious URL, or even just set an appointment to call Grandma back the next day.
What? It only stays enabled for exactly 1 hour after the 24 hour timer?
I was under the impression that it would stay enabled permanently after waiting the 24 hours once.
IIRC, it's the button to permanently activate it that is only available for one hour. Once you do manage to press it, you've permanently enabled it. If you miss the window, you have to start the 24 hours again.
They're not necessarily wrong about it being scam resistant, based on some of the research into the psychology of scams. Adding time defuses the urgency of phone scams, leaving plenty of time to seek a second opinion from family members or the internet, and forcing the scammer to re-explain what the original goal was. It's too much time to breathe and defuses the fight or flight reaction needed for a high success rate. You mention URLs, but a web browser based scam page doesn't accomplish much, because the scammer's goal with fake apps is to acquire persistent remote access (akin to how the AnyDesk Android app uses accessibility permissions for Teamviewer-like remote access to an entire phone).
But yeah, it's hilarious that they're pushing this so hard when the Google Play Store still has so much malware.
So basically Google is being now more of an asshole than Apple (that now allows app sideloading and third party stores, at least in the EU). I'm and Android user since the beginning and for once I'm start considering for the next phone that I could as well get an iPhone, basically all the good open stuff of Android is long gone (back in the days I used to flash a new ROM every week), and at least Apple is better in regards of privacy than Google.
The current lockdown plan is that you'll need to wait 24 hours before installing the first unauthorized app, right? So probably exactly the same as it is now except setting up a phone will take 24 hours longer.
There is an entire world of Android phones not controlled by Google, including GrapheneOS, LineageOS, and countless variations in China and other places where Google is effectively banned.
It looks exactly the same as now. You will have to do Google's 24 hour flow thing, but it's not like that's going to stop anyone who appreciates what F-droid brings to the table.
Users and maintained packages would probably go down due to less users being able to use it, but users of Android (see GrapheneOS, LineageOS) without Google's Rookit can and will still continue to use it.
From an Android developer perspective, not good. All apps on f-droid will have to be certified by the developer with Google (it's per-app I checked) otherwise they won't work at all. And the process of not easy, even for a verified play store developer, I still have to jump through hoops to register.
Then you have to explain to users how to enable this. Not too mention the onerous F-droid requirements for publishing, it's bad enough as it is.
Average users are not going to do this, just like Google wants. Hopefully someone sues them and wins or we get Linux phones, not holding my breath though
jjice · · focus · HN ↗
pritambaral · · focus · HN ↗
trinsic2 · · focus · HN ↗
wongarsu · · focus · HN ↗
inquirerGeneral · · focus · HN ↗
[dead]
OroPla · · focus · HN ↗
autoexec · · focus · HN ↗
Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google.
McDyver · · focus · HN ↗
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
ragequittah · · focus · HN ↗
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
catlikesshrimp · · focus · HN ↗
g-b-r · · focus · HN ↗
That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.
charcircuit · · focus · HN ↗
The "personal computer" has a terrible track record.
g-b-r · · focus · HN ↗
charcircuit · · focus · HN ↗
g-b-r · · focus · HN ↗
The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs.
Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google
krzyk · · focus · HN ↗
It doesn't mean one can't buy nice things because one is afraid of being robbed.
charcircuit · · focus · HN ↗
Vrondi · · focus · HN ↗
krzyk · · focus · HN ↗
ragequittah · · focus · HN ↗
Vrondi · · focus · HN ↗
charcircuit · · focus · HN ↗
Society didn't ban doing it, but put up barriers that help the average person from doing something dangerous.
g-b-r · · focus · HN ↗
I think the pumps still fit where I live, btw
bryankaplan · · focus · HN ↗
Making the nozzle shapes incompatible is a smart solution, but in the US at least I'm pretty sure they're interchangeable.
dogmatism · · focus · HN ↗
m4rtink · · focus · HN ↗
JumpCrisscross · · focus · HN ↗
To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking.
g-b-r · · focus · HN ↗
The move to apps made things more difficult, if anything
JumpCrisscross · · focus · HN ↗
g-b-r · · focus · HN ↗
And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.
tpxl · · focus · HN ↗
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
landgenoot · · focus · HN ↗
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
m4rtink · · focus · HN ↗
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.
bluebarbet · · focus · HN ↗
g-b-r · · focus · HN ↗
Today people get in debt to have the latest orange iPhone, for a long time before that most people in, ok, developed countries somehow got hold of a computer.
Maybe with less brain cells burned by
g-b-r · · focus · HN ↗
encom · · focus · HN ↗
bluebarbet · · focus · HN ↗
g-b-r · · focus · HN ↗
bluebarbet · · focus · HN ↗
[1] <a href="https://worldpopulationreview.com/country-rankings/computers-per-capita-by-country" rel="nofollow">https://worldpopulationreview.com/country-rankings/computers...
OroPla · · focus · HN ↗
I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc.
casualscience · · focus · HN ↗
paulryanrogers · · focus · HN ↗
Without regulation markets coalesce as the winners eat each other like a game of snake. It's a miracle Apple hasn't yet eliminated Android. Although I suppose for some institutions there is only iPhone.
SECProto · · focus · HN ↗
casualscience · · focus · HN ↗
SECProto · · focus · HN ↗
I was simply stating you can perform banking without a phone. You can check your email (or do your banking) on a phone... But you can do it on a desktop computer just as easily.
casualscience · · focus · HN ↗
What you can do is create a second email that is not at all accessible on your phone, but this is not what 99.9% of people do.
OroPla · · focus · HN ↗
krzyk · · focus · HN ↗
Blocking apps is like blocking buying of knifes because one can hurt themselves.
halostatue · · focus · HN ↗
There's not an easy answer, but the non-answer of "people just need to be educated" is trivially dismissed.
Aachen · · focus · HN ↗
wizzwizz4 · · focus · HN ↗
ragequittah · · focus · HN ↗
"Everyone should just be smarter/more educated" is what I used to think as well. I now fully understand some people have no desire to be educated in any way and it's a net good for society to not have a large % of devices compromised.
LtWorf · · focus · HN ↗
The logical conclusion is that fdroid should be allowed and google play banned by default.
dogmatism · · focus · HN ↗
Now my in-laws (similar age) one very demented, the other thinks he knows best because he was a chemical engineer...they could use some built in protections
so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch
ragequittah · · focus · HN ↗
Which is really exactly what google is implementing here and why I'm so perplexed so many people are upset. You or I or smart parents (my mother has never used a computer in her life and wouldn't want to) will have absolutely no issue sideloading apps after the proposed changes.
folkrav · · focus · HN ↗
ragequittah · · focus · HN ↗
Given that google is now forced to have competing app stores due to Epic v. Google and the ninth circuit courts went into long and arduous detail in that anti-trust case about sideloading restrictions I don't think they have a leg to stand on if they get rid of sideloading completely. Oddly Apple continues to get away with it no problem.
folkrav · · focus · HN ↗
They've been chipping away at AOSP for years, pulling more and more parts of the Android experience into their proprietary Google Play Services. In this case, they're doubling down in the same direction. Sure, it may be more or less transparent from a user-facing perspective, but it's a fundamental change to the model.
Previously, it was ultimately a local decision: Android warned you, you enabled the permission, and you installed the APK. It now becomes dependent on a Google-controlled verification/authorization mechanism. That's fundamentally different from making the existing "unknown sources" toggle more annoying.
tpxl · · focus · HN ↗
bigstrat2003 · · focus · HN ↗
ragequittah · · focus · HN ↗
And I generally wouldn't care "have at it" if their phone/computer being compromised only harmed them. But a bulk amount of compromised devices harms us all.
"Think of how stupid the average person is and then realize half of them are stupider than that!" -George Carlin
krzyk · · focus · HN ↗
Family should be responsible on education or making phone of people that are not educated enough (minors, elderly, etc.) limited - I do that using Family Link. I have there my child and also my in-laws - both of them can't install new apps without my permission.
So the tech is already there, one just needs to use it.
ragequittah · · focus · HN ↗
krzyk · · focus · HN ↗
Look at apps on fdroid, no such thing.
So the solution is simple - ban google play and allow only fdroid if one wants good apps.
You can't protect everyone. Just like there are people oblivious to bad eating habits - it is a tax on ignorance.
m4rtink · · focus · HN ↗
redsocksfan45 · · focus · HN ↗
[dead]
folkrav · · focus · HN ↗
landdate · · focus · HN ↗
trinsic2 · · focus · HN ↗
rom1v · · focus · HN ↗
aquariusDue · · focus · HN ↗
OutOfHere · · focus · HN ↗
Irrespective, people should probably be migrating to a GrapheneOS or similar OS asap once the OS ships with a device.
jjice · · focus · HN ↗
Brian_K_White · · focus · HN ↗
autoexec · · focus · HN ↗
rurban · · focus · HN ↗
tazjin · · focus · HN ↗
microtonal · · focus · HN ↗
g-b-r · · focus · HN ↗
There are occasional good deals for (unused) older models on eBay, but they're surprisingly rare.
I wonder if Google demands stores to give the old models back, after the release of newer ones; they disappear from every store extremely quickly.
microtonal · · focus · HN ↗
g-b-r · · focus · HN ↗
OroPla · · focus · HN ↗
someonebaggy · · focus · HN ↗
ghetsisharmonia · · focus · HN ↗
drnick1 · · focus · HN ↗
OroPla · · focus · HN ↗
dogmatism · · focus · HN ↗
flexagoon · · focus · HN ↗
russelg · · focus · HN ↗
rdsubhas · · focus · HN ↗
someonebaggy · · focus · HN ↗
Elfener · · focus · HN ↗
burningChrome · · focus · HN ↗
In short, google has referred to this as "increased user friction" to try and deter people from doing this. Essentially not making it impossible; just really frustrating for users so they get sick of the process and just install verified apps through them.
The only way I know around this is to install a custom rom like GrapheneOS or Lineage OS since this change targets Because the policy targets the Google Mobile Services (GMS) framework rather than the foundational Android Open Source Project (AOSP).
iamjackg · · focus · HN ↗
izacus · · focus · HN ↗
krzyk · · focus · HN ↗
LtWorf · · focus · HN ↗
krzyk · · focus · HN ↗
hurfdurf · · focus · HN ↗
faust201 · · focus · HN ↗
creatonez · · focus · HN ↗
reddalo · · focus · HN ↗
Knowing Google, that's a big assumption
3RTB297 · · focus · HN ↗
Then it starts a 24 hour timer. When that hits zero, you have 1 hour to go back in and select that you want to install apps on a device you own and paid money to own.
It's not scam-resistant at all. Any scammer will gladly work around this and send someone to one of many malicious apps in the play store, or a malicious URL, or even just set an appointment to call Grandma back the next day.
SlackingOff123 · · focus · HN ↗
creatonez · · focus · HN ↗
creatonez · · focus · HN ↗
But yeah, it's hilarious that they're pushing this so hard when the Google Play Store still has so much malware.
whatsThisBtn4 · · focus · HN ↗
Getting some 9-11 security theater vibes.
anticensor · · focus · HN ↗
alerighi · · focus · HN ↗
whatsThisBtn4 · · focus · HN ↗
But dear... Google has no idea that they have/had the genuine nerds and are blowing it.
someonebaggy · · focus · HN ↗
drnick1 · · focus · HN ↗
epihelix · · focus · HN ↗
garbagepatch · · focus · HN ↗
preisschild · · focus · HN ↗
aembleton · · focus · HN ↗
tomjuggler · · focus · HN ↗
Then you have to explain to users how to enable this. Not too mention the onerous F-droid requirements for publishing, it's bad enough as it is.
Average users are not going to do this, just like Google wants. Hopefully someone sues them and wins or we get Linux phones, not holding my breath though
whatsThisBtn4 · · focus · HN ↗
Not that Apple is better, but they lose a huge selling point.