Since F-Droid (i.e., the repositories, not the app) builds all apps, a practical solution would be for the repositories (i.e., their signing keys) to be recognized by El Goog. Whether and how much help / obstacle the "maybe we do evil" company puts up for / against this is a different question.
It seems to me this is a blocker to use if google can restrict sideloading like this. Its not going to end with just get people requiring to register their app with an identity. Wont they be able to put presser on f-droid devs to lock out software they consider a threat to some business model?
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
The world may not of ended but to of people have been hurt by malware ruining their computer, cryptolocking all of their company's files for ransom, stealing all of your login credentials, stealing cryptocurrency, taking secret photos with your webcam, screen recording what you are doing on your computer, etc.
The "personal computer" has a terrible track record.
It is much rarer since it needs 0 day to do these at the same level as possible on a pc. The play store scanning apps for malware is an important safety mechanism against this. Further more imposter apps like YouTube but with no ads that are Trojans that steal people's accounts.
Or the accessibility permission, or to some degree the access all files ones; but it's also enough for the app to pilfer the data you trust it with.
The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs.
Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google
For many decades, people have been mistakenly putting diesel fuel into their gasoline cars, yet we never outlawed diesel vehicles. You can only do so much to protect people without destroying their rights to their property.
> And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
> The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use.
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
Yeah, compared to separate hardware HSMs mobile banking is a massive downgrade in both security as well as user being in control of the hardware they own (by forcing locked down closer source OS & forcing hardware updates).
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.
Today people get in debt to have the latest orange iPhone, for a long time before that most people in, ok, developed countries somehow got hold of a computer.
It was true then and it is true now. Outside businesspeople and students and the middle class of OECD countries (all amounting to a low single-digit percentage of the world population), ordinary people never bought desktop or laptop computers. By contrast, everyone has a mobile one in their pocket today.
More likely you're living in a bubble unrepresentative of the rest of the world. I just did some research, inconclusive because nobody is tracking this data. Personal-computer ownership in rich countries (i.e. "OECD") is indeed high. But only 12% of the world's population lives in Europe and North America combined. The figure is much much lower elsewhere in the world, where everyone lives. For example, 16 computers per 100 people in Brazil in the 2010s. [1] Most people in the world have never touched a laptop or desktop. Now that computing has gone mobile-first, the figure is only going to keep dropping.
jjice · · focus · HN ↗
pritambaral · · focus · HN ↗
trinsic2 · · focus · HN ↗
McDyver · · focus · HN ↗
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
ragequittah · · focus · HN ↗
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
g-b-r · · focus · HN ↗
That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.
charcircuit · · focus · HN ↗
The "personal computer" has a terrible track record.
g-b-r · · focus · HN ↗
charcircuit · · focus · HN ↗
g-b-r · · focus · HN ↗
The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs.
Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google
krzyk · · focus · HN ↗
It doesn't mean one can't buy nice things because one is afraid of being robbed.
charcircuit · · focus · HN ↗
Vrondi · · focus · HN ↗
krzyk · · focus · HN ↗
ragequittah · · focus · HN ↗
Vrondi · · focus · HN ↗
charcircuit · · focus · HN ↗
Society didn't ban doing it, but put up barriers that help the average person from doing something dangerous.
g-b-r · · focus · HN ↗
I think the pumps still fit where I live, btw
bryankaplan · · focus · HN ↗
Making the nozzle shapes incompatible is a smart solution, but in the US at least I'm pretty sure they're interchangeable.
dogmatism · · focus · HN ↗
m4rtink · · focus · HN ↗
JumpCrisscross · · focus · HN ↗
To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking.
g-b-r · · focus · HN ↗
The move to apps made things more difficult, if anything
JumpCrisscross · · focus · HN ↗
g-b-r · · focus · HN ↗
And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.
tpxl · · focus · HN ↗
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
landgenoot · · focus · HN ↗
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
m4rtink · · focus · HN ↗
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.
bluebarbet · · focus · HN ↗
g-b-r · · focus · HN ↗
Today people get in debt to have the latest orange iPhone, for a long time before that most people in, ok, developed countries somehow got hold of a computer.
Maybe with less brain cells burned by
g-b-r · · focus · HN ↗
encom · · focus · HN ↗
bluebarbet · · focus · HN ↗
g-b-r · · focus · HN ↗
bluebarbet · · focus · HN ↗
[1] <a href="https://worldpopulationreview.com/country-rankings/computers-per-capita-by-country" rel="nofollow">https://worldpopulationreview.com/country-rankings/computers...