‹ BackHN Continuity

Thread

F-Droid 2.0

1465 points · 420 comments · daveoc64

  1. jjice · · focus · HN ↗
    What does the future of something like F-Droid look like once Google does their lock down next year?
    1. creatonez · · focus · HN ↗
      It seems google is going to allow an "advanced flow" that is scam resistant by requiring the user to wait 24 hours before they can start installing their own apps. It sucks, but assuming they don't change the plan again, F-Droid should be able to continue working.
      1. 3RTB297 · · focus · HN ↗
        It's already live, I had to go through it last week. It's in developer options, then it asks if you're moving the selector to allow the installation of non-play store apps because you're being asked to by someone.

        Then it starts a 24 hour timer. When that hits zero, you have 1 hour to go back in and select that you want to install apps on a device you own and paid money to own.

        It's not scam-resistant at all. Any scammer will gladly work around this and send someone to one of many malicious apps in the play store, or a malicious URL, or even just set an appointment to call Grandma back the next day.

        1. SlackingOff123 · · focus · HN ↗
          What? It only stays enabled for exactly 1 hour after the 24 hour timer? I was under the impression that it would stay enabled permanently after waiting the 24 hours once.
          1. creatonez · · focus · HN ↗
            IIRC, it's the button to permanently activate it that is only available for one hour. Once you do manage to press it, you've permanently enabled it. If you miss the window, you have to start the 24 hours again.
        2. creatonez · · focus · HN ↗
          They're not necessarily wrong about it being scam resistant, based on some of the research into the psychology of scams. Adding time defuses the urgency of phone scams, leaving plenty of time to seek a second opinion from family members or the internet, and forcing the scammer to re-explain what the original goal was. It's too much time to breathe and defuses the fight or flight reaction needed for a high success rate. You mention URLs, but a web browser based scam page doesn't accomplish much, because the scammer's goal with fake apps is to acquire persistent remote access (akin to how the AnyDesk Android app uses accessibility permissions for Teamviewer-like remote access to an entire phone).

          But yeah, it's hilarious that they're pushing this so hard when the Google Play Store still has so much malware.

          1. whatsThisBtn4 · · focus · HN ↗
            Isn't this only an issue because they don't support fdroid?

            Getting some 9-11 security theater vibes.

        3. anticensor · · focus · HN ↗
          Yeah, a "hang up today, come back in tomorrow" scheme is perfectly viable.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.