• kbal@fedia.io
    link
    fedilink
    arrow-up
    21
    ·
    5 hours ago

    Just think of all the other things that could benefit from a “protective waiting period” to enhance your safety.

    Turning off location tracking, using a web browser other than Chrome, using a mail server other than Gmail, visiting duckduckgo.com — if Google really cared about your privacy and security they’d add a 24-hour delay to all these dangerous activities.

  • COASTER1921@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 hours ago

    If this is really as straightforward as it sounds then I’d consider this the best case scenario. Google could have gone full Apple style lockdown or even just have implemented this flow on a per app basis, but needing to wait 24hr one time to enable unverified app installation isn’t a bad idea from a security perspective. It prevents a bad actor with temporary access from being able to do much while not getting in the way of us power users after the initial 24hr period.

    My bigger problem is how Google is leveraging their monopoly to implement this single-handedly and only for themselves. If they had instead gone through AOSP this perhaps could have been implemented in a better way to allow other parties than just Google to be the verifier, and that 24hr waiting period could be applied to any verifier that is not the phone’s default. I’d argue this would be an equally reasonable security measure considering how many scams are out there preying on those who aren’t technologically savvy, yet would maintain transparency.

    • Eximius@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 hours ago

      I’ve heard of security by obscurity being accepted, but never heard of security by obtuseness being accepted as valid.

  • MountainMan@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 hours ago

    They will just redefine what 24h means!

    Don’t think for a second that these companies are working in good faith, and would change their evil plans due to some pushback from the rabble. They will just find ways to circumvent things. They have everyone by the nads, there are no competitors.

  • Kissaki@feddit.org
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 hours ago

    Why is it called developer mode if it’s supposedly an advanced flow? That has a bad implication.

  • smeg@infosec.pub
    link
    fedilink
    English
    arrow-up
    47
    ·
    10 hours ago
    • enable developer options
    • confirm that you are not tricked
    • restart phone and re-authenticate
    • wait one day
    • confirm with biometrics that you know what you are doing
    • decide if you only want unrestricted installs for 1 week or forever
    • confirm that you accept the risks
    • enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
    • FauxLiving@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 hours ago

      I can understand this workflow being created to protect the legions of people who are tricked into installing spyware.

      It doesn’t remotely affect me because I use GrapheneOS and if this is an issue for you then you’re probably someone who should look at installing GOS or Lineage.

      I don’t think Google should be able to do this and it is likely part of a longer-term strategy to strangle any competition. At the same time, I can understand how this change will save a lot of grandparents from clicking a link in a text from their ‘grandchildren’ and installing spyware that’ll steal all of their bank information.

      • low@lemmy.today
        link
        fedilink
        English
        arrow-up
        1
        ·
        47 minutes ago

        Bro did you want them to ban it? A one-time 24 hour wait is literally nothing compared to having 0 viable phones on the market where you can sideload.

        Am I tripping? How is this not good news?

      • low@lemmy.today
        link
        fedilink
        English
        arrow-up
        1
        ·
        54 minutes ago

        I bought an Android specifically because iPhone doesn’t allow sideloading. If Android bans sideloading, there’s no viable options left until Linux phone develops to a usable state.

        The win is that they’re not banning sideloading, obviously. Personally I don’t gaf if I gotta wait 24 hours as long as you can do it.

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    7
    ·
    10 hours ago

    This would not have affected me since I use Lineage OS without Google Play Services, but I am now more seriously than ever looking into using a Linux phone like Postmarket OS.

    • fluxx@mander.xyz
      link
      fedilink
      English
      arrow-up
      6
      ·
      8 hours ago

      It would affect a lot of users, then it will indirectly affect you too, as a lot of devs won’t be as interested in maintaining their apps for so few users. But I hope it will at least give a bit of a push to developing postmarket os. I personally am sure going to get a second hand phone to install postmarketos too and hope I can contribute at least a little bit. I am prepared to suffer, at least a little bit for the right cause.

    • Squizzy@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 hours ago
      1. Camera
      2. Phone projection for cars
      3. Contactless pay/ wallet/pay alternative

      Give me a device that can do these and I am in for ditching android. I only use browsers or off store apps that have linux support mainly anymore anyway.

      • fluxx@mander.xyz
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 hours ago

        At least the last one won’t happen, as banks would have to be on board. And banks are not on your side with this one.

        • Squizzy@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          To be honest this one is in hand, curve has an alternative product and a lot of banks across EU have nativr NFC. My country does not have those banks though. I hope revolut bring it in.

          I do want something that takes me tickets for shows and flights and membership cards too though

          • fluxx@mander.xyz
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            Yeah, im in a similar situation. Curve doesn’t work in my country and banks don’t have their own solution. And google pay won’t work on my grapheneos pixel.

  • Ganbat@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    51
    ·
    15 hours ago

    In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee.

    Fuck you sideways, Google.

      • MrScottyTay@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        11 hours ago

        They want developers to share their IDs to have their apps on the play store. The limited groups is so hobbyist developers can still share apps without having to jump through those hoops and so the users don’t need to go and enable sideloading, with the caveat that there’s a call on how many users you can send it to it looks like.

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          6
          ·
          edit-2
          9 hours ago

          That’s already the case. The new thing is that they want developers to share their ID to have their apps be installable on Android in the first place, even if they don’t use the Play Store.

          • Arcadeep@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            I wonder if this is a direct result of apps like ICE watch or ones that track billionaire planes and stuff

  • shrek_is_love@lemmy.ml
    link
    fedilink
    English
    arrow-up
    35
    ·
    16 hours ago

    They think this will take some of the heat off of them. Hopefully no one actually thinks this is a reasonable compromise. If I want to help an elderly family member install something on their phone during Thanksgiving dinner or a family reunion, I’m not gonna want to wait a day. Uncle Paul’s flying back to Florida tomorrow morning!

  • ben@lemmy.zip
    link
    fedilink
    English
    arrow-up
    96
    ·
    19 hours ago

    Okay but, installing an apk is not the kind of thing a scammer does. They’ll just install some standard off the shelf remote access software from the play store

    This very much feels like they just needed to come up with a new justification for this process and opted for scammers for some reason. Even though they’re completely disconnected

    • cecilkorik@piefed.ca
      link
      fedilink
      English
      arrow-up
      51
      ·
      18 hours ago

      This very much feels like they just needed to come up with a new justification for this process

      It feels that way because that’s exactly what happened.

      • ben@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 hours ago

        I was hoping for at least something slightly believable, someone let Gemini write the justification I guess

        • cecilkorik@piefed.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          13 minutes ago

          They don’t even respect us enough to bother with trying to make their lies convincing anymore.

      • Ada@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        50
        ·
        19 hours ago

        At this stage, I’m thinking one of the Motorola phones that will run Graphene out of the box.

      • somethingDotExe@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        19 hours ago

        Fairphone with /e/os or Jolla phone with sailfishos (waiting for the reviews of their new preordered flagship phone coming out this fall.)

        • Lost_My_Mind@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          18 hours ago

          Well, that runs into a different problem with the same results.

          Sure, GOOGLE can’t hinder you from installing apps, but the fact that nobody has heard of these OS’s before means your selection of available apps is what hinders your ability to install apps.

          • Arcadeep@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            5 hours ago

            e/os and Sailfish are pretty popular alternative OSs (OSes? OSii?) and e/os is an android fork, with Sailfish having an android compatibility layer, so they work with standard Android apps.

            Source: I use e/os.

            Why are you in here arguing losing points with no reason or even knowledge about them?

          • illi@piefed.social
            link
            fedilink
            English
            arrow-up
            3
            ·
            9 hours ago

            /e/ OS is just a degoogled Android (similar to Graphene, but not so security oriented). You can install the same apps - though some might not work properly.

            Sailfish OS is Linux, but if I understand it correctly they have a compatibility layer enabling you to seamlessly install Android apps on it.

          • somethingDotExe@lemmy.world
            link
            fedilink
            English
            arrow-up
            6
            ·
            14 hours ago

            “Nobody has Heard of these os’” - wtf you talk about? They are gaining popularity here in EU as well as in Turkey. It’s getting popular to de-google/de-americanize. People are hating on the monopoly iOS and Android has on the industry. Better to do something than being a sheep about it, and just let thos mofos suck the data out of your life forever?

          • Zak@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            14 hours ago

            /e/os is Android without Google proprietary stuff. It runs most Android apps.

            • Tetsuo@jlai.lu
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 hours ago

              While technically correct, it runs apps, it’s misleading because it won’t run the majority of apps from the playstore.

              Google holds people captive with the playstore and the very sneaky google play services.

              Only the most hardcore tinkerers and privacy oriented would run a pure AOSP phone.

              • Zak@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                57 minutes ago

                I’ve tried it, and only ran into a couple apps that wouldn’t work with MicroG. I won’t pretend it’s painless, but it’s workable for someone with sufficient motivation.

              • Teknikal@anarchist.nexus
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                3 hours ago

                These devices have replaced play services with things like micro g, so yes they will run pretty much any android app even Google ones would work but that would be defeating the purpose.

            • halcyoncmdr@piefed.social
              link
              fedilink
              English
              arrow-up
              6
              ·
              17 hours ago

              That exact issue killed Blackberry, the largest smartphone maker at the time. Even after they built a compatibility layer to run Android apps.

              You think anywhere near enough people are going to go out of their way to try something that doesn’t have marketshare already to maintain an entire alternative hardware and software ecosystem? Where can I get wherever awesome shit you’re smoking?

              • MrScottyTay@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                11 hours ago

                When i was a kid, blackberries were more common than android. At least in my area it was the “in” thing to be on BBM