Google's plan to restrict sideloading on Android has a potential escape hatch for users
https://www.androidauthority.com/how-android-sideloading-restrictions-may-work-3595355/
https://www.androidauthority.com/how-android-sideloading-restrictions-may-work-3595355/
256 Comments
ideonek@piefed.social · 316 pts · 343d
JohnEdwa@sopuli.xyz · 89 pts · 343d
It is, because it's actually the term that defines the process of transferring files not from an external networked device - downloading - or to an external networked device - uploading - but between two local devices - sideloading.
It's over two decades old, you downloaded an mp3 from kazaa, and then sideloaded it to your player.
For android apps, I believe the term originates from the method of using ADB to directly write the app to the phone memory, the command of which is "adb sideload filename"
ideonek@piefed.social · 39 pts · 343d
And companies ofted do it. Thay recoined jaywalking to put the blaim of the accidents to pedestrians and take away the road from them. They change what littering means in attrmpt to delute the responsibility for polution... We are better than that this time, right?
Ulrich@feddit.org · -25 pts · 343d
How do you suppose that works, exactly?
ozymandias117@lemmy.world · 42 pts · 343d
I assume you're unaware of the concerted advertising campaigns by auto manufacturers to take public streets away from pedestrians, including things like
https://missedhistory.com/1800/lobbying-trick-blamed-pedestrians-inventing-jaywalking/
"Jay" had started as a word for drivers driving on the wrong side of the road
https://debrabernier.com/the-history-of-jaywalking-in-the-u-s/
Ulrich@feddit.org · -43 pts · 343d
Maybe try to stay on topic?
So jay-walker seems appropriate, does it not?
ozymandias117@lemmy.world · 35 pts · 343d
It's extremely on topic for the thread you responded to.
Google has a concerted effort to make "sideloading" bad, so they can remove it without public backlash
The next comment in the chain mentioned how auto manufacturers did the same thing, villainizing people using public spaces by calling it "jaywalking" until it became illegal to walk on public roads
That was done to take public spaces away from pedestrians and give it to cars
This is being done to take software outside of Google Play away and give the only profit to google
Ulrich@feddit.org · -28 pts · 343d
The topic was how the existence of the term "jaywalking" "blames pedestrians" when they're not actually to blame.
ideonek@piefed.social · 17 pts · 342d
How is that offtopic? It's direct answer to the question that was asked.
https://youtu.be/vxopfjXkArM
Ulrich@feddit.org · -10 pts · 342d
How is it not off-topic? It has nothing to do with the suggestion that the word is used to blame pedestrians as a whole.
G3NI5Y5@piefed.social · 62 pts · 342d
ideonek@piefed.social · 12 pts · 342d
And "littering" is the "real" culprit why we all drawn in uneccesey plastic. We should blame consumers not the polluters.
Corporations do it all the time.
turmacar@lemmy.world · 1 pts · 342d
Yes, but littering used to be a legitimately big problem to. Like the hole in the ozone, now that it's "solved"/ the norm for it to be getting better the focus should shift to other things.
ideonek@piefed.social · 2 pts · 342d
For sure. That's why it worked so well. You take a valid problem and abuse it for your corporate gains.
joshchandra@midwest.social · 2 pts · 341d
FTFY, at least here in a certain country...
Ulrich@feddit.org · -18 pts · 343d
What would you call it?
Wrrzag@lemmy.ml · 53 pts · 343d
"installing" as in "installing software"
Ulrich@feddit.org · -34 pts · 343d
Okay but it's specifically software from outside the Play Store?
grue@lemmy.world · 35 pts · 343d
The point is, there shouldn't be a distinction. To make one is to support prejudice against installing software from elsewhere.
If you use "installing" for stuff from the Google store but any other word for stuff from other sources, you are aiding and abetting Google's anti-property-rights propaganda.
Ulrich@feddit.org · -31 pts · 343d
There has to be. When 99% of installs come from one location, there needs to be a way to describe that other than "Installing apps from outside the default app store".
No? It isn't.
Vespair@lemmy.zip · 13 pts · 342d
The majority of PC game sales happen via steam but we don't call games purchased from GOG "sideloaded."
There is no necessary reason to make the distinction
Ulrich@feddit.org · -5 pts · 342d
There is and I've already given it. MS app store doesn't make up 99% of installations.
choochooMF@lemmy.world · 6 pts · 342d
Ulrich@feddit.org · -6 pts · 342d
It's simply not the same thing and if you can't understand how that makes it different, I don't know how to help you.
yardratianSoma@lemmy.ca · 2 pts · 342d
The words for distinguishing between apps that come from one trusted location vs others is usually untrusted or unverified apps versus trusted or verified ones. "Installing apps from outside the default app store" converts to, "Installing an untrusted app".
It's not that complicated.
Ulrich@feddit.org · -1 pts · 342d
It doesn't. It's not that complicated.
BootLoop@sh.itjust.works · 23 pts · 342d
The same word that I use to when I get software that's not on the Microsoft Store, the Mac App Store, or whatever distro's Software GUI when I am using my desktop..
Ulrich@feddit.org · -15 pts · 342d
If the MS Store and Mac App store made up 99% of installs, that might make sense.
ideonek@piefed.social · 12 pts · 342d
Why? That's a perfect example. There is no qualitative difrence between Microsoft Store and Play Store. Why quantitative difference in the market share would make any distinction in the terminology we use around the process?
Ulrich@feddit.org · -4 pts · 342d
I've already explained why. I don't know what more there is to say. If you don't get it, that's okay.
BootLoop@sh.itjust.works · 3 pts · 342d
So when I install an app from Fdroid, it's only "installing" if lots of other people do it? But if other people don't use it as much it's "sideloading"?
Ulrich@feddit.org · -4 pts · 342d
"lots of other people" was not the words I used.
It can be both "installing" and "sideloading". One is just more specific.
Cethin@lemmy.zip · 15 pts · 342d
When I install software from the Arch User Repository I still just call it installing, even though it isn't through the standard path. Everywhere else, you don't make the distinction. For some reason on phones we've come to call it sideloading, even though the software is just software —it doesn't care where it came from.
Ulrich@feddit.org · -15 pts · 342d
Because 99% of people are getting it from the same place...
yardratianSoma@lemmy.ca · 11 pts · 342d
even within android, if you attempt to install an apk directly, it doesn't say "would you like to sideload this application?", but instead says, "Do you want to install this app?".
Even Google's own OS doesn't use made up language.
Ulrich@feddit.org · -6 pts · 342d
I don't know what that's supposed to prove. Use of the word is not mandatory.
Cethin@lemmy.zip · 4 pts · 342d
Again, when I install something from the AUR (which is not where most software comes from —99+% are from official repositories) it isn't given a special term. It's the exact same situation as "sideloading" but we just call it installing. Can you explain what the difference is between them?
Ulrich@feddit.org · -5 pts · 342d
LOL you just lumped every other repository into one and then excepted the AUR for...reasons?
jjlinux@lemmy.zip · 14 pts · 342d
When you install a '.exe' file in Windows, you don't call it 'sideloading', you call it 'downloading and installing'.
This is the exact same thing. I download from sites, F-Droid, Obtainium, etc., and install the software that is the file I downloaded. I'm effectively NOT side-anything.
Ulrich@feddit.org · -6 pts · 342d
You might call it that if 99% of software was installed from MS store.
DrDystopia@lemy.lol · 7 pts · 342d
0% of my android software is installed through Google Play. Then what?
Ulrich@feddit.org · -6 pts · 342d
I don't even know what that's supposed to mean. We're not talking about you.
EldritchFeminity@lemmy.blahaj.zone · 9 pts · 342d
The issue people have with making the distinction is that Google is trying to spin the narrative and make side loading seem like a dangerous and bad thing to the average user base who don't know any better.
They're taking umbrage with you agreeing that quantitative usage of a storefront makes something simply installing vs side loading a program. Because it helps Google's narrative in a way.
Ulrich@feddit.org · -2 pts · 342d
I understand exactly what people think the issue is. I don't understand or agree with any of the logic. Google did not invent the term. Apple did not invent the term. There's nothing in the term itself to imply anything nefarious. It's nothing but a word used to describe apps installed from outside the default store. When 99-100% of users are all installing exclusively from the default store, it makes sense to have a term that describes that instead of saying "installing apps from outside the default app store" every time.
sem@lemmy.blahaj.zone · 6 pts · 342d
Installing software without a store was just called installing software.
Sideloading is when you download from the side, e.g. downloading software from a separate device instead of from the internet or physical media.
Ulrich@feddit.org · -2 pts · 342d
It isn't.
EldritchFeminity@lemmy.blahaj.zone · 2 pts · 342d
Google is twisting the word to justify their purpose of preventing people from installing anything that isn't from their walled garden. So anything that sounds even close to support for that motive is going to be met with pushback, even if it is a word that existed before Google's use of it. Google's implicitly saying that installing something from anywhere other than their store is something nefarious or otherwise bad/risky. Google is trying to perform the same kind of security theatre as the US with the NSA at airports.
Honestly, it doesn't matter to me where you install an app from because you're simply installing it. Whether that's from Google's storefront, Apple's, or somewhere else, you're installing an app. The circumstances where I'd need a term to specifically say that I'm installing an app from outside the default app store would also be covered by simply saying "I got it from GitHub (or wherever)." It takes the same energy to answer the question of where you got it from regardless of whether you say that you installed it or you side loaded it.
Ulrich@feddit.org · -1 pts · 342d
How is it being twisted? They're using it in exactly the way it is intended to be used?
track_stick_baboon@lemmy.world · 5 pts · 342d
Installing software from outside the play store should be called installing software. It's installing software from the play store what should have a special name, like "gatedloading" for example.
Ulrich@feddit.org · -3 pts · 342d
Good news. It is!
Make it hap'n Cap'n. You're still not invalidating the term of "sideloading".
Wrrzag@lemmy.ml · 2 pts · 342d
If you need to be that specific, "installing" as in "installing software from outside the play store"
Ulrich@feddit.org · -6 pts · 342d
We have words for things for a reason. We don't call doctors "guys who heal people".
Wrrzag@lemmy.ml · 1 pts · 341d
Yet we call people who hold a doctorate "doctors", and if we need to specify we use terms like "medical doctors" or "doctors in philosophy".
sem@lemmy.blahaj.zone · 1 pts · 342d
Doctor can mean different things to different people.
Grazed@lemmy.world · 2 pts · 341d
In what way is installing from the play store fundamentally different? Just because it was preloaded on your phone? What if F droid was preloaded on your phone instead? Is it still sideloading? Google's logic breaks down pretty quickly when you think about it
blockheadjt@sh.itjust.works · 1 pts · 343d
Ulrich@feddit.org · -10 pts · 343d
Yes, so what do you call it when referring specifically to those apps?
yardratianSoma@lemmy.ca · -18 pts · 343d
Don't forget "side effects", when really, medications only have "effects". Whether the effects are intended or not doesn't change the fact that they happen.
knitwitt@lemmy.world · 32 pts · 343d
Cough medicine can induce drowsiness, but you probably shouldn't be taking it as a sleep aid. The distinction between intended vs unintended effects is an important distinction to make, in my opinion, to prevent drugs from being unintentionally misused.
badgermurphy@lemmy.world · 6 pts · 343d
Tollana1234567@lemmy.today · 5 pts · 342d
you shouldnt be taking medication not for his intended purpose, it has many warnings.
yardratianSoma@lemmy.ca · 3 pts · 342d
Talking to the wrong guy here, I've taken many a medications against their intended purpose: I am a curious guy.
But that sounds like saying, in the context of Google's intention of disabling app sideloading, that warning users that it poses a security risk because it's their intended purpose for android, is fine because the authority on android is Google.
Don't just take the word of authority at face value, when they prioritize profit and mindshare over personal freedom.
jjlinux@lemmy.zip · 4 pts · 342d
Wait, so now I have to talk to a doctor before installing from F-Droid? Well, shit.
For all intents and purposes, your comment actually invalidates the premise of using 'sideloading' as a term for installing from outside the 'official' method.
You buy cough syrup because you're coughing, not because you want to be drowsy (I would hope that's the case). In the same way, you install Spotify to listen to music, not to get all your data extracted and sold. Getting drowsy is an inconvenient side effect of the medication, the same way that data grab and ads are an inconvenient side effect of the app.
You're not 'side-medicating'.
sem@lemmy.blahaj.zone · 2 pts · 342d
It's a bad comparison because some people do take the medicine to get the side effects. For example taking benadryl to fall asleep.
yardratianSoma@lemmy.ca · 2 pts · 342d
You are the master of your body, the person who decides ultimately what goes in and out of your body, No doctor can force you to take anything. That's what I mean, The play store aka the doctor wants to become the master that decides what apps go in or out of your phone, instead of the user. My comment doesn't invalidate the premise of the use of the term sideloading, because I don't agree with the term to begin with.
Whether the effect is ideal or not does not change what is chemically happening in the body. The body can't tell apart side effects from the main ones, so this distinction exists because humans deemed it so, just like the distinction between play store sanctioned apps, and everything else. It's a distinction that Google is now abusing for it's own monetary benefit.
ryannathans@aussie.zone · 251 pts · 342d
Call sideloading what it is, installing apps.
ReallyActuallyFrankenstein@lemmynsfw.com · 49 pts · 342d
I know, I know. People don't understand how they've already conceded the war with language.
Me: Like...Yeah, I'm just going to "jailbreak" the small computer I bought to... run a program.
The public unironically: Oh man, I hope you don't get arrested.
StarMerchant938@lemmy.world · 17 pts · 342d
Goodlucksil@lemmy.dbzer0.com · 2 pts · 342d
Sideload refers to moving files between two devices, like P2P
AbidanYre@lemmy.world · 219 pts · 343d
Is it though? Really?
radix@lemmy.world · 152 pts · 343d
The security of their bank balance.
Sxan@piefed.zip · 35 pts · 343d
No.
Ulrich@feddit.org · 27 pts · 343d
This publication is always repeating Google's nonsense.
scarabic@lemmy.world · -16 pts · 342d
What ulterior motive do they have for blocking sideloading?
AndyMFK@lemmy.dbzer0.com · 29 pts · 342d
Essentially banning any apps that would hurt googles profits.
I thought that was pretty obvious.
scarabic@lemmy.world · -4 pts · 341d
It’s not. They already allow multiple app stores so they are not profiting off of every app.
EDIT: people keep downvoting me like I’m bootlicking or disagreeing. I’m actually trying to understand what the suspicion actually is over ending sideloading. There’s definitely a security case to be made, but people don’t seem to buy that. What actually ARE you thinking?
QuestionMark@lemmy.ml · 205 pts · 342d
This is an obvious lie.
Tollana1234567@lemmy.today · 44 pts · 342d
they want to improve thier AI and datamining capabilities.
nomadjoanne@lemmy.world · 5 pts · 342d
What am I not seeing? How does this improve datamining capabilities?
Vespair@lemmy.zip · 25 pts · 342d
Target can track your purchases when you shop at Target, but can't really do that when you're shopping at a local store. Same applies here.
llama@lemmy.zip · 2 pts · 342d
But you can't shop at Target with some random app, only the Target app. Even a small business has an accessible pathway to publish their app. Besides Fortnite and my gimbal nobody out here trying to educate customers on how to install their apk file.
EldritchFeminity@lemmy.blahaj.zone · 4 pts · 342d
They mean a physical Target store, not a phone app. Target can track customers walking in and out the door and what they buy, how long they stay, etc. but they can't track anything about you if you just go to a different store, especially something like a small business which isn't hooked into the ad data sponge.
Buddahriffic@lemmy.world · 4 pts · 341d
Also if the CEO of target decides he really doesn't like a popular shirt and is able to force everyone to only shop at target, then he can come a lot closer to snuffing out the existence of that shirt.
Knock_Knock_Lemmy_In@lemmy.world · 2 pts · 341d
Some apps let you watch YouTube without being a YouTube app.
Eggyhead@lemmings.world · 26 pts · 342d
They never specified who’s security…
SCmSTR@lemmy.blahaj.zone · 6 pts · 341d
Whose*
Who's = who + is
Whose = an indication of possession
k0e3@lemmy.ca · 4 pts · 341d
I will always remember this grammar rule thanks to the show "Whose Line Is It Anyway?" because I would see that title every morning before school.
Eggyhead@lemmings.world · 1 pts · 341d
The question is still valid, even if the meaning changes.
espentan@lemmy.world · 5 pts · 341d
Their revenue probably felt very threatened.
Ulrich@feddit.org · 144 pts · 343d
tl;dr you can still "sideload" via adb.
This is so incredibly inconvenient as to be meaningless.
gaylord_fartmaster@lemmy.world · 60 pts · 343d
It's not completely meaningless because if it's truly the only option I'm going to be using it until I eventually replace my current phone with one with an unlocked bootloader.
Ulrich@feddit.org · 33 pts · 343d
I'm afraid that won't help. There will be even fewer people developing apps specifically for the 0.01% of us using custom ROMs.
gaylord_fartmaster@lemmy.world · 21 pts · 343d
They're already developing the apps for the 1% of us not just using proprietary apps from the play store. I don't think this just kills open source app development.
Ulrich@feddit.org · 14 pts · 343d
That's not who we're talking about. We're talking about the 0.1% who have custom ROMs.
It won't kill it completely but it will severely hurt it. The more complicated it becomes, the smaller the userbase becomes.
Apps like Syncthing have already discontinued development due to Google shenanigans + lack of users. That'll only get worse as the userbase shrinks.
JohnEdwa@sopuli.xyz · 8 pts · 343d
There are plenty of people developing apps that require root, and users who run those are already jumping through a million hoops of cat and mouse to keep their fucking mcdonalds app detecting it so they can get cheaper coffees and free fries.
Like seriously, wtf McDonalds, your app is like the ultimate root/safetynet/device id detection tool, I don't think there exists even a banking app that is as hard to fool.
watson387@sopuli.xyz · 16 pts · 343d
When my current phone dies I'll be buying a flip phone.
Ulrich@feddit.org · 7 pts · 343d
Guess what!? Those are all Android too!
yessikg@fedia.io · 1 pts · 343d
Nope, some of them run KaiOS
Ulrich@feddit.org · 2 pts · 343d
Guess what!? KaiOS is Android!
yessikg@fedia.io · 0 pts · 343d
They can go back to being a Linux OS much easier than anybody else
balder1991@lemmy.world · 1 pts · 342d
But I guess those don’t have Google Play or anything Google, they’re more like a limited Android.
Goodlucksil@lemmy.dbzer0.com · 3 pts · 342d
Rimjob_steve moment
blargh513@sh.itjust.works · 16 pts · 343d
It will be stupid, but I presume there will be a rise in desktop apps or webapps that require you to only plug the phone in and it will handle the rest.
gaylord_fartmaster@lemmy.world · 8 pts · 343d
Yeah, if something like Obtanium needs to run on my desktop instead of my phone and I have to plug it in every once in a while, that's not the end of the world.
balder1991@lemmy.world · 3 pts · 342d
I think adb can also work over Wi-Fi, just like Android Studio can connect to the phone and build and install without plugging it.
KSPAtlas@sopuli.xyz · 2 pts · 342d
There are already android apps that allow you to ADB into your own phone without root, so you could VERY EASILY just make an app store that utilises that, you only need to install the app from desktop once
dukatos@lemmy.zip · 15 pts · 343d
good luck updating all your apps that way...
Ulrich@feddit.org · 4 pts · 343d
Exactly
cmnybo@discuss.tchncs.de · 3 pts · 343d
We already have to do that to install older apps. It's inconvenient, but not as bad as having to boot up an ancient phone every time you need to use the app.
Arghblarg@lemmy.ca · 3 pts · 343d
Perhaps someone could write an 'adb loopback' app -- get that into the official app store, and said app would then squirt other .apk files through adb on the phone to itself, thus sideloading it.
KSPAtlas@sopuli.xyz · 4 pts · 342d
ADB loopback apps already exist, such as Shizuku
Ulrich@feddit.org · 2 pts · 343d
As far as I know, ADB needs to be run on another device which is plugged into the phone.
I suppose one could write a script/app that detects the device is plugged in, and automatically looks for and installs updates using adb. That would be the least amount of friction.
fmstrat@lemmy.nowsci.com · 1 pts · 342d
I think you can run ADB on another Android device, so maybe an Obtainium+ADB device that stays at home.
hansolo@lemmy.today · -14 pts · 343d
Not at all, just get comfortable with ADB and use Claude to walk you through the steps.
I see this as an absolute win. /s
Edit: Y'all, ADB isn't hard to use. At all.
Ulrich@feddit.org · 9 pts · 343d
No one thinks it's hard. It is, however, as I said, extremely inconvenient and time-consuming to do this every day, and no one wants to do that.
hansolo@lemmy.today · 0 pts · 342d
Every day? Who needs to install an app every day?
Not saying this isn't annoying AF, it is, but it's not the absolute lockdown that we all feared.
Ulrich@feddit.org · 3 pts · 342d
My guy, have you ever heard of "updates"? How do you suppose they get installed?
hansolo@lemmy.today · 0 pts · 342d
So just take one day a month and do your maintance. Anything that isn't from the Play store isn't exactly getting Dev work every day to patch whatever.
Whatever, I don't love this either, but it's not some absolute deal breaker IMO. Maybe 6/10 dealbreaker. We disagree and thats fine. Now please downvote like you were going to do anyway.
Ulrich@feddit.org · 3 pts · 342d
I get several updates/day from FDroid, Obtainium and Accrescent. Some of them are security updates.
gnuplusmatt@reddthat.com · 115 pts · 342d
I'm not sure why google is over engineering this, proper mainline distros have this solved since forever. Let the community setup trusted repos with gpg keys, then let me trust the repos. If Fdroid trusts the package and I trust Fdroid, who should care?
Lemminary@lemmy.world · 123 pts · 342d
Probably because they want to target software that cracks theirs to avoid ads, like ReVanced.
SaharaMaleikuhm@feddit.org · 50 pts · 342d
Ding ding ding ding ding. It's so obvious, it's because Google wants to be in control and block apps it would rather not exist. Newpipe, FreeTube, Revanced and the like.
Xatolos@reddthat.com · 7 pts · 342d
Then why aren't they already doing that by blocking DuckDuckGo?
The DuckDuckGo app blocks all apps from sending to Google (and other advertisers) tracking/ad data on a system level. And it's freely available on the Play Store (has been for years.
https://play.google.com/store/apps/details?id=com.duckduckgo.mobile.android
If they wanted to prevent apps from blocking their ad abilities, this app would never have been allowed on the Play Store.
communist@lemmy.frozeninferno.xyz · 9 pts · 342d
Antitrust lawsuits and plausible deniability
littleguy@lemmy.cif.su · 8 pts · 342d
Does it actually block ads in apps?
Blokada 5 blocks ads in apps and it was removed from the google store years ago. You have to sideload it in order to use it.
There's a neutered version on the google store, but it doesn't block ads effectively.
Google also removed an addon called Adnauseam, which clicked ads in additional to blocking them. That way, advertisers still have to pay site owners for your visit. Google removed it without justifiable reason, then kept it removed since there was no sufficient backlash.
It's the main reason why I switched to Firefox. That kind of abuse is for useful idiots.
moakley@lemmy.world · 7 pts · 342d
If they blocked it now, people would just sideload it.
PeanutBrain@lemmy.world · 5 pts · 342d
Thank you random lemming, didn't know about duckduckgo-s tracker blocking capabilities, have it installed now.
olsonexi@lemmy.world · 76 pts · 342d
Because it was never actually about security to begin with. That's obviously BS. Google just wants control.
Zak@lemmy.world · 63 pts · 343d
If Google wanted to add developer verification without being evil, it could use SSL certificates connected to domain names. I think the whole concept is ill-conceived, though I'll admit to a modest bias against protecting people from themselves.
tauonite@lemmy.world · 3 pts · 343d
They couldn't. Domains and SSL certificates can be obtained very easily anonymously and thus wouldn't let Google identify the developers of malicious apps, which is the goal of this
coolmojo@lemmy.world · 28 pts · 343d
The trouble is Google’s definition of malicious apps. Are adblockers malicious? How about alternative apps for YouTube? Based on the recent history, I don’t think you will be able to install those apps on the phone you purchased.
tauonite@lemmy.world · 6 pts · 342d
Yes, I agree. Google will use this to control the Android app ecosystem beyond the Play Store and I don't like it either
aeternum@lemmy.blahaj.zone · 6 pts · 342d
Zak@lemmy.world · 12 pts · 343d
It provides a way to open an investigation into a malicious developer without giving Google the ability to ban anyone it doesn't like.
Squiddork@lemmy.world · 6 pts · 343d
Yeah I mean some form of asymmetric encryption/validation would work but it stops the real reason why Google wants to implement this.
LodeMike@lemmy.today · -2 pts · 343d
The problem with that is that certificates expire before someone would want to keep using the app.
Zak@lemmy.world · 5 pts · 343d
It need only check at install time.
LodeMike@lemmy.today · 4 pts · 343d
Correction: SSL certificates can expire before someone would want to continue being able to install any given app.
Zak@lemmy.world · 5 pts · 343d
Sure, the developer needs to keep the certificate up to date and re-sign the APK on occasion.
LodeMike@lemmy.today · 3 pts · 342d
So any APK I download will just expire at some point in time that's probably really annoying to know, and then I have to dig through the internet again so I can install the app again?
pycorax@sh.itjust.works · 1 pts · 342d
If it's anything like how Windows does it, you would still be able to override it. It just gives you a scary warning and hides the option unless you click "more info" or something.
Zak@lemmy.world · 1 pts · 341d
Another option is to allow otherwise-valid signatures after expiration. It's generally still possible to check them.
LodeMike@lemmy.today · 1 pts · 341d
That completely nullifies the entire point of signature validations.
LodeMike@lemmy.today · 1 pts · 343d
These two are identical for software.
xthexder@l.sw0.com · 5 pts · 342d
Code signing certificates work a little differently than SSL certificates. A timestamp is included in the signature so the certificate only needs to be valid at the time of signing. The executable will remain valid forever, even if the certificate later expires. (This is how it works on Windows)
InnerScientist@lemmy.world · 1 pts · 342d
Doesn't work, the reason they can expire is to make certificate rotation possible. If an expired ssl certificate is cracked it doesn't matter because no browser will accept the expired certificate, with your idea the expired certificate just signs an app with the date of 1984 and it works.
Certificates in SSL can't change the date because that date is signed by a certificate higher in the hierarchy.
xthexder@l.sw0.com · 2 pts · 342d
This isn't "my idea", this is how the industry already does code signing. You can't sign something with a date of 1984 because your certificate has a start and end date, and is usually only valid for 1 year.
You can read more about how this works here: https://knowledge.digicert.com/general-information/rfc3161-compliant-time-stamp-authority-server
https://en.wikipedia.org/wiki/Trusted_timestamping
InnerScientist@lemmy.world · 2 pts · 342d
Then you need a Trusted Third Party, right? Still requires some though on how to prevent that third party from blocking applications they don't like but I can see how a group of trusted authorities could work.
xthexder@l.sw0.com · 2 pts · 342d
The trusted 3rd party in this case is actually multiple 3rd parties. There's several options for trusted timestamping just like there's multiple trusted root CAs for SSL. Since the timestamping service is free and public, anyone can use it to sign anything, even self-signed certificates. There's no mechanism to deny access, at least for this portion.
There's always a risk the root CAs all collude and refuse to give out certificates to people they don't like, but at least so far this hasn't been a problem. I don't have a better solution unfortunately. If we could have a 100% decentralized signing scheme that would be ideal, but I have no idea how you would build such a thing without identity verification and some inherit trust in the system
drmoose@lemmy.world · 55 pts · 342d
This is actually worse than integration in Play Protect which can be disabled very easily. Now you can only install unsigned apps via ADB which means just developers can do it.
arararagi@ani.social · 30 pts · 342d
And very annoying too since some government apps don't like it when you have developer mode on.
Zanshi@lemmy.world · 23 pts · 342d
Not only government. I can't see my daughter's insulin pump status if I don't disable developer mode.
LifeInMultipleChoice@lemmy.world · 3 pts · 342d
I believe I got a notification that it disables NFC payments when developer mode is enabled. Which I know not as many people use it in the U.S. but some do.
greedytacothief@lemmy.dbzer0.com · 1 pts · 342d
Shit, I've disabled developer mode and still can't access my bank app
SparroHawc@lemmy.zip · 15 pts · 342d
Or anyone with a computer who installs ADB. You don't have to be a developer.
drmoose@lemmy.world · 7 pts · 341d
Nah you can't realistically distribute your app with adb requirement. No one will bother to go through such friction.
SparroHawc@lemmy.zip · -3 pts · 341d
Although you are correct, you still don't have to be a developer to find use in ADB. I've used it and I've never been interested enough in developing for Android to do more than install the SDK for it once.
Miaou@jlai.lu · 4 pts · 341d
Knowing what an SDK is already puts you in the 1% most knowledgeable users
sudoer777@lemmy.ml · 1 pts · 341d
COASTER1921@lemmy.ml · 8 pts · 341d
Leaving ADB open to unverified apps is more than I was expecting. ADB is reasonably straightforward to use even without actually being an Android developer.
There was never any way they'd integrate it to play protect and still allow play protect to be disabled. I prefer this to being required to use play protect personally, though the services do seem somewhat redundant. Presumably the whole point of doing this is to create an Apple style walled garden (which is of course very profitable). Google likely doesn't want to fully lock it down and risk legal trouble, they just need to make it difficult enough that the masses don't bother installing unapproved apps that may not act in Google's interests.
I still hope the EU takes legal action against this anyway.
drmoose@lemmy.world · 6 pts · 341d
I don't think this adds anything tbh as peoppe with adb would always be able to bypass this. The issue is that this kills distribution and thats exactly what Google wants - have full competitive control. Once they don't like your app they'll block your account and what do you do with your customer base? Give them adb install instructions? That's basically a death sentence for any app.
6nk06@sh.itjust.works · 51 pts · 343d
lol, adb is the first loophole that will be closed.
balder1991@lemmy.world · 1 pts · 342d
I don’t know, even people here are already considering it a loss of the only way is through ADB, because it’s not practical for everyday usage. But it’s better than nothing.
cupcakezealot@piefed.blahaj.zone · 36 pts · 343d
why can google not just code something like this into android:
allow apps from:
( ) All sources (how it is now; allow each app to install apps from external sources)
( ) Just Google Play
( ) Apps which have been verified by Google Developer Program
cerebralhawks@lemmy.dbzer0.com · 63 pts · 343d
Because they want to stop people from using ad blockers.
palordrolap@fedia.io · 40 pts · 343d
Option 1 is a potential cause of "lost" revenue.
Late stage capitalism absolutely forbids anything that could cause that, even if the cost of implementation outweighs any potential gain.
mariusafa@lemmy.sdf.org · 16 pts · 343d
Because it's Google
cupcakezealot@piefed.blahaj.zone · 2 pts · 342d
bing! thy turkey's done
SanctimoniousApe@lemmings.world · 10 pts · 343d
Taking Google at their word for a moment, it's far too easy to scam the clueless masses into selecting the first one. Might work okay if it's strictly an ADB command, tho.
Feyd@programming.dev · 13 pts · 343d
And why should we do that?
Zak@lemmy.world · 10 pts · 343d
I'm inclined to think that's not the job of an OS vendor to prevent. Sure, put a warning label on it, but it's the user's device; once they say they know what they're doing, that should be that.
dust_accelerator@discuss.tchncs.de · 4 pts · 343d
The implication here is, if they implement this, is that they volunteer to assume liability, should e.g., your bank account be drained despite undergoing their forced strict lockdown on paid and owned devices.
Fat chance, because laws are meaningless to crime syndicates
Zak@lemmy.world · 6 pts · 343d
It might be a reasonable trade for users to make if Google assumed liability. In fact, that would be an interesting way to implement laws to discourage practices like these.
Ulrich@feddit.org · 4 pts · 343d
If someone can be socially engineered into disabling security mechanisms, then that should just be their fate. There's no sense in fucking everyone else in order to protect them.
cupcakezealot@piefed.blahaj.zone · 1 pts · 343d
but they could make it be google play or samsung store only as the default as a compromise
SanctimoniousApe@lemmings.world · 5 pts · 343d
That would just continue to ensure lock-in, and at least the EU would never go for that (& neither would I). Sideloading should still be allowed.
Google's Play Store security has never been all that stellar, anyway.
littleguy@lemmy.cif.su · 5 pts · 342d
That would give users choice, and corporations want as many people as possible to be incapable of making decisions for themselves.
stevedice@sh.itjust.works · 4 pts · 341d
I can see it already:
() Just Google Play (safe)
() Verified apps (not recommended)
Advanced settings
click on Advanced settings
() All sources (Unsafe. Will probably kill your cat and burn down your house)
tick the box
Are you sure?
click yes
ARE YOU SURE?
click yes again
ONE HUNDRED PERCENT SURE?
wait for the 30 seconds timer to count down
click yes
( ) I do not love my cat and want him to die.
tick the box
( ) I accept the very real risk of my house burning down
tick the box
Please wait 24 hours for the change to apply. You can reverse it at any time from this menu.
get spammed every hour for the next 24 hours with notifications asking me to fix my security settings
get a bigass ⚠️ every time I turn on the phone
every once in a while the change just straight up reverses and I have to do it all over again
mastod0n@lemmy.world · 17 pts · 343d
We should embrace oldschool SciFy and go for (DIY) Cyberdecks.
SanctimoniousApe@lemmings.world · 11 pts · 343d
Thankfully, for those of us without the time for all that there are Linux phones such as this one I'm considering.
balder1991@lemmy.world · 3 pts · 342d
I’d love to play around with something like this, as a programmer myself, but unfortunately the cost is prohibitive in my country.
SanctimoniousApe@lemmings.world · 2 pts · 342d
Yeah, that's why it's still in the "considering" phase for me as well - especially considering Trump's tariffs crap. It also seems a tad underpowered for the price, and they still don't have the promised removable battery replacements in their store.
It's worth remembering, though, that the cost covers the constant software updates, as well as their user support. As such, it's much like the Apple model of business, except much more open - so in the end it's probably worth it.
watson387@sopuli.xyz · 2 pts · 342d
Yo I've never seen this one. Thanks for the link!
covert_czar@lemmy.dbzer0.com · 13 pts · 342d
Which means I can make an app for this "Sideloading" by shizuku..
themachinestops@lemmy.dbzer0.com · 2 pts · 341d
I heard of shizuku before how does it work? Does it need root?
covert_czar@lemmy.dbzer0.com · 1 pts · 341d
goatinspace@feddit.org · 8 pts · 343d
umbrella@lemmy.ml · 4 pts · 341d
hendrik@palaver.p3x.de · 3 pts · 341d
So a lot of speculation and we don't know much except 2 paragraphs in the FAQ... I'd like to mention though, they've recently stripped the Pixel devices of their status as developer devices and now push for their emulator for development. Once they follow that kind of logic, there isn't really a reason to keep ADB working as is, at least not on real devices.
napkin2020@sh.itjust.works · 2 pts · 342d
I honestly think that this is just not going to happen. It's already a giant pain in the ass to install apps from anywhere else than Play Store. With Shizuku it got much, much better.
GreenShimada@lemmy.world · 18 pts · 342d
You may want to re-evaluate how you're installing non-Play apps. I use F-droid all the time and never had anything even approach "inconvenient."
napkin2020@sh.itjust.works · 6 pts · 342d
Like I said, Samsung does this crap in certain regions, specifically South Korea. I'm using Shizuku now and couldn't be happier.
GreenShimada@lemmy.world · 3 pts · 342d
AAAAAaaaaaaaaaaaahhhhhhhhhh, ok, say no more. Samsung used to be much easier to work around and they're really joining the "lock it down!" club lately.
viking@infosec.pub · 12 pts · 342d
Huh? Downloading an apk and clicking open with -> package installer is nothing but straightforward.
napkin2020@sh.itjust.works · 3 pts · 342d
It nags me a lot, sometimes downright blocks me from installing without adb shit. Samsung.
pycorax@sh.itjust.works · 1 pts · 342d
What kind of apps are you installing? I've never ever had any issue with installing APKs on Samsung, you just have to allow the app that triggered it to install APKs one time and every subsequent time, it just works.
napkin2020@sh.itjust.works · 1 pts · 342d
In some regions, afaik, you just CANNOT install certain apps without adb, this in my experience includes: KDEConnect, Fdroid, Newpipe...etc. The list changes time to time.
pycorax@sh.itjust.works · 1 pts · 342d
What region are you in if you don't mind me asking? It works perfectly fine in Singapore.
Hawk@lemmy.dbzer0.com · 2 pts · 342d
This simply doesn't work anymore for all apps on my Pixel 8.
Many I installed manually just redirect to the Play store with the message it could harm your device and you should download from Play.
pineapplelover@lemmy.dbzer0.com · 4 pts · 342d
Pixel 8a on graphene here so I'm not getting this. Maybe on stock
faerbit@sh.itjust.works · 3 pts · 342d
Pixel 8a on stock here. I have no idea what @Hawk is talking about. I just install any app, that I want. I might had to alter some settings, to do it, but I don't remember doing that.
KingRandomGuy@lemmy.world · 2 pts · 342d
GrapheneOS patches this behavior if apps match their Google play signature IIRC. This is a behavior that apps on the play store can opt into (basically they block operation if they aren't installed via Play).
It was rather annoying until recently, since some apps require you to be on a certified Android install to find them in the Play store, but don't actually check play integrity in the app. These apps when installed via Aurora wouldn't work for me until Graphene patched this.