• smeg@infosec.pub
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    20 days ago
    • enable developer options
    • confirm that you are not tricked
    • restart phone and re-authenticate
    • wait one day
    • confirm with biometrics that you know what you are doing
    • decide if you only want unrestricted installs for 1 week or forever
    • confirm that you accept the risks
    • enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
    • wonderingwanderer@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      19 days ago

      Combined with the news that they’re going to start requiring developer age verification even in the alternate app repositories…

    • FauxLiving@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      20 days ago

      I can understand this workflow being created to protect the legions of people who are tricked into installing spyware.

      It doesn’t remotely affect me because I use GrapheneOS and if this is an issue for you then you’re probably someone who should look at installing GOS or Lineage.

      I don’t think Google should be able to do this and it is likely part of a longer-term strategy to strangle any competition. At the same time, I can understand how this change will save a lot of grandparents from clicking a link in a text from their ‘grandchildren’ and installing spyware that’ll steal all of their bank information.

      • AHemlocksLie@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        20 days ago

        GrapheneOS is built on AOSP, which is where the change is being made. Graphene and other custom ROMs will need to maintain a fork that cuts out the feature if they want to avoid. Google is also starting to close off Android to make that more difficult, so it’ll become a genuine project to maintain the fork well.

      • fallaciousBasis@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        20 days ago

        I mean… This is kind of why I never let people use my phone.

        I have installations from various sources enabled… Like my browser, because I know what I’m doing. But I wouldn’t trust anyone as the process is currently effortless…

        If someone is trying to install spyware on you (like a partner or parent.) this might offer some notification and prevention.

        I don’t really see the big deal. You do it once, enable it forever, and wipe up those tears.

        I think a better way would just to have maybe like a biometric/pin confirmation upon installation. Simple. Clean.

        • reksas@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          1
          ·
          19 days ago

          they want to suppress the developers, not users. By making it so bothersome, so many people will just stop using sources from outside google play. First they do this and at some later time they will add more hoops to it. If they manage to strangle any developers that make stuff, people will have nowhere to turn yet they cant complain either because google will have undeniable monopoly.

  • Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    4
    ·
    19 days ago

    Who are these smooth-talking scammers that can guide a regular-ass user to jump through hoops in settings to install a malicious app?

    Maybe I should ask them how they do it, because I cannot convince my family to download and use Signal. You know, the legit app from the official app store.

    • goldman60@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      19 days ago

      People who can’t operate a computer will somehow become gods at following instructions if someone calls “from Microsoft”

      • d00ery@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        19 days ago

        Yes exactly this. I try and explain a computer thing to someone and get ignored. That same person talks to some sales rep in the electronics store and comes away “ohh they said I need to buy super expensive antivirus, that’ll solve my issue with my screen resolution being too low”. 🤦

        • plyth@feddit.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          19 days ago

          The sales rep offered a solution to that person’s problem.

          You want that person to be right which they perceive as you want to dominate them.

          So they try to resist you while they are highly motivated to follow the instructions of the sales person.

          • d00ery@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            19 days ago

            Interesting explanation of the psychology and I don’t necessarily doubt it, But I also offered a solution. The solution I’ve offered fixes the problem, the salesman’s solution sounds like it solves the problem but does not.

  • ben@lemmy.zip
    link
    fedilink
    English
    arrow-up
    3
    ·
    21 days ago

    Okay but, installing an apk is not the kind of thing a scammer does. They’ll just install some standard off the shelf remote access software from the play store

    This very much feels like they just needed to come up with a new justification for this process and opted for scammers for some reason. Even though they’re completely disconnected

    • cecilkorik@piefed.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 days ago

      This very much feels like they just needed to come up with a new justification for this process

      It feels that way because that’s exactly what happened.

  • Ganbat@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    20 days ago

    In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee.

    Fuck you sideways, Google.

      • MrScottyTay@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        20 days ago

        They want developers to share their IDs to have their apps on the play store. The limited groups is so hobbyist developers can still share apps without having to jump through those hoops and so the users don’t need to go and enable sideloading, with the caveat that there’s a call on how many users you can send it to it looks like.

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          20 days ago

          That’s already the case. The new thing is that they want developers to share their ID to have their apps be installable on Android in the first place, even if they don’t use the Play Store.

            • dev_null@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              19 days ago

              From what angle is it easy to do?

              • Enable developer mode (using a hidden process where you have to know where to find it)
              • Go through a scary form
              • Restart the device
              • Wait 24 hours?!
              • Go to the settings again
              • Do some more scary confirmations
              • Check another scary checkbox
              • And then… confirm again every single time you install an app

              And you are telling me it’s easy to do? I can go publish a diet tracking app and Aunt Flo will happily go through this and I won’t lose customers?

              • MrScottyTay@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                0
                ·
                19 days ago

                I feel like if someone knows what an .apk is and where to download them, they’ll also know how to search for how to install them

                • dev_null@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  18 days ago

                  Yeah, and currently you don’t need to know what an apk is to install them.

    • MasterNerd@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      19 days ago

      Bruh what? You’re gonna be waiting a long time for that. Better to use one of the pre-existing alternatives than wait for an OS that probably won’t ever exist, and probably won’t support your hardware if it ever does.

  • kbal@fedia.io
    link
    fedilink
    arrow-up
    2
    ·
    20 days ago

    Just think of all the other things that could benefit from a “protective waiting period” to enhance your safety.

    Turning off location tracking, using a web browser other than Chrome, using a mail server other than Gmail, visiting duckduckgo.com — if Google really cared about your privacy and security they’d add a 24-hour delay to all these dangerous activities.

  • tidderuuf@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    21 days ago

    I hate how much more difficult my work or life has to be because some people shouldn’t have a smartphone.

  • Kissaki@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    20 days ago

    Why is it called developer mode if it’s supposedly an advanced flow? That has a bad implication.

  • shrek_is_love@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    20 days ago

    They think this will take some of the heat off of them. Hopefully no one actually thinks this is a reasonable compromise. If I want to help an elderly family member install something on their phone during Thanksgiving dinner or a family reunion, I’m not gonna want to wait a day. Uncle Paul’s flying back to Florida tomorrow morning!

  • Horsey@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    20 days ago

    If graphene had Liquid Glass I’d unironically switch to it. I can’t stand flat looking UI.