Blocking of unverified apps on Android starts in Brazil and other three countries

27 points by rodrigo 9 hours ago on tildes | 38 comments

Eric_the_Cerise | 5 hours ago

Reading the comments in here ... IDK ... perhaps we've reached that stage where a large percentage--perhaps even a majority--of people have effectively forgotten what it means to own stuff.

I mean, when did we get to the point that people seriously think an advertising company deserves any say whatsoever in what we do with our own phones?

This company's entire reason for existing is to sell advertising space to companies, and to credibly convince those companies that their ads will be seen by a lot of people who are predisposed to spend money because of those ads.

Where does "protecting phone owners from themselves" enter into that equation?

wervenyt | 5 hours ago

this is how we will own nothing and be happy (about that, at least): being incapable of wielding the benefits of ownership while the responsibility of it gets loaded onto us continuously

I wonder if people will ever realize how much they're being manipulated

Asinine | 4 hours ago

I've recently joined another company (due to a monopolistic takeover an acquisition) and I can no longer use the Outlook app with the new policy standards, because my hardened GrapheneOS is flagged as rooted, courtesy of the Microsoft Intune app. Ironically, I can open Outlook in my phone's browser without issues.
I know the unverified bs for Google is coming, but as a GenXer who maybe is just old and yelling at kids to get off my lawn and turn their music down, I also figured how to not get wrecked by downloading questionable items on Napster, or using sketchy stuff like my first jailbroken smart phone (iPhone 3GS), or refusing to actually use programs, apps, or any technology that could actually make my life more convenient but at the sake of privacy and becoming the product being sold.

I find it amusing that as a kid, I thought integrity was standing up for your personal rights for which you should be responsible (with ongoing events (edited for typo) [and themes like the Cold War, punk rock, Robin Hood mentality, etc.]), and now I see in hindsight that it was. But I guess society in general thought we won that battle somehow, and now we can relax and let someone else take over.

skybrian | 4 hours ago

There are plenty of products that are regulated to protect people from themselves. Food and drugs are regulated. Cars are regulated. Don’t let the libertarians fool you, this is totally normal.

"Libertarians"? I stand with the others - I'm insulted by this comment. This is not a libertarian stance. This is very clearly a way for Google to give themselves just a bit more control over the platform under the guise of safety, which, if you haven't noticed, has very much been their M.O. for the past few decades. And they've been very successful. Have you seen any successful open source RCS clients out there? Remind me how many web rendering engines there are that aren't Chromium based again. Google, just like any other megacorporation out there, is going to try to control everything - it's just trying to do it slowly so people don't object to it so much.

wervenyt | 4 hours ago

Equivocating this with governmental regulation is ridiculous. Insultingly so.

Eric_the_Cerise | 4 hours ago

... just as Ford famously forced all automakers to install seatbelts.

Hey, apologies, that was snarky.

A proper response is to point out that an advertising company further locking down its "open" product (after I bought it, but let's not even open that can of worms) to further consolidate its stealth monopoly is the polar opposite of "regulation". Given the motivation, I believe I could make a strong argument that this is actually "late-stage Libertarianism".

Governments regulate products for consumer protection. Ad companies do not.

This is a giant corporation that exists in a duopoly with massive barriers to entry restricting consumer freedom to benefit their bottom line. Don't let the libertarians fool you, this should be regulated.

sunset | 3 hours ago

I install cameras and security systems for a living. The main camera manufacturers are all Chinese (Dahua and HikVision being the biggest where I live)

A few years back, due to Trump nonsense, the app for HikVision cameras (HikConnect) got removed from the Play Store. It's back now, I guess Trump got his bribe, but for a long time I had to download an APK and side-load it for customers, just because the US had yet another stupid spat with China. It was annoying for the customers, but at least it was an option.

Now if it happens again, I'd need to convince each customer to do nonsense like enabling developer options, waiting 24 hours (?!) and so on.

I do not understand why as a European, I need to rely on a fascist-loving US company to approve what I install.

It's really depressing how many people I see, even here where people are intelligent, supporting this awful garbage.

sunset | 3 hours ago

Here, I made a meme since laughter is often a better way to change minds than arguments

https://i.imgur.com/T74inwb.png

Weldawadyathink | 2 hours ago

Just to clarify, you would have only had to do this if google also revoked their developer account. This process isn’t for everything side loaded. It is only for apks that aren’t signed by an android developer account. I am not familiar enough to know what that situation was at the time. And even if their dev account was revoked, you can just install it with adb from a computer and bypass this entire process.

sunset | 2 hours ago

Hikvision was placed on the US Entity List, which forced Google to remove their app from the play store. I have no idea why anyone would think Google would do that, but somehow not revoke the dev account too.

Why do people keep making excuses for this fascist nonsense.

Seriously, I am done discussing this. People like you fill me with HATE. I don't want to hate you, so I'll just ignore you and end this conversation.

Asinine | an hour ago

Well, presuming you've left the conversation, I'll just reply to the rest here...
China has known data collection tendrils throughout their electronics' software, and that doesn't bode well for most countries who'd rather not just share all their inhabitants' information to them.

Things like security (cameras and systems) are especially tense to keep intact when Google wants in on the still-legal-portion of the data. So as I'm backing up Weldawadyathink, I suspect that's their reason for their response.

Yeah it's a bit funny to be installing fascist surveillance systems and complain about a fascist (really just capitalist) phone system.

slashtab | 5 hours ago

It is both good and bad but mostly bad. It takes away more of Android user's freedom. scammers will find another way, there is already "install from this source" in setting which shows your intention.

The only one gaining most from this is Google. there is a pattern to what google is doing.

If you're using a device, you should know what you're getting into, at least the basics. If not, you shouldn't use that device. dumbing down of tech, instead of educating population is suffocating.

skybrian | 4 hours ago

On the contrary, Android phones are primarily for the masses, not us techies. If you’re more technical then there’s plenty of hardware you can buy to hack on. if you want to root your phone, make sure you buy one where the bootloader can be unlocked. (Such as any Pixel phone that you buy direct from Google.)

I don't want to "hack on" on the computer I own - or rather whether I want it is besides the point. What I want is to have the final say in what apps I do and don't install on it and not outsource that to some adversarial monopolist behind the ocean. Ridiculous.

Tiraon | 5 hours ago

I view this as same way as forced updates and security measures. It is theoretically good if done with benevolent intent or controllable by the theoretical owner of the device.

The updates are generally ads, telemetry or ways to restrict blocking ads or telemetry, security is always from you and restricting installing unverified apps is to control what is run.

skybrian | 5 hours ago

There’s also plenty being done to protect people from malware, whether it’s bad websites or bad apps. But when it doesn’t affect you directly, maybe it’s less noticeable.

There's not. Or rather: define malware.
I would include spyware and addiction-inducing gambling leeches in the list of unwanted software. After all, their intent is malevolent. Guess what makes up 99.99% of the play store.

[OP] rodrigo | 9 hours ago

I am in the minority that thinks this is a good idea and execution, I guess.

Pavouk106 | 9 hours ago

Care to elaborate why ypu think it's a good idea?

I mean we can install whatever we want on our PCs, why shouldn't we be able to do so on our phones?

steezyaspie | 7 hours ago

As far as I can tell, you are still able to install whatever you want. You’ll need to jump through some extra hoops to enable it, but it’s straightforward enough if you’re remotely technically savvy.

stu2b50 | 7 hours ago

It works similarly on PCs, on macOS and windows. Applications need to be signed, or both OSes will show a warning on first launch that it's an unsigned app and you should take caution. You can override it, just like you will be able to on Android.

AugustusFerdinand | 7 hours ago

I wouldn't call going deep into settings and performing a non-obvious series of actions (tapping an About section seven times), restarting a device, reauthenticating, waiting a day, reauthenticating again, and being asked if you want to do this again in a week as "works similarly".

slashtab | 5 hours ago

It certainly is irritating for those who know what they're doing but there is large number of Android users who don't, they install some third party apk by intention or accidentally and get scammed. It will certainly hinder that.

On the other side I can't deny Google is trying to grip it(Android) harder, allowing users to be more dependent on them while there is smokescreen of it being OS. the freedom on Android and how Google treating it is certainly raising red flags.

These corporations often do terrible things for customer in the name of security.

I'm just surprised by the complaints about all the taps because I thought tech savvy users were used to tapping that button seven times to enable developer options anyway.

Weldawadyathink | 8 hours ago

I also think it’s a good idea and reasonable execution. The one modification I would make is have some way to bypass the 24 hour wait when setting up the phone. If you know already that you will be developing with a phone, or installing unregistered apps, you should be able to set it up from scratch to do so. But besides that exception, I think it is a good policy.

moocow1452 | 7 hours ago

ADB is still operational if you want to sideload apps that way without the reboot. But I agree a 24 hour hold is excessive.

Sheep | 7 hours ago

I also think it's a good idea the way it's implemented. Some folks vastly underestimate how much scammers prey on our sense of urgency. It's like their number one trick and what gets even tech literate people. A 24 hour waiting period that gives you proper time to think before you can install unsigned apps could easily be what lets, say, an elderly person call their child to ask if this is normal. It's a direct counter to scammers.

Yes, in a perfect world we wouldn't need this, but we live in a world where there is not enough technical literacy and large segments of people are very vulnerable to being scammed. If we are forcing everyone to have a digital life, then we should also have a responsibility to protect them from organized crime.

Of course, I do also think that stuff like this should be accompanied by more education efforts but, on the other hand, I am already bombarded by every institution I interact with with warnings about scams and phishing, so I don't know if there's much more that can be done. People keep getting scammed en masse despite ample warning and losing money/personal info. Sitting around doing nothing doesn't seem good. So I think this is a decent compromise.

My only concern, which I think is very valid, is that Google could use this as a stepping stone to later fully block unsigned apps unless you use adb, and that's the point where I think we're crossing the line. Remains to be seen if that's the direction they're headed toward.

Tiraon | 6 hours ago

Remains to be seen if that's the direction they're headed toward.

That is absolutely the direction they are headed towards. What remains to be seen is when and if it will be the step directly after this or there will be an intermediary one.

Agreed. Google has been tightening their control over the Android ecosystem over the last decade or so because they'd love Apple level control (and profits) that being the only App Store in town comes with.

It’s funny that Apple is being dragged kicking and screaming to open up their platform while Google is trying to lock it down.

skybrian | 4 hours ago

People say that but Android has been around for 18 years now and there are still plenty of manufacturers making them. If Google didn’t want other manufacturers making Android phones, you’d think they’d have done something about it by now?

They also seem suspiciously slow at acting against alternative app stores.

And why does Google only sell phones with an unlocked bootloader? They didn’t have to do that.

Maybe don’t believe everything you read online about what a company’s motives might be.

The dismissive and snarky attitude isn’t needed.

I wasn’t talking about hardware. I was talking about software ecosystem since that’s what this whole change is about, not the devices themselves. Google wants others to make phones because they get paid a percentage, just like Microsoft.

They want to control the software ecosystem because it gives them ongoing revenue after someone buys the phone.

stu2b50 | 3 hours ago

Google already has Apple level control. Whatever amount of people side-load apps regularly, it's a rounding error. Google absolutely controls the app ecosystem outside of China, and they absolutely enjoy Apple levels of profit over it. There's no real threat to that, either. Epic tried - they really tried - and it did not work. The only thing they miss from Apple, really, is that they are banned in China whereas Apple gets a lot of sweet sweet IAP money from the 2nd largest economy.

Google itself is the biggest source of spyware. Will this help against that?

I mean, depending on what metric you're quantifying with, I would argue China is a bigger source of spyware than Google...

goose | 2 hours ago

I agree, I think it's a reasonably good idea, and reasonably good execution. Is there a better solution, and execution? Probably, but I can't think of one, without spending a significant amount of time musing over it.

I own some firearms, because I (used to) hunt, and also enjoyed shooting for sport. That includes an AR-style rifle I bought to hunt boar that were killing the chickens and baby goats on a farm that an old family friend lives on/runs. In same train of thought that if a national ban on AR style rifles were passed in the name of "gun safety", I'd be willing to give mine up for the greater good, I can accept this in the same way for the sake of "user safety".

The solution certainly isn't training our aging generation(s) to learn what pop ups are real and what aren't -- I've been trying to do that for 25+ years with my own parents, with little to no success. And while I'm happy to field my mom's phone calls and forwarded emails asking if something is real or not, I'm not 100% available at her times of need. Just last week she received a scam call from someone trying to obtain an SMS OTP from her that I stopped in real time, because I happened to stop by her house to pick my kids up.

I'm a pretty tech-capable person, I use a Pixel phone, and regularly use an unsigned app (Revanced). This is (or will be, once it hits the US market) a minor/one time inconvenience for me. I get the arguments about "stepping stones" and the concern about this eventually leading to no unsigned apps being installable without abd, but I don't see them as having a lot of weight currently. Of course none of us really know one way or the other, but I think that there would be warning signs before it ever got to that point, such as bootloaders no longer being unlocked. But that this point, it's not like we have any less functionality, there's just a one time wait period for unsigned apps. I think that other than active app developers, the people who might be affected by this the most are most likely the people who tend to prefer things like Graphene and F-Droid over stock Android and the Play Store anyway (and would therefore probably be unaffected).