• Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    19
    ·
    14 hours ago

    Who are these smooth-talking scammers that can guide a regular-ass user to jump through hoops in settings to install a malicious app?

    Maybe I should ask them how they do it, because I cannot convince my family to download and use Signal. You know, the legit app from the official app store.

    • goldman60@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      10 hours ago

      People who can’t operate a computer will somehow become gods at following instructions if someone calls “from Microsoft”

      • d00ery@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        9 hours ago

        Yes exactly this. I try and explain a computer thing to someone and get ignored. That same person talks to some sales rep in the electronics store and comes away “ohh they said I need to buy super expensive antivirus, that’ll solve my issue with my screen resolution being too low”. 🤦

        • plyth@feddit.org
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          9 hours ago

          The sales rep offered a solution to that person’s problem.

          You want that person to be right which they perceive as you want to dominate them.

          So they try to resist you while they are highly motivated to follow the instructions of the sales person.

          • d00ery@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            7 hours ago

            Interesting explanation of the psychology and I don’t necessarily doubt it, But I also offered a solution. The solution I’ve offered fixes the problem, the salesman’s solution sounds like it solves the problem but does not.

            • plyth@feddit.org
              link
              fedilink
              English
              arrow-up
              2
              ·
              6 hours ago

              A solution without demand is worthless. At first the demand has to be created. Some people value understanding and are thankful but that’s a small minority.

  • kbal@fedia.io
    link
    fedilink
    arrow-up
    46
    ·
    1 day ago

    Just think of all the other things that could benefit from a “protective waiting period” to enhance your safety.

    Turning off location tracking, using a web browser other than Chrome, using a mail server other than Gmail, visiting duckduckgo.com — if Google really cared about your privacy and security they’d add a 24-hour delay to all these dangerous activities.

  • smeg@infosec.pub
    link
    fedilink
    English
    arrow-up
    76
    ·
    1 day ago
    • enable developer options
    • confirm that you are not tricked
    • restart phone and re-authenticate
    • wait one day
    • confirm with biometrics that you know what you are doing
    • decide if you only want unrestricted installs for 1 week or forever
    • confirm that you accept the risks
    • enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
    • wonderingwanderer@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      Combined with the news that they’re going to start requiring developer age verification even in the alternate app repositories…

    • flying_sheep@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 hours ago

      The biometrics part makes no sense, you can disable biometrics. You mean that you have to do a security confirmation however you’ve set it up.

    • FauxLiving@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      17
      ·
      1 day ago

      I can understand this workflow being created to protect the legions of people who are tricked into installing spyware.

      It doesn’t remotely affect me because I use GrapheneOS and if this is an issue for you then you’re probably someone who should look at installing GOS or Lineage.

      I don’t think Google should be able to do this and it is likely part of a longer-term strategy to strangle any competition. At the same time, I can understand how this change will save a lot of grandparents from clicking a link in a text from their ‘grandchildren’ and installing spyware that’ll steal all of their bank information.

      • fallaciousBasis@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        14 hours ago

        I mean… This is kind of why I never let people use my phone.

        I have installations from various sources enabled… Like my browser, because I know what I’m doing. But I wouldn’t trust anyone as the process is currently effortless…

        If someone is trying to install spyware on you (like a partner or parent.) this might offer some notification and prevention.

        I don’t really see the big deal. You do it once, enable it forever, and wipe up those tears.

        I think a better way would just to have maybe like a biometric/pin confirmation upon installation. Simple. Clean.

        • FauxLiving@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          The delay is almost assuredly to prevent live scamming. Like a grandparent picking up a random call or text and being tricked into thinking they’re a family member/bank worker/etc.

          I’ll admit it’s annoying, and could be used by Google later to do more annoying shit.

          Taking their explanations in good faith and looking at it from an customer security point of view, I can see this cutting back on some common scam types. This is kind of like how, when you go to rustdesk.com there’s a giant ‘YOU’RE PROBABLY GETTING SCAMMED’ banner across the top of the page:

          These little steps can seems pointless or annoying to us, as most of us are probably in the upper range of tech skills, but consider the average user and it starts to make a lot more sense.

        • reksas@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 hours ago

          they want to suppress the developers, not users. By making it so bothersome, so many people will just stop using sources from outside google play. First they do this and at some later time they will add more hoops to it. If they manage to strangle any developers that make stuff, people will have nowhere to turn yet they cant complain either because google will have undeniable monopoly.

      • AHemlocksLie@lemmy.zip
        link
        fedilink
        English
        arrow-up
        16
        ·
        1 day ago

        GrapheneOS is built on AOSP, which is where the change is being made. Graphene and other custom ROMs will need to maintain a fork that cuts out the feature if they want to avoid. Google is also starting to close off Android to make that more difficult, so it’ll become a genuine project to maintain the fork well.

  • MountainMan@lemmy.zip
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    1 day ago

    They will just redefine what 24h means!

    Don’t think for a second that these companies are working in good faith, and would change their evil plans due to some pushback from the rabble. They will just find ways to circumvent things. They have everyone by the nads, there are no competitors.

  • Ganbat@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    62
    ·
    2 days ago

    In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee.

    Fuck you sideways, Google.

      • MrScottyTay@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        8
        ·
        1 day ago

        They want developers to share their IDs to have their apps on the play store. The limited groups is so hobbyist developers can still share apps without having to jump through those hoops and so the users don’t need to go and enable sideloading, with the caveat that there’s a call on how many users you can send it to it looks like.

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          8
          ·
          1 day ago

          That’s already the case. The new thing is that they want developers to share their ID to have their apps be installable on Android in the first place, even if they don’t use the Play Store.

          • Arcadeep@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            1 day ago

            I wonder if this is a direct result of apps like ICE watch or ones that track billionaire planes and stuff

            • iSeth@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 hours ago

              Google did just say they’re “…leaning more into military contracts…” or something…

            • dev_null@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 hour ago

              From what angle is it easy to do?

              • Enable developer mode (using a hidden process where you have to know where to find it)
              • Go through a scary form
              • Restart the device
              • Wait 24 hours?!
              • Go to the settings again
              • Do some more scary confirmations
              • Check another scary checkbox
              • And then… confirm again every single time you install an app

              And you are telling me it’s easy to do? I can go publish a diet tracking app and Aunt Flo will happily go through this and I won’t lose customers?

  • ben@lemmy.zip
    link
    fedilink
    English
    arrow-up
    129
    ·
    2 days ago

    Okay but, installing an apk is not the kind of thing a scammer does. They’ll just install some standard off the shelf remote access software from the play store

    This very much feels like they just needed to come up with a new justification for this process and opted for scammers for some reason. Even though they’re completely disconnected

    • cecilkorik@piefed.ca
      link
      fedilink
      English
      arrow-up
      71
      ·
      2 days ago

      This very much feels like they just needed to come up with a new justification for this process

      It feels that way because that’s exactly what happened.

      • ben@lemmy.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 day ago

        I was hoping for at least something slightly believable, someone let Gemini write the justification I guess

  • Kissaki@feddit.org
    link
    fedilink
    English
    arrow-up
    7
    ·
    1 day ago

    Why is it called developer mode if it’s supposedly an advanced flow? That has a bad implication.

  • shrek_is_love@lemmy.ml
    link
    fedilink
    English
    arrow-up
    41
    ·
    2 days ago

    They think this will take some of the heat off of them. Hopefully no one actually thinks this is a reasonable compromise. If I want to help an elderly family member install something on their phone during Thanksgiving dinner or a family reunion, I’m not gonna want to wait a day. Uncle Paul’s flying back to Florida tomorrow morning!

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    12
    ·
    1 day ago

    This would not have affected me since I use Lineage OS without Google Play Services, but I am now more seriously than ever looking into using a Linux phone like Postmarket OS.

    • fluxx@mander.xyz
      link
      fedilink
      English
      arrow-up
      14
      ·
      1 day ago

      It would affect a lot of users, then it will indirectly affect you too, as a lot of devs won’t be as interested in maintaining their apps for so few users. But I hope it will at least give a bit of a push to developing postmarket os. I personally am sure going to get a second hand phone to install postmarketos too and hope I can contribute at least a little bit. I am prepared to suffer, at least a little bit for the right cause.

    • Squizzy@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago
      1. Camera
      2. Phone projection for cars
      3. Contactless pay/ wallet/pay alternative

      Give me a device that can do these and I am in for ditching android. I only use browsers or off store apps that have linux support mainly anymore anyway.

      • fluxx@mander.xyz
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        At least the last one won’t happen, as banks would have to be on board. And banks are not on your side with this one.

        • Squizzy@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          To be honest this one is in hand, curve has an alternative product and a lot of banks across EU have nativr NFC. My country does not have those banks though. I hope revolut bring it in.

          I do want something that takes me tickets for shows and flights and membership cards too though

          • fluxx@mander.xyz
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 day ago

            Yeah, im in a similar situation. Curve doesn’t work in my country and banks don’t have their own solution. And google pay won’t work on my grapheneos pixel.

            • Squizzy@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              17 hours ago

              I got a pixel for graphene but had to go back for android auto and payments. The camera was lacking compared to pixelOS but that was fixable.

              Sucks to be with google more than ever

      • Ada@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        57
        arrow-down
        2
        ·
        2 days ago

        At this stage, I’m thinking one of the Motorola phones that will run Graphene out of the box.

      • somethingDotExe@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 days ago

        Fairphone with /e/os or Jolla phone with sailfishos (waiting for the reviews of their new preordered flagship phone coming out this fall.)

        • Lost_My_Mind@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          10
          ·
          2 days ago

          Well, that runs into a different problem with the same results.

          Sure, GOOGLE can’t hinder you from installing apps, but the fact that nobody has heard of these OS’s before means your selection of available apps is what hinders your ability to install apps.

          • illi@piefed.social
            link
            fedilink
            English
            arrow-up
            5
            ·
            1 day ago

            /e/ OS is just a degoogled Android (similar to Graphene, but not so security oriented). You can install the same apps - though some might not work properly.

            Sailfish OS is Linux, but if I understand it correctly they have a compatibility layer enabling you to seamlessly install Android apps on it.

          • somethingDotExe@lemmy.world
            link
            fedilink
            English
            arrow-up
            10
            arrow-down
            1
            ·
            2 days ago

            “Nobody has Heard of these os’” - wtf you talk about? They are gaining popularity here in EU as well as in Turkey. It’s getting popular to de-google/de-americanize. People are hating on the monopoly iOS and Android has on the industry. Better to do something than being a sheep about it, and just let thos mofos suck the data out of your life forever?

          • Arcadeep@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            1 day ago

            e/os and Sailfish are pretty popular alternative OSs (OSes? OSii?) and e/os is an android fork, with Sailfish having an android compatibility layer, so they work with standard Android apps.

            Source: I use e/os.

            Why are you in here arguing losing points with no reason or even knowledge about them?

          • Zak@lemmy.world
            link
            fedilink
            English
            arrow-up
            7
            ·
            2 days ago

            /e/os is Android without Google proprietary stuff. It runs most Android apps.

            • Tetsuo@jlai.lu
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 day ago

              While technically correct, it runs apps, it’s misleading because it won’t run the majority of apps from the playstore.

              Google holds people captive with the playstore and the very sneaky google play services.

              Only the most hardcore tinkerers and privacy oriented would run a pure AOSP phone.

              • iSeth@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                4 hours ago

                I love my LineageOS (AOSP) phone without micro-g. So a few evil apps don’t work without Google’s spyware… Win-win.

              • Zak@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                23 hours ago

                I’ve tried it, and only ran into a couple apps that wouldn’t work with MicroG. I won’t pretend it’s painless, but it’s workable for someone with sufficient motivation.

              • Teknikal@anarchist.nexus
                link
                fedilink
                English
                arrow-up
                2
                ·
                1 day ago

                These devices have replaced play services with things like micro g, so yes they will run pretty much any android app even Google ones would work but that would be defeating the purpose.

            • halcyoncmdr@piefed.social
              link
              fedilink
              English
              arrow-up
              6
              arrow-down
              2
              ·
              2 days ago

              That exact issue killed Blackberry, the largest smartphone maker at the time. Even after they built a compatibility layer to run Android apps.

              You think anywhere near enough people are going to go out of their way to try something that doesn’t have marketshare already to maintain an entire alternative hardware and software ecosystem? Where can I get wherever awesome shit you’re smoking?

              • MrScottyTay@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                1 day ago

                When i was a kid, blackberries were more common than android. At least in my area it was the “in” thing to be on BBM