6 ms·
Web downloads work fine on Android
by dangero 5y ago
Web downloads work fine on Android
- realusername 5y agoNot really, you have to enable some scary settings and they are no update or auto-update mechanism for web downloads on Android yet. It's technically "there" but not good enough to be a reliable form of distribution.
- yorwba 5y agoIf the app knows its own download address, it can just periodically check for a new version, download it, and prompt the user to install it. I have multiple apps installed that use this update mechanism, there's nothing unreliable about it. Yes, there are warnings, but what is the alternative? You download an app once, it installs without warning and keeps updating in the background? That'd make it way too easy for malware authors.
- realusername 5y agoMalware is supposed to be stopped by the sandbox & Play protect mechanisms. If the sandbox isn't good enough to be trusted for that, I don't think I have a good answer except maybe just not downloading any app at all including on the Play Store. How I see it personally is you download the apk, tap "install", then the same permission prompt as the Play Store opens. The app is updated later the exact same way as the Play Store update (either automatically by pulling from an url or manually, depending of what the users have set as a rule for the Play Store)
- echelon 5y agoGoogle scares you after you download them. And you have to enable the setting. This should be as seamless as using web apps, and permissions dialogues should come up when the app attempts to use certain device features. (No different than App Store downloads today.) All of this to say that web-downloaded native apps are not first class on Android. They should be.
- int_19h 5y agoPermission dialogs are very ineffective in desktop OSes, with users effectively being trained to just click through them to "get things done". Is there any research showing that they fare better on mobile?
- echelon 5y agoIf web-based installs were the norm, there would be better security hardening efforts made. Today Apple and Google don't have to care about it. If there reputation was at stake, they would care a great deal. I'm also of the belief that we don't have to be a nanny state. We trust people to pour gasoline, drive death chariots at 70 miles per hour, open lines of credit as teenagers, buy and shoot guns, etc. Why all the ceremony here? I think it serves the owners of the platform more than us.
- natch 5y agoSo they should care about their reputation, but they should also let their platform be known as a place where they allow malware to flourish?
- hulitu 5y ago> If web-based installs were the norm, there would be better security hardening efforts made. Today Apple and Google don't have to care about it. If there reputation was at stake, they would care a great deal. Well, web base installs are the norm. That's how malware and ransomware spreads. The problem with security is that is usually anti features. That't why webbrowsers use the path of least resistance and declare that they are secure, they have containers and isolation etc. And Google with project Zero is playing the good guy. It is all security theater. Security is expensive and no one wants to invest in it because it does not have a clear ROI. > I'm also of the belief that we don't have to be a nanny state. We trust people to pour gasoline, drive death chariots at 70 miles per hour, open lines of credit as teenagers, buy and shoot guns, etc. We do not trust people to buy and shoot guns. > Why all the ceremony here? I think it serves the owners of the platform more than us. Of course it serves only them. Security in android stops when you give apps access to SD card or camera or microfone or phone or contacts. And the fact that Google apps have all this access by default says a lot about how much google is interested in security.