4 ms·
Isnt the title a bit dramatic? I remember reading you can still install apps but you just need to click a few buttons.
by bitpush 5mo ago
Isnt the title a bit dramatic? I remember reading you can still install apps but you just need to click a few buttons.
- benoau 5mo agoThis isn't referring to the efforts Google has gone to try to thwart sideloading. It is another requirement of Google's, where all developers must be registered to them and apps must be signed by them and anything that isn't will be blocked.
- jjgreen 5mo agoFrom TFA: Delve into System Settings, find Developer Options Tap the build number seven times to enable Developer Mode Dismiss scare screens about coercion Enter your PIN Restart the device Wait 24 hours Come back, dismiss more scare screens Pick "allow temporarily" (7 days) or "allow indefinitely" Confirm, again, that you understand "the risks" Nine steps. A mandatory 24-hour cooling-off period. For installing software on a device you own.
- 0x3f 5mo agoSounds a bit like trying to transfer my own money to myself at the bank. I.e. it seems designed to prevent old people getting scammed.
- hungryhobbit 5mo agoThat's exactly what this is: Google is trying to prevent tech illiterate users from installing malware. (Or at least, that's their take on this. You can choose to read between the lines, or not, as to whether they have other motivations also.)
- raverbashing 5mo agoOf course they have other motivations But for 1 person wanting to run their own software there are hundreds of people with the potential to install malware/crapware/etc
- lucb1e 5mo agoHad to read that sentence twice. You really think that there's more people getting scammed via "please tap the build number seven times and then go to extra settings and enable untrusted installs and then go to this website that I will dictate the URL of and you should ignore that install warning" etc etc etc. to install an apk to run software that can barely access more than a simple webpage could, than there are people (like HN'ers) who install apk files from github and f-droid?! (Also note that "crapware" describes basically every app you find in google's store. I try on occasion, when nobody made an open source this-or-that, and it's such a minefield. If that's the thing you're trying to avoid, I don't know how you could possibly feel positive about a requirement to only use the Play Store for the tech-illiterate)
- raverbashing 5mo ago> You really think that there's more people getting scammed via "please tap the build number seven times Yes, because this whole procedure is new > Also note that "crapware" describes basically every app you find in google's store Go back to emacs then I guess
- lucb1e 5mo agoInstalling apks has required going into settings for years now. 'Scary' steps aren't new > Go back to emacs then I guess way to have a conversation
- 0x3f 5mo ago> more people getting scammed via "please tap the build number seven times and then go to extra settings and enable untrusted installs and then go to this website that I will dictate the URL of and you should ignore that install warning" etc etc etc. I don't really understand. You seem to be against the 'annoyance' of the protections, but that annoyance is precisely why the scammed count is lower, no? I certainly believe _more generally_ that the market for scam victims is much bigger than the market for sideloaders, for example.
- mulmen 5mo agoDefine malware.
- kube-system 5mo agoThe scams this directly targets are well known and common. Someone gets a phishing message, they have someone install some sort of malware on the device, then their bank accounts are drained into some offshore account never to be seen again. That's why there's a requirement for restarting the phone and waiting 24 hours. The restart ends the connection for any remote-access software or phone call that might be driving the operation -- and the 24 hour wait period breaks the "urgency" part of the scam that prevents other people who know better from stopping the vicim from continuing.
- mulmen 5mo agoMalware is whatever Google says it is.
- selectively 5mo agoYes! That is because banking malware is specifically what is being targeted here: https://android-developers.googleblog.com/2026/03/android-developer-verification.html https://android-developers.googleblog.com/2026/03/android-de...
- nine_k 5mo agoI see zero trouble as long as it requires no additional identification, no additional payment, and no mandatory time limit for the sideloaded apps. That is, fine by me. I can wait for 24 hours once in a few years when I acquire a new mobile phone.
- moralestapia 5mo agoWhy would you do all that to install an app in a device that you own? It's bollocks.
- nine_k 5mo agoBecause grandmas all over the world are getting swindled by scam apps. Look, I can't locally install a web extension I wrote on an open-source Firefox browser, because security. I have to install a Developer Edition, or get the extension reviewed and signed by Mozilla, for the very same reasons of thwarting scammers. Is this stifling, or is it making my browser not mine? Is anybody making a big deal out of that? The world we inhabit is not always friendly. It has a ton of determined and sophisticated bad actors, and a lot of people with less technical savvy than you and me. We have to deal with that, instead of being cantankerous.
- rcxdude 5mo agoIt's not obvious to me that this will help much with scamming. Especially when it affects safer app repositories like F-droid more than the cesspit that is the official Play store.
- gruez 5mo ago>It's not obvious to me that this will help much with scamming. Because as a reader to this forum, you're probably more tech savvy that the average person. Moreover this type of scam seems to be more common in Asia than the West, see: https://cdn.economistdatateam.com/videos/cyber-scams/fake-vietnamese-app_700.webm https://cdn.economistdatateam.com/videos/cyber-scams/fake-vi... https://www.economist.com/interactive/asia/2026/04/10/scam-inc-has-a-new-weapon https://www.economist.com/interactive/asia/2026/04/10/scam-i... They convince users to download a "government app", grant it accessibility permissions, then use that to take over their phone and drain their bank accounts. >Especially when it affects safer app repositories like F-droid more than the cesspit that is the official Play store. Where do you draw the line? If you whitelist f-droid, do you have to whitelist third party f-droid repos too? What about other app "stores" like obtanium? Moreover f-droid being less of a "cesspool" is likely because its reach is smaller, not because it has better moderation.
- moralestapia 5mo ago>Wait 24 hours Somehow bank vaults and heroin storage boxes don’t take this long.
- kube-system 5mo agoThe 24 hour wait period is so the scammer can't use the element of urgency to keep the victim on the phone where they don't have the opportunity to speak with trusted friends/family who would stop the scam.
- sowbug 5mo agoSee also https://en.wikipedia.org/wiki/Cooling-off_period_(consumer_rights) https://en.wikipedia.org/wiki/Cooling-off_period_(consumer_r.... It's an old solution to an old problem: give the potential victim a chance to think clearly while the damage can still be undone.
- tromp 5mo agoYou left out the crucial bit: Worse: this flow runs entirely through Google Play Services, not the Android OS. Google can change it, tighten it, or kill it at any time, with no OS update required and no consent needed. And as of today, it hasn't shipped in any beta, preview, or canary build. It exists only as a blog post and some mockups.
- Markoff 5mo agothat seems better, not worse, that they don't implement this on OS level, so no gapps users are not affected at all
- wstrange 5mo agoTo be fair, that's a one time process. You do not need to do that for every app you want to sideload. The malware issue that the flow is designed to mitigate is a very real problem. Perhaps there is a better way, but it's not immediately clear what that is.
- jmcomets 5mo agoFrom NewPipe : https://github.com/woheller69/FreeDroidWarn?tab=readme-ov-file#solutions https://github.com/woheller69/FreeDroidWarn?tab=readme-ov-fi... I wouldn't consider this "a few buttons", it's enough to turn off the less savvy users
- 627467 5mo agoLess savy and unmotivated users.. maybe? Whats the main use cases for newpipe? Let me guess: get premium features for free (no ads, downloads etc). Do you think people wont click 9 buttons and wait 24hs for this? Its like people forgot how pirated windows/sw used to run on millions (billions) on devices in the past until ads (and some convenience from non-so-cheap-anymore subscriptions) became the norm
- lynndotpy 5mo agoIn addition to what others have said, it means some developers who were building for Android are going to stop. You can't install an app when someone is obstructed from building it in the first place. > every Android app developer must register centrally with Google before their software can be installed on any device. Not just Play Store apps: all apps. > Registration requires: > Paying a fee to Google > Agreeing to Google's Terms and Conditions > Surrendering your government-issued identification > Providing evidence of your private signing key > Listing all current and all future application identifiers Google is not an entity you can can trust with this.