• ben@lemmy.zip
    link
    fedilink
    English
    arrow-up
    133
    ·
    12 days ago

    Okay but, installing an apk is not the kind of thing a scammer does. They’ll just install some standard off the shelf remote access software from the play store

    This very much feels like they just needed to come up with a new justification for this process and opted for scammers for some reason. Even though they’re completely disconnected

    • cecilkorik@piefed.ca
      link
      fedilink
      English
      arrow-up
      73
      ·
      12 days ago

      This very much feels like they just needed to come up with a new justification for this process

      It feels that way because that’s exactly what happened.

      • ben@lemmy.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        12 days ago

        I was hoping for at least something slightly believable, someone let Gemini write the justification I guess

  • smeg@infosec.pub
    link
    fedilink
    English
    arrow-up
    87
    ·
    12 days ago
    • enable developer options
    • confirm that you are not tricked
    • restart phone and re-authenticate
    • wait one day
    • confirm with biometrics that you know what you are doing
    • decide if you only want unrestricted installs for 1 week or forever
    • confirm that you accept the risks
    • enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
    • wonderingwanderer@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      4
      ·
      11 days ago

      Combined with the news that they’re going to start requiring developer age verification even in the alternate app repositories…

    • flying_sheep@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      11 days ago

      The biometrics part makes no sense, you can disable biometrics. You mean that you have to do a security confirmation however you’ve set it up.

  • Ganbat@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    70
    ·
    12 days ago

    In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee.

    Fuck you sideways, Google.

      • MrScottyTay@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        8
        ·
        12 days ago

        They want developers to share their IDs to have their apps on the play store. The limited groups is so hobbyist developers can still share apps without having to jump through those hoops and so the users don’t need to go and enable sideloading, with the caveat that there’s a call on how many users you can send it to it looks like.

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          7
          ·
          12 days ago

          That’s already the case. The new thing is that they want developers to share their ID to have their apps be installable on Android in the first place, even if they don’t use the Play Store.

          • Arcadeep@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            12 days ago

            I wonder if this is a direct result of apps like ICE watch or ones that track billionaire planes and stuff

            • iSeth@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              11 days ago

              Google did just say they’re “…leaning more into military contracts…” or something…

            • dev_null@lemmy.ml
              link
              fedilink
              English
              arrow-up
              3
              ·
              11 days ago

              From what angle is it easy to do?

              • Enable developer mode (using a hidden process where you have to know where to find it)
              • Go through a scary form
              • Restart the device
              • Wait 24 hours?!
              • Go to the settings again
              • Do some more scary confirmations
              • Check another scary checkbox
              • And then… confirm again every single time you install an app

              And you are telling me it’s easy to do? I can go publish a diet tracking app and Aunt Flo will happily go through this and I won’t lose customers?

              • MrScottyTay@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                10 days ago

                I feel like if someone knows what an .apk is and where to download them, they’ll also know how to search for how to install them

                • dev_null@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  10 days ago

                  Yeah, and currently you don’t need to know what an apk is to install them.

  • kbal@fedia.io
    link
    fedilink
    arrow-up
    50
    ·
    12 days ago

    Just think of all the other things that could benefit from a “protective waiting period” to enhance your safety.

    Turning off location tracking, using a web browser other than Chrome, using a mail server other than Gmail, visiting duckduckgo.com — if Google really cared about your privacy and security they’d add a 24-hour delay to all these dangerous activities.

  • shrek_is_love@lemmy.ml
    link
    fedilink
    English
    arrow-up
    42
    ·
    12 days ago

    They think this will take some of the heat off of them. Hopefully no one actually thinks this is a reasonable compromise. If I want to help an elderly family member install something on their phone during Thanksgiving dinner or a family reunion, I’m not gonna want to wait a day. Uncle Paul’s flying back to Florida tomorrow morning!

  • Yaky@slrpnk.net
    link
    fedilink
    English
    arrow-up
    25
    ·
    11 days ago

    Who are these smooth-talking scammers that can guide a regular-ass user to jump through hoops in settings to install a malicious app?

    Maybe I should ask them how they do it, because I cannot convince my family to download and use Signal. You know, the legit app from the official app store.

    • goldman60@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      11 days ago

      People who can’t operate a computer will somehow become gods at following instructions if someone calls “from Microsoft”

    • sveltecider@lemmy.ca
      link
      fedilink
      English
      arrow-up
      5
      ·
      10 days ago

      Who are these smooth-talking scammers that can guide a regular-ass user to jump through hoops in settings to install a malicious app?

      you would be extremely surprised. I think lemmy users fail to realize that not everyone has an IT job and is a sys admin.

      • favoredponcho@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 days ago

        Exactly… there are a ton of older people falling for scams everyday. It’s all over the news. They manipulate people by pretending to be a love interest or a family member.

  • MountainMan@lemmy.zip
    link
    fedilink
    English
    arrow-up
    14
    ·
    12 days ago

    They will just redefine what 24h means!

    Don’t think for a second that these companies are working in good faith, and would change their evil plans due to some pushback from the rabble. They will just find ways to circumvent things. They have everyone by the nads, there are no competitors.

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    12
    ·
    12 days ago

    This would not have affected me since I use Lineage OS without Google Play Services, but I am now more seriously than ever looking into using a Linux phone like Postmarket OS.

    • fluxx@mander.xyz
      link
      fedilink
      English
      arrow-up
      14
      ·
      12 days ago

      It would affect a lot of users, then it will indirectly affect you too, as a lot of devs won’t be as interested in maintaining their apps for so few users. But I hope it will at least give a bit of a push to developing postmarket os. I personally am sure going to get a second hand phone to install postmarketos too and hope I can contribute at least a little bit. I am prepared to suffer, at least a little bit for the right cause.

    • morto@piefed.social
      link
      fedilink
      English
      arrow-up
      32
      ·
      12 days ago

      Their strategy:

      • announce they will make extreme restrictions
      • people get crazy over it and backlash
      • announce that they’re listening to people and will soften the proposed restrictions
      • people relax and accept the restrictions, while the media portray them as the good guys
    • spectrums_coherence@piefed.social
      link
      fedilink
      English
      arrow-up
      11
      ·
      12 days ago

      I feel if everything they said is true, then this is a reasonable solution. But from my many Youtube scammer video experience, like people have already mentioned, most scammers use standard remote access software, not some bespoke APK.

    • MasterNerd@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      ·
      10 days ago

      Bruh what? You’re gonna be waiting a long time for that. Better to use one of the pre-existing alternatives than wait for an OS that probably won’t ever exist, and probably won’t support your hardware if it ever does.

  • Kissaki@feddit.org
    link
    fedilink
    English
    arrow-up
    7
    ·
    12 days ago

    Why is it called developer mode if it’s supposedly an advanced flow? That has a bad implication.