The "advanced flow" will be available before verification enforcement begins later this year.
See full article...
See full article...
But how can surveillance capitalism do surveillance capitalism--if they can't surveillance capitalism?Avoid unauthorized malware on your phone while Google harvests everything you do and create to train their next shitty LLM.
Oh, yeah, sure. "Combating malware." That's the chief motivation, just like "saving the children" is the chief motivation in other contexts recently.aimed at combating malware
But they can't do that and mass layoff workers to keep pumping their stock price--if they do that.Perhaps they should concentrate on removing all the malware and scam apps from the Play Store first
To verify, devs releasing apps outside of Google Play will have to provide identification, upload a copy of their signing keys, and pay a $25 fee.
this is designed to combat the rising use of high-pressure social engineering attacks
It’s working as intended.Perhaps they should concentrate on removing all the malware and scam apps from the Play Store first
an application package that “causes harm to the user’s device or personal data that the user did not intend.
Here are the steps:
- Enable developer options by tapping the software build number in About Phone seven times
- In Settings > System, open Developer Options and scroll down to “Allow Unverified Packages.”
- Flip the toggle and tap to confirm you are not being coerced
- Enter device unlock code
- Restart your device
- Wait 24 hours
- Return to the unverified packages menu at the end of the security delay
- Scroll past additional warnings and select either “Allow temporarily” (seven days) or “Allow indefinitely.”
- Check the box confirming you understand the risks.
- You can now install unverified packages on the device by tapping the “Install anyway” option in the package manager.
It's obviously smarter than that.How does it measure the 24-hour wait time? Could I manually change the date on my phone to skip the wait, or is it smarter than that?
For the record, the Boomers don't give a shit about this. 99% of them see their phone as...Wont someone think of the boomers!?
Maybe they can use the age verification requirements to disable this crap for anyone born after 1980.
Do I get this correct. Google will demand signing keys from the devs. Meaning that google can at any point create a modified app and sign it with those keys pretending to be devs?
One time fees never stay that way.I assume this is your typical public/private key situation where Google gets the public key so they can verify the apps are signed by the dev private key. They can't sign something as the dev just verify the packages are from a particular dev who has been verified.
I don't think the $25 for verifying is that bad. It's a one time thing for an account as far as I can tell. That's pretty minimal and then you can presumably release as many apps as you want with any updates you want at any time. You don't want to make it completely free because people abuse the verified accounts and treat them as disposable. At least if you've got a minor fee there is some cost and you can do things like looking for someone verifying dozens or hundreds of accounts with the same payment info to prevent abuse.
I also think the 24 hours thing is fine. You average user is never going to go into this in the first place. If you know you want to be able to side load things just go in and do this when you first setup the phone and set it to indefinite. You've now opened it up to side load as much as you want with out any delays. You've got your behavior that you want. I don't have a problem with the assumption that your typical person suddenly wanting to sideload something is probably being scammed and a 24 hour road block is probably a good thing.
I don't think so, at least if I read this correctly: https://developer.android.com/developer-verification/guides/android-developer-consoleDo I get this correct. Google will demand signing keys from the devs. Meaning that google can at any point create a modified app and sign it with those keys pretending to be devs?
While there are certainly reasons Google might like the control verification gives it, the Android team has felt real pressure from regulators in areas with malware issues to address platform security.
No.I see that I am in the minority with this opinion, but I think the 24-hour cooldown is a really good compromise to help prevent coercion and, more likely, someone with temporary unauthorized access. And for the power user who needs to sideload apps all the time, it doesn't seem too onerous to wait 24-hours once when you get the phone and set it to indefinitely allow.
That’s on the event for not doing the trivial amount of work to get the app authorised on the App Store.Usually I have to install an app because I didn't know I needed it (because it is just some stupid wrapper for the internet but that's another whole thing)
What if it is used for some sort of event? And that event is happening TODAY.
That 24 hour wait time is gonna get some people real mad when it starts costing them $$$.
I am mostly in agreement with you on the method to allow full sideloading like that. I have stopped people mid scam as someone on the phone was walking them through installing some malicious app. There are just too many scammers out there and the average user truly has no idea how their phone works or what they are doing.I see that I am in the minority with this opinion, but I think the 24-hour cooldown is a really good compromise to help prevent coercion and, more likely, someone with temporary unauthorized access. And for the power user who needs to sideload apps all the time, it doesn't seem too onerous to wait 24-hours once when you get the phone and set it to indefinitely allow.
The $25 fee and other hurdles for developers seems like the much bigger issue here.
Wait, aren't there detailed instructions in this article?Ryan Whitwam said:The verification bypass is different and will not be revealed to users.
So the next time I'm being coerced, that verification step will save me.Ryan Whitwam said:Flip the toggle and tap to confirm you are not being coerced