back
498 comments
"sideloading" connotates something that is negative.

On systems before apple's locked-down iphone, it was just called "installing".

The PC revolution started with people just inserting their software into the comptuer and running it. You didn't have to ask the computer manufacturer or the OS vendor permission to do it.

And note that apple doesn't allow you to protect yourself. You cannot install a firewall and block arbitrary software on your phone. For example, you can not block apple telemetry.

1. I buy computer hardware, like an iPhone

2. I try to install my own software.

3. I'm prevented in installing my software on my device without "permission" from manufacturer.

4. Therefore, I do not own said hardware; manufacturer still does.

5. Therefore this is a indefinite rental instead of a sale.

6. I was defrauded with a fake sale, and Apple is defrauding IRS by not being properly taxed over millions of rental units (phones, tablets)

Sideloading sounds like sidestepping (synonyms: circumventing, avoiding, evading, bypassing, ignoring, dodging, escaping, skirting). I wonder if the term originated on iOS, where you did have to circumvent things to install programs manually.
Which is why alongside freedom came the business of anti-virus.
No it doesn't, it just connotes not using the "integrated with the OS" install path. There has been a big push to differentiate "developers" from "users" in general, and that is co-opted in a corporate environment to try to restrict the "user" layer while only parceling out the ability to really leverage the system to those deemed "blessed".
If you consider developer has the right to determine who runs their software, it is actually.

My last 10 apk installs:

- 9 apps not available in the local store - 1 app I changed some setting in the manifest

For less technical people it will also include some shady apk's for example promising free La Liga match broadcast but then scraping everything from phone.

> On systems before apple's locked-down iphone, it was just called "installing".

If the phone people could make a solid permissions system, this wouldn't be a problem. Applications should by default be able to read their own install files, and have dedicated directories for their local storage, caches, and such. They can make network connections to their home site, if the user allows it. That's all they get.

This covers most games. What else does it cover?

Indeed, and some of those bits of hardware were phones.
> You cannot install a firewall and block arbitrary software on your phone.

Why would you block iMessage from running every picture it receives as a zero click exploit ? /s

It is for your security. Ahm, and to protect the children.

Yes and called viruses, dozens of toolbars on your computer, key loggers, malware, ransomware, etc.

If you want an open phone, buy one. But I instruct all of the older members of my family to buy iPhones and iPads.

I’ve been programming computers since 1986 and even I have never said it would be cool to side load on my phone.

Answer is yes. But 'safety' is not the reason for the recent Google move.

It is a move taken in lockstep with EU's Chat Control and UK's Online Safety Act, and the proposed Kids Online Safety Act in the US. The common objective of all is total control of digital lives of citizens and allowing the government to snoop on all internet communication while not disabling end to end encryption. They need end to end encryption to lock out external adversaries (Russia China etc) but they need to see the contents of encrypted messages to monitor internal adversaries.

First step is blocking you from running any apps not allowed by Google/Apple.

Second step is putting in the systems to snoop on end to end encrypted communication apps on the endpoints, enabling intel agencies to detect thoughtcrime without exposing everyone's chats to Chinese/Russian intelligence. This will most likely be done by OSes recognizing the apps and extracting private keys on demand.

Last step is locking the bootloaders so you cannot have a phone which lacks the 'features' added in the second step.

The owner of a device should have the final say. The way a lot of this is set up basically deprives the owner of one of their core property rights, in particular the right of exclusion. Instead, in many systems the decision about what software to include or exclude is made cryptographically by a third party rather than by the device’s owner. I don’t think we should support limiting people’s property rights for “safety” or other reasons. iOS is probably one the worst in this regard and it sad to see android moving more and more towards this direction.

I have posted multiple times before that this effectively limits people’s property rights. Here are some other posts I have made on the subject:

* https://news.ycombinator.com/item?id=39349288

* https://news.ycombinator.com/item?id=39236853

* https://news.ycombinator.com/item?id=35067455

* https://news.ycombinator.com/item?id=40727203

> Do we pour billions into educating users not to click "yes" to every prompt they see?

Yes, obviously yes. In the same way we teach people to operate cars safely and expect them to carry and utilise that knowledge. Does it work perfectly? Of course not, but at least we entertain the idea that if you crash your car into a wall because you’re not paying attention it might actually be your fault.

Computers are a critical aspect of work and life. While I’m a big proponent of making technology less of a requirement in day to day life—you shouldn’t need to own a smartphone and download an app to pay for parking or charge your car—but in cases where it is reasonable to expect someone to use a computer, it’s also reasonable to expect a baseline competency from the operator. To support that, we clearly need better computer education at all ages.

By all means, design with the user’s interests at front of mind and make doing the right thing easiest, but at some point you have to meet in the middle. We can’t reorient entire industry practices because some people refuse to read the words in front of them.

It's not sideloading, you are not doing anything nefarious,shady, on the side, on the edge. It's software installation on your device, your own device. This newspeak is purposely invented to negatively portrait software installation from sources not controlled by Google/Apple
> The first is that a user has no right to run anyone else's code, if the code owner doesn't want to make it available to them. Consider a bank which has an app. /../ I think the bank has the right to say "your machine is too risky - we don't want our code to run on it."

But should they? Should we also accept Google's browser signing and ban all browsers the bank doesn't like? Am I allowed to accept calls from people they haven't vetted or is it too much of a risk to the bank's bottom line that they might talk me into a scam.

I suppose we should also write off the inevitable privacy and freedom violations in the name of "security".[0] I don't have anything to hide after all.

[0]: https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...

It's not sideloading it is installing an application. Don't use enemy words.

There are some comments attempting to trick people into thinking that some of the least intelligent people of society have more freedom than regular people.

Freedom of speech and to own your belongings is first. This includes installing what you want on your device.

I think the premise that app stores, notarisarion and such protect users is false. It’s like saying sunglasses protect you from the sun - they help you not get blinded by it right away, but you still need sunscreen, wear a hat etc.

Apple/Google rejecting some obvious scam apps doesn’t mean people don’t get scammed or hurt in other ways. Just like online age verification doesn’t actually protect children or make you a better parent… its just straw man of sorts, designed to remove agency from users through a false sense of safety.

There are really two separate issues here:

A) It should be harder for non-technical users to accidentally install apps designed to harm them.

B) It should also be possible for anyone to run whatever code they want on hardware they own.

Both can be true, and platforms should support both. Ultimately, it is up to the platform to decide what they want to allow and how they protect their users.

I get why Android is tightening controls: plenty of people install shady APKs they get from random websites or Telegram/WhatsApp groups and get burned. But forcing developers to register with Google isn’t the answer. If I want to run a hobby project on my own phone, I for sure shouldn't have to jump through bureaucratic hoops.

The thing is that Google already has the mechanism to protect users: the Play Store. The real problem is that its review process is weak and flooded with low-quality and malicious apps. Fixing that would do far more good than punishing independent developers. They also don't want to open up anti-trust behavior by actually prioritizing the Play Store and saying that you shouldn't trust an app from a random Chinese App Store.

If Google wants to make Android safer, step one should be cleaning up the Play Store. Step two is making that the obvious, prioritized channel. Only after that should they even think about playing Big Brother.

The examples in the post are bad.

The people who were scammed did not run rooted phones. Rooting your phone may allow you to install pirated applications containing malware. But most banking losses comes from scams where the user itself initiated a transaction.

Is it possible to protect users from themselves in every circumstance?

Yes. Remove all of the features from the software. Now, I know you're wondering, "What if my users eat the battery?"

Next, remove the hardware itself. Now users cannot harm themselves at all.

> Here's the story of a bank literally telling a man he was being scammed and he still proceeded to transfer funds to a fraudster.

> The bank blocked a number of transactions, it spoke to James on the phone to warn him and even called him into a branch to speak to him face-to-face.

Y'know, at some point the cost of protecting the dumbest people is too much to be worth it. I am perfectly fine with some people getting hacked, doxxed and scammed out of their life savings if the alternative is everyone losing their freedoms.

Freedoms are important because without them people with power go unchecked more and more. It's a slow process but it culminates in 1) dictatorship at the state level 2) exploitation at the corporate level.

The elephant in the room is not addressed: software in Google Play with so many antifeatures that it can only be called malware (except that Google doesn't call it malware because it brings revenue), and no alternatives except apps outside Google Play that are not signed by a developer who would submit their identity to Google.
> Vulnerable members of society should be protected from scams.

I'd like to have some clarification what kind of safety level people generally expect from their devices.

As an analogy, consider the different safety expectations of public transport (buses, trains, planes, etc) and individual transport (cars, bikes, scooters, etc).

In public transport, I'm responsible for exactly two things: Choosing the right transport to get on and getting off at the right moment. Everything else is the line operator's fault. The operator is also well within their rights to keep me from unscrewing random panels inside the train, conducting scientific experiments with a plane's onboard WiFi or thrashing the seats when I'm drunk. They can kick me out if I behave too badly. (They can not on arbitrary grounds deny me service if that would trigger anti discrimination protections)

In short, I don't own the train, I don't have any expectations of arbitrary control, but in exchange I do have very high expectations of the service provided, even with very little knowledge of the internal workings of a train.

In contrast, with private transport, I'm much more involved in the technical details of the trip: I have to know the exact route, I have to take every turn myself, I'm expected to know traffic rules and safely interact with other participants and I should at least have a basic knowledge of the internals of my bike or car.

In exchange, I also have much more freedom to modify my transport or to pick a different route.

The question is if the safety expectations for phones are more like the ones of public or of private transport.

Is it possible to let owners use their hardware as they wish, without having large companies control what they deem "safe"?

I'm not the user of my phone, I'm its owner.

> I think the bank has the right to say "your machine is too risky - we don't want our code to run on it."

I disagree. Let's go with preferring user agency until banks are in trouble.

> Again, it probably isn't fair to ban users who run on permissive software, but it is a rational choice by the manufacturer. And, yet again, I think software authors probably should be able to restrict things which cause them harm.

I disagree. Ban users when they cheat, not when they have the power to cheat.

For me it’s a matter of settings. As a user I would have option to choose “secure” mode that disallow installing apps from unofficial sources, but if I want to I should have option to allow side loading. Everything else is just corporations need to have to much control.
Have a persistent "developer mode" flag.

When the device is being set up for the first time, ask the user if they want to enable developer mode. Make the warnings as scary as you like. When the device is booting, display a prominent "developer mode enabled" message. But, once the device is booted, there should be no way for apps to query developer-mode status, to prevent discriminatory apps.

The only way to toggle the flag after setup would entail a full factory reset of the device. You could go one step further and have it be a fully permanent flag, in efuses.

The problem is that apps can detect when I say "no you cannot have this data"

A decade ago, we had Xposed modules that would hook into the permissions systems, and give you the option to feed apps fake, generated data. So if it tried to scrape my location or phone number or whatever else, it got garbage

What universele are these people in? Though the app/play store is a fantastic way to obtain shitware that either steals data (seems to be nearly mandatory, if you look at the apps of these store operators), CPU time through mining of some sort, eats through your brain (by inserting horrific amounts of ads, much of which such clear scams I really don't get how this is allowed) or simply ask extra money for essential features one by one.

Everything about the so called stores is so decrepit, the safest way to get any decent software on is side loading / fdroid. How could you in sincerity argue any different?

Users aren't safe anyway when the gatekeeper is Google. They're deeply evil these days and our phones are mainly a surveillance tool for them.

Apple is only slightly better. They limit espionage from other parties but not their own. And meta ads still exist so they block was not very effective.

MacOS handles it pretty well, I can use it to do what Doctorow calls general computing and my mother can use it to shop and do email. Apple allowing freedom for MacOS but not iOS is inconsistent and I see no good reason for that.
I find it telling that all the exemples of scams they use to justify preventing apps installation without registering through an American corporation are entirely unrelated to apps installation. Just show the protect the users angle is completely bogus.
I create apps just for myself, just started learning, self taught, not a student taking programming course in university, not professional

Apps created by me for my routine,

Does that mean i would not be able to install my apps ??

“allow side loading” is a premise I object to.

Now that Android is going full retard with their authoritarian BS, it’s time to build a new phone operating system or at least make the ones we already have viable.

It’s a monumental undertaking, but it needs to be done.

Yet Google has no problem with displaying these vulnerable people scammy ads (which is also the most common way they actually discover these malicious APKs), since it brings them revenue..

What if we'd instead require users to verify themselves before being allowed to see ads? I'm sure that would be more effective for preventing scams, fraud and abuse.

I remain wholly unconvinced that side loading and user safety are even related at scale. They are orthogonal.

There are plenty of apps available through the Play store that are not safe. Even if side loading requires chain-of-trust, malicious behavior will remain rampant. I'll concede that it restricts the ease with which one can redistribute malware but by how much? It doesn't seem significant to me compared to the hassle for end users/developers.

It all seems so contrived. The only rational explanation to all of this is backpedaling into a closed garden.

The answer to this question is yes. You need to make enabling sideloading somewhat difficult and make it require a modicum of tech literacy. The only reason that the phone companies do what they do is to make more money from their stores. They don’t care about people or their safety.
>Is it possible to allow sideloading and keep users safe?

Why is this a question of _allow_? Who is my hardware provider that he is somehow my guardian and must _allow_ me to install software that I want to install?

>Is it possible to allow people to do sports and keep them safe?

>Is it possible to allow people to roam freely and keep them safe?

>Is it possible to allow people to not be locked up in a padded cell and keep them safe?

People are responsible for what they are doing, and teaching them about technology is the best way to do deal with this example here, as it doesn't infringe anyone's human rights and would give anyone the resources to check their sources.

What about making side loading require some moderate level of technical sophistication? Like connecting to the phone over usb and having to manually type some long shell commands, or exit vim, or write a compiling c program, or some other layman proof filter to activate installing outside apps. I feel like grandma would be too intmimidated by this (good), making it too frustrating for even the most determine scammer to explain, no matter how desperate they are for her social security checks. Have it be done in the bootloader so you can't follow these instructions while on the phone, and require physical interactivity with the device (can't be automated over usb). Regardless, this policy is an unacceptable infringement on digital freedom by google.
Evolution used to work by some people dying before they could reproduce.

That's how we become the smartest animal on the planet. But it no longer works, we are very good at keeping everyone alive. And there's nothing wrong with that, as long as we don't compromise our freedoms to achieve it.

Some people getting exploited is the modern equivalent of leopards eating your face. It would be nice to protect people from it happening but NOT by everyone giving up basic human rights. And yes, in the modern world, running any software on your hardware should be a basic human right.

Especially at a time where computation is starting to resemble intelligence. Otherwise we all become serfs all over again.

> There are, I think, two small cracks in that argument.

> The first is that a user has no right to run anyone else's code, if the code owner doesn't want to make it available to them. Consider a bank which has an app. When customers are scammed, the bank is often liable. The bank wants to reduce its liability so it says "you can't run our app on a rooted phone".

> Is that fair? Probably not. Rooting allows a user to fully control and customise their device. But rooting also allows malware to intercept communications, send commands, and perform unwanted actions. I think the bank has the right to say "your machine is too risky - we don't want our code to run on it."

> The same is true of video games with strong "anti-cheat" protection. It is disruptive to other players - and to the business model - if untrustworthy clients can disrupt the game. Again, it probably isn't fair to ban users who run on permissive software, but it is a rational choice by the manufacturer. And, yet again, I think software authors probably should be able to restrict things which cause them harm.

It's not clear to me whether in this fragment the author is stating the two alleged cracks in the argument or rather only the first one — the second one being Google's ostensible justification for the change. Either way, neither of these examples are generalisable arguments supporting that 'a user has no right to run anyone else's code, if the code owner doesn't want to make it available to them'.

With regards to banking apps, the key point has been glossed over, which is that that when customers are scammed the bank is 'often' liable. Are banks really liable for scams caused by customer negligence on their devices? If they're not, this 'crack' can be thrown out of the window; if they are, then it is not an argument for "you can't run our app on a rooted phone", but rather "we are not liable for scams which are only possible on a rooted phone".

As for the second example, anti-cheat protection in gaming, the ultimate motivation of game companies is not to prevent 'untrustworthy clients' from 'running their code'. The ability of these clients to be 'disruptive to other players' is not ultimately contingent on their ability to run the code, but rather to connect to the multiplayer servers run by the gaming company or their partners. The game company's legitimate right 'to ban users who run on permissive software' is not a legitimate argument in favour of users not having full control over their system.

> 00. Users should be free to run whatever code they like.

> 01. Vulnerable members of society should be protected from scams.

00: yes, always; 01: yes, but not at the expense of 00 (or probably some other things)

Yes. Next question.

The push to lock down the Google app ecosystem is just Google's eternal quest to lower costs.

Reviewing apps, even if automated, is expensive. A while ago they demanded that all app publishers get a DUNS number. It's obvious why they did this - they want to rely on the reputation of the company (easy, automated) rather than detect malicious apps (slow, may require manual intervention).

One important thing to note is, the threat model changes depending on the user. If a "poweruser" installs a card game app, and it suddenly pops up a screen that looks like their bank login, they're going to close the app and report it. Grandma might get confused and think she was checking her bank balance. So they need a complex set of tiers and warnings to ensure that only users who know what they're doing get apps that could do something like that.

But, we all know that the above scenario is hardly the worst thing an app can do. Thanks to mysteriously bad security, there have been all kinds of Android vulnerabilities that allow one app to spy on another app's data files. Maybe locking down the ecosystem so that only "good" apps can spy on one another is the win/win solution for them.

The most secure OS existing, Qubes OS, allows and encourages installing any untrusted software and protects you with strong, hardware-assisted virtualization.
Wait, how does the requirement to only install apps signed by Google comply with the DMA?

If it doesn't, don't we all have our answer on what we should do?

There are millions of homeless or otherwise struggling people all around the world, who would let anyone to use their identity for a small compensation. I don't really see how this requirement to register in Google will help with app security. So the malware will be signed with John Smith living under a bridge, now what?
A better question would be:

Is it possible to restrict software installation and keep users free?

Even assuming this is a good faith effort by Google (which I seriously down of course), there's a point where you can only do so much to protect people.

Showing them the permissions requested, training them to not install things from outside the store unless they know what they're doing, explicitly needing to manually enable installation of software from the outside, etc etc.

That's it. You've done your job.

And if, despite all that, some people still want to continue to use their phones in a dangerous manner LET THEM suffer the consequences of their ignorance. Let them bruise their knee. They're grown ups, presumably. Some people just need to learn the hard way, and we shouldn't architect the entire system to protect that lowest common denominator.

You absolutely do not need to childproof the entire phone to protect people from themselves. For me, that's why it's patently obvious that this move has an ulterior motive.

I have come to the conclusion that both Android and iOS, along with the banking systems, are all doomed platforms.

Even something like GrapheneOS, in theory the best path to security and privacy and liberty, was falling way short even before this latest announcement from Google.

The problem lies partially in the app ecosystems, which embrace spyware and exploiting users (requiring all the worst Google APIs), and partially in governments, which will leverage any centralized organization like Google to gain control (EU chat control etc.).

The solution cannot be just a custom OS or an OS fork. In fact, ecosystem compatibility is toxic and slows down growth of real alternatives. There needs to be some wholly independent and decentralized offering.

The challenge is hardware compatibility and core services like digital IDs. Most apps should be solved by using a website instead.

These issues are especially important because the future is increasingly digital. Smart phones, smart glasses, smart watches, VR glasses, smart homes, and even brain implants. I don't want to live in a future where I'm either left behind or my whole life is controlled by Google/Apple/the government/etc.