• smeg@infosec.pub
    link
    fedilink
    English
    arrow-up
    61
    ·
    21 hours ago
    • enable developer options
    • confirm that you are not tricked
    • restart phone and re-authenticate
    • wait one day
    • confirm with biometrics that you know what you are doing
    • decide if you only want unrestricted installs for 1 week or forever
    • confirm that you accept the risks
    • enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
    • FauxLiving@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      7
      ·
      19 hours ago

      I can understand this workflow being created to protect the legions of people who are tricked into installing spyware.

      It doesn’t remotely affect me because I use GrapheneOS and if this is an issue for you then you’re probably someone who should look at installing GOS or Lineage.

      I don’t think Google should be able to do this and it is likely part of a longer-term strategy to strangle any competition. At the same time, I can understand how this change will save a lot of grandparents from clicking a link in a text from their ‘grandchildren’ and installing spyware that’ll steal all of their bank information.

      • fallaciousBasis@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        I mean… This is kind of why I never let people use my phone.

        I have installations from various sources enabled… Like my browser, because I know what I’m doing. But I wouldn’t trust anyone as the process is currently effortless…

        If someone is trying to install spyware on you (like a partner or parent.) this might offer some notification and prevention.

        I don’t really see the big deal. You do it once, enable it forever, and wipe up those tears.

        I think a better way would just to have maybe like a biometric/pin confirmation upon installation. Simple. Clean.

      • AHemlocksLie@lemmy.zip
        link
        fedilink
        English
        arrow-up
        7
        ·
        17 hours ago

        GrapheneOS is built on AOSP, which is where the change is being made. Graphene and other custom ROMs will need to maintain a fork that cuts out the feature if they want to avoid. Google is also starting to close off Android to make that more difficult, so it’ll become a genuine project to maintain the fork well.