upvote
> sideloading

That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised

reply
Fully agree. Installing software is installing software, signed or unsigned, app store or not.
reply
Surely you see how installing unvetted software on a device that holds your entire life, bank info, photos, etc. probably shouldn't be part of the "happy path" for most people. You shouldn't even install software you haven't fully vetted from the google play store. This should be drilled into non-technical people.

Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.

reply
> a device that holds your entire life, bank info, photos, etc.

I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc.

reply
How do you get around this? Literally every bank, brokerage, etc... is hell bent on you using your phone for everything from 2FA to passkeys, etc... They dont even imagine people have computers anymore or want two+ physical devices/controls on what can be done with which factors
reply
That means education for people: don't perform actions that are in emails.

Blocking apps is like blocking buying of knifes because one can hurt themselves.

reply
Have you ever tried to educate a 70+ year old person on this kind of stuff? Their eyes gloss over and they don't care. I've told my mother not to install random apps on her phone several times yet she still does it. I could probably send her a phishing e-mail right now that 'looks like' it's from me (so long as my name is in the from: field that's enough) and she'd follow the instructions to install a malicious apk too.

"Everyone should just be smarter/more educated" is what I used to think as well. I now fully understand some people have no desire to be educated in any way and it's a net good for society to not have a large % of devices compromised.

reply
yes, got my father on linux a decade (or more) ago. He's 84. No problem. Most recently we discussed being vigilant against vishing.

Now my in-laws (similar age) one very demented, the other thinks he knows best because he was a chemical engineer...they could use some built in protections

so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch

reply
>so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch

Which is really exactly what google is implementing here and why I'm so perplexed so many people are upset. You or I or smart parents (my mother has never used a computer in her life and wouldn't want to) will have absolutely no issue sideloading apps after the proposed changes.

reply
It's full of malicious apps on google play. There are none on f-droid.

The logical conclusion is that fdroid should be allowed and google play banned by default.

reply
Because education has worked so well on Windows.

There's not an easy answer, but the non-answer of "people just need to be educated" is trivially dismissed.

reply
I'm not sure the situations are comparable when Windows doesn't have this permission system where the apps are still very limited in what they can access unless you grant specific directory access or access to the contact list or such
reply
It does, but approximately nobody uses it, because Microsoft also tried to apply loads of constraints on what kinds of program could exist when they rolled it out, as part of their "all Windows software should also work on Windows Phone and Xbox" campaign.
reply
> a device that holds your entire life, bank info, photos, etc

That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.

reply
The difference is that the only people who used those personal computers were (are) an educated subset of the middle class in developed countries.
reply
> That device was called personal computer

To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking.

reply
Web banking was offered by all banks long before banking apps, and you could of course access it from smartphones

The move to apps made things more difficult, if anything

reply
Offered but less broadly adopted. Having a platform that doesn't tend to get infected when used by normal users helped with that.
reply
It was adopted by everyone I knew

And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............

It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.

reply
The world may not of ended but to of people have been hurt by malware ruining their computer, cryptolocking all of their company's files for ransom, stealing all of your login credentials, stealing cryptocurrency, taking secret photos with your webcam, screen recording what you are doing on your computer, etc.

The "personal computer" has a terrible track record.

reply
For many decades, people have been mistakenly putting diesel fuel into their gasoline cars, yet we never outlawed diesel vehicles. You can only do so much to protect people without destroying their rights to their property.
reply
the pump handles are green tho
reply
Society moved to having it so diesel fuel pump would not fit into gasoline cars.

Society didn't ban doing it, but put up barriers that help the average person from doing something dangerous.

reply
Just like people get robbed, it is as common as that.

It doesn't mean one can't buy nice things because one is afraid of being robbed.

reply
Except a sane society puts rules in place against robbers and then bans such people from society.
reply
There have already been laws against scammers and hackers for a long time.
reply
That seems to happen on phones too
reply
It is much rarer since it needs 0 day to do these at the same level as possible on a pc. The play store scanning apps for malware is an important safety mechanism against this. Further more imposter apps like YouTube but with no ads that are Trojans that steal people's accounts.
reply
Or the accessibility permission, or to some degree the access all files ones; but it's also enough for the app to pilfer the data you trust it with.

The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs.

Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google

reply
Block installs outside of playstore ON/OFF (ON by default) isn't any less secure. "Sideloading" is scaremongering.
reply
If the issue Google has with sideloading is really just the rampant app piracy (and the malware that comes with cracked apps) that might be something F-Droid can accomodate.
reply
I don't think malware is the problem, as most malware comes directly via Google's ecosystem carried by ads. Just recently I had to uninstall some app from the play store since it tried to distribute malware through scary pop-ups and had it replaced with something from f-droid for someone I know.
reply
> most malware comes directly via Google's ecosystem carried by ads.

Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google.

reply