I'm fine with an opt-in lock-down feature so people can do it for their parents/grandparents/children.
Also, just let people get used to it. People will get burned, then tell their friends and they will then know not to simply follow what a stranger guides them to do over the phone. Maybe they will actually have second thoughts about what personal data they enter on their phone and when and where and who it may be sent to.
Same as with emails telling you to buy gift cards at the gas station. Should the clerk tell people to come back tomorrow if they want to buy a gift card, just in case they are being "guided" by a Nigerian prince scammer?
> I'm fine with an opt-in lock-down feature
Me too, but it's really just some UI semantics whether this is 'opt-in' or 'opt-out'. Essentially it would be an option to set up the phone in "developer mode".
With billions of Android users, there's only millions of people who need or really want this. So like 1%. My point is stop thinking about your mom's windows box and consider the scale.
I'm just spitballing something which would be completely trivial for any 'techie' (and wouldn't require jumping through 24 hr hoops), while improving the situation for the other 99%. Or Android becomes iOS and some minority of techies use some weirdo linux phone, whatever.
Yes, sad, but works.
People will learn about scams, but scammers are unfortunately a few steps ahead. (Lots of scammers, good techniques spread faster among them than among the general public.)
Also Chrome trusts like 300 CAs. Does that work? Probably not if you live in 200 of those countries.
I have had to actually verify my “investment profile” with a major broker in order to unfreeze some trades, in a high friction process. To the extent that a sideloaded app that looks exactly like the bank app has a low friction install, then people can get fooled and irrevocably lose savings.
If the lock-down is opt-in, almost nobody will opt in to it. If the lockdown is opt-out, then whether scams still happen depends on how much friction there is in opting out.
Freedom to install other unsigned sandboxed apps has a solution: Banks could use passkeys and other non-phishable methods. Sideloaded apps in Android can’t get to the bank app’s passkey.
Passkeys or hardware tokens get worries about the enshittification of the theoretical recovery process. Which, if that’s the case, I guess we should hope for/pay a better world, at least with banks and brokers. For them specifically, for account recovery allow either showing up in person or using ID checks.
Both for personal accounts and business accounts (i.e. with Business Email Compromise), I believe the onus should be on the bank to use non-phishable methods to show the human-readable payee from their app for irrevocable transfers.
I don't know how I feel about this change but context does in fact matter about whether something is a good idea or not
In physical world, there’s only so many people who can rob you if you do something stupid (like constantly give away copies of your keys to strangers), they will be very noticeable when they are doing so, and if you feel like something’s off you can always change the lock.
On the Internet, an you are fair game to anyone and everyone in the entire world (where in some jurisdictions even if it’s known precisely who is the figurative robber they wouldn’t face any consequences), you could get pwned as a result of an undirected mass attack, and if you do get pwned you get pwned invisibly and persistently.
Some might say in these circumstances the management company installing a (figurative) biometric lock is warranted, and the most reliable way to stop unsuspecting residents from figuratively giving access to random masked strangers (in exchange for often very minor promised convenience) is to require money to change hands. Of course, that is predicated on that figurative management company 1) constantly upping their defences against tenacious, well-funded adversaries across the globe and 2) themselves being careful about their roster of approved trusted parties, whom they make it easy to grant access to your premises to.
Meanwhile installing software on your own device is the thing that isn't that. They're preventing it even when you're the owner of the device and have physical access to it. They're not installing a lock so that only you can get in, they're locking you out of your own building so they can install a toll booth on the door.
Essential means to get fucking lost and let me do with the hardware I paid for whatever I want.
All these changes are attacks on general purpose computing and computing sovereignty and personal control over one's data, and one's digital agency.
Yeah I'm aware that we can only watch from the sidelines. At least we can write these comments.
The new world will be constant AI surveillance of all your biosignals, age and ID verification, only approved and audited computation, all data and messaging in ID attached non e2e encrypted cloud storage and so on. And people will say it keeps you safe and you have nothing to fear if you are a law abiding person.
That situation is not acceptable. Got something better than insults like "pretty dumb" to say about how to resolve this abuse of the two-player oligopoly in the mobile phone market?
Meanwhile, those same banks have websites.
For an example think about how mods are treated on cars. There can be very good reasons for those restrictions, but if your goal is to be able to modify phones in the way you want, that might not be the best way to go about it.
In short, be careful what you wish for because sometimes you get it. :)
"Nils Bejerot, a Swedish criminologist and psychiatrist, invented the term after the Stockholm police asked him for assistance with analyzing the victims' reactions to the robbery and their status as hostages. Bejerot never met, spoke to, or corresponded with the hostages, during or after the incident, yet diagnosed them with a condition he invented."
"According to accounts by Kristin Enmark, one of the hostages, the authorities were careless, and their initial approach to the robbers nearly compromised the hostages' safety.[6] Enmark criticized Sweden's prime minister, Olof Palme, for endangering their lives. Palme believed that if Olsson saw one of his close relatives, he might be willing to surrender the hostages; however, the police made a careless mistake. They misidentified Olsson, and sent a 16-year old boy who was unrelated into the bank. This caused confusion and resulted in Olsson firing rounds at the boy who barely escaped. Olsson became much more agitated in general. After that, Enmark and the other three hostages were fearful that they were just as likely to be killed by police incompetence as by the robbers.[7][8][9] Ultimately, Enmark explained she was more afraid of the police, whose attitude seemed to be a much larger, direct threat to her life than the robbers.[10]"
I paid for my phone.
These are general purpose computing devices. It's sure taking a long time, but Cory Doctorow's talk on the war on general purpose computing is sure starting to become a depressing reality: https://www.youtube.com/watch?v=HUEvRyemKSg
Windows S mode is a streamlined version of Windows designed for enhanced security and performance, allowing only apps from the Microsoft Store and requiring Microsoft Edge for safe browsing.I'm not the only one who has noticed: https://www.reddit.com/r/windows/s/6y39VNaLUh
Even if you are a bank or whatever, you shouldn't store global secrets on the app itself, obfuscated or not. And once you have good engineering practices to not store global secrets (user specific secrets is ok), then there is no reason why the source code couldn't be public.
It's not a coincidence that Linux distros are much less susceptible to malware in their official repositories. It's a result of the system. Trusted software currated and reviewed by maintainers.
The play store will always have significant amounts of malware, so this entire conversation is moot.
1. "Most open source repositories do have eyes on the code"
Seems basically impossible that this is true.
"Debian often has separate maintainers who maintain patches specific to Debian." does not support the previous statement. Debian cherry picks patches, yes.
2. "It's not a coincidence that Linux distros are much less susceptible to malware in their official repositories."
Not only is it not a coincidence, it seems to not even be true.
3. "The play store will always have significant amounts of malware, so this entire conversation is moot."
This seems to just be "a problem can not be totally solved, therefor making progress on this problem is pointless to attempt". I... just reject this?
Tongue-in-cheek example, just to get the point across: instead of calling it Developer Mode, call it "Scam mode (dangerous)". Require pressing a button that says "Someone might be scamming me right now." Then require the user to type (not paste) in a long sentence like "STOP! DO NOT CONTINUE IF SOMEONE IS TELLING YOU TO DO THIS! THIS IS A SCAM!"... you get the idea. Maybe ask them to type in some Linux command with special symbols to find the contents of some file with a random name. Then require a reboot for good measure and maybe require typing in another bit of text like "If a stranger told me to do this, it's a scam." Basically, make it as ridiculous and obnoxious as possible so that the message gets across loud and clear to anybody who doesn't know what they're doing.
The problem with this line of reasoning is that it proves too much, which really gets to the heart of the issue.
If people are willing to be led to the slaughterhouse in a blindfold then it's not just installing third party code which is a problem. You can't allow them to use the official bank app on an approved device to transfer money because a scammer could convince them to do it (and then string them along until the dispute window is closed). You can't allow them to read their own email or SMS or they'll give the scammer the code. If the user is willing to follow malicious instructions then the attacker doesn't need the device to be running malicious code. Those users can't be saved by the thing that purportedly exists only to save them.
Whereas if you can expect them to think for two seconds before doing something, what's wrong with letting them make their own choices about what to install?
This isn't actually that obvious, for a number of reasons.
The first is that it causes there to be more sheep. If you add friction to running your own software then fewer people start learning about it to begin with. Cynical cliches about the government wanting a stupid population aside, as a matter of policy that's bad. You don't want a default that erodes the inherent defenses of people to being victimized and forces them to rely on a corporate bureaucracy that doesn't always work. And it's not just bad because it makes people easier to scam. You don't want to be eroding your industrial base of nerds. They tend to be pretty important if you ever want anything new to be invented, or have to fight a war, or even just want to continue building bridges that don't fall down and planes that don't fall out of the sky.
Another major one is that it's massively anti-competitive. If the incumbents get a veto, guess what they're going to veto. This is, of course, the thing the incumbents are using the scams as an excuse to do on purpose. But destroying competition is also bad, even for sheep. Nobody benefits from an oligopoly except the incumbents.
And it's not just competition between platforms. Think about how "scratch that itch" apps get created: Some nerd writes the app and it has only one feature and is full of bugs, but they post it on the internet for other people to try. If trying it is easy, other people do, and then they get bug reports, other people contribute code, etc. Eventually it gets good enough that everyone, including the sheep, will want to use it, and by that point it might even be in the big app store. But if trying it is hard when it's still a pile of bugs and the original author isn't sure anybody else even wants to use it, then nobody else tries it and it never gets developed to the point that ordinary people can use it.
So maybe the scam we should most be worried about here is the one where scams are used as an excuse to justify making it hard for people to try new apps and competing app stores, and deal with the other scams in a different way. Like putting the people who commit fraud in prison.
No. This assumption is the core fault with the entire line of reasoning. The typical sheep will not do arbitrary things for a stranger such as sending you his entire bank account because you told him he needed to pay an IRS penalty in crypto to avoid being picked up by the state police who are already en route in 15 minutes.
It's a continuum. The question is how much of the low end needs to be protected by the system.
Binning into discreet blocks to match your example, the question is where to place the dividers between the three categories - nerd, sheep, and incompetent. We don't care to accommodate the third.
In theory I have no problem with the idea of hanging the incompetents out to dry, when I imagine them as unsympathetic idiots, the same people who litter, and can’t drive correctly. But actually I think most of us would be horrified when it turns out that category of incompetents includes our parents and grandparents, or, increasingly, our children (Gen Z has been increasingly falling victim to scams, partly because they have no idea how computers work since modern ones present only highly abstract surfaces to them, and I suspect Alpha will be the same).
The entire point here is that sheep do not need an overly protective mode. It's a false premise.
I know plenty of them. I help them navigate modern tech. I install fdroid on their phones. They lie on a continuum and none of them are going to turn on developer mode (or whatever BigTech wants to call it) because a stranger on the phone told them to.
There is a small sliver on the far end of the continuum that will do things like that. But in general they are sufficiently gullible that no measure that can be bypassed will ever work for them. They require a Fisher-Price device.
BigTech wants to hold that small sliver up as justification for their anticompetitive practices.
You (or another commenter) are right though that blocking sideloading eliminates but one avenue for this abuse, which at first makes us feel good that we then shouldn't have to give this freedom up! Now, the bad news is that from Big Tech's pov, the open Web is the next enemy in the crosshairs. The future "Sheep mode" may simply be App Store (only sanctioned scams, paying their 30% cut, are allowed there!) + a "Web Browser" without an address bar, which can open any of the "Thousands of Safe Sites" on the OS Vendor's allow-list. Getting on the list is of course "easy," and just requires a $999/year subscription, and proving SOC2, GDPR, and CCPA compliance.
Maybe 10-20%, generously. The people who are falling for it under current protections clearly are not reading anything they're looking at or thinking about security at all, they've fallen for social engineering scams and sincerely believe they're at imminent risk of being arrested by the FBI or that their adult child is about to be killed. They're in fight or flight mode already, not critical thinking and careful deliberation mode.
If you were to rank everyone by gullibility, these people would largely be clustered in the top 1-2% of most gullible people. There is very little you can do to protect these people, realistically.
That actually sounds like an argument is favor of this restriction. If someone is in a position of deep trust with the scammer then waiting a day is nothing. But if they're in a panic, not thinking things through or calling anyone for advice, that state probably won't last 24 hours.
What I would challenge you to consider is this: where do we draw the "good enough" line, where we finally stop sacrificing freedom over the devices we purchased under terms that originally included freedom, control, and ownership at the altar of protecting the vulnerable?
Do scam victims need to be 0.1% of all Android users? 0.01%? 0.0001%? Should this extend to computers too - should local admin become completely unavailable to all Windows users? Should root become unavailable to all Mac users? To all Linux users? Should you be allowed to own technology at all, or merely rent it as a managed service, to protect those who cannot be trusted to own devices without getting scammed?
> What I would challenge you to consider is this: where do we draw the "good enough" line, where we finally stop sacrificing freedom over the devices we purchased under terms that originally included freedom, control, and ownership at the altar of protecting the vulnerable?
There's nothing to challenge here. The method I proposed keeps you fully in control and owning your device. Anybody can follow that process if they want. It's not like I said each person has to get approval from Google before enabling developer mode on their phone.
> Do scam victims need to be 0.1% of all Android users? 0.01%? 0.0001%?
This is not some kind of paradox like you're making it out to be. A very reasonable starting point would be "get this scam rate down to match {that of another less-common scam}". Iterate until/unless new data comes along suggesting otherwise.
> Should this extend to computers too - should local admin become completely unavailable to all Windows users? Should root become unavailable to all Mac users? To all Linux users?
"Too"?! Where did I ever suggest root should be "completely unavailable" to all Android users?
> Should you be allowed to own technology at all, or merely rent it as a managed service, to protect those who cannot be trusted to own devices without getting scammed?
Where did I suggest any of this?
When you say "Iterate until/unless new data comes along suggesting otherwise", does that mean you will want to continue adding more friction and more restrictions as long as a number or percentage of people (that exceeds some threshold) continue to get scammed?
What I am asking you to do, as a thought exercise, is to define that threshold, and then to consider that if we never meet that threshold, how far are you willing to go with iterating and adding more friction, stripping user control in pursuit of it?
It seems to me that you have a mental model where some small, reasonable changes will dramatically reduce the number of scam victims to near zero. All I'm asking you to do is sincerely consider what your preferred course of action looks like if you are wrong about how effective each additional layer of controls are.
All it means is "keep reevaluating the situation and your approach based on the data." I can't possibly claim to have all the answers for every hypothetical available right here.
> It seems to me that you have a mental model where some small, reasonable changes will dramatically reduce the number of scam victims to near zero.
Replace "will...near zero" with "has a reasonable chance of...low enough that the fish becomes too small to fry" and you might be capturing my thoughts better.
> All I'm asking you to do is sincerely consider what your preferred course of action looks like if you are wrong about how effective each additional layer of controls are.
I am not a prophet (or a dictator). I'm an engineer. I see a potential solution or mitigation, I evaluate the trade-offs, and if it seems worthwhile, I suggest/try it. If it works out well, great. If not, I reevaluate everything based on the facts at that point. "I don't have any good idea anymore" is certainly a possibility I could reach, as is "I have another idea"...
Clearly there are a million factors to consider in each situation. Some predictable, some not. Just to list a few obvious ones off the top of my head: how fast we get there, how users react, how governments and lawmakers react, the magnitude of the scamming (not just rate! but also monetary amount), what other threats pop up in the meantime, what threats go away, what other mitigations or alternatives are available to try next, what the financial system even looks like at that point... these are all relevant. I can't predict what we should do in a vague, underspecified hypothetical where the only concrete premise seems to be that my predictions are wrong. (!) What I can see and suggest some solution for is the reality right now.
There are just as many scam apps in play store and this system does nothing to help with those.
Locking down computing is just fundamentally wrong and leads to an unfree society.
Why destroy the ecosystem that gives you the freedom to shoot yourself in the foot?
Turning Android into another walled garden removes user choice from the equation.
https://blog.lastpass.com/posts/warning-fraudulent-app-imper...
Oh, turns out they just let you pretend to be the real company to sell your scam app.
What a load of good that "Approval" process does.
Then Google can do whatever they want with their OS and I can do what I need with mine. You might actually get phone OS competition. This is what the walled garden is actually meant to prevent.
You can’t feasibly protect someone that believes the person on the phone is their family member or the chief of police.
This kind of thing has to be verified like how they try drugs. Just randomly doing things will surely be useless, similar to how randomly optimizing parts of a program is generally worthless.
I think a big warning in red "Warning :If you don't personally know the person asking you to install this app, you are getting scammed. No legitimate business or Institution will ask you to install this app"
Done.
Pretending that this is about anything but Google's greed is giving them far too much credit.
...which clearly companies don't want, because complacent mindless idiots are easier to brainwash, control, and milk.
I'd wipe the Play Store off the face of the earth. Have you looked at the garbage on there that Google considers legit?
This: https://news.ycombinator.com/item?id=47447600
is is the shit people are exposed to when they go through the Play Store. You don't find that on F-droid.
The second thing I'd do to combat scammers is the same thing I'd do to combat child porn and disinformation: educate people. This silly process is a technical answer to a social problem, and those rarely work well.
Furthermore, this verification system also functions as a US sanction mechanism—one that can be triggered against any entity the US decides to ban.