Google's own Play Store is filled with outright malware too, no ads needed. The idea that Google has to control what people are allowed to install on their phones isn't really for the protection of anyone except Google.
That newspeak term should just disappeared. It only contributes to the image that downloading and installing an app is something that is outside the "happy path". Installing software of your choice on a device you own shouldn't be demonised
Those of us who want to can easily bypass it. My mom who doesn't know what she's doing and gets a phishing email with a fancy apk attached should probably have a hard time using it.
That device was called personal computer for decades, and the world didn't end for the simplicity of installing software on it.
The "personal computer" has a terrible track record.
The Play Store's scanning is very far from perfect, and the amount of crap that's on it, combined with the trust that people have towards it, and apps' unfettered access to internet, makes malicious software easily more common than on PCs.
Even without considering as malicious the enormous data collection that almost everything on the Play Store does, encouraged by Google
It doesn't mean one can't buy nice things because one is afraid of being robbed.
Society didn't ban doing it, but put up barriers that help the average person from doing something dangerous.
I think the pumps still fit where I live, btw
Making the nozzle shapes incompatible is a smart solution, but in the US at least I'm pretty sure they're interchangeable.
To be fair, mobile phones being locked down probably contributed to the mass adoption of e.g. mobile payments and banking.
The move to apps made things more difficult, if anything
And they used an actually secure OTP dongle, eventually ditched by most banks because, yeah SMS codes and apps are safer............
It's now that a lot of people can't use any remote banking, because their bank's app is huge or refuses to run on their phone.
The EU mandates the 2FA method shows information about the purchase you're authenticating (timestamp, amount and cc used in my case), making unconnected dongles impossible to use. This makes me sad, but it does have merit.
FWIW I still use the website to do all my payments. I find banking apps to be madness - you're entrusting all your money to what is essentially a toy.
There are unconnected photoTAN devices that support this. They have a camera that reads a QR code. Some European banks use this. E.g. Vasco digipass 770
If mobile banking really wanted to be secure, they would support something like a NFC yubikey for transaction verification. The fact they fully ignore separate secure HSMs tells you what you need to know about their security.
Today people get in debt to have the latest orange iPhone, for a long time before that most people in, ok, developed countries somehow got hold of a computer.
Maybe with less brain cells burned by
[1] https://worldpopulationreview.com/country-rankings/computers...
I'd see it the other way around and say that a device running an operating system controlled by some company shouldn't hold your entire life, bank info, photos, etc.
Without regulation markets coalesce as the winners eat each other like a game of snake. It's a miracle Apple hasn't yet eliminated Android. Although I suppose for some institutions there is only iPhone.
Blocking apps is like blocking buying of knifes because one can hurt themselves.
There's not an easy answer, but the non-answer of "people just need to be educated" is trivially dismissed.
"Everyone should just be smarter/more educated" is what I used to think as well. I now fully understand some people have no desire to be educated in any way and it's a net good for society to not have a large % of devices compromised.
The logical conclusion is that fdroid should be allowed and google play banned by default.
Now my in-laws (similar age) one very demented, the other thinks he knows best because he was a chemical engineer...they could use some built in protections
so ultimately I think some default level of "guardrail" is appropriate, but it should have a not too burdensome escape hatch
Which is really exactly what google is implementing here and why I'm so perplexed so many people are upset. You or I or smart parents (my mother has never used a computer in her life and wouldn't want to) will have absolutely no issue sideloading apps after the proposed changes.
Given that google is now forced to have competing app stores due to Epic v. Google and the ninth circuit courts went into long and arduous detail in that anti-trust case about sideloading restrictions I don't think they have a leg to stand on if they get rid of sideloading completely. Oddly Apple continues to get away with it no problem.
They've been chipping away at AOSP for years, pulling more and more parts of the Android experience into their proprietary Google Play Services. In this case, they're doubling down in the same direction. Sure, it may be more or less transparent from a user-facing perspective, but it's a fundamental change to the model.
Previously, it was ultimately a local decision: Android warned you, you enabled the permission, and you installed the APK. It now becomes dependent on a Google-controlled verification/authorization mechanism. That's fundamentally different from making the existing "unknown sources" toggle more annoying.
And I generally wouldn't care "have at it" if their phone/computer being compromised only harmed them. But a bulk amount of compromised devices harms us all.
"Think of how stupid the average person is and then realize half of them are stupider than that!" -George Carlin
Family should be responsible on education or making phone of people that are not educated enough (minors, elderly, etc.) limited - I do that using Family Link. I have there my child and also my in-laws - both of them can't install new apps without my permission.
So the tech is already there, one just needs to use it.
Look at apps on fdroid, no such thing.
So the solution is simple - ban google play and allow only fdroid if one wants good apps.
You can't protect everyone. Just like there are people oblivious to bad eating habits - it is a tax on ignorance.
Knowing Google, that's a big assumption
Then it starts a 24 hour timer. When that hits zero, you have 1 hour to go back in and select that you want to install apps on a device you own and paid money to own.
It's not scam-resistant at all. Any scammer will gladly work around this and send someone to one of many malicious apps in the play store, or a malicious URL, or even just set an appointment to call Grandma back the next day.
But yeah, it's hilarious that they're pushing this so hard when the Google Play Store still has so much malware.
Getting some 9-11 security theater vibes.
But dear... Google has no idea that they have/had the genuine nerds and are blowing it.
Irrespective, people should probably be migrating to a GrapheneOS or similar OS asap once the OS ships with a device.
There are occasional good deals for (unused) older models on eBay, but they're surprisingly rare.
I wonder if Google demands stores to give the old models back, after the release of newer ones; they disappear from every store extremely quickly.
In short, google has referred to this as "increased user friction" to try and deter people from doing this. Essentially not making it impossible; just really frustrating for users so they get sick of the process and just install verified apps through them.
The only way I know around this is to install a custom rom like GrapheneOS or Lineage OS since this change targets Because the policy targets the Google Mobile Services (GMS) framework rather than the foundational Android Open Source Project (AOSP).
Not that Apple is better, but they lose a huge selling point.
Then you have to explain to users how to enable this. Not too mention the onerous F-droid requirements for publishing, it's bad enough as it is.
Average users are not going to do this, just like Google wants. Hopefully someone sues them and wins or we get Linux phones, not holding my breath though