Remix.run Logo
BrenBarn 5 hours ago

The key question for me is whether this "advanced flow" will allow the practical use of entirely separate app stores (like F-Droid) or if they're going to throw up tons of barriers for every individual app install.

sowbug 3 hours ago | parent | next [-]

If I were designing the advanced flow, I'd require the decision to be made at phone setup time. Changing your mind later requires a factory reset.

Real sideloaders (F-Droid users, etc.) know at setup time that that's how they'll be using their phone, so it works for them. But ordinary users who are targets for sideloading malware will become a lot less attractive if attackers must convince them to wipe their phone to complete the coercive instructions.

Aliexpress has a similar approach to protect their accounts from takeovers. If you change or forget your password, all your saved payment methods are erased. This makes the account less valuable to an attacker, at the cost of a little pain to authentic account holders.

201984 3 hours ago | parent | next [-]

No, that's ridiculous. If I want to send an app to someone, now they have to wipe their phone to install it? That would kill installing non-Play apps far more than Google's original proposal.

eviks 18 minutes ago | parent | prev | next [-]

But wiping your phone isn't "a little pain"

arcfour 3 hours ago | parent | prev | next [-]

I hadn't installed a non-Play Store app for something like 5 years until this year. I don't see why I should have been forced to factory reset my phone then.

g-b-r 2 hours ago | parent | prev [-]

Great, at phone setup when many people don't know anything about the implications of the choice.

And factory reset when it's impossible to backup and restore everything, or anything at all without a Google account

tadfisher 5 hours ago | parent | prev | next [-]

There's a second path, whereby F-Droid registers as an "alternative app store", which is a new category of app created in the fallout of Epic Games v. Google [0]. This is interesting because it applies to all regions and will necessarily need more elevated permissions than the typical REQUEST_INSTALL_PACKAGES permission used today. No idea what requirements Google will impose on such apps.

[0]: https://en.wikipedia.org/wiki/Epic_Games_v._Google

kragen 2 hours ago | parent | next [-]

What would they have to offer Google in return for being granted this status? Would they have to ban NewPipe, for example?

gpm 21 minutes ago | parent [-]

Up to what a committee of 3 people (or in the alternate district court judge James Donato) believes this means, assuming the judge approves the proposed modification to the injunction in the first place

> Google may create reasonable requirements for certification as a Registered App Store, including but not limited to review of the app store by Google’s Android team and the payment of reasonable fees to cover the operational costs associated with the review and certification process. Such fees may not be revenue proportionate.

One appointed by Google, one by Epic, one appointed by the other two. All three will be barred from private communications about any of this with any parties.

Considering this is an anti-trust suit I suspect the judge would be extremely unamused if the committee members found that "must ban NewPipe" was a reasonable requirement.

BrenBarn 2 hours ago | parent | prev [-]

Yes, that possibility has occurred to me as well, and is potentially a reasonable compromise (depending on those requirements).

NewJazz 5 hours ago | parent | prev | next [-]

If F-Droid is no longer part of the android community, then neither will I.

I'm not too worried. My employer should be, though.

AndrewDavis 5 hours ago | parent | prev | next [-]

It all depends on how the flow is implemented.

If it's a one time unlock, eg like developer mode then hopefully it'll just work.

If it's a big long flow per install... Yikes, that's not much better than adb install

andrepd 5 hours ago | parent | prev [-]

Correct me if I'm wrong but doesn't the EU digital markets act mandate this?

advisedwang 2 hours ago | parent | next [-]

EU digital markets mandates that you can install apps through f-droid... but doesn't mandate that those apps don't to comply with Google's signing policy.

gumby271 5 hours ago | parent | prev [-]

Isn't Apple technically complying with this even while forcing notarization? Seems like Google could get away with the same scheme.

gpm 4 hours ago | parent [-]

Apple says they are. The EU says they aren't. They're fighting over it.