Remix.run Logo
Taterr 3 hours ago

I understand usually the megacorporation is simply being anti-consumer with these kinds of changes, and who knows maybe this is the same. But I think this might be an actual exception. They seem to be actually implementing a lot of high effort scam protection features recently in android so unless they did all of that just as an excuse to make side loading harder then they've fooled me.

https://security.googleblog.com/2026/02/strengthening-androi... https://blog.google/innovation-and-ai/technology/safety-secu...

For more context, the the "reason" they're increasing the friction in sideloading is to prevent one extremely specific scam where someone instructs you over the phone to download a malicious android app, which then steals your banks 2 factor verification code from your notifications and sends it to the scammers. The 24 hour limitation does seem specifically designed to prevent that so I'm inclined to believe them.

procaryote 2 hours ago | parent | next [-]

It's pretty easy to make up a reasonable sounding excuse for something you do for your own profit as a company. If they don't even provide any statistic on how frequent these scams are, it can be just words

Also, if your bank 2fa code is in your notifications, you should switch 2fa methods to something other than sms, or switch banks.

Taterr 5 minutes ago | parent [-]

So we should just accept that all apps must treat android notifications as a compromised communication channel?

The scammers will find some other way to abuse the very generous permissions allowed by an android app if you prevent the notification attack.

sunaookami an hour ago | parent | prev [-]

Do you also believe mass surveillance is necessary to protect children?

Taterr 26 minutes ago | parent [-]

No. Their stated implementations should be also privacy preserving as they are using on-device LLM models. Not sending your calls or texts to a datacenter.