This is Android's new 'advanced flow' for sideloading apps without verification, includes one-day waiting period
This is Android's new 'advanced flow' for sideloading apps without verification, includes one-day waiting period
It appears that the “security wait” will be a one time thing when you first allow installing from unverified sources. After enabling it it will remain on indefiniately.
Not quite as bad as I was fearing, but will kinda annoying.
It looks like a glorified ‘developer mode’ switch that has the 1 day wait to prevent someone from grabbing your phone, turning on sideloading, installing some hazardous app, and then having their way with your info. This appears to be the best of both worlds.
Like when unlocking your bootloader wiped your info. Just do it first. not a year in to using your device, if thats your plan.
Lmfao. I’ll invent a better way and it will only take me negative 50 years.
Passcode.
There is absolutely nothing positive about this. It is only nefarious, full stop. I could open a million dollar restaurant that served microwaved cat shit, but on the menu it’s called “Tbone Steak” and with your logic, people wouldn’t notice the difference.
Okay, pump the breaks a second.
I agree a day wait is bullshit, but you think a passcode is enough to keep someone from… anything? You can shoulder surf a passcode in no time at all. Hell, it’s not even difficult. Go to a bar, talk someone up, give a legit reason to use someone’s phone, intentionally lock and force a passcode and 99% of people at bars will put their pin in within eyesight, or tell you the code.
A passcode isn’t as big a deterrent as most people seem to think it is. It’ll keep you out of an unattended phone you found, but there are plenty of ways to socially engineer your way into having it for the vast majority of targets.
And yes, you likely wouldn’t give your passcode out. But this is how a number of ne’er-do-wells got unfettered access to hundreds of iPhones, and prompted Apple to put a semi similar 24 hour lock on certain security actions if you aren’t in a “known to the phone” location (somewhere you frequent like home or work).
When you couple what you just said with what they’re trying to do, your own argument can be made in my favor.
One of my hobbies in college was shoulder surfing classmates passwords just to repeat it back to them later in the day. Though on a phone you have far fewer reasons to type in an associated accounts password.
Never tell anyone else this again, and stop doing it. What an insane invasion of privacy.
My security should be my choice on my device end of story. My password/passcode plus encryption with easily accessible ways to put it into lockdown mode and have lockdown mode on a continuous timer is absolutely enough for my threat model.
I don’t need any else making any addition call on it, and I definitely don’t need someone that is willingly bragging about invading others privacy coaching me on what these companies are intending while actively trying to take my right to privacy away.