Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hmm I hope there's still a way to bypass this. I sideload all my apps using aurora store (so I don't have to sign in with a Google account) and I don't want them limited in functionality.


Yes, if you're willing to jump through scare dialogs and search for where in the UI to find "hidden" settings, you can manually override it per app as before.


Apps installed from alternative stores (using APIs made for those) aren't subject to those restrictions - it's written in the article.

It's explicilty restricted only to apps that don't use the new "app store" APIs in Android.


As with all non-feature creep, I feel the need to compulsively blurt out: "Yet."


Aurora isn't an official third party store. There isn't much chance that Google will whitelist it because it's a privacy alternative for the play store itself. Google has been all over it trying to block it so I doubt it will select it as an exception.


What do you mean "official third party store"? There's no such thing. It's an OS level API where store needs to register itself as a store unrelated to Google (it's an AOSP concept).


Read the article. There's an explicit white-list for being exempt from this new restriction and only "trusted installers" will be on it. Clearly the Play Store will be exempt, but we have no idea what will be put on the white list according to what criteria. As pointed out in the article's conclusion.


> Apps installed from alternative stores (using APIs made for those) aren't subject to those restrictions

These restrictions already exist for in call audio accessibility APIs. At least one call recorder app has gone as far as making their own app store to bypass these restrictions.


Increased restrictions on which programs may run and what they can do are the future of computing. We really can't afford the risks of letting everybody just run arbitrary code. Windows and macOS are next.

It didn't mention apps installed with 'adb install'. I think you might be able to run those with no restrictions. And LineageOS, GrapheneOS, and so forth may give you the option of disabling this feature or making it more configurable.


As far as desktop OSes go, I think the much larger problem is how to let users control the degree of sandboxing an application has. On mobile we're broadly used to each application asking for permissions (and whether we've trained users to just hammer 'allow' until it proceeds) and each is largely independent.

Windows also has its legacy software that wouldn't know about new restrictions, so would need dummy access until allowed, and UI for the user to gain understanding about why their newly downloaded utility can't access their webcam and all their files yet, and how to rectify that. Windows already has something like this through controlled folder access, but I've yet to hear of someone who turns it on. Part of the biggest strength of desktops is how all the software/hardware parts combine, so I think this is high stakes in terms of not pissing people off so the feature actually gets used.


Yes, the open software war has been lost fairly comprehensively and many programs that are routinely installed on computers are dreadful spyware, but instead of being random ill-advised junk from some forum, they're 389MB of analytics masquerading as productivity software from the very biggest corporate names in software.

Who know what all that evil junk is doing with its execute bit and filesystem and network access. (https://xkcd.com/1200/)

And if you think the situation is bad with Teams and Dropbox and other "Western-style" software, it's way worse elsewhere in the world.


'So today we have marketing departments who say things like "we don't need computers, we need... appliances. Make me a computer that doesn't run every program, just a program that does this specialized task, like streaming audio, or routing packets, or playing Xbox games, and make sure it doesn't run programs that I haven't authorized that might undermine our profits". And on the surface, this seems like a reasonable idea -- just a program that does one specialized task -- after all, we can put an electric motor in a blender, and we can install a motor in a dishwasher, and we don't worry if it's still possible to run a dishwashing program in a blender. But that's not what we do when we turn a computer into an appliance. We're not making a computer that runs only the "appliance" app; we're making a computer that can run every program, but which uses some combination of rootkits, spyware, and code-signing to prevent the user from knowing which processes are running, from installing her own software, and from terminating processes that she doesn't want. In other words, an appliance is not a stripped-down computer -- it is a fully functional computer with spyware on it out of the box.'

https://en.wikisource.org/wiki/The_Coming_War_on_General_Com...


If Macs too far down that road I’ll move to Linux for my desktop computing. It’s already getting annoying.


If it happens to you with any degree of regularity does that not imply that you are regularly granting new code access to sensitive aspects of your machine?

macOS is a far far cry from, let’s say, Vista UAC.


Updates break thing tha used to work. My mouse situation drives me crazy, and my Wacom Cintiq stopped working a couple of months back. File management is starting to be a problem.


Yes exactly. I already did just that.


> We really can't afford the risks of letting everybody just run arbitrary code.

The pleb running applications they want on the device they own? Madness!


While poorly phrased, I think the concern is legit. As somebody who wants full control over my system, I don't want most of the applications I use on a day to day basis to have that same full control over my system. I'm a separate entity from the programs I use and the people who make the programs I use. The world is so much more complex than it used to be. I'd rather applications be limited in what they can access on my system by default, and a way to change it based on my needs. I don't want the programs to decide on their own what they're entitled to anymore. There's been a fundamental breach of trust by too many actors too many times.


Yes, you should be able to run apps you want in a way you want. Not the way the manufacturer or OS vendor wants.

Of course sandboxing options should be available, but if you wanted to run an app fully unrestricted, you should be able to.

I am still quite upset that I cannot run call recording apps on Android as they can't obtain permission to record audio during a call.

edit:

Just to add, call recording is legal in my country. Years ago it saved me from losing money when insurance company attempted to scam me. I agreed to a policy over the phone based on the promised features. When I got the documents mailed, it turned out most of what was promised was missing in the agreement. Then company said they never promised these things and wanted to charge me substantial cancellation fee. Once I told them I have recordings, they backtracked on everything and cancelled it.

The other ways I found it very useful was recording calls with my doctor so I could listen again in case I forgot or misheard something and also I used to record calls with my very ill relative to have some memories of him.

Now I cannot do that anymore.


The key point for someone "who wants full control over my system" is that *you*, the end user, have the final say over what programs are entitled to.


End users can't be trusted. Most of them are a "Taylor Swift nudes here! Download this file, open it, and enable all requested permissions" away from being pwned. The most effective defense against this kind of attack has been allowlisting what can be run.


>We really can't afford the risks of letting everybody just run arbitrary code.

You are, of course, talking about JavaShit right?




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: