frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Google adds 24-hour wait and mandatory reboot to Android sideloading flow

https://android-developers.googleblog.com/2025/08/elevating-android-security.html
88•dfordp11•1h ago

Comments

taspeotis•1h ago
Did they add another one?

https://news.ycombinator.com/item?id=47442690

dfordp11•1h ago
I must have missed that yesterday.
RicoElectrico•35m ago
This is so outrageous I wouldn't mind it being on the front page every day until they back off.
riedel•13m ago
Actually this OP seems to be the old announcement from 2025 with no additional news as far as I saw. If implemented like this, it will be horror.

The baseline for a usable solution for me is still that I can keep my banking apps and that I am able to use fdroid trusted builds from source, can install builds from other open source CI builds, install builds from my students I know personally without needing them to verify with a foreign entity and publishing their personal data.

Practically the law will require me to buy another 'developer phone' the for work. Actually allowing more profiles like the work or hidden profile would allow users to at least chose per profile and could at least put their banking apps into a sandbox where they work (requirement would be that Google wallet can also run from such a profile) . I actually would be very happy to run the main profile without any Google play services like Graphene does: I guess a lot of data protection risks would be solved by this.

dfordp11•11m ago
yeah i accidently added an old article while copy pasting the link, the orginal blog was released yesterday on developer blog and is prob linked below.

I have asked the admin to update this with the latest blog, as i can't update it myself nor i can remove the submission

panny•1h ago
>A new layer of security for certified Android devices

May I purchase a non-certified android device now? Because frankly, fuck you.

girvo•1h ago
Not if you want to run any of your banking apps or all sorts of things. The open android I knew and loved is long gone
koolala•1h ago
It could be worse. Do this after you buy the phone and then in 24 hours its like normal.
gabordemooij•18m ago
no because, from what I understand you have to do this on a per-app (per version even?) basis
selectively•1h ago
The 'headline' is false. This is specifically for unsigned applications, not for all sideloaded apps.
phr4ts•58m ago
I hope consumers return these phones in droves like Windows RT and Windows 10 S. The issue is that sideloading isn’t an immediate concern—users would only realize the limitation later, when it’s too late to return the device.
fluxusars•12m ago
Return them and get what instead? Every other popular phone platform is even more restrictive.
butz•41m ago
Following this logic, adding a checkbox "I swear this app does not contain malware" to app publishing process would solve the problem with malicious apps on Play Store, right?
askonomm•31m ago
So I buy a device ... with my own money ... which I supposedly then own, but then I need to ask some corporation permission to use it, and it treats me like a toddler by giving me a 24 hour wait period for the ability to install applications on that device? I'd understand if this "feature" was a part of Parental Controls, but I'm not a child, so this is insulting. I see Google saw how Microsoft likes to spit on its users and wanted a piece of that action. How is this legal?
xyzzy123•22m ago
This will not be a popular comment, but...

A 24 hour wait like this can sometimes be the result of a security team not knowing what else to do. There are all sorts of weird threat models when you think hard about how devices are used, like partners who have legit access to a phone at a certain point in time.

askonomm•10m ago
What's next? I buy a car which I cannot drive in certain locations unless I ask for permission and wait 24h? Daddy Car Dealership please let me drive in this location, pretty please?
Markoff•22m ago
you buy your hardware, you don't buy the software, you buy the license to use the software according license terms
b00ty4breakfast•16m ago
If the hardware wasn't locked down on so many devices, this wouldn't be an issue because people could choose to use a different OS.
gabordemooij•14m ago
fine, but can you buy alternatives that run your software then?
globular-toast•18m ago
You are essentially a child to them. A child is just someone who has not yet developed the power to survive in a world full of adults. This is why parents guard and protect children, and when that fails society steps in to do it instead.

You are just a child to them. Not powerful enough to stick up for yourself. Ripe for abuse. The difference is society has decided not to step in to protect you from your abusive parents.

L-four•18m ago
This post is propaganda. You don't own the phone. The term "buy" is defined as "revocable anytime lease".
pmarin•29m ago
WHy not just add a hardware switch to allow Android sideloading?

Are these multibillion companies so incompetent to not think about it?

pprotas•27m ago
It’s not incompetence, it’s malice
rapidaneurism•21m ago
If they add a switch people might use the switch. You are confusing the excuse with the reason.
tuom1s•27m ago
I may be missing something, but what does the title have to do with the article? There is no mention about any waiting or mandatory reboot. What does OP have in mind?
dfordp11•25m ago
yeah i was researching and accidently added an old article while copy pasting the link, the orginal blog was released yesterday on developer blog and is prob linked below.

I would have added it here, but i don't want hn to be label my account as spam

r721•23m ago
>25 August 2025
Markoff•20m ago
this was already discussed, so no point for dupe, but there is no wait period for ADB install

and AFAIK this also affects only unverified developers, though hard to imagine why would someone install app from verified dev outside the play store, for the record I don't have gapps in my phone and use Aurora

gabordemooij•19m ago
Would it not be nicer to have a dual boot phone where one OS is baked in rom and only contains certain necessary government/banking/medical service apps and the other is just completely free to use for whatever purpose? Just a thought...
mindslight•15m ago
The only sane way to buy a device is to pick a user-representing OS (eg Graphene), pick a device from its list of supported devices, and then install your desired OS on that device as soon as you get it as part of your setup process. Then if it's 24, 48, or 168 hours to receive your unlock code to install the secure OS, it's all just part of the setup process (and if they refuse to unlock for whatever reason, then you're still in the return period!). The longer you let the surveillance industry keep its hooks in you, the more friction and dependence they will add to every single thing you want to do that goes against their business interests.
Narkov•14m ago
> Think of it like an ID check at the airport

That's an interesting way of selling this.

ece•13m ago
There should be one screen each for self signing individual apps and updates, and another one for adding a public app store key to allow verifying apps and updates from that key. That would be factual and not scary. Yes, the question should be asked of the play store too.

People should by default not trust a developer or store that is scaring you into doing something.

petterroea•7m ago
In school I learned the definition of politics was "the distribution of benefits and burdens". We can and probably should view this as a political question. The benefit is the consumer right to do whatever you want with the device you bought (used by some), vs the burden of making yourself attackable by scammers etc. Google are pushing first and foremost for protecting end-users from scammers. They do benefit from this, so there is probably an incentive for them to do so. It is very practical that they can call locking down their phones "protecting users".

The big question here is where on the balance scale we care about "protecting users against scammers" vs "protecting users against enshittification, closed ecosystems, and possible future power grabs". One side is very tangible and easy to understand, the other more abstract, and most consumers simply don't understand it well enough to make educated choices about it. This uncertainty is being used by powers that benefit from pushing towards the "lock-down" extreme of the scale. Peter Thiel said so himself.

It is also worth noting that it is these security guys' job at Google to invent security schemes. All in all they did their job as engineers, and ignoring personal responsibility to engineer solutions that balance needs not only technical but also social, they did everything right. In a larger society there should be people who take on the job of setting boundaries for these technical solutions. Just like you need technical people to push back on technical demands from non-technical people within a company, we people who push back on this sort of stuff in our society. Us technical folks are best suited to do this job.

TL;DR: The political question boils down to how many grandmas are we as a society happy with getting scammed in the name of protecting consumer freedoms? In the extreme and hyperbolic case, are we happy with an infinite number of grandmas being sacrificed? Where on the line do we want to be? And what other measures can we put into place to make the problem easier to solve without sacrificing basic freedoms? If you are technical you should probably consider taking more space in the public debate.

Sexual Harassment by Japan Railways Staff and Japan's Accessibility Barriers

1•LemurianHiro•12m ago•0 comments

The Black Sun

https://twitter.com/netcapgirl/status/2034472134022500462
1•tosh•16m ago•0 comments

Man pleads guilty to $8M AI-generated music scheme

https://therecord.media/man-pleads-guilty-8-million-ai-music-scheme
6•nstj•18m ago•0 comments

Show HN: Another open source photo management system

https://github.com/openphotos-ca/openphotos
1•apollo1213•18m ago•0 comments

Microsoft Clarity returning 503 on all tag requests?

1•maiconburn•20m ago•0 comments

Interwhen: A Generalizable Framework for Verifiable Reasoning

https://arxiv.org/abs/2602.11202
1•dimmuborgir•23m ago•0 comments

Blocking Internet Archive Won't Stop AI, but Will Erase Web's Historical Record

https://www.eff.org/deeplinks/2026/03/blocking-internet-archive-wont-stop-ai-it-will-erase-webs-h...
3•pabs3•24m ago•0 comments

Zvec – A lightweight in-process vector database

https://zvec.org/en/
1•lormayna•24m ago•1 comments

Page-Agent.js: The GUI Agent Living in Your Webpage

https://github.com/alibaba/page-agent
2•fofoz•31m ago•0 comments

The Displacement of Cognitive Labor and What Comes After

https://sahajgarg.github.io/blog/cognitive-labor/
1•vinhnx•33m ago•0 comments

Tangem's firmware cannot be updated – by design, to eliminate attack vectors

https://tangem.com/en/blog/post/tangem-vs-ledger-comparison/
1•swq115•34m ago•0 comments

Trending GitHub Repositories ( trending_repos) / X

https://x.com/trending_repos
1•tomstig•39m ago•0 comments

Getlamina.ai – Tools for Building

https://getlamina.ai
1•baskins•40m ago•0 comments

Our Commitment to Windows Quality

https://m135.e-mails.microsoft.com/rest/head/mirrorPage/@Bzb1dZA3t5JH6FnvgPs_KP3QOnL8brb0QOk2GnyX...
2•chris_wot•44m ago•0 comments

FBI: Russia targeting 'high intelligence value' Americans on Signal

https://thehill.com/policy/international/5794275-russian-hackers-target-americans-signal/
1•0in•45m ago•0 comments

Added cross-device reading sync to my Chrome extension

https://chromewebstore.google.com/detail/readr-–-clean-page-one-cl/acpeognnfhdbfdmdpkfbjgppjpgp...
1•Ogbon•52m ago•0 comments

A micro sandbox, built by agents for agents

https://chenhunghan.github.io/sanbox/
1•chenhunghan•52m ago•1 comments

Houston Woman sues Tesla for $1B following self-driving crash [video]

https://www.wfaa.com/video/news/local/a-houston-woman-sues-tesla-claiming-her-truck-crashed-while...
1•6stringmerc•57m ago•0 comments

Been There, Done That – A History of Replacing Schools with AI

https://stager.tv/?p=7675
2•the-mitr•58m ago•0 comments

Democracy Is a Liability

https://geohot.github.io//blog/jekyll/update/2026/03/21/democracy-liability.html
2•rvz•1h ago•0 comments

Italy, Belgium set to lose gas supply after biggest LNG plant bombed

https://www.politico.eu/article/italy-belgium-lose-gas-supply-world-biggest-lng-plant-bombed/
10•leonidasrup•1h ago•0 comments

What Is ProxyBase MPP?

https://proxybase.xyz/blog/what-is-proxybase-mpp
1•m00dy•1h ago•0 comments

Save up to 60% API costs without TOON

https://lesstokens.hive-hub.ai/
1•GuilhermeVNZ•1h ago•1 comments

Add age verification to accounts service

https://gitlab.freedesktop.org/accountsservice/accountsservice/-/merge_requests/176#0b07c0cc4d49b...
4•e145bc455f1•1h ago•1 comments

Israeli startup Thermagix harvesting low grade heat

https://www.calcalistech.com/ctechnews/article/dfpboxzg9
2•tomerbd•1h ago•0 comments

Writing a Verified Postfix Expression Calculator in Ada/Spark

https://pyjarrett.github.io/2025/06/10/postfix-calculator.html
1•notagoodidea•1h ago•0 comments

Re:Do Workouts

https://redoworkouts.com/
1•danielauener•1h ago•0 comments

Ask ChatGPT to pick a number from 1-10000, it generally selects from 7200-7500

https://old.reddit.com/r/ChatGPT/comments/1rz2ooh/i_am_betting_my_house_that_if_you_ask_gpt_to_pick/
32•mellosouls•1h ago•35 comments

World Cup Trophy Theft: Gangsters, Spies and the Dog That Found It

https://www.bloomberg.com/news/articles/2026-03-20/the-1966-world-cup-trophy-theft-gangsters-spie...
1•helsinkiandrew•1h ago•0 comments

Google adds 24-hour wait and mandatory reboot to Android sideloading flow

https://android-developers.googleblog.com/2025/08/elevating-android-security.html
88•dfordp11•1h ago•38 comments