Live data from Hacker News

Google will allow only apps from verified developers to be installed on Android

9to5google.com

101–110 of 1001 posts

Re: Google will allow only apps from verified developers to be installed on Android

#102

Anyone even remotely privacy or security conscious needs to vote with their wallet in protest and stop buying Android phones, otherwise it's only a matter of time 'til Google bans side-loading and it becomes impossible to buy a phone that can run any kind of anonymous or end-to-end encrypted communication software.

Stop buying Android and what? Buy an iPhone that's even more locked down or live like an outcast that can't access essential services? Because those are the realistic options.

Re: Google will allow only apps from verified developers to be installed on Android

#104
They have the ecosystem by the balls. Phone manufacturers in recent years have been making unlocking & modifying their devices more and more difficult, google and app developers have been cracking down harder on modded devices by implementing TPM equivalents in the hardware to sign and verify that your system is a google-appproved one, and alternatives still are decades behind in terms of app ecosystem.

I think they might just get away with it.

Re: Google will allow only apps from verified developers to be installed on Android

#105

Official announcement: https://android-developers.googleblog.com/2025/08/elevating-... More info: https://developer.android.com/developer-verification https://support.google.com/googleplay/android-developer/answ... Personally...we all know the Play Store is chock full of malicious garbage, so the verification requirements there don't do jack to protect users. The way I see it, this is nothing but a power grab, a way…

> But it's hidden, apparently because keeping users from using it to block ads on apps is of greater concern to Google than keeping people safe. The internet permission has nothing to do with ads? It's a hidden permission because: 1) Internet connection is so ubiquitous as to just be noise if displayed 2) It's not robust, apps without Internet permission can still exfiltrate data relatively easily by bouncing off of…

> 1) Internet connection is so ubiquitous as to just be noise if displayed

That doesn't make it any less useful.

> 2) It's not robust, apps without Internet permission can still exfiltrate data relatively easily by bouncing off of other apps using Intents and similar

I've heard claims that the Internet permission is flawed, yes, but I've never managed to find even a single PoC bypassing it. But even if it is flawed, don't you think Google would be a bit more incentivized to make the Internet permission work as expected if people could disable it?

Re: Google will allow only apps from verified developers to be installed on Android

#108

So that's it then. If this actually goes through, there will be no option in the mobile OS market for an OS that both: a) allows the installation of apps without any contractual relationship with any party, and b) allows the use of mainstream and secure apps like banking

In time, you will only be able to access banking from your desktop using an approved OS and browser with attestation...

De facto, this is already the case - you can use your computer as a display but to actually authorize a login or transaction you need your phone with said attestation.

Re: Google will allow only apps from verified developers to be installed on Android

#109
(Responding to https://techcrunch.com/2025/08/25/google-will-require-develo... )

> Starting next year, Google will begin to verify the identities of developers distributing their apps on Android devices, not just those who distribute via the Play Store.

Odd little phrase, "distributing their apps on Android devices".

I think "distributing" in this context is in the sense of product distribution, not in the sense of distributed systems.

But "distributing...on" sounds a little odd, like Google is still providing a distribution service. (Contrary to all the precedent of how we've thought of installing software, other than the proprietary, captive-user app stores.)

And so, maybe "distributing...on" makes it sound more like Google is (once again) entitled to gatekeep what you can run on your device/computer.

> However, developers who appreciated the anonymity of alternative distribution methods will no longer have that option. Google says this will help to cut down on bad actors who hide their identity to distribute malware, commit financial fraud, or steal users’ personal data.

Maybe it's not "developers who appreciated the anonymity" (which we immediately try to conflate with bad actors), but that the whole point lately has been to stop the greedy proprietary lock-in app store monopolies, and not have them gatekeeping what everyone else can do.

Post reply on HN