Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

131–140 of 694 posts

Re: Android developer verification: Early access starts

#131

There are many real-world sideloading abuse cases in China. Attackers often trick victims with plausible stories—e.g., claiming a flight is delayed—and ask them to sideload an app (a remote‑meeting or remote‑control tool) to share their screen. Once installed, the attacker can view the victim’s screen and intercept SMS 2FA codes for online banking or other sensitive accounts. Other schemes include impersonating sex w…

Yes, this is called malware and isn't the fault of being able to install software on your device.

If someone tricks you into handing over the keys to the kingdom, the solution isn't to remove your door.

Re: Android developer verification: Early access starts

#132
post #120

The key question for me is whether this "advanced flow" will allow the practical use of entirely separate app stores (like F-Droid) or if they're going to throw up tons of barriers for every individual app install.

If I were designing the advanced flow, I'd require the decision to be made at phone setup time. Changing your mind later requires a factory reset. Real sideloaders (F-Droid users, etc.) know at setup time that that's how they'll be using their phone, so it works for them. But ordinary users who are targets for sideloading malware will become a lot less attractive if attackers must convince them to wipe their phone to…

No, that's ridiculous. If I want to send an app to someone, now they have to wipe their phone to install it? That would kill installing non-Play apps far more than Google's original proposal.

Re: Android developer verification: Early access starts

#133
post #36
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

I bought the hardware, therefore I have the right to modify and repair. Natural right, full stop. That right ends are your nose, as the saying goes.

This is correct. Our natural rights go much further than unnatural prohibitions from the government.

Do what you please and get enough people to do it with you, and no one can stop you.

Re: Android developer verification: Early access starts

#134
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

> the governments of countries where such scams are widespread will hold Google responsible.

This argument is FUD at this point.

Sovereign governments have ways to make clear what they want: they pass laws, and there needs to be no back deal or veiled threats. If they intend to punish Google for the rampant scams, they'll need a legal framework for that. That's exactly how it went down with the DMA, and how other countries are dealing with Google/Apple.

Otherwise we're just fantasizing on vague rumors, exchanges that might have happened but represent nothing (some politicians telling bullshit isn't a law of the country that will lead to enforcement).

This would be another story if we're discussing exchanges with the mafia and/or private parties, but here you're explicitely mentionning governments.

Re: Android developer verification: Early access starts

#135
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

If nobody pushed back on anything we'd all be subjected to the laws of the worst country on earth, because big tech companies want to do business there, and putting an if/else around the user's country takes effort.

Re: Android developer verification: Early access starts

#136
post #123
post #104

Earlier quoted context omitted.

BINGO! Google doesn't care at all about user security. - Just yesterday there was a story on here about how Google found esoteric bugs in FFMPEG, and told volunteers to fix it. - Another classic example, about how Google doesn't give a stuff about their user's security is the scam ads they allow on youtube. Google knows these are scams, but don't care because they there isn't regulation requiring oversight.

> Just yesterday there was a story on here about how Google found [a security vulnerability that anyone running `ffmpeg -i ...` was vulnerable to] in FFMPEG, and told [the world about it so that everyone could take appropriate action before hackers found the same thing and exploited it, having first told the ffmpeg developers about it in case they wanted to fix it before it was announced publicly] Fixed that for you.…

> and highly appreciated.

Not by the maintainers it wasn't Mr. Google.

Re: Android developer verification: Early access starts

#137
post #136
post #123

Earlier quoted context omitted.

> Just yesterday there was a story on here about how Google found [a security vulnerability that anyone running `ffmpeg -i ...` was vulnerable to] in FFMPEG, and told [the world about it so that everyone could take appropriate action before hackers found the same thing and exploited it, having first told the ffmpeg developers about it in case they wanted to fix it before it was announced publicly] Fixed that for you.…

> and highly appreciated. Not by the maintainers it wasn't Mr. Google.

Yes, but it was a public service not a service for the maintainers, and as a member of the public who like anyone who had run `ffmpeg -i ` was previously exposed to the vulnerability I highly appreciate their service.

I'd highly appreciate even if the maintainers never did anything with the report, because in that case I would know to stop using ffmpeg on untrusted files.

Re: Android developer verification: Early access starts

#138
post #17

Earlier quoted context omitted.

Google have their own reasons too. They would love to kill off YouTube ReVanced and other haxx0red clients that give features for free which Google would rather sell you on subscription. Just look at everything they've done to break yt-dlp over and over again. In fact their newest countermeasure is a frontpage story right beside this one: https://news.ycombinator.com/item?id=45898407

yt-dlp's days are fairly numbered as Google has a trump card they can eventually deploy: all content is gated behind DRM. IIRC the only reason YouTube content is not yet served exclusively through DRM is to maintain compatibility with older hardware like smart TVs.

All levels of Widevine are cracked, but only the software-exclusive vulnerabilities are publicly available. It's only used for valuable content though (netflix/disney+/primevideo), so it might still work out for YouTube as no one will want to waste a vulnerability on a Mr. Beast slop video.

Re: Android developer verification: Early access starts

#139
post #41

Earlier quoted context omitted.

But see also the next section ("empowering experienced users"): > We are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified

it's probably just gonna be under the Developer Options "secret" menu

Which is totally fine IMO, it was weird to me that they weren't going with this approach when they first announced it.

Macs blocked launching apps from unverified devs, but you can override in settings. I thought they could just do something along those lines.

Re: Android developer verification: Early access starts

#140

There are many real-world sideloading abuse cases in China. Attackers often trick victims with plausible stories—e.g., claiming a flight is delayed—and ask them to sideload an app (a remote‑meeting or remote‑control tool) to share their screen. Once installed, the attacker can view the victim’s screen and intercept SMS 2FA codes for online banking or other sensitive accounts. Other schemes include impersonating sex w…

Why should that mean anyone else should lose control of their device? Maybe at some point you have to accept that it's the user's responsibility? Maybe empower users to be aware of what the apps they install are doing, without take their control away?

This is how loss of autonomy always happens in every sphere: make an argument that it's for their own safety that individuals are losing autonomy, and the entity gaining control is superior in knowing what's best, and is taking control only out of the goodness of their heart.

Post reply on HN