Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

191–200 of 694 posts

Re: Android developer verification: Early access starts

#191
post #51
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

Or maybe Google just has empathy for people losing millions to scams?

The Play Store is full of of scam apps so obviouly they don't.

Re: Android developer verification: Early access starts

#192
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

> there cannot exist an easy way for a typical non-technical user to install “unverified apps” (whatever that means), because the governments of countries where such scams are widespread will hold Google responsible.

What, the same way they hold Microsoft responsible for the fact that you can install whatever you want in Windows?

Obviously, there can exist an easy way for a non-technical user to install unverified apps, because there has always been one.

Re: Android developer verification: Early access starts

#193

Earlier quoted context omitted.

Yeah, let's ask the Debian team about installing packages from third party repos. I'm not on the side of locking people out, but this is a poor argument.

> Yeah, let's ask the Debian team about installing packages from third party repos. Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows. Hence you don't realize how good of an argument it is, because you even bamboozled yourself without realizing it. It gets a worse argument if we want to discuss Qubes and other di…

"Debian already is sideloaded on the graciousness of Microsoft's UEFI bootloader keys. Without that key, you could not install anything else than MS Windows."

This is only true if you use Secure boot. It is already not needed and insecure so should be turned off. Then any OS can be installed.

Re: Android developer verification: Early access starts

#195
post #2

Sounds like they're rolling back the mandatory verification flow: Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure…

I'm a little nervous about what this advanced flow is going to look like, given that sideloading already requires jumping through a bunch of hoops to enable and even that apparently wasn't enough to satisfy Google.

I'm cautiously optimistic though. I'm generally okay with nanny features as long as there's a way to turn them off and it sounds like that's what this "advanced flow" does.

Re: Android developer verification: Early access starts

#196
post #31

Earlier quoted context omitted.

So.. all this drama over an alert(yes/no) box? Wow, this really pulls back the veil. This Vendor (google) is only looking out for numero uno.

> So.. all this drama over an alert(yes/no) box? The angry social media narratives have been running wild from people who insert their own assumptions into what’s happening. It’s been fairly clear from the start that this wasn’t the end of sideloading, period. However that doesn’t get as many clicks and shares as writing a headline claiming that Google is taking away your rights.

> The angry social media narratives have been running wild from people who insert their own assumptions into what’s happening.

No, until this post, Google had said that it wouldn't be possible to install an app from a developer who hadn't been blessed by Google completely on your device. That is unacceptable. This blog post contains a policy change from Google.

Re: Android developer verification: Early access starts

#197
post #101

Earlier quoted context omitted.

I would like a world where buying something means you get final say over how it operates even if you might do something dangerous/harmful/illegal.

I would like a world where I have the final say over whether I should have a final say. One way to achieve this is to only allow sideloading in "developer mode", which could only be activated from the setup / onboarding screen. That way, power users who know they'll want to sideload could still sideload. The rest could enjoy the benefits of an ecosystem where somebody more competent than their 80-year-old nontechnica…

I'm not sure I like the idea of "you have to wait 48 hours now for sideloading in case you are an idiot". Most idiots will then have sideloading on after 48 hours and still get hit with the next scam anyway.

Re: Android developer verification: Early access starts

#198
post #36
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

I bought the hardware, therefore I have the right to modify and repair. Natural right, full stop. That right ends are your nose, as the saying goes.

Oh, so you're good with everyone having the "natural right" to turn handguns into automatic weapons simply because they find themselves in possession of the correct atoms? How about adding a 3rd story on the top of your house without needing a permit or structural evaluation?

Note that adding "full stop" pointlessly to the end of sentences does not strengthen your argument.

Re: Android developer verification: Early access starts

#199
post #128

> When the user logs into their real banking app, the malware captures their two-factor authentication codes That seems like a severe security bug in Android APIs or sandboxing or something else. > bad actors can spin up new harmful apps instantly Why are harmful apps possible at all?

As soon as a platform gives control to the fullscreen, harmful apps are possible.

See for example Apple detecting if a user is typing on a keyboard while in a fullscreen website, and then blocking the website. Yes it's as crazy as it's sounds.

Re: Android developer verification: Early access starts

#200
post #108

Earlier quoted context omitted.

> Why should apps have access to a user's SMS / RCS? It could be an alternative SMS app like TextSecure. One of the best features of Android is that even built-in default applications like the keyboard, browser, launcher, etc can be replaced by alternative implementations. It could also be a SMS backup application (which can also be used to transfer the whole SMS history to a new phone). Or it could be something like…

That's all indeed valid. > One of the best features of Android is that even built-in default applications like the keyboard, browser, launcher, etc can be replaced by alternative implementations. When sideloading is barred all that can easily change. If you are forced to install everything from the Google Play Store, Google can easily bar such things, again in the name of "security" - alternate keyboards can steal yo…

> Instead of that, why not make it so that an app can access SMS / RCS only when that option is allowed when you have a special Google Account?

Because then you still need a special Google Account to install your app when it needs to access SMS / RCS.

How about solving this problem in a way that doesn't involve Google rather than the owner of the device making decisions about what they can do with it? Like don't let the app request certain permissions by default, instead require the user to manually go into settings to turn them on, but if they do then it's still possible. Meanwhile apps that are installed from an app store can request that permission when the store allows it, so then users have an easy way to install apps like that, but in that case the app has been approved by Google or F-Droid etc. And the "be an app store" permission works the same way, so you have to do it once when you install F-Droid but then it can set those permissions the same as Google Play.

It's not Google's job to say no for you. It's only their job to make sure you know what you're saying yes to when you make the decision yourself.

Post reply on HN