Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

211–220 of 694 posts

Re: Android developer verification: Early access starts

#211
post #74

Earlier quoted context omitted.

Its my device. Not google's. Imagine telling you which NPM/PIP packages you can install from your terminal. Also, its not SIDE loading. Its installing an app.

I agree, but I don't see why Google gets more critical attention than the iPhone or Xbox.

iPhone has always been that way (try installing an .ipa file that's not signed with a valid apple developer certificate). For Google forced app verification is a major change. Xbox I don't know..

Re: Android developer verification: Early access starts

#213
post #128

> When the user logs into their real banking app, the malware captures their two-factor authentication codes That seems like a severe security bug in Android APIs or sandboxing or something else. > bad actors can spin up new harmful apps instantly Why are harmful apps possible at all?

> That seems like a severe security bug in Android APIs or sandboxing or something else.

No, this is the permissioned API that makes KDE Connect work, which makes Apple's Continuity look like a toy and that also lets me programmatically filter notifications.

Re: Android developer verification: Early access starts

#214
post #109
post #92

Earlier quoted context omitted.

> So.. all this drama over an alert(yes/no) box? A simple yes/no alert box is not "[...] specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer". In fact, AFAIK we already have exactly that alert box. No, what they want is something so complicated that no muggle could possibly enable it, either by accident or by being guided on the ph…

I imagine what they're going to do involves a time delay so a scammer cannot wait on the phone with a victim while they do it.

I agree. Waiting to see for how long. Has to be 24 hours at a minimum I'd guess.

Re: Android developer verification: Early access starts

#215
post #36

Earlier quoted context omitted.

I bought the hardware, therefore I have the right to modify and repair. Natural right, full stop. That right ends are your nose, as the saying goes.

I suppose you have the right to do whatever you want with it, including zapping it in the microwave or using it as a rectal probe. I am not sure that right extends are far as forcing companies to deliver a product to your specifications (open software, hardware, or otherwise)

You won't believe it, but many years ago the TVs for sale where required to come with their full schematics and they really did.

Re: Android developer verification: Early access starts

#216
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

I don't buy this argument at all that this specific implementation is under pressure from the government - if the problem is indeed malware getting access to personal data, then the very obvious solution is to ensure that such personal data is not accessible by apps in the first place! Why should apps have access to a user's SMS / RCS? (Yeah, I know it makes onboarding / verification easy and all, if an app can acces…

Because Tasker is fundamental for some. Those arguments are similar to "think of children".

Re: Android developer verification: Early access starts

#217
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

> there cannot exist an easy way for a typical non-technical user to install “unverified apps” (whatever that means), because the governments of countries where such scams are widespread will hold Google responsible. What, the same way they hold Microsoft responsible for the fact that you can install whatever you want in Windows? Obviously, there can exist an easy way for a non-technical user to install unverified ap…

This is actually a good point, and something I've been wondering about too. What changed between the 90s and now, that Microsoft didn't get blamed for malware on Windows, but Google/Apple would be blamed now for malware on their devices? It seems that the environment today is different, in the sense that if (widespread) PCs only came into existence now, the PC makers would be considered responsible for harms therefrom (this is a subjective opinion of course).

Assuming this is true (ignore if you disagree), why is that? Is it that PCs never became as widespread as phones (used by lots of people who are likely targets for scammers and losing their life savings etc), or technology was still new and lawmakers didn't concern themselves with it, or PCs (despite the name) were still to a large extent "office" devices, or the sophistication of scammers was lower then, or…? Even today PCs are being affected by ransomware (for example) but Microsoft doesn't get held responsible, so why are phones different?

Re: Android developer verification: Early access starts

#218

Earlier quoted context omitted.

It's not a separate problem, Google are actively suppressing any possibility of open mobile hardware. They force HW manufacturers to keep their specs secret and make them choose between their ecosystem and any other, not both. There's a humongous conflict of interests and they're abusing their dominating position.

> They force HW manufacturers to keep their specs secret Spoken like someone who has never ever worked with any hardware manufacturers. They do not need reasons for that. They all believe their mundane shit is the most secret-worthy shit ever. They have always done this. This predates google, and will outlive it.

Often it is because they don't know their own devices. We got a dev board from Qualcomm once and the documentation was totally bogus.

Re: Android developer verification: Early access starts

#219
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

I don't buy this argument at all that this specific implementation is under pressure from the government - if the problem is indeed malware getting access to personal data, then the very obvious solution is to ensure that such personal data is not accessible by apps in the first place! Why should apps have access to a user's SMS / RCS? (Yeah, I know it makes onboarding / verification easy and all, if an app can acces…

Its a fact even if you dont buy this

Re: Android developer verification: Early access starts

#220
They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed.

You will not be able to use any of your banking apps without first removing all of those...

We need alternatives, this will not work and is a risk to freedom/democracy for all of us.

Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. However Google and Apple can just remove it, what then?

[1] https://github.com/swiyu-admin-ch

Post reply on HN