Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

361–370 of 694 posts

Re: Android developer verification: Early access starts

#361

> we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choi…

I also think we should stop calling it "sideloading". We need a better word. Sideloading has a negative vibe, as if it's a dangerous thing to install apps from sources other than the Play Store.

Re: Android developer verification: Early access starts

#362
post #3

> Keeping users safe on Android is our top priority. I highly doubt this is your "top" priority. Or if it is then you're gotten there by completely ignoring Google account security. > intercepts the victim's notifications And who controls these notifications and forces application developers to use a specific service? > bad actors can spin up new harmful apps instantly. Like banking applications that use push or SMS…

Their top priority is preventing people from using YouTube ReVanced or uBlock Origin on Firefox. That's their top priority.

Re: Android developer verification: Early access starts

#363

Earlier quoted context omitted.

>instead require the user to manually go into settings to turn them on, but if they do then it's still possible They clearly addressed this option in the post, under sufficient social engineering pressure these settings will easily be circumvented. You'd need at least a 24h timeout or similar to mitigate the social pressure.

> They clearly addressed this option in the post, under sufficient social engineering pressure these settings will easily be circumvented. You'd need at least a 24h timeout or similar to mitigate the social pressure. "Under sufficient social engineering pressure" is the thing that proves too much. A 24h timeout can't withstand that either. Nor can the ability for the user to use their phone to send money, or access t…

>By the time you're done the phone is a brick that can't do anything useful. At some point you have to admit that adults are responsible for the choices they make.

Absolutely this! It's just nanny state all over again.

Re: Android developer verification: Early access starts

#364
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad.

How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

Re: Android developer verification: Early access starts

#365
post #250

Earlier quoted context omitted.

This is not a win. This is having independent distribution shut down and controlled. We no longer own our devices. We're in a worse state than we were in before. Google is becoming a dictator like Apple.

It's not being shut down though. The article says that there will be a way to install unverified apps.

Ok, but sideloading is already a thing. What will this way to install unverified apps be? I doubt it will be an extra screen asking "Are you super-duper sure you want to enable sidloading???" after the one already asking the same question.

Re: Android developer verification: Early access starts

#366

Earlier quoted context omitted.

> because the governments of countries where such scams are widespread will hold Google responsible. This is the unsurprising consequence of trying to hold big companies accountable for the things people do with their devices: The only reasonable response is to reduce freedoms with those devices, or pull out of those countries entirely. This happened a lot in the early days of the GDPR regulations when the exact laws…

These two things are not the same. The GDPR afforded rights to common people. Those companies that would pull out are the ones that were abusing data that was never theirs and could no longer do so.

Nah. I know of several startups that had nothing but anonymous telemetry and they blocked all Europe because there was no capacity for compliance. I was at an incubator at the time and the decision was unanimous across a dozen or so companies. It’s not like anyone was going to lose out on VC money from that market

Re: Android developer verification: Early access starts

#367
post #108

Earlier quoted context omitted.

I don't buy this argument at all that this specific implementation is under pressure from the government - if the problem is indeed malware getting access to personal data, then the very obvious solution is to ensure that such personal data is not accessible by apps in the first place! Why should apps have access to a user's SMS / RCS? (Yeah, I know it makes onboarding / verification easy and all, if an app can acces…

> Why should apps have access to a user's SMS / RCS? It could be an alternative SMS app like TextSecure. One of the best features of Android is that even built-in default applications like the keyboard, browser, launcher, etc can be replaced by alternative implementations. It could also be a SMS backup application (which can also be used to transfer the whole SMS history to a new phone). Or it could be something like…

I'm not sure it's entirely fair to say this is just Google flexing control

Re: Android developer verification: Early access starts

#368
post #4

Edit: be sure to read geoffschmidt's reply below /edit The buried lede: > a dedicated account type for students and hobbyists. This will allow you to distribute your creations to a limited number of devices without going through the full verification So a natural limit on how big a hobby project can get. The example they give, where verification would require scammers to burn an identity to build another app instead…

You're right: if the logic is that low-install apps are the most dangerous (because they can fly under the radar), then making it easier for unverified apps to reach a "small" audience doesn't really solve the problem

Re: Android developer verification: Early access starts

#369

Earlier quoted context omitted.

> They clearly addressed this option in the post, under sufficient social engineering pressure these settings will easily be circumvented. You'd need at least a 24h timeout or similar to mitigate the social pressure. "Under sufficient social engineering pressure" is the thing that proves too much. A 24h timeout can't withstand that either. Nor can the ability for the user to use their phone to send money, or access t…

>By the time you're done the phone is a brick that can't do anything useful. At some point you have to admit that adults are responsible for the choices they make. Absolutely this! It's just nanny state all over again.

This is somehow even worse. It's strictly enforced with no regard for context, you don't have the constitutional rights you have against the government and you can't vote them out.

Markets are supposed to be better because you can switch to a competitor but that only applies when there is actually competition. Two companies both doing the same thing is not a competitive market.

Re: Android developer verification: Early access starts

#370

> we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choi…

The key will be whether they treat experienced users like adults after the initial opt-in
Post reply on HN