Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

371–380 of 694 posts

Re: Android developer verification: Early access starts

#372
>we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified.

This is exactly the right thing to do and the best possible outcome. Google is correct that arbitrary Software installation can be harmful to users, especially those with limited technical knowledge. At the same time there are many users who want to install software freely and should be able to do so.

The compromise of a clear and unambiguous warning of the potential dangers, which the user is then allowed to accept, seems very good and the right thing to do.

Re: Android developer verification: Early access starts

#373
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

In many cases developer e-mail address changes, IP address changes, billing address changes, tax ID changes...

Re: Android developer verification: Early access starts

#374

Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

> No App should be able to read SMS.

I disagree - one feature in KDE Connect that is super useful is being able to forward your notifications, including your text messages. This would also harm non Android smartwatches, such as the recently revived Pebble.

Re: Android developer verification: Early access starts

#375
post #360
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

The tension here is classic: governments want accountability, Google wants plausible deniability, and users want control

...and users want ̶c̶o̶n̶t̶r̶o̶l̶ convenience.

Seems more appropriate.

Re: Android developer verification: Early access starts

#376
post #365
post #250

Earlier quoted context omitted.

It's not being shut down though. The article says that there will be a way to install unverified apps.

Ok, but sideloading is already a thing. What will this way to install unverified apps be? I doubt it will be an extra screen asking "Are you super-duper sure you want to enable sidloading???" after the one already asking the same question.

They talk about doing it under pressure, so my guess is there might be a waiting period before you're allowed free reign, or maybe per-app. Or some level of calling google, listening to 10 minutes of how poor billionaires are going to starve if you have control of your own device before being allowed to unlock it.

Re: Android developer verification: Early access starts

#377
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

[deleted]

Re: Android developer verification: Early access starts

#378
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

To be fair, on Google Play you have the option to transfer the app to someone else's account. People don't need to trade accounts...

Re: Android developer verification: Early access starts

#379

Earlier quoted context omitted.

Which is totally fine IMO, it was weird to me that they weren't going with this approach when they first announced it. Macs blocked launching apps from unverified devs, but you can override in settings. I thought they could just do something along those lines.

It's not fine. Some apps particularly banking apps have developer mode detection and refuse to work if developer mode is enabled.

I've switched banks for less.

Re: Android developer verification: Early access starts

#380
post #109

Earlier quoted context omitted.

I imagine what they're going to do involves a time delay so a scammer cannot wait on the phone with a victim while they do it.

I agree. Waiting to see for how long. Has to be 24 hours at a minimum I'd guess.

They could make us fill capchas to pass the time...
Post reply on HN