Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

501–510 of 694 posts

Re: Android developer verification: Early access starts

#501
post #485
post #416

Earlier quoted context omitted.

Until there are no banks left to switch to Maybe this sounds dark but see also how the net is tightening around phones that allow you to run open firmware after you've bought the hardware for the full and fair price. We're slowly being relegated to crappy hobbyist projects once the last major vendors decide on this as well, and I don't even understand what crime it is I'm being locked out for We're too small a group…

I think pretty soon I'll carry a "normal" phone in my bag for things like communication and banking/ticketing, but I'll carry a device I actually like in my pocket. It'll be the best of both worlds - content I want to see often and easily in my pocket, and the stuff I don't want to be distracted by will be harder to reach on a whim.

Yes, I think I'll have to do the same. I've been in the market for a new phone but the one I had pretty much settled on removed the option to update the boot verification chain so I'm obviously not buying that. Might as well buy apple then

It seems like a finite solution though. Having a second phone is not something most people will do, so the apps that are relegated to run on such devices will become less popular, less maintained, less and less good

Currently, you can run open software alongside e.g. government verification software. I think it's important to keep that option if somehow possible

Re: Android developer verification: Early access starts

#502
post #499

Excuse me, what exactly is "sideloading"? If I wanted to run third-party code on a system through the means that's supported by the system, then it should be called "running", it's a part of normal operation. The word "sideload" made it sound like you're smuggle something you shouldn't onto the system. Subtle word tricks like this could sneak poisons into your mind, be watchful.

newspeak FTW!

Re: Android developer verification: Early access starts

#503

Earlier quoted context omitted.

I also think we should stop calling it "sideloading". We need a better word. Sideloading has a negative vibe, as if it's a dangerous thing to install apps from sources other than the Play Store.

>Sideloading has a negative vibe Maybe you've just been drinking the propaganda? "Sideloading" to me rolls off the tongue no worse than "hotswapping" or "overclocking".

We've always called it "install".

Re: Android developer verification: Early access starts

#504
post #494

Earlier quoted context omitted.

Some apps would use this for loopback addresses, which as far as I know will then need network permission. The problem here is the permission system itself because ironically Google Play is full of malicious software. And neither Android nor iOS a safer than modern Desktop systems. On the contrary because leaking data is its own security issue.

Wasn't the loopback address recently used maliciously?

Yes. Facebook/Meta was using a locally hosted proxy to get info smuggled back without using routes that are increasingly obstructed by things like ad blockers if I recall correctly.

https://securityonline.info/androids-secret-tracking-meta-ya...

Search string for DDG: Meta proxy localhost data exfiltration

Re: Android developer verification: Early access starts

#505
post #336

> Google will allow users to sideload Android apps without verification Ford will allow drivers to carry passengers without verification. Sounds silly, doesn't it?

If 90% of passengers were scamming the drivers or hijacking the car for some nefarious purpose that affects other cars, you definitely wouldn't find that silly.

I would think it is pretty silly if I needed some sort of verification to drive people I personally know around because other people were getting their car hijacked after choosing to pick up strangers they found on the highway.

Re: Android developer verification: Early access starts

#506
"Allow". This is the entirety of the problem. They are allowing things on my machine that I purchased with monies that I leased my soul for.

Anyway, I am already planning for a future in which Google does not feature as prominently as did until now. Small steps so far ( grapheneOS ), but to me the writing the wall is unmistakable. Google got cold feet over feedback and now they can allow things.

When negative publicity ends, they will start working towards further locking it in again. I am personally done with passively accepting it. It might be annoying, but it degoogling is a simple necessity.

Re: Android developer verification: Early access starts

#507
"Keeping users safe on Android is our top priority." This is propaganda. It is a statement made to dissuade people from the real issue. The top priority is to make money.

It is hard to to trust anyone who starts communication with an obvious falsehood. Users beware.

Re: Android developer verification: Early access starts

#508
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

If "automatic updates" were optional and off-by-default then users would not be vulnerable to something like SimpleMobileTools Why not let the user decide Letting someone else decide has potential consequences Using F-Droid app ("automatic updates") is optional, as it should be "Automatic updates" is another way of saying "allow somone else to remotely install software on this computer" Some computer owners might not…

> If "automatic updates" were optional and off-by-default then users would not be vulnerable to something like SimpleMobileTools

The problem is the vast majority of users want this on by default; they don't want to be bothered with looking at every update and deciding if they should update or not.

Re: Android developer verification: Early access starts

#509
post #142

> we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choi…

What if it imposed a longish (one time) cooldown period? A day?

Exactly, this would greatly reduce the ability for scammers in "urgent" situations, but for power users who flip the switch on day one it would rarely be a problem. What would be terrible though ... is if Google made it require a network connection or Google approval.

Re: Android developer verification: Early access starts

#510
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

I'm pretty sure Brazil doesn't have a law saying that Google must forbid sideload. I'm sure that government (be it President, Central Bank etc) doesn't pressure Google about it.

I'm sure some private actors (for example, banks) would love that smartphones are as tight as possible (reason: [0]). Perhaps the same reason applies to Google [1]. But no, "Brazil" isn't demanding that from Google.

[0]: consider that some virus (insecure apps, for example) could somehow steal information from bank apps (even as simple as capture login information). The client might sue the bank and the bank might have to prove that their app is secure and the problem was in the client's smartphone.

[1]: the client, the bank etc might complain to Google that their Android is insecure

Post reply on HN