Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

31–40 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#31
post #27

Earlier quoted context omitted.

If you can "coach someone to ignore standard security warnings", you can coach them to give you the two-factor authentication codes, or any number of other approaches to phishing.

The 2-factor SMS messages usually say: "Do not give this code to anyone! The bank will NEVER ask you for this code!". The sideloading warning is much much milder, something like "are you sure you want to install this?".

the main issue is the bank using sms and OTP apps instead of something like passkeys and mandatory in bank setup.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#33
post #27

Earlier quoted context omitted.

If you can "coach someone to ignore standard security warnings", you can coach them to give you the two-factor authentication codes, or any number of other approaches to phishing.

The 2-factor SMS messages usually say: "Do not give this code to anyone! The bank will NEVER ask you for this code!". The sideloading warning is much much milder, something like "are you sure you want to install this?".

You'll then get more warnings if you want to give the sideloaded app additional permissions. And if they want to make the sideloading warnings more dire, that wouldn't be nearly as unreasonable.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#34
post #19

Earlier quoted context omitted.

If you can "coach someone to ignore standard security warnings", you can coach them to give you the two-factor authentication codes, or any number of other approaches to phishing.

Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. In contrast, convincing someone to read an OTP over the phone is a one-time manual bypass. To use your logic.. A insalled app - Like a hidden camera in a room. Social engineering over phone - Like convincing someone to leave the door unlocked once.

> Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access.

The motivating example as described involves "giving the scammer everything they need to drain the account". Once they've drained the account, they don't need ongoing access.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#35

Earlier quoted context omitted.

> You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. oh nice, i love this game. you cant carry a kitchen knife that is too long, you cant carry your kitchen knife into a school, you cant brandish your kitchen knife at police, you cant let a small child run around with a kitchen knife... literally most of what "the state" does is be a "nanny" (not agreeing or disagreeing with go…

you cant buy a kitchen knife that is too long What?

sorry, should say "carry", not "buy". most states have a maximum length you can carry (4-5.5 inches is common).

although, i would imagine at some length, it becomes a "sword" (even if marketed as a knife) and falls under some other "nanny"-ing. i have not googled that.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#36

Earlier quoted context omitted.

> You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. oh nice, i love this game. you cant carry a kitchen knife that is too long, you cant carry your kitchen knife into a school, you cant brandish your kitchen knife at police, you cant let a small child run around with a kitchen knife... literally most of what "the state" does is be a "nanny" (not agreeing or disagreeing with go…

you cant buy a kitchen knife that is too long What?

Long knives in the UK are like full auto guns in the rest of the world.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#37

Earlier quoted context omitted.

you cant buy a kitchen knife that is too long What?

sorry, should say "carry", not "buy". most states have a maximum length you can carry (4-5.5 inches is common). although, i would imagine at some length, it becomes a "sword" (even if marketed as a knife) and falls under some other "nanny"-ing. i have not googled that.

You still have an hour or two to edit your comment. Look in that line of text where you see your user name, click “Edit”.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#38
post #14

Wrong approach. Vote with your wallet instead. My next mobile phone will not have OS from Google (not from Apple).

Good luck with that.

No luck needed.

Linux based phones are starting to become viable as daily drivers. [0] They are even coming with VM Android in case an application is needed that does not have a Linux equivalent.

I am interested in how Google's gatekeeper tactics are going to affect Android like platforms such as /e/os and GrapheneOS. [1]

[0] http://furilabs.com/

[1] https://murena.com/america/products/smartphones/

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#39
post #7

Earlier quoted context omitted.

Agree with this middle path you point out. On one hand, I do not want some apps to be distributed anonymously, I need to know who is behind it in order to trust the app. On the other hand, many apps are benign. Permissions are a great way to distinguish.

Do you need Google to compel the author to start a business relationship with them, which they can cut off at any time? Or would you be OK knowing that Thunderbird you downloaded from https://thunderbird.net/ is signed by the thunderbird.net certificate owner?

Typo squatting is a thing, and so are Unicode homographs.

The permissions approach isn't bad. I may trust Thunderbird for some things, but permission to read SMS and notifications is permission to bypass SMS 2FA for every other account using that phone number. It deserves a special gate that's very hard for a scammer to pass. The exact nature of the gate can be reasonably debated.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#40

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

If you can "coach someone to ignore standard security warnings", you can coach them to give you the two-factor authentication codes, or any number of other approaches to phishing.

Never ending worm approach is to get remote control via methods on android or apple. Then scam other contacts. It’s built into FaceTime. Need 3rd party apps for android.
Post reply on HN