Earlier quoted context omitted.
Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. In contrast, convincing someone to read an OTP over the phone is a one-time manual bypass. To use your logic.. A insalled app - Like a hidden camera in a room. Social engineering over phone - Like convincing someone to leave the door unlocked once.
> Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. The motivating example as described involves "giving the scammer everything they need to drain the account". Once they've drained the account, they don't need ongoing access.
Open Letter to Google on Mandatory Developer Registration for App Distribution
61–70 of 392 posts
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#62Earlier quoted context omitted.
If you can "coach someone to ignore standard security warnings", you can coach them to give you the two-factor authentication codes, or any number of other approaches to phishing.
The 2-factor SMS messages usually say: "Do not give this code to anyone! The bank will NEVER ask you for this code!". The sideloading warning is much much milder, something like "are you sure you want to install this?".
> Please enter the code we sent you in the app.
lol, lmao even
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#63Wrong approach. Vote with your wallet instead. My next mobile phone will not have OS from Google (not from Apple).
In the time it took you to read this comment, 200 phones were sold.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#64Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#65The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…
OK, so instead of educating stupid (or overly naive) people, we implement "protections" to limit any and all people to do useful things with their devices? And as a "side effect" force them to use "our" app store only? Something doesn't smell that good here …
How about a less drastic measure, like imposing a serious delay for "side loading" … let's say I'd to tell my phone that I want to install F-Droid and then would have to wait for some hours before the installation is possible? While using the device as usual, of course.
The count down could be combined with optional tutorials to teach people to contact their bank by phone meanwhile. Or whatever small printed tips might appear suitable.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#66Earlier quoted context omitted.
Developer registration doesn't prevent this problem. Stolen ID can be found for a lot less money than what a day in a scam farm's operation will bring in. A criminal with access to Google can sign and deploy a new version of their scam app every hour of the day if they wish. The problem lies in (technical) literacy, to some extent people's natural tendency to trust what others are telling them, the incompetence of in…
> Stolen ID can be found for a lot less money than what a day in a scam farm's operation will bring in. Well, in that case, Google has an easy escalation path that they already use for Google Business Listings: They send you a physical card, in the mail, with a code, to the address listed. If this turns out to be a real problem at scale, the patch is barely an inconvenience.
Now they'll need to pay off a local mailman to give them all of Google's letters with an address in an area they control so they can register a town's worth of addresses, big whoop. It'll cost them a bit more than the registration fee, but I doubt it'll be enough to solve the problem.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#67The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…
Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adults, which includes letting them make very bad decisions if they insist on doing so.
Someone being gullible and willing to do things that a scammer tells them to do over the phone is not an "attack vector". It is people making a bad decision with their freedom. And that is not sufficient reason to disallow installing applications on the devices they own, any more than it would be acceptable for a bank to tell an alcoholic "we aren't going to let you withdraw your money because we know you're just spending it at the liquor store".
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#68Earlier quoted context omitted.
> community needs a better response to this problem than "nuh uh, everything's fine as it is." You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. Google and the state are not your nannies.
> You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. oh nice, i love this game. you cant carry a kitchen knife that is too long, you cant carry your kitchen knife into a school, you cant brandish your kitchen knife at police, you cant let a small child run around with a kitchen knife... literally most of what "the state" does is be a "nanny" (not agreeing or disagreeing with go…
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#69The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…
The community does not need to do that. Installing software on my device should not require identification to be uploaded to a third party beforehand.
We're getting into dystopian levels of compliance here because grandma and grandpa are incapable of detecting a scam. I sympathize, not everyone is in their peak mental state at all times, but this seems like a problem for the bank to solve, not Android.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#70Dear Undersigned, I have an APK I would like you to install on your personal phones. No, I won't tell you who I am. Please let me know when you are comfortable with this.