Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

201–210 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#201

Earlier quoted context omitted.

Would you say that iOS ecosystem suffers the same rate of malware as Android?

Of course not. In other news, a new study shows that cutting off your feet is 100% effective against athlete's foot.

Haven't seen that one but I've seen working medication, it does exist on the market and does work, why not switching to use it?

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#202

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

The main problem here is the banks relying on an untrusted device as second factor.

Only immutable devices should be allowed as second factor.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#203

Earlier quoted context omitted.

Would you say that iOS ecosystem suffers the same rate of malware as Android?

Of course not. In other news, a new study shows that cutting off your feet is 100% effective against athlete's foot.

[deleted]

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#204
post #97

Earlier quoted context omitted.

> At some point you need to treat people as adults, which includes letting them make very bad decisions if they insist on doing so. The world does not consist of all rational actors, and this opens the door to all kinds of exploitation. The attacks today are very sophisticated, and I don't trust my 80-yr old dad to be able to detect them, nor many of my non-tech-savvy friends. > any more than it would be acceptable f…

It's not a false equivalence at all. Both situations are taking away someone's control of something that they own, borne from a paternalistic desire to protect that person from themselves. If one is acceptable, the other should be. Conversely if one is unacceptable, the other should be unacceptable as well. Either paternalistic refusal to let people do as they wish is ok, or it isn't.

The alcoholic knows the bad outcomes, and chooses to ignore them. The hapless Android user does not understand the negative consequences of sideloading. I think this makes for a substantial differerence between those two.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#205

Earlier quoted context omitted.

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

> Life is not safe, nor can it be made safe without taking away freedom. So... no food and safety regulations, because life is not safe, and people should have the freedom to poison food with cheaper, lethal ingredients because their freedom matters more? You're right that things can't be made more safe without taking away the freedom to harm people. Which is why even the most freedom-loving countries on earth strike…

Your analogy is terrible because it doesn't do a proper accounting of "harm" and "risk."

Food and seatbelts, that's literal health and life-and-death; very immediate and visible.

"Cybersecurity" rarely is; and even when it is, the problem is that the centralized established authorities (like google) aren't at all provably good at this.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#207

Earlier quoted context omitted.

It's not a false equivalence at all. Both situations are taking away someone's control of something that they own, borne from a paternalistic desire to protect that person from themselves. If one is acceptable, the other should be. Conversely if one is unacceptable, the other should be unacceptable as well. Either paternalistic refusal to let people do as they wish is ok, or it isn't.

Maybe not, but I think that overextending any idea like that in the opposite direction of whatever point you are trying to make at least devolves into a "slippery slope" argument. For instance, is your point that all security on phones that impede freedom of the user (for instance, HTTPS, forced password on initial startup, not allowing apps to access certain parts of the phone without user permissions, verifying boo…

But it's not a slippery slope, because it's not taking it to the next level. It's the same level, just a different thing.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#208

Earlier quoted context omitted.

There is some world where somebody scammed through sideloading loses their life savings, and every country is politically fine with the customer, not the bank, taking the losses. But for regular people, that is not really the world they want. If the bank app wrongly shows they’re paying a legitimate payee, such as the bank, themselves or the tax authority, people politically want the bank to reimburse. Then the quest…

Why do banks go through all the know-your-customer (KYC) process if not to identify the beneficial owner of every account? If they receive a transfer via fraud, then they either get it clawed back, have to pay it back, and/or get identified to law enforcement. If the last bank in the chain doesn't want to play by the rules, then other banks shouldn't transfer into them, or that bank itself should be held liable. This…

In the case of some knowing or blindfully unknowing money mule in the chain or at the end of the chain, the intermediary or final banks may not be at fault. The bank could have followed KYC procedures in that somebody with that name actually existed who controlled the account.

The money mule themselves is almost certainly insolvent to pay the damages. Currencies can also change by the money mule (either to a different fiat currency or crypto), putting the ultimate link completely out of reach of the originating country.

If intermediary banks are deputized and become liable in a no-fault sense, then legitimate transfers out become very difficult. How does a bank prove a negative for where the funds come from? De-banking has already been a problem for a process-based AML regime.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#209
post #164
post #107

Earlier quoted context omitted.

Right, but this same problem (scamming) exists on PCs. Would it make sense to then argue that enforcing TPM-backed measured boot and binary signature verification is a legitimate way to address the problem?

Their point, applied to that situation, would be that if someone does argue for enforcing TPM-backed measured boot yadda yadda to address scamming, trying to counter it by dismissing scamming as not a real problem is useless.

I get it dude, but my wider point is that we need to question where this line of argumentation leads to.

Are we saying that, because scamming exists and we haven’t proposed an alternative, it means that clamping down on software installation methods is a legitimate solution to the problem?

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#210

Earlier quoted context omitted.

It's not a false equivalence at all. Both situations are taking away someone's control of something that they own, borne from a paternalistic desire to protect that person from themselves. If one is acceptable, the other should be. Conversely if one is unacceptable, the other should be unacceptable as well. Either paternalistic refusal to let people do as they wish is ok, or it isn't.

Protecting from scams isn't protection from the victim themselves. That should be obvious from the fact that very intelligent and technologically literate people too can fall for phishing attacks. Tell me for example, how many people in your life know how a bank would ACTUALLY contact you about a suspected hijacking and what the process should look like? And how about any of the dozens of other cover stories used? No…

None of these things requires "locking down phones." Every single thing you've mentioned can be done in a smarter way that doesn't involve "individuals aren't allowed to modify the devices they purchase."
Post reply on HN