Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

301–310 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#301

Earlier quoted context omitted.

>The play store and apple app store both contain malware Wow, that a major claim. What apps are malware, exactly? >This is still not a root cause solution, it's just a mitigation. Requiring signed apps solves the issue though, as it provides identification of whoever is running the scam and a method for remuneration or prosecution.

> Wow, that a major claim. What apps are malware, exactly? I don't understand how this is a major claim at all, it should be obvious. All repositories of large enough sizes contain malware because malware doesn't declare itself as malware. This is exacerbated by the fact the Google Play Store and Apple App Store allow closed-source applications. It's much easier to validate behavior on things like the Debian repos, w…

A lot of what you said in the second portion isn't at all true (for instance, Google definitely doesn't just ask the author if what they are uploading is malware as a sole check if an app is malware). But I don't think we can even continue the discussion until you prove the "obvious" assertion that there are apps in the Play Store that are malware. So I am going to ask again: give a single name of an app currently in the Play Store that is malware. We are not talking about Apple, but I will extend it so that you can give an app in the Apple App Store that is malware as well.

Let me know when you can provide a single specific name.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#302

Earlier quoted context omitted.

Like you said, for years now they have added more and more restrictions to address various scams. So far none of them had any effect, other than annoying users of legitimate apps, because all the new restrictions were on the user side . This new approach restricts developers , but is actually a complete non-issue for most, since the vast majority of apps is distributed via Google Play already. In the section "Existin…

Because without this early resistance, there wouldn't even be vague promises of hobbyist/student exemptions. I think it's important to make community objection to the entire idea known loud and clear, especially when changes like these are absolutely ratcheting.

Starting from their first announcement of this, Google has explicitly asked for comments and feedback from affected developers. They have a Google Form for exactly that linked on all the announcement pages.

The exceptions for students/hobbyist were always promised, but the "advanced flow" came later based on this feedback. AFAICT Google has, so far, only made things better after the initial announcement. I don't see why we shouldn't give them the benefit of doubt, at least until we have some specifics.

Pushing this open letter out just days/weeks before Google promised the next major update just seems off.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#303

Earlier quoted context omitted.

You now need to have a variety of fake addresses you can use, since scammed addresses will get banned. You also need fake IDs. So again, the bar has now been raised from "run a bot to make fake Facebook accounts" to "I have a large number of physical addresses and the ability to create arbitrary fake government IDs". > Amazon has a huge problem with packages being sent to fake people at different addresses. This usua…

I still think it’s doable. Fake IDs aren’t exactly hard to come by. You could also pay randos a $30 gift card to sign up for a developer account and share access. Enough people will do it. I guess this does raise the cost a little though.

> You could also pay randos a $30 gift card to sign up for a developer account and share access. Enough people will do it.

This could work, but the issue here is that a lot of these scams rely on the "zero cost"-ness of turnup and use that as a asymmetry. If it costs you nothing to turn up new scam-accounts, and it costs me something to investigate and remove them, you win. If it costs you $10 to create new scam accounts then as long as I can get the EV of a scam account below $10, the scam isn't worthwhile.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#304

The judge told Google that Apple is not anti-competitive because Apple has no competitors on it's platform (this all stemming from the Epic lawsuits). Google listened. Blame the judge for one of the worst legal calls in recent history. Google is a monopoly and Apple is not. Simple fix for Google... Same comment I made a few days ago, I feel it bears repeating as much as possible until it's really driven home how detr…

[deleted]

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#305

Earlier quoted context omitted.

Codes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app. On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible.

If they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.

There are about a half dozen permissions that are regularly abused by malware. These permissions are also extremely useful for a ton of completely legitimate features.

I am pretty confident that if Google had enabled this policy only for apps which use these permissions that the community would still be upset.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#306
post #274

Earlier quoted context omitted.

Codes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app. On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible.

Only require Developer Registration for apps with READ_SMS then.

There are about a half dozen permissions that are regularly abused by malware. These permissions are also extremely useful for a ton of completely legitimate features.

I am pretty confident that if Google had enabled this policy only for apps which use these permissions that the community would still be upset.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#307

Earlier quoted context omitted.

Friction does matter. Yes, criminals will create fake accounts with stolen IDs and stolen credit cards. But creating 1,000s of these is hard. Creating polymorphic banking trojans is simple. I don't know if this trade off is worth it, but the idea that it won't affect this abuse at all is false.

If you can convince someone over the phone to install malware thru a million "don't do this" screens, you can convince them to just give you their login credentials. Which is both easier, cheaper, and, I imagine, more effective.

And yet, criminals create banking trojans at scale. They wouldn't do this if it was more effective to always do traditional phishing.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#308

Earlier quoted context omitted.

Like many things in the US, this should be settled by congress not judges. Things that everyone relies on for life are generally regulated by law. Telecom platforms for instance. I’d say the mandatory software platform I need for my bank, drivers license, daily communication, etc should be in this bucket. The EU declaring both Apple and Google gateway platforms is a much better approach. Congress is abdicating its re…

"Like many things in the US, this should be settled by congress" The US government is by design supposed to be as minimal as possible, and the laws affecting you kept as local as possible. We're not supposed to have a "the government" that's the same as EU governments. "The federal government should make laws" should be an absolute last resort. When you say "congress is abdicating its responsibility", I'd like you to…

The federal government regulates interstate commerce. Apple and Google fit that definition. This is really no constitutional ambiguity here. Congress is 100% capable of acting if they wanted to.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#309

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

You say that until it happens to your mother/father/bf/gf/grandparent/…

Then we will see how you will react.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#310
post #299

Earlier quoted context omitted.

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

the problem is that in developing countries smart phones are a massive technology jump for people who lack the education to even have a clue whats going on. treating people as adults does not work if they don't have the education needed for that. these people aren't gullible. they are ignorant (in the uneducated sense). they are not making bad decisions. they are not even aware that there is a decision to be made. an…

To add to that, I think it's important to point out that the problem of people not understanding how to safely use their devices is in big part caused by technology companies racing to get widest adoption everywhere, both in terms of location and in terms of industries. I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence. We shouldn't now let them pick the most convenient option, the option that just happens to also increase their powers over the users, as a way to "fix" the problem.
Post reply on HN