Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

321–330 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#321
post #310
post #299

Earlier quoted context omitted.

the problem is that in developing countries smart phones are a massive technology jump for people who lack the education to even have a clue whats going on. treating people as adults does not work if they don't have the education needed for that. these people aren't gullible. they are ignorant (in the uneducated sense). they are not making bad decisions. they are not even aware that there is a decision to be made. an…

To add to that, I think it's important to point out that the problem of people not understanding how to safely use their devices is in big part caused by technology companies racing to get widest adoption everywhere, both in terms of location and in terms of industries. I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence. We shouldn't now let them pick the most convenient…

I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence.

how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence)

how is a UI designed that doesn't fuel incompetence?

i have a hard time imagining what design aspects matter here, and how to improve upon them.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#322
post #287

Earlier quoted context omitted.

With banks, typically a combination of your account number, pin and some confirmation code sent via email or SMS. And of course unregistering your previous device. Not sure where you're going with this though?

I am just pointing out that you are essentially saying passkeys can be phished because banks can allow phishable credentials to bypass passkeys.

I never said that passkeys can be phished, I said they don't solve this problem, but yeah. Locking the front door while leaving the back door wide open, as they say. But unless you can convince people to go into the bank counter every time they change their phone, that's life.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#323
post #204

Earlier quoted context omitted.

It's not a false equivalence at all. Both situations are taking away someone's control of something that they own, borne from a paternalistic desire to protect that person from themselves. If one is acceptable, the other should be. Conversely if one is unacceptable, the other should be unacceptable as well. Either paternalistic refusal to let people do as they wish is ok, or it isn't.

The alcoholic knows the bad outcomes, and chooses to ignore them. The hapless Android user does not understand the negative consequences of sideloading. I think this makes for a substantial differerence between those two.

> The hapless Android user does not understand the negative consequences of sideloading.

Then make sideloading disabled by default but enable it when the users tap 7 times on whatever settings item. At that time, explain those "negative consequences" to them, explain them real good, don't spare anything and if they still hit "Yes, continue to enable sideloading" you do that immediately in order to avoid increasing their haplessness with other made-up excuses.

Simple.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#324
post #319
post #241

Earlier quoted context omitted.

It was a catchy rethorical question. Desired emphasis on the fact that a smartphone is a computing device. If you like to not be able to run whatever software you want on your computer, and the one your family owns, that's your thing. Its another pretense, like disabling full disk encryption, where people came with these ideas (instead of other options), because its convenient to them to pretend its the right thing.

When systems scale you have to look at the effects in aggregate. Android is a tool used to manage billions of people’s finances. If you allow unreviewed apps, people get scammed by fake banking apps. You might say people shouldn’t be so dumb, or that we should educate them, but the fact is that it happens. If you allow unreviewed apps, people get scammed at a higher rate. If you allow a backdoor, people get scammed a…

The elites are the rich fucks at the top literally dumping waste in everything. Let's get this straight first!

If we like to exaggerate, let's not allow people to leave their homes anymore. Should reduce crime by a bigger percent than the random numbers you throw out :))

Your argument feels like an excuse. Following stuff from KitBoga and Scammer Payback install random app on mobile doesn't seem the most prolific approach. Heck, in my country its still fake calls/sms/whatsapp messages that guide you to insert your credit card willy nilly. And it works.

Colission should be what happens between the pavement and the enlighted heads at Google that want to go ahead with this decision. Fucking Google where I, and other people in my country, repeatly reported phising ads (invest now 1000% return, with deepfakes) on youtube and they did nothing. That fucking Google that now pretends it does shit for the interest of the user.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#325
post #312

Earlier quoted context omitted.

Cars worked fine without seatbelts too. Just because the world goes on doesn't mean we can't do better. Taking a step back though, I suspect there are cultural differences in approach here. Growing up in Europe, the idea of a regulation to make everyone safer is perfectly acceptable to me, whereas I get the impression that many folks who grew up in the US would feel differently. That's fine! But we also have to recog…

I really don't think that's a cultural difference. I also grew up and live in the EU. What Google wants just does not solve the problem in any way. And it's also not actual regulation, just new TOS from a company many are basically forced to interact with.

It might not "solve" the problem, but I'd expect it to significantly address the problem no?

I've heard much criticism of it being too heavy-handed, but I don't think I understand criticism that it won't improve security. Could you expand on that?

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#326

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

I have a radical solution - it should not be possible to contact someone unsolicited. All phone calls, SMS, emails, and instant messages should be blocked unless the other party is in my contacts or I have reached out to them first (plus opt-in contact from contacts of contacts, etc). Ideally, cryptographically verified. I would argue this is the real solution to spam and scamming - why on earth are random people all…

I have an even more radical solution. The real root of the problem is that we use this "money" concept to represent value. If money didn't exist there wouldn't be any reason to steal, hack, or scam.

What do we replace it with? Haha, idk man. How about water? More difficult to hoard in ridiculous quantities, better spend it before it evaporates, and it occasionally falls from the sky (UBI). That's what I call a liquid asset!

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#327

Earlier quoted context omitted.

> Life is not safe, nor can it be made safe without taking away freedom. So... no food and safety regulations, because life is not safe, and people should have the freedom to poison food with cheaper, lethal ingredients because their freedom matters more? You're right that things can't be made more safe without taking away the freedom to harm people. Which is why even the most freedom-loving countries on earth strike…

Your post is addressing a strawman, not what I said. But to answer the words you so ungraciously put in my mouth: > So... no food and safety regulations, because life is not safe, and people should have the freedom to poison food with cheaper, lethal ingredients because their freedom matters more? This is harm to others and is very obviously something we should enforce. There are unreasonable laws about food (banning…

When you say:

> Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world... Someone being gullible and willing to do things that a scammer tells them to do over the phone is not an "attack vector". It is people making a bad decision with their freedom.

That sounds pretty black and white extreme to me, when you talk about things like "life is not safe" and a "fundamental truth". I don't see any appreciation of balance there.

Maybe it's not what you meant to write, but your comment continues to absolutely come across as extremist and anti-balance to me. It seems like I was mischaracterizing what you actually believe (now that you've elaborated), but I don't think I mischaracterized what you wrote.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#328

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

Are you not aware of cases where marks physically went to the bank, withdrew all cash and dropped it off to the criminals, also taking out loans and yelling at bank employees when they were trying to stop them? No app involved.

You'll always find individual cases where people do extremely dumb stuff, but using that as a justification is also dumb. If you want to significantly curtail that freedoms of a large group, it's on you to come up with a good evaluation of tradeoffs, so

> the community needs a better response to this problem than "nuh uh, everything's fine as it is."

They already have, but you choose to use a fake simplification as a representative

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#329

Earlier quoted context omitted.

If I want to run a piece of software on my phone, I shouldn't need to go ask google whether they're cool with it

This is already true if you want to run a piece of software on an iPhone, on MacOS, on Windows, on any video game console.

You can run whatever you want on macOS and windows

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#330
post #275

Earlier quoted context omitted.

You can download any APK you like on the internet and run it without google/gov getting in the way

Yes, but the already have the power to ban apps if they wanted to. They just don't. That's the point.

No they don't?
Post reply on HN