Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

371–380 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#371

Earlier quoted context omitted.

I have a radical solution - it should not be possible to contact someone unsolicited. All phone calls, SMS, emails, and instant messages should be blocked unless the other party is in my contacts or I have reached out to them first (plus opt-in contact from contacts of contacts, etc). Ideally, cryptographically verified. I would argue this is the real solution to spam and scamming - why on earth are random people all…

I have an even more radical solution. The real root of the problem is that we use this "money" concept to represent value. If money didn't exist there wouldn't be any reason to steal, hack, or scam. What do we replace it with? Haha, idk man. How about water? More difficult to hoard in ridiculous quantities, better spend it before it evaporates, and it occasionally falls from the sky (UBI). That's what I call a liquid…

For sure, getting rid of money would help if we had an alternative.

I am actually pitching an alternative though that doesn't seem that out there to me. I'm honestly surprised it isn't already an option in mainstream messengers (or at least Signal).

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#372
post #318

Earlier quoted context omitted.

I do? It's a trivially comparable thing? I'm not even talking about ALL prescription drugs. I'm talking about the fact that some have interactions that can kill you. Having "life savings gone" consequences from a random app install is that level of danger. A non-trivial number of people should probably have to go see a specialist before being able to unlock sideloading in my opinion... which means we probably all wou…

I have a hard time with this because it's the world we've lived in forever. Everyone knows installing an "app" installs an executable. Doesnt android require a specific permission to be user-accepted for an installed app to read notifications? I think it's separate from the post-notifications permission. This seems to be an issue of user literacy. If so, doesn't it make more sense for a user to have the option to opt…

this. just like how when you start playing a hard esoteric game like an RTS or MOBA, they ask you what your degree of comfort/experience with the genre is to avoid making a pro player go through the tutorial and vice versa.

In an ideal world where governments and corporations weren't trying to lock us into a closed system for massive surveillance and control, during the installation/setup of a mobile phone should be a question about tech literacy and protection. Selecting any option that isn't "I'm tech illiterate, please protect me" should be very annoying. There should be many warnings in uppercase bold red letters telling the user it can be dangerous and listing those dangers. But if I'm a developer and want to patch my kernel or modify the system as I please, I should be able to do so. If i want to install a malware app in a burner phone to study its behavior (or just for fun) I should be able to do so.

There would probably be one or two grandmas that would still somehow choose the pro hacker mode and get scammed down the line, but I think that minuscule amount of harm done is very much preferable to closing out *literally everyone else* from using the devices THEY BOUGHT.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#373
post #204

Earlier quoted context omitted.

The alcoholic knows the bad outcomes, and chooses to ignore them. The hapless Android user does not understand the negative consequences of sideloading. I think this makes for a substantial differerence between those two.

> The hapless Android user does not understand the negative consequences of sideloading. Then make sideloading disabled by default but enable it when the users tap 7 times on whatever settings item. At that time, explain those "negative consequences" to them, explain them real good, don't spare anything and if they still hit "Yes, continue to enable sideloading" you do that immediately in order to avoid increasing th…

I don't see how people are against this. Especially tech-savvy people who browse HN. It really seems to me like everyone here who's on Google's side is just a bot in a botfarm somewhere. they can't possibly be real

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#374

Earlier quoted context omitted.

> Protecting from scams isn't protection from the victim themselves. That is where we differ. It is, ultimately, the victim of a scam who makes the choice of "yes, this person is trustworthy and I will do what they say". The only way to prevent that is to block the user from having the power to make that decision, which is to say protecting them from themselves.

But the proposal here, requiring developers to register their identities, doesn't actually impact consumers at all. They still have the ability to make the decision about whether or not to trust someone.

Yes it does, especially when you remember the fact that developers are also consumers. But even if they (we) weren't, it would still impact consumers. I, android user who's completely ignorant when it comes to android development or even mobile in general, would be heavily impacted by this. My custom youtube clients would never be approved by google. My (free) apps for watching anime and reading manga would never get approved by Google. And something that's approved today could stop being approved tomorrow. it's up to Google / Microsoft / Apple to decide after all, they're the ones in control of our devices. If they stop liking my open-source ad-free minesweeper game, then I can't play it anymore. I'll have to download their bloated proprietary version with ads and a subscription to keep playing.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#375
post #256

Earlier quoted context omitted.

The point is "a warning" is not enough to communicate to people the gravity of what they are doing. It is not enough to write "be careful" on a bag you get from a pharmacy... certain medications require you to both have a prescription, and also to have a conversation with a pharmacist because of how dangerous the decisions the consumer makes can be. Normal human beings can be very dumb. It's entirely reasonable to ex…

OK so make the warning more annoying. Have a security quiz. Cooldown period of one day to enable. Require unlock via adb connected to laptop. There are alternative solutions if the true goal is maintaining user freedom while protecting dumb users. But that is not the true goal of the upcoming changes.

Would that satisfy most commenters here?

Prediction: Android will roll out a flow for “experienced users” that they promised in November with “in the coming months” (https://android-developers.googleblog.com/2025/11/android-de...), which will allow “experienced users to accept the risks of installing software that isn't verified”. And even then people will still complain Google is being too controlling by making the warnings too scary / the process too onerous, etc. (I don't expect installing apps from source via adb connected to laptop to go away!)

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#376
post #210

Earlier quoted context omitted.

Protecting from scams isn't protection from the victim themselves. That should be obvious from the fact that very intelligent and technologically literate people too can fall for phishing attacks. Tell me for example, how many people in your life know how a bank would ACTUALLY contact you about a suspected hijacking and what the process should look like? And how about any of the dozens of other cover stories used? No…

None of these things requires "locking down phones." Every single thing you've mentioned can be done in a smarter way that doesn't involve "individuals aren't allowed to modify the devices they purchase."

I'm very against the changes Google are doing, but I'm also against the claim that "people who get scammed are stupid and deserve it".

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#377

Earlier quoted context omitted.

If you can convince someone over the phone to install malware thru a million "don't do this" screens, you can convince them to just give you their login credentials. Which is both easier, cheaper, and, I imagine, more effective.

And yet, criminals create banking trojans at scale. They wouldn't do this if it was more effective to always do traditional phishing.

Well they do both, and as I said I imagine most phishing is traditional, through the phone or email. Casting a wide net is just good business, but simply eradicating malware won't make phishing no longer possible.

And I'm being extremely generous here, because this won't erradicate malware. It will make a specific subset of malware harder to distribute. I imagine most malware is distributed through the play store, and naturally that will be unaffected.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#378

Earlier quoted context omitted.

> Wow, that a major claim. What apps are malware, exactly? I don't understand how this is a major claim at all, it should be obvious. All repositories of large enough sizes contain malware because malware doesn't declare itself as malware. This is exacerbated by the fact the Google Play Store and Apple App Store allow closed-source applications. It's much easier to validate behavior on things like the Debian repos, w…

A lot of what you said in the second portion isn't at all true (for instance, Google definitely doesn't just ask the author if what they are uploading is malware as a sole check if an app is malware). But I don't think we can even continue the discussion until you prove the "obvious" assertion that there are apps in the Play Store that are malware. So I am going to ask again: give a single name of an app currently in…

I never said it was a sole check, I said it was a check. The reality is that app is not thoroughly tested and, even if it was, this would not catch all malware because, again, it's trivial to write malware that can pass a review period and flip on later.

First Google search https://www.malwarebytes.com/blog/news/2025/08/77-malicious-...

Here's 77 found by researchers and then removed. Relying on researchers to find malware isn't a very good bet.

If I were a betting man, I would say there are thousands of apps on the play store that you can classify as malware.

We will never know the true number because one of the primary goals of malware is to be as difficult to detect as possible. They're not going to declare they're malware, duh.

If you know of some algorithm to detect malware, I'd love to hear it. Evidently even trillion dollar companies cannot come up with one. To this day, the best way to detect malware is source code analysis and thorough behavior testing.

Google and Apple do neither. Those are just the facts. Do with that what you will, I don't care.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#379
post #349

Earlier quoted context omitted.

It might not "solve" the problem, but I'd expect it to significantly address the problem no? I've heard much criticism of it being too heavy-handed, but I don't think I understand criticism that it won't improve security. Could you expand on that?

No. You seem to be implicitly arguing that that unsigned apps are inherently less trustworthy than PlayStore apps. That's a claim that needs to be proven first. And based on the huge amount of documented data exfiltration performed by Google-approved apps, I'm going to say that claim is false.

I'm arguing that a curation process that includes security review is likely to produce a more secure set of software. Admittedly it might be completely ineffective, but I think that's an unreasonable assumption. So some review is more secure than no review. Now I'm not saying "better", you could argue it's a false sense of security, but it's still more security.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#380

Earlier quoted context omitted.

A lot of what you said in the second portion isn't at all true (for instance, Google definitely doesn't just ask the author if what they are uploading is malware as a sole check if an app is malware). But I don't think we can even continue the discussion until you prove the "obvious" assertion that there are apps in the Play Store that are malware. So I am going to ask again: give a single name of an app currently in…

I never said it was a sole check, I said it was a check. The reality is that app is not thoroughly tested and, even if it was, this would not catch all malware because, again, it's trivial to write malware that can pass a review period and flip on later. First Google search https://www.malwarebytes.com/blog/news/2025/08/77-malicious-... Here's 77 found by researchers and then removed. Relying on researchers to find m…

That is actually hilarious, did you actually read the MO of those Apps?

>The core payload has been updated to incorporate a new keylogger variant of Anatsa. Additionally, the malware utilizes a well-known Android APK ZIP obfuscator for enhanced evasion. The DEX payload is concealed within a JSON file, which is dynamically dropped at runtime and promptly deleted after being loaded.

I wonder if there is anything that Google can do to prevent this specific attack. :)

Post reply on HN