Live data from Hacker News

A theoretical way to circumvent Android developer verification

enaix.github.io

111–120 of 185 posts

Re: A theoretical way to circumvent Android developer verification

#111

Earlier quoted context omitted.

So we're gonna get access to Von Der Layen Pfizer sms right? Were you offered to vote for Von Der Layen by the way?

The EU is a parliamentary democracy. Von Der Leyen was proposed by the democratically elected heads of the member states. She was approved by the democratically elected parliament. The chancellor in Germany is also not directly elected by majority vote but by parliament. Its a reasonable criticism that the EU structures make democratic legitimisation very indirect, but that is at least partly a result of the EU being…

FWIW EU members are sovereign. If they disobey EU laws they can have benefits withheld but they won't be militarily invaded for ignoring EU law the way a US state would (unless they do something military themselves like invading another country).

Re: A theoretical way to circumvent Android developer verification

#112
post #30

Earlier quoted context omitted.

A secure OS is a prerequisite for secure digital services. We can agree on that, right? The task, therefore, is to convince enough politicians to establish an independent unit that can address this issue without direct political influence. Fund the unit with enough money so that it can take care of the cybersecurity and sovereignty of all citizens. A side effect of this would hopefully be that these politicians would…

> A secure OS is a prerequisite for secure digital services. We can agree on that, right? Secure for who, and from whom? Remote Attestation and Developer Verification both make Android OS and platform more secure against malicious actors that would want to defeat the guarantees the platform gives, guarantees that enable secure digital services. Yes, this includes protecting the banking services and DRM media services…

> Chat Control improves security of the society against threats such as sexual predators who want to hurt children,

no it doesn't. Chat Control is single-use.

Re: A theoretical way to circumvent Android developer verification

#113
post #51
post #33

I'm already banned from publishing Android apps through Google, but apart from that, what would stop me making a server you can upload any app to and sign it with my certificate?

That could actually be done solely on the device. You can develop an app to sign arbitrary APKs with users' own hobbyist certificate. Lucky Patcher have done that for a decade.

I could even just give out my certificate and private key (if I'm allowed to have one). It's not like I need it to be private. Google would probably blacklist the certificate and then we get to sue Google based on the fact they said doing this would allow the app to work, but they didn't follow through with what they said.

Re: A theoretical way to circumvent Android developer verification

#114
post #88

Earlier quoted context omitted.

The EU is a big place, run by a lot of different people, with true separation of powers. They don't have a president-king who can just ignore court decisions.

So we're gonna get access to Von Der Layen Pfizer sms right? Were you offered to vote for Von Der Layen by the way?

I'm not in the EU! I can explain when somebody is wrong without having a horse in the race myself.

Re: A theoretical way to circumvent Android developer verification

#115
post #3

While it is technically feasible, it is not a good idea to try and find a technical solution to a people/organisation problem. Do not accept the premise of assholes. I hope we can get the EU to fund a truly open Android Fork. Maybe under some organisation similar to NL Labs. --- edit --- Furthermore, the need for a trustworthy binary to be auditable to a certain hash or something would make banning this a simple task…

The same EU that's doing Chat Control?

The same EU that shut down another attempt at Chat Control.

Bad legislation gets written everywhere, the difference is, in the EU it doesn't pass.

Re: A theoretical way to circumvent Android developer verification

#116
post #110

Earlier quoted context omitted.

I thought Brent Simmons did a great job laying out why PWAs don't work: https://inessential.com/2025/10/04/why-netnewswire-is-not-we... The tl;dr is that a PWA implies an app which is based in the cloud. So suddenly you need a server, and you need to store user data, which means costs and dealing with privacy and security.

Basically every native app has a server behind it to harvest user data nowadays. So I don’t think it’s an argument for why PWAs won’t work.

If the app is made by a company, sure.

It seems to me that, ironically, PWAs are uniquely ill-suited for the type of non-corporate software where distribution outside mainstream channels makes the most sense.

Re: A theoretical way to circumvent Android developer verification

#117
post #8

Well, I'd rather verify myself with the government identity than accept a stock OS that literally woke me up with a fake message promoting Gemini despite me spending almost 2 hours turning every possible privacy-invasive setting off. To me, the attention to these verification changes seems misplaced. We need to defend the ability to unlock the bootloader, pressure Google to revive AOSP and then encourage people to sw…

The issue with government IDs is that they are, for all we know, not trustworthy, but everyone treats them like they are. And you know, I am not going to "verify" myself with Google with this kind of toilet paperwork.

If Google decides to pull this off, then I guess reflashing to a custom ROM with this crap patched out will be a very first step I'll be recommending to anyone who cares.

Re: A theoretical way to circumvent Android developer verification

#118
post #88

Earlier quoted context omitted.

The EU is a big place, run by a lot of different people, with true separation of powers. They don't have a president-king who can just ignore court decisions.

So we're gonna get access to Von Der Layen Pfizer sms right? Were you offered to vote for Von Der Layen by the way?

technically people didn’t vote for Trump they voted for electors which voted for him.

Re: A theoretical way to circumvent Android developer verification

#119
post #51
post #33

I'm already banned from publishing Android apps through Google, but apart from that, what would stop me making a server you can upload any app to and sign it with my certificate?

That could actually be done solely on the device. You can develop an app to sign arbitrary APKs with users' own hobbyist certificate. Lucky Patcher have done that for a decade.

Making every user to "verify" themselves with a government ID is a no-go, because government IDs are no more trustworthy than a toilet paper.

Re: A theoretical way to circumvent Android developer verification

#120
What about this idea? Make a movement among the devs who are willing to distribute "legitimately" (via Google Play or "authorized" sideload), to sign their apps with intentionally insecure private key. Then some community will just mine up these certificates in already published apps and publish them somewhere on GitHub.
Post reply on HN