Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

121–130 of 345 posts

Re: Android Developer Verification

#121
It's kinda funny. I used to run custom roms all Android phones came with a shit OS.

I stopped because Pixel AOSP phones were actually decent.

Now I guess i'll be buying phones based on which I can flash with custom roms again.

Re: Android Developer Verification

#122
post #33
post #31

It really seems like they are doing a lot to appease the tiny minority of us power users, adb load unaffected, one time toggle in settings to opt out, no change to alternative app stores as long as the apk was built by a verified developer. Crazy how harsh the sentiment is here, there are real people being harmed by scam apps intercepting sms one time codes and this will reduce the rate of that happening. It's not li…

Because the initial announcement included none of that... it wasn't addressed at all until the harsh sentiment.

It still hasn't been addressed. They walked back half of their wholly unreasonable position in an attempt to legitimize the other half.

Re: Android Developer Verification

#123
post #5

I don't see a way out of this except government regulation. The EU has the most motivation to do it, as a huge economic bloc with a lot of motivation right now to become as independent from the US as possible. I guess I can sort of manage to keep my head above water and keep buying secondhand phones which I unlock and install a supported version of LineageOS. But it's cumbersome, it gets more difficult and more restr…

But what motivation has the EU to promulgate these regulations?

* Chat control is toothless if users can simply side-load an app without snooping.

* The EU companies who successfully lobbied for regulations against Apple now see that the 15% tax is worth it when they can A/B test the counterfactual. So those companies no longer care if Google will do the same thing.

* The EU is now in an awkward position that it is ok for a newspaper to sell your personal info via pay-or-consent, but not for a social network to do it. Some will keep yammering on about "gatekeepers", but it's sort of an emperor has no clothes moment.

* Declaring that iPadOs is a gatekeeper (after it failed to meet the quantitative criteria for such) was another such emperor has not clothes moment. The whole "gatekeeper" narrative has turned into a farce.

* The people commenting on this forum are not even a rounding error in the EU electorate.

> It's not reasonable to expect consumers to figure out if the meat they buy is tainted, just as it's not to figure out if their phone spies on them, manipulates information, or sells their data (especially when there's a duopoly).

Indeed! Neither would it be reasonable for the sellers of meat to demand anonymity! If one sells tainted meat, he should be held accountable! We should identify him!

Yet, the creators and sellers of software for a General Purpose Computer (remember, that is the argument why phones should be regulated) demand that they should be above the law, anonymous and unaccountable!

Schrodinger's computing device: The one which is so vital to everyday life that we must not prohibit the user to run whatever software he likes, yet so unimportant that we have not a care in the world to identify any fraudster who might wish to distribute software.

Re: Android Developer Verification

#124

What % of Android users actually want this? Do they know or care? I've been using Android since 2010 because it was open in ways that the Apple ecosystem wasn't. I do not want this and imagine hardly any other power users (for lack of a better term) do. I'm already using a mostly deGoogled device but this really seals the deal. I have been longing for a true Linux phone for years and now seems like a good time to get…

Being able to side load apps was why I switched to android 10 years ago

I switched from iOS to Android about three years ago. I saved all the APKs for everything I installed (or updated) on that first phone. When I got a new phone last fall it was pleasantly like getting a new PC. I imported my SMS and contacts from my last backup (taken with an open source took I'd installed from an APK), then installed all the apps I use and imported or manually set any settings I wanted to customize.

Every non-stock app on my phone was installed from an APK directly downloaded from the manufacturer or open source developer's site / Github releases. I've never had a Google Play account and have never used any Android "app store".

The biggest pain was having to manually logon the couple of sites I allow to keep persistent cookies since device owners aren't allowed to just import/export cookies from mobile Chrome.

It has been a very nice experience. I appreciate the feeling of sovereignty and ownership of my device (even though it does have a locked bootloader and I don't actually have root).

Of course Google would take this away. >sigh<

Re: Android Developer Verification

#125

What % of Android users actually want this? Do they know or care? I've been using Android since 2010 because it was open in ways that the Apple ecosystem wasn't. I do not want this and imagine hardly any other power users (for lack of a better term) do. I'm already using a mostly deGoogled device but this really seals the deal. I have been longing for a true Linux phone for years and now seems like a good time to get…

Pretty much everyone would hate it if a relative lost their life savings to a scammer, though they may not know it yet. The idea isn't to protect the power users or average users. It's to protect the most vulnerable. Android is for everyone . Us power users will have a minor speed bump, but we can deal.

I would buy this argument if the Play Store wasn't already full of garbage and viruses and scams.

Re: Android Developer Verification

#126

> However, our recent analysis found over 90 times more malware from sideloaded sources than on Google Play Google has seemingly never seen an elderly person's phone, where it is completely infected with crap including literal popup ads (that somehow overlay other apps), yet all of it was downloaded from GPlay.

100.00% this take. Google is redefining "malware" to fit their corporate narrative so ads-with-ads-with-tracking is labeled as fine wine. It simply cannot be malware because that truth would decimate their shareholders. Malware by any other definition remains software that disrupts the user's ability to operate the device:

https://en.wikipedia.org/wiki/Malware

https://www.ibm.com/think/topics/malware

https://www.cloudflare.com/learning/ddos/glossary/malware/

https://www.cisco.com/site/us/en/products/security/what-is-m...

https://www.britannica.com/technology/malware

https://www.fortinet.com/resources/cyberglossary/malware

https://www.kaspersky.com/resource-center/threats/what-is-ma...

https://www.mcafee.com/learn/malware/

https://www.trendmicro.com/en_us/what-is/malware.html

https://www.t-mobile.com/home-internet/the-signal/internet-h...

https://www.merriam-webster.com/dictionary/malware

Re: Android Developer Verification

#127
post #35

The Android verification is such a broken experience. Recently I decided to purchase a dev account for my company, so far: 1) Provided my company DUNS number etc. once to create the payment profile. I did this some times ago, don’t remember the details but it was an involved verification process and it is marked as verified business payment profile. 2) Later on the payment step verified myself with a passport and ban…

The whole Google Play experience is awful.

Recent things I've had to do:

1) Re-submit an app after it was rejected and labelled a gambling app (it wasn't even close - a 15 second look by a real human would have seen that. This one was even appealed and the support was utterly useless. I ended up changing one word and re-submitting the app, approved no problem.

2) An existing app, in the Play store for years but a nice app - only about 500 installs. I had to submit a new version for no reason whatsoever... Except to keep the customers developer account active.

Those are just issues I've dealt with in the last month or two.

Every single time, Google Support is completely useless - including the appeals process, which is an absolute joke.

Re: Android Developer Verification

#128
post #29

> our recent analysis found over 90 times more malware from sideloaded sources than on Google Play So what's the solution then? At the same time, I'm curious how this ends up happening to end users. Enabling unknown sources is trivial in a way (it's just one check box and if you try to install an APK from, say, Firefox, it'll take you right there), but how are people even getting to that point??

Phone scammers guiding users to install apps.

Re: Android Developer Verification

#129
post #127
post #35

The Android verification is such a broken experience. Recently I decided to purchase a dev account for my company, so far: 1) Provided my company DUNS number etc. once to create the payment profile. I did this some times ago, don’t remember the details but it was an involved verification process and it is marked as verified business payment profile. 2) Later on the payment step verified myself with a passport and ban…

The whole Google Play experience is awful. Recent things I've had to do: 1) Re-submit an app after it was rejected and labelled a gambling app (it wasn't even close - a 15 second look by a real human would have seen that. This one was even appealed and the support was utterly useless. I ended up changing one word and re-submitting the app, approved no problem. 2) An existing app, in the Play store for years but a nic…

Not to mention if you made one app in college and then didn't keep up with the SDK updates, Google perma-closes the entire Play account such that the only way to publish a new app is by creating a brand new gmail account

Re: Android Developer Verification

#130

Earlier quoted context omitted.

If this is a business account why do they want your passport? And why are you paying with a personal bank card rather than a business one? Or do I misunderstand?

They may want proof that you, the human filling out this form, are authorized to publish apps, communications, etc. as the company you say you represent.

How does a passport solve that? Most small private companies are entirely opaque. A government ID doesn't help you determine authorization. It won't even help you determine ownership since anyone doing things sensibly will be using a registered agent to hold the company on his behalf.

The correct approach here (AFAIK) is to punt the trust decision to the bank by requiring payment with a method that you can confidently trace to the company.

Post reply on HN