Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

151–160 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#151

Earlier quoted context omitted.

You're right, all Android users who are upset about this change are free to switch to iOS.

Right like someone who can only afford a $100 phone can buy the cheapest iPhone which is 5x more expensive. This is about like the geeks who hate the idea of ad supported services and think that everyone should just pay for every service they use. FWIW: I do exclusively buy Apple devices, pay for streaming services ad free tier, the Stratechery podcast bundle, ATP and the Downstream podcasts and Slate. I also pay for…

I think that OP's point was that the alternative is even more locked down. There is no option for people who don't want to be nannied.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#152
post #119

Earlier quoted context omitted.

No luck needed. Linux based phones are starting to become viable as daily drivers. [0] They are even coming with VM Android in case an application is needed that does not have a Linux equivalent. I am interested in how Google's gatekeeper tactics are going to affect Android like platforms such as /e/os and GrapheneOS. [1] [0] http://furilabs.com/ [1] https://murena.com/america/products/smartphones/

> > Good luck with that. > No luck needed. Linux based phones are starting to become viable as daily drivers. Then please tell me, which non-Android Linux-based phone can I buy here in Brazil (one of the first places where Android would have these new restrictions)? I'd love to know (not sarcasm, I'm being sincere). Keep in mind that only phones with ANATEL certification can be imported, non-certified phones will be…

Indeed, and since Brazil now has mandatory age checking in the OS, it's illegal to own or operate such phones in the country, thus they will never be certified by ANATEL.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#153
post #84
post #46

Earlier quoted context omitted.

Does your logic extend to PCs? If not, why? Because I hope you realize that clamping down on “sideloading” (read: installing unsigned software) on PCs is the next logical step. TPMs are already present on a large chunk of consumer PCs - they just need to be used.

Of course it extends to PCs. It'd suck for us, but end users, software vendors, content providers, and service providers all benefit from a more restricted platform that can provide certain guarantees against malware, fraud, piracy, and so forth. It's pathologically programmer-brained to assume that the good old days of being able to run arbitrary code on a networked computing device would last forever. That freedom…

Users get way more out of it when the device is free. Even if they don't use this option, it makes it easier to set up competing services. This includes ones that would never be allowed in an official store because they're DRM-free alternatives to big streaming services but still offer all the same content. The existence of such alternatives, if they are easy to use, can force the big services to become more user-friendly. Just as happened back then with Napster.

Also every user is free to simply not use the option of installing things outside of the store.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#154
post #104

Earlier quoted context omitted.

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

What if we asked users if they want extra protection? I think that would be nice..

You can add 5 layers of "are you sure you want to do this unsafe thing" and it just adds 5 easy steps to the scam where they say "agree to the annoying popup"

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#155
post #119

Earlier quoted context omitted.

> > Good luck with that. > No luck needed. Linux based phones are starting to become viable as daily drivers. Then please tell me, which non-Android Linux-based phone can I buy here in Brazil (one of the first places where Android would have these new restrictions)? I'd love to know (not sarcasm, I'm being sincere). Keep in mind that only phones with ANATEL certification can be imported, non-certified phones will be…

My condolences, that sucks that you’re stuck in such an authoritarian country. If you look at the PostmarketOS site, you may be able to find a legal phone (weird to type that phrase) that can be reflashed. Or you could buy one while on vacation, my guess is they don’t check models at the border if it looks like a personal device.

Illegal in Brazil per the Digital Child and Adolescent Statute. Operating systems are legally required to provide age verification functionality in a manner approved by the government.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#156
post #28

Registration just creates friction for legitimate developers (thousands) while bad actors simply rotate shell companies and fake/stolen IDs. This conflates identity verification with criminal deterrence, they're not the same thing.

Friction does matter. Yes, criminals will create fake accounts with stolen IDs and stolen credit cards. But creating 1,000s of these is hard. Creating polymorphic banking trojans is simple.

I don't know if this trade off is worth it, but the idea that it won't affect this abuse at all is false.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#157
post #117

Earlier quoted context omitted.

Read my previous comment again. Passkeys are nice, but they don't solve the problem that's being discussed here.

I'm not sure if you understand what makes passkeys phishing-resistant? The backdoored version of the app would need to have a different app ID, since the attacker does not have the legitimate publisher's signing keys. So the OS shouldn't let it access the legitimate app's credentials.

Correction: nothing prevents the attacker from using the app's legit package ID other than requiring the uninstall of the existing app.

The spoofed app can't request passkeys for the legit app because the legit app's domain is associated with the legit app's signing key fingerprint via .well-known/assetlinks.json, and the CredentialManager service checks that association.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#158
The judge told Google that Apple is not anti-competitive because Apple has no competitors on it's platform (this all stemming from the Epic lawsuits).

Google listened.

Blame the judge for one of the worst legal calls in recent history. Google is a monopoly and Apple is not. Simple fix for Google...

Same comment I made a few days ago, I feel it bears repeating as much as possible until it's really driven home how detrimental and uninformed that decision was.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#159

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

I am the author of the letter and the coordinator of the signatories. We aren't saying "nuh uh, everything's fine as it is." Rather, we are pointing out that Android has progressively been enhanced over the years to make it more secure and to address emerging new threat models. For example, the "Restricted Settings"¹ feature (introduced in Android 13 and expanded in Android 14) addresses the specific scam technique o…

> all evidence points to them working fairly well.

What is this evidence? Please share it.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#160

The problem with mandatory developer registration, is that it gives Google and Governments the ability to veto apps. It would not be unsurprising for a government to tell Google they must block any VPN apps from being installed on devices, and Google using the developer requirements to carry out the ban.

> The problem with mandatory developer registration, is that it gives Google and Governments the ability to veto apps. Don't they already have that power?

No judgement whatsoever, but for almost everyone they too will think, no big deal you only install software through stores right? Nothing changes for them, in fact they can't conceive of an alternative anymore.
Post reply on HN