Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

161–170 of 345 posts

Re: Android Developer Verification

#161

> However, our recent analysis found over 90 times more malware from sideloaded sources than on Google Play Google has seemingly never seen an elderly person's phone, where it is completely infected with crap including literal popup ads (that somehow overlay other apps), yet all of it was downloaded from GPlay.

Both things might be true. Sideloaded apps are probably way more likely to be malicious, but also most installed malware/crapware is quite likely coming from Google Play.

Re: Android Developer Verification

#162
I'd say Hackernews knows enough people at Google to raise a stink about this, but it's not going to do any good. Sometime at the last WEF or Bilderberg meeting it was decided that KYC level identity verification should be required to use a computer or the internet, with more stringent requirements to program one. This, and much worse, is going to happen whether we like it or not.

Re: Android Developer Verification

#163
post #90

Earlier quoted context omitted.

I don't necessarily like the idea of a company wiping their hands clean and saying "well - not our problem!" either though. Companies shouldn't wait to solve issues like this - they should be proactively helping their most vulnerable users. That is the "do no evil" motto. I don't know enough to say whether this method is the right approach however.

Saying that computer/OS manufacturers should prevent malware is effectively equivalent to saying that they should not sell general purpose computers to the public. A general purpose computer is one that can run any program the users tells it to, which necessarily includes one that's malicious. That doesn't necessarily preclude helping the user to notice when they're doing something dangerous, but a waiting period bef…

> Saying that computer/OS manufacturers should prevent malware is effectively equivalent to saying that they should not sell general purpose computers to the public.

(in Gilbert Huph (Wallace Shawn) voice) Yes, precisely!

Re: Android Developer Verification

#164

Don't love it but (1) it's addressing a serious problem and I'm not sure what the alternative is and (2) if you all remember the starting place, it was staggeringly, dramatically worse, practically a death sentence for F-Droid and seemingly testing the waters for if they could simply power through and do it despite objection. This is a major course correction that doesn't kill F-Droid. A one time 24 hour hoop to jump…

Is it a serious problem that you can run whatever software you want on your computer? Should we make it so that no one can do that without permission to protect them? I recommend Cory Doctorow's talk on why this is a serious problem for society: https://en.wikisource.org/wiki/The_Coming_War_on_General_Com... https://www.youtube.com/watch?v=HUEvRyemKSg

Not enough people give a shit about "general purpose computing" to matter. They use computers for a few things and as long as they can do those things they're fine with it. My wife loves all her Apple gear. It provides her with a wonderful, curated experience. Okay, maybe it hasn't been so good with recent iOS releases but it still beats Android or Microslop. Being able to hack, modify, or install arbitrary stuff on your device is something only a minority of a minority care about, statistical noise in the quarterly sales figures. When you compare that to the harm done by malware, illegal or indecent material, and the negative blowback to YOUR OS's reputation—or worse, the "felony contempt of business model" enabled by a general-purpose OS (piracy, ad blocking, etc.)—it's a no-brainer to implement restrictions.

Re: Android Developer Verification

#165

tl;dr how to install an app from unverified developer ("advanced flow") 1. enable developer mode 2. confirm you aren't being coached 3. restart your phone and reauthenticate 4. come back after 24 hours and unlock device 5. install app from unverified developer, option of enabling for 7 days or indefinitely This is apparently a one-time process. Advanced flow for users launches globally August 2026. Verification requi…

Nah. This sucks. My banking app refuses to open if devtools are enabled. 24h window means I can't do dev work on my personal phone.

Re: Android Developer Verification

#166

Earlier quoted context omitted.

Yeah I would imagine that the value the get out of a passport is not anything to do with validating a company (they’re cheap and easy to make anyway) but validating the person (which is not a throwaway entity)

Fair point. However that invites those bad scenarios where someone gets blacklisted by BigTech in some manner, later gets hired by a small business, the new employer adds an association to the blacklisted account, and suddenly the company app is banned from the app store seemingly without reason. At least a few such stories have appeared on HN over the years. I feel like pay to play ought to be sufficient because in…

There are better ways to do it but Google has long demonstrated they’re not primarily concerned with accuracy or user experience, but instead, whichever solution can be automated and effective.

Re: Android Developer Verification

#167

Earlier quoted context omitted.

Pretty much everyone would hate it if a relative lost their life savings to a scammer, though they may not know it yet. The idea isn't to protect the power users or average users. It's to protect the most vulnerable. Android is for everyone . Us power users will have a minor speed bump, but we can deal.

Android is for everyone, provided they submit to Google exclusively. It's not about power users, and that isn't a speed bump. You can protect vulnerable users without centralizing power like they did, but that's not their motivation so here we are.

What's an example of a decentralized system that protects people from scammers?

Re: Android Developer Verification

#168

Earlier quoted context omitted.

They may want proof that you, the human filling out this form, are authorized to publish apps, communications, etc. as the company you say you represent.

How does a passport solve that? Most small private companies are entirely opaque. A government ID doesn't help you determine authorization. It won't even help you determine ownership since anyone doing things sensibly will be using a registered agent to hold the company on his behalf. The correct approach here (AFAIK) is to punt the trust decision to the bank by requiring payment with a method that you can confidentl…

My government ID card expired and I was too lazy to renew it but I had my passport at hand so why not?

BTW both the id card and the passport have cryptographic authentication and you are able to open a bank account or use govt services completely online by scanning it with the phone Rfid . They could have make me scan that, scan my face and be done with the identity verification. My identity is already verified and tied to my company the same way and also listed in the companies registry which means they could have had skipped all the other company verification stuff too.

Re: Android Developer Verification

#169

What % of Android users actually want this? Do they know or care? I've been using Android since 2010 because it was open in ways that the Apple ecosystem wasn't. I do not want this and imagine hardly any other power users (for lack of a better term) do. I'm already using a mostly deGoogled device but this really seals the deal. I have been longing for a true Linux phone for years and now seems like a good time to get…

Rounded to the nearest percent, I'd guess power users make up 0% of android user base.

And what is your view on the percentage of power users among iphone user base? Also zero? One hundred? So interesting.

Re: Android Developer Verification

#170
post #108

Earlier quoted context omitted.

Being able to side load apps was why I switched to android 10 years ago

Please call it what it is and always has been: I.N.S.T.A.L.L.I.N.G S.O.F.T.W.A.R.E "side load" is like "jay walking' seeks to stigmatize humans being human.

When you jay walk you take the risk of being hit by a car, causing injuries to you, to the driver, and to other nearby people.

So I don't understand your analogy? Are you suggesting that pedestrians own the streets and should do what they please, as users own their phone and should have the right to do as they please? Or something else?

Post reply on HN