Dear Undersigned, I have an APK I would like you to install on your personal phones. No, I won't tell you who I am. Please let me know when you are comfortable with this.
Open Letter to Google on Mandatory Developer Registration for App Distribution
291–300 of 392 posts
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#292Earlier quoted context omitted.
>I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." OK, so instead of educating stupid (or overly naive) people, we implement "protections" to limit any and all people to do useful things with their devices? And as a "side effect" force them to use "our" app store only? Something doesn't sme…
How would that solve scammer-driven installs? The scammer is not in a rush, they already have the victim listening and following their instructions.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#293Earlier quoted context omitted.
> Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. The motivating example as described involves "giving the scammer everything they need to drain the account". Once they've drained the account, they don't need ongoing access.
Persistence allows the scammer free license to attempt password recoveries for every account the victim could possibly have. Other banks, retirement accounts, the victim's email account.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#294Earlier quoted context omitted.
> There simply isn't a known solution to this problem. If you give users the ability to install unverified apps, then bad actors can trick them into installing bad ones that steal their auth codes and whatnot. This is also true if they can only install verified apps, because no company on earth has the resources to have an actually functional verification process and stuff gets through every day.
> This is also true if they can only install verified apps, because no company on earth has the resources to have an actually functional verification process and stuff gets through every day. This is true, but if this goes through, I imagine that the next step for safety fascists will be to require developer licensing and insurance like general contractors have. And after that, expensive audits, etc, until independen…
Why do drug companies deserve justice for developing and pushing heroin-analogues, but not tech companies?
Our work has real consequences.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#295Earlier quoted context omitted.
Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. In contrast, convincing someone to read an OTP over the phone is a one-time manual bypass. To use your logic.. A insalled app - Like a hidden camera in a room. Social engineering over phone - Like convincing someone to leave the door unlocked once.
This is still not a root cause solution, it's just a mitigation. Because you do not require side loading to install malware. The play store and apple app store both contain malware, as well as apps which can be used for nefarious purposes, such as remote desktop. A root cause solution is proper sandboxing. Google and apple will not do this, because they rely on applications have far too much access to make their mone…
Oh they do this quite well. Thing is, these sandboxes are meant to protect apps from you, not the other way around. That's why some apps - not just platform vendor apps but also select third-party apps - get special access and elevated privileges, while you can't even see what data they store in `/storage/emulated/0/android/data` even with ADB trickery.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#296The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…
> community needs a better response to this problem than "nuh uh, everything's fine as it is." You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. Google and the state are not your nannies.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#297Earlier quoted context omitted.
If they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.
So no access to SMS for apps distributed on F-Droid?
(I'm being facetious here but this is massively preferable to disabling sideloading altogether)
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#298Earlier quoted context omitted.
How did the service authenticate the user in order to create the new credential within the attacker-controlled app?
With banks, typically a combination of your account number, pin and some confirmation code sent via email or SMS. And of course unregistering your previous device. Not sure where you're going with this though?
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#299The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…
> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…
these people aren't gullible. they are ignorant (in the uneducated sense). they are not making bad decisions. they are not even aware that there is a decision to be made.
and worst of all, this problem affects the majority of those populations. if more than half of our population was alcoholic then we absolutely would restrict the access to alcohol through whatever means possible.
it's a pandemic. and we all know what restrictions that required.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#300Earlier quoted context omitted.
In this example we still don't require you to register with anyone to buy a knife, get the blessing of some institution to sell knives, or, as in this case, get a certification before you can start making knives.
its crazy that different things, like knives and app stores, have different rules. maybe thats why the quip about the knife sounded super cool but fell apart as an analogy for this scenario when thought about for more than 5 seconds? the point of my comment was that the state does implement a lot of rules (read: "is a nanny"), despite the claim otherwise.