Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

291–300 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#291
post #50

Dear Undersigned, I have an APK I would like you to install on your personal phones. No, I won't tell you who I am. Please let me know when you are comfortable with this.

Sure thing, as long as it doesn't require any permissions. I have installed multiple apks on my phone from unknown people. Note that Google's requirement is also for completely permissionless apps like games.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#292
post #65

Earlier quoted context omitted.

>I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." OK, so instead of educating stupid (or overly naive) people, we implement "protections" to limit any and all people to do useful things with their devices? And as a "side effect" force them to use "our" app store only? Something doesn't sme…

How would that solve scammer-driven installs? The scammer is not in a rush, they already have the victim listening and following their instructions.

[deleted]

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#293

Earlier quoted context omitted.

> Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. The motivating example as described involves "giving the scammer everything they need to drain the account". Once they've drained the account, they don't need ongoing access.

Persistence allows the scammer free license to attempt password recoveries for every account the victim could possibly have. Other banks, retirement accounts, the victim's email account.

Scammer that thrive are greedy, but not too greedy. Easier to break into one type of account for 10 victims, than to break into 10 different account of one victim. Persistence is risk.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#294

Earlier quoted context omitted.

> There simply isn't a known solution to this problem. If you give users the ability to install unverified apps, then bad actors can trick them into installing bad ones that steal their auth codes and whatnot. This is also true if they can only install verified apps, because no company on earth has the resources to have an actually functional verification process and stuff gets through every day.

> This is also true if they can only install verified apps, because no company on earth has the resources to have an actually functional verification process and stuff gets through every day. This is true, but if this goes through, I imagine that the next step for safety fascists will be to require developer licensing and insurance like general contractors have. And after that, expensive audits, etc, until independen…

I don’t know if I agree, but we are very much in a world where that would make sense.

Why do drug companies deserve justice for developing and pushing heroin-analogues, but not tech companies?

Our work has real consequences.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#295
post #19

Earlier quoted context omitted.

Installing an app that silently intercepts SMS/MMS data is a persistent technical compromise. Once the app is there, the attacker has ongoing access. In contrast, convincing someone to read an OTP over the phone is a one-time manual bypass. To use your logic.. A insalled app - Like a hidden camera in a room. Social engineering over phone - Like convincing someone to leave the door unlocked once.

This is still not a root cause solution, it's just a mitigation. Because you do not require side loading to install malware. The play store and apple app store both contain malware, as well as apps which can be used for nefarious purposes, such as remote desktop. A root cause solution is proper sandboxing. Google and apple will not do this, because they rely on applications have far too much access to make their mone…

> A root cause solution is proper sandboxing. Google and apple will not do this, because they rely on applications have far too much access to make their money.

Oh they do this quite well. Thing is, these sandboxes are meant to protect apps from you, not the other way around. That's why some apps - not just platform vendor apps but also select third-party apps - get special access and elevated privileges, while you can't even see what data they store in `/storage/emulated/0/android/data` even with ADB trickery.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#296

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

> community needs a better response to this problem than "nuh uh, everything's fine as it is." You can also cut yourself with a kitchen knife but nobody proposes banning kitchen knives. Google and the state are not your nannies.

Laws protect people from being hurt by others, keeping society safe and fair for everyone.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#297

Earlier quoted context omitted.

If they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.

So no access to SMS for apps distributed on F-Droid?

Fine by me, what are people using SMS for in 2026 except for spam and sending 2FA codes insecurely?

(I'm being facetious here but this is massively preferable to disabling sideloading altogether)

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#298
post #287

Earlier quoted context omitted.

How did the service authenticate the user in order to create the new credential within the attacker-controlled app?

With banks, typically a combination of your account number, pin and some confirmation code sent via email or SMS. And of course unregistering your previous device. Not sure where you're going with this though?

I am just pointing out that you are essentially saying passkeys can be phished because banks can allow phishable credentials to bypass passkeys.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#299

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

the problem is that in developing countries smart phones are a massive technology jump for people who lack the education to even have a clue whats going on. treating people as adults does not work if they don't have the education needed for that.

these people aren't gullible. they are ignorant (in the uneducated sense). they are not making bad decisions. they are not even aware that there is a decision to be made.

and worst of all, this problem affects the majority of those populations. if more than half of our population was alcoholic then we absolutely would restrict the access to alcohol through whatever means possible.

it's a pandemic. and we all know what restrictions that required.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#300
post #68

Earlier quoted context omitted.

In this example we still don't require you to register with anyone to buy a knife, get the blessing of some institution to sell knives, or, as in this case, get a certification before you can start making knives.

its crazy that different things, like knives and app stores, have different rules. maybe thats why the quip about the knife sounded super cool but fell apart as an analogy for this scenario when thought about for more than 5 seconds? the point of my comment was that the state does implement a lot of rules (read: "is a nanny"), despite the claim otherwise.

Yes, the strawman version of an analogy falls apart if you poke it. You didn't actually engage the analogy at all.
Post reply on HN