Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

301–310 of 694 posts

Re: Android developer verification: Early access starts

#301
post #270

Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

So your father: 1. Downloaded a weird file from a stranger 2. Went to the settings and about pyone sceeen 3. Tapped the thing 5 times to activate developer mode 4. Activated installing from third party sources despite the warning there 5. Installed the APK May I suggest the problem is not that this is possible, but a lack of education? If your father is the type that would jump into the bathtub with a toaster because…

One does not need to enable developer mode to install a 3rd party APK.

Re: Android developer verification: Early access starts

#302
post #101

Earlier quoted context omitted.

I would like a world where buying something means you get final say over how it operates even if you might do something dangerous/harmful/illegal.

I would like a world where I have the final say over whether I should have a final say. One way to achieve this is to only allow sideloading in "developer mode", which could only be activated from the setup / onboarding screen. That way, power users who know they'll want to sideload could still sideload. The rest could enjoy the benefits of an ecosystem where somebody more competent than their 80-year-old nontechnica…

These two solutions wouldn't work for me. My phone is covered, I use a custom ROM, but I like being able to help people install cool stuff that's not necessarily on the Play store, organically, without planning.

Re: Android developer verification: Early access starts

#303
post #36

Earlier quoted context omitted.

I bought the hardware, therefore I have the right to modify and repair. Natural right, full stop. That right ends are your nose, as the saying goes.

I don't think it's illegal to do whatever you want with your phone. That doesn't mean google legally is required to make it easy or even possible. That being said I ethically they should allow it, and considering their near monopoly status they should be forced to keep things open. In fact there should be right to repair laws too.

The way to go from fervently hoping they make the ethical choice to actually protecting the users is to regulate it

Re: Android developer verification: Early access starts

#304

Ancedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.

For real? No, thanks I'd like to keep my SMS app

Re: Android developer verification: Early access starts

#305

They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…

Is the digital ID just to identify yourself online? Because I've never had to do that. Kind of seems like a solution in search of a problem.

The digital ID e.g. eID is for example if you want to order a government document online. At the current time you need to print out your request and send a copy of your ID in the mail or go to the counter and show it. Same if you get a bank account or new phone contract although those usually let you scan your ID with your phone. A eID would make that more secure although people are already being tricked into doing face validations[1]...

Offline it would make it possible to verify your age at the self-checkout registers without having someone have to check in person.

In the future (if the law allows it, which it currently does not) it should be possible for you to purchase an item online completely anonymously, at least to the vendor. There would no longer be a possibility of leaked address, etc. as the vendor would not have it. All the vendor has are signed tokens. When they send a package they send it with a token to the post office and only the post office knows your address.

[1] https://www.srf.ch/sendungen/kassensturz-espresso/espresso/m...

Re: Android developer verification: Early access starts

#306

They will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. H…

Seriously though, can anyone tell me why the fuck banking apps try so hard to find any possible excuse to not run on customised devices? I just can't see any good reason for it but my banking app has invested more work into detecting any possible hint of rooting than into its UX. It's absurd.

How useful is it to have a unique global ID, that the target willingly carries and manages, but doesn't have any meaningful control over?

Re: Android developer verification: Early access starts

#307
post #98
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

this is an unresolvable issue security = 1/convenience or in this case: security = 1/freedom or agency

Security isn't an absolute and this doesn't notably improve it

Re: Android developer verification: Early access starts

#309

Earlier quoted context omitted.

This is also how it works on my Samsung Galaxy S21. There's no need to enable developer settings.

I have definitely seen this "you need to go deep in the settings to enable 3rd party installs at all" flow before, but I don't remember which device it was. (Just saying that the commenter above is not just inventing something, I was surprised when I saw it as well)

There definitely is such setting, but I have no idea when it was introduced. S21 is an old phone (not to disparage it in any way).

    Your Galaxy phone or tablet is configured by default to prevent the installation of apps from sources other than the Play Store and Galaxy Store.
https://www.samsung.com/ae/support/mobile-devices/how-to-ena...
Post reply on HN