Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

311–320 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#311

Earlier quoted context omitted.

> This is also true if they can only install verified apps, because no company on earth has the resources to have an actually functional verification process and stuff gets through every day. This is true, but if this goes through, I imagine that the next step for safety fascists will be to require developer licensing and insurance like general contractors have. And after that, expensive audits, etc, until independen…

I don’t know if I agree, but we are very much in a world where that would make sense. Why do drug companies deserve justice for developing and pushing heroin-analogues, but not tech companies? Our work has real consequences.

And here we have it, the endgame of safety fascism. Do you have a loicense for that compiler?

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#312

Earlier quoted context omitted.

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

Cars worked fine without seatbelts too. Just because the world goes on doesn't mean we can't do better. Taking a step back though, I suspect there are cultural differences in approach here. Growing up in Europe, the idea of a regulation to make everyone safer is perfectly acceptable to me, whereas I get the impression that many folks who grew up in the US would feel differently. That's fine! But we also have to recog…

I really don't think that's a cultural difference. I also grew up and live in the EU. What Google wants just does not solve the problem in any way.

And it's also not actual regulation, just new TOS from a company many are basically forced to interact with.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#313
post #256

Earlier quoted context omitted.

This is the status quo. APK installation is disabled by default, and there is a warning when you go to enable it.

The point is "a warning" is not enough to communicate to people the gravity of what they are doing. It is not enough to write "be careful" on a bag you get from a pharmacy... certain medications require you to both have a prescription, and also to have a conversation with a pharmacist because of how dangerous the decisions the consumer makes can be. Normal human beings can be very dumb. It's entirely reasonable to ex…

Sure, but I don't think decreasing chances of scam-by-app on Android by some minuscule amount is in any way comparable to prescription drugs.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#315
post #50

Dear Undersigned, I have an APK I would like you to install on your personal phones. No, I won't tell you who I am. Please let me know when you are comfortable with this.

If I want to run a piece of software on my phone, I shouldn't need to go ask google whether they're cool with it

This is already true if you want to run a piece of software on an iPhone, on MacOS, on Windows, on any video game console.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#316
post #154
post #104

Earlier quoted context omitted.

What if we asked users if they want extra protection? I think that would be nice..

You can add 5 layers of "are you sure you want to do this unsafe thing" and it just adds 5 easy steps to the scam where they say "agree to the annoying popup"

Think about it the way you think about reading the fine print on agreements you sign. These can also have bad consequences.

But I guess not reading the TOS is another wide problem, also fueled by companies like Google.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#317

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

I have a radical solution - it should not be possible to contact someone unsolicited. All phone calls, SMS, emails, and instant messages should be blocked unless the other party is in my contacts or I have reached out to them first (plus opt-in contact from contacts of contacts, etc). Ideally, cryptographically verified. I would argue this is the real solution to spam and scamming - why on earth are random people all…

How are you going to reach out to someone first if all communication is blocked because they don't already know you?

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#318
post #313
post #256

Earlier quoted context omitted.

The point is "a warning" is not enough to communicate to people the gravity of what they are doing. It is not enough to write "be careful" on a bag you get from a pharmacy... certain medications require you to both have a prescription, and also to have a conversation with a pharmacist because of how dangerous the decisions the consumer makes can be. Normal human beings can be very dumb. It's entirely reasonable to ex…

Sure, but I don't think decreasing chances of scam-by-app on Android by some minuscule amount is in any way comparable to prescription drugs.

I do? It's a trivially comparable thing? I'm not even talking about ALL prescription drugs. I'm talking about the fact that some have interactions that can kill you. Having "life savings gone" consequences from a random app install is that level of danger.

A non-trivial number of people should probably have to go see a specialist before being able to unlock sideloading in my opinion... which means we probably all would have to. It's annoying, but I actually care about other people.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#319
post #241
post #140

Earlier quoted context omitted.

Wym? Google says it’s the one to decide. They are doing this because side loading causes fraud. There is pressure and lobbying (like this open letter) to stop them from locking it down.

It was a catchy rethorical question. Desired emphasis on the fact that a smartphone is a computing device. If you like to not be able to run whatever software you want on your computer, and the one your family owns, that's your thing. Its another pretense, like disabling full disk encryption, where people came with these ideas (instead of other options), because its convenient to them to pretend its the right thing.

When systems scale you have to look at the effects in aggregate. Android is a tool used to manage billions of people’s finances. If you allow unreviewed apps, people get scammed by fake banking apps.

You might say people shouldn’t be so dumb, or that we should educate them, but the fact is that it happens. If you allow unreviewed apps, people get scammed at a higher rate. If you allow a backdoor, people get scammed at a higher rate. People still get scammed with app store review, but the difference between 1%, .9%, and .8% is millions of lives ruined.

I’m a hacker at heart and I like general purpose computers, but when a tool becomes essential, it can ruin lives. You have to consider your externalities. Otherwise you are a factory dumping pollution in the river.

This debate is an interesting collision between the well being of the general public versus a tiny, elite class (hackers) and their ideology.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#320

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

Ah this explains why so many banks are making their own 2FA apps with warnings to never share the codes. Well a lot of people are very annoyed to install them because they perceive it as a technological downgrade when it's the opposite. I can only imagine asking them to use passkeys or hardware keys would be difficult, especially if there is some FUD (or truth?!) about how $boogeyman has your keys if you use them.
Post reply on HN