Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

311–320 of 345 posts

Re: Android Developer Verification

#311
post #187
post #156

Earlier quoted context omitted.

That sounds a lot like my experience as an Apple Developer too, with the added bonus (unclear from your description if you experienced this too) that they took my money before the verification process was finished and wouldn't refund it once their AI couldn't connect my face to my ID and wouldn't let me connect with a real person (the first dozen times were on them, but after that it was maybe my fault for including…

Going through hell with Apple Developer too. I didn't have to do much in terms of verification (probably because I created an account as an individual) but app submission is another story: - first time I got rejected for mentioning a name of a third party in my app description. The app description said: DISCLAIMER: not affiliated with xxx - after fixing the app description I got rejected for using my app name(?!), mu…

Lieutenant Appleby rejected my submission almost immediately. The notice informed me that I had committed the grave offense of impersonating a third party in the description.

"I didn't impersonate a third party," I explained in my message to Lieutenant Appleby. "I only wrote a disclaimer stating: Not affiliated with ACME."

"Exactly," lieutenant appleby replied. "By stating you have nothing to do with ACME, you have involved ACME. Therefore, you are unlawfully impersonating an unaffiliated party."

"But I only mentioned them to prove I wasn't affiliated with them!"

"Which is a violation," Lieutenant Appleby pointed out.

It was a Catch-22. The Guidelines stated that to prove you were not affiliated with a third party, you had to write a disclaimer. But to write the disclaimer, you had to type the third party’s name, which was a strict violation of the rule against mentioning third parties you were not affiliated with.

I deleted the disclaimer, thereby making myself safely affiliated with nobody by refusing to acknowledge anyone. I resubmitted the app.

Lieutenant Appleby rejected it again.

"What is it this time?" I asked.

"You are using your app's name," Lieutenant Appleby replied.

"Of course I am using my app's name," I replied back. "It is the name of my app."

"You cannot use that name. It is trademark infringement."

"Infringing on whose trademark?"

"The app's."

"But I am the app! It is my app!"

"Which is exactly why you cannot use it," Lieutenant Appleby wrote patiently. "If you use the app's name, you are impersonating the app. And impersonation is strictly forbidden by the Guidelines. An app cannot go around pretending to be itself!"

Re: Android Developer Verification

#312
post #177

Earlier quoted context omitted.

I’ve never found a malicious app on F-Droid.

F-Droid is a teeny store and requires extra steps like open sourcing such that it is not an appealing vector for malware authors. Either you want to target the Play store so that you can get a wider install base but need to deal with tighter controls or you want to distribute flagrantly malicious stuff to people for banking trojans or whatever via social engineering to get them to sideload. F-Droid doesn't help with…

> requires extra steps like open sourcing such that it is not an appealing vector for malware authors

So choosing FLOSS protects you from malware.

Re: Android Developer Verification

#313

> Android is for everyone. It’s built on a commitment to an open and safe platform. Users should feel confident installing apps, no matter where they get them from. This intro immediately tells me that whatever comes after will be horrible for users and developers. Surprise surprise, I was right. Software to "verify" side loaded apps is a bad, anti user idea.

"side loaded apps" is merely a pejorative Google and Apple use for "apps".

What they call "apps" are "apps that we like and we distribute to you under our control of both yourself as a registered user and the developers".

Well, I guess I'll need to install a non-Android distribution then. I hope one would be available for my phone by the end of the year :-(

Re: Android Developer Verification

#315
post #47
post #42

Earlier quoted context omitted.

What you're describing is not "broken", it's the process and it appears it hasn't even failed for you. My experience with getting a verified "business" developer account from Google mirrors the experience as getting one from Apple, except it's a one-time fee and much less than Apple. Yes there are hoops to jump through, identification usually requires some hoops, but pretty it's straightforward. I am not commenting o…

With Apple I filled the forms, accepted the agreements, entered the DUNS and paid with a card on my name and that was it. How does that mirror uploading my passport many times, entering company details many times, typing my e-mail and phone numbers many times both because I had to start over and because I was asked many times even if I provided these some steps back? Now I paid and waiting, hopefully I will later be…

Other people seem to have different experiences: https://news.ycombinator.com/item?id=47582372

Re: Android Developer Verification

#316
Maybe it's just me but what happened to "don't send your government id to anyone". I am from the EU but this is what was indoctrinated to me. Just seems very strange to all off a sudden send all this information to any company you require a service from.

Also the person is not the company, why is Google making the developer identify oneself while many apps are released under a company? My understanding is that Google has been mishandling this for a while but with the verification linked to a government id that just seems like another can of worms.

A few scenarios to consider:

- The developer is fired/resigns and the company does not want to be associated with the developer, for example if the developer is convicted for something.

- The developer is fired/resigns and the developer does not want to be associated with the company, developer found out about certain practices of the company they don't condone.

- The developer and the company part in good faith, however one of them is being exploited/pressured by a third party to abuse the relationship to the app.

- The developer or the company is on legal hold due to legal issues, arrests, malpractice etc.

- The developer passes away or the company ceases to exist.

- How does this work if you are making an app as a developer for hire, when entering into a contract with a publisher for example. Who will verify and how will that work (especially on small scale apps).

Re: Android Developer Verification

#317

Earlier quoted context omitted.

That can have some very extreme legal ramifications. Consider - it's a voip dialing client which has a requirement to provide location for E911 support. If the OS vendor starts providing invalid data, it's the OS vendor which ends up being liable for the person's death. e.g. https://www.cnet.com/home/internet/texas-sues-vonage-over-91... which is from 2005, but gives you an idea of the liability involved.

Phone companies are required to make sure 911 works on their phones. Random people on the internet aren't required to make sure 911 works on random apps, even if they look like phones.

The comment you're replying to literally has an example of an internet calling service being fined $20,000 for not properly directing 911 calls.

I guess Vonage should try to appeal the case and say pocksuppet said they're not required to do that.

Re: Android Developer Verification

#318
post #156
post #35

The Android verification is such a broken experience. Recently I decided to purchase a dev account for my company, so far: 1) Provided my company DUNS number etc. once to create the payment profile. I did this some times ago, don’t remember the details but it was an involved verification process and it is marked as verified business payment profile. 2) Later on the payment step verified myself with a passport and ban…

That sounds a lot like my experience as an Apple Developer too, with the added bonus (unclear from your description if you experienced this too) that they took my money before the verification process was finished and wouldn't refund it once their AI couldn't connect my face to my ID and wouldn't let me connect with a real person (the first dozen times were on them, but after that it was maybe my fault for including…

> Is there a way around this shitocracy?

If you are in EU you could try complaining to your local DPA. That certainly sounds like "automated decision which produces legal effects concerning him or her or similarly significantly affects him or her" which is against article 22 of GDPR. Or you could consider suing them directly at least for the refund.

Outside of EU maybe try passing law like GDPR to actually get some rights back.

Re: Android Developer Verification

#319
post #35

The Android verification is such a broken experience. Recently I decided to purchase a dev account for my company, so far: 1) Provided my company DUNS number etc. once to create the payment profile. I did this some times ago, don’t remember the details but it was an involved verification process and it is marked as verified business payment profile. 2) Later on the payment step verified myself with a passport and ban…

I released an Android app to the Play Store ~10 years ago and the most important advice people were always sounding alarms about online in Android dev communities was to not publish under your real Google account you care about, because it's not unlikely a bot will ban your entire account because of some vague infraction that's near impossible to appeal.

Google seems to actively hate people who develop for their platforms. Which I don't believe is a good move with their current hand, where young people in wealthy countries (i.e. the future of people who will spend money on apps) are something like 90% iPhone users these days.

Re: Android Developer Verification

#320

tl;dr how to install an app from unverified developer ("advanced flow") 1. enable developer mode 2. confirm you aren't being coached 3. restart your phone and reauthenticate 4. come back after 24 hours and unlock device 5. install app from unverified developer, option of enabling for 7 days or indefinitely This is apparently a one-time process. Advanced flow for users launches globally August 2026. Verification requi…

Nah. This sucks. My banking app refuses to open if devtools are enabled. 24h window means I can't do dev work on my personal phone.

I have that problem too, and it's a banking app I use nearly every day.

Needing to turn Developer mode off and on every time I open the app is really annoying.

It was extra annoying when I needed to log all my phone's Bluetooth HCI protocol activity for a day for product development. I wouldn't be able to take that measurement using a separate dev-specific phone, because it wouldn't contain realistic usage.

Post reply on HN