Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

331–340 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#331

Earlier quoted context omitted.

The status quo may not be perfect but it is the best we can do. We try to educate people about scams. We give them warnings that what they are doing can be dangerous if misused. If they choose to ignore those things and proceed anyway, the only further step society could take is to take away the person's freedom to choose. And that is an unacceptable solution.

> The status quo may not be perfect but it is the best we can do. Nope. We could, for example, ask developers to register with their legal identity to release apps.

The original post laids out why it's not possible to do well: privacy apps, sanctioned countries, apps made by people for themselves to avoid clouds and third parties, etc.

Simple example: I have a foss VPN app running on my phone to avoid censorship and surveillance in some countries I visit. While using this app is no problem, non-anonymous development might carry consequences to the developer in some dictatorship jurisdictions (which are plenty of). I'm not sure all devs of such system would be willing to give their ids.

Another example is that this way US can cut out countries and people they don't like from mobile usage (which basically equals to modern social life). Look into sanctioned judges of international court because US protects war criminals.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#332

Earlier quoted context omitted.

Google's announcement is just trolling, there's an order of magnitude more scams on the Play store and they don't call for its closure. Right now when I search for "ChatGPT", the top app is a counterfeit app with a fake logo, is it really this store which is supposed to help us fight scams?

> Right now when I search for "ChatGPT", the top app is a counterfeit app with a fake logo, is it really this store which is supposed to help us fight scams? Just did Play search for "ChatGPT" and the top-2 results were for OpenAI's app (one result was sponsored by OpenAI one result was from Google's search). So anecdotally your results may vary.

See what I'm seeing on my device : https://ibb.co/DJKGM8d

So maybe before talking about anything about direct installs, they could fix the big scams on the Play Store.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#333

Earlier quoted context omitted.

This is still not a root cause solution, it's just a mitigation. Because you do not require side loading to install malware. The play store and apple app store both contain malware, as well as apps which can be used for nefarious purposes, such as remote desktop. A root cause solution is proper sandboxing. Google and apple will not do this, because they rely on applications have far too much access to make their mone…

>The play store and apple app store both contain malware Wow, that a major claim. What apps are malware, exactly? >This is still not a root cause solution, it's just a mitigation. Requiring signed apps solves the issue though, as it provides identification of whoever is running the scam and a method for remuneration or prosecution.

https://peabee.substack.com/p/everyone-knows-what-apps-you-u...

This has been going on for years, Google knows about it, and intentionally leaves it unfixed.

> Out of 47 Indian apps I randomly analyzed, 31 of them used the "ACTION_MAIN" filter - giving them access to see all the apps on your phone without any disclosure. That's 2 out of 3 apps.

Of course there's hundreds of other variants of malware, this is just one of the most prevalent.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#334

Earlier quoted context omitted.

So no access to SMS for apps distributed on F-Droid?

Fine by me, what are people using SMS for in 2026 except for spam and sending 2FA codes insecurely? (I'm being facetious here but this is massively preferable to disabling sideloading altogether)

> sideloading

If you care about the topic, which you seemingly do, stop using this doubleplusgood term.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#335

Earlier quoted context omitted.

That's the status quo, though. Apple's App Store and Google's Play Store are essentially unmoderated. The sheer scale of them and both platforms' technical architectures prohibits either company from properly validating their stores' contents - they can't even catch the easy cases, like all the apps that impersonate ChatGPT. The main thing they manage to do is inconvenience innocent indie devs once in a while. The re…

Why do you expect another app store to be different? At what scales do the dynamics of what you have described change?

F-Droid does not contain malware. There were cases of maintainers going rogue, such as Simple apps being bought by an adware firm, which resulted in a timely takedown, directing users to a maintained fork Fossify. Like a distro repository, the user safety comes not from reactive moderation but active curation.

Meanwhile my parents are getting hammered by inescapable malvertisements from Google, a TTS voice ordering them to install a "cleaner" app or have their phone die, no matter how many you report or what knobs you touch under ad personalization. Facebook knew 20% of their yearly revenue was scams and intentionally deferred moderator action to keep that business. All this "trust" is so overwhelming, the only way to make our computing more trusted is if OEM auto-installed the malware themselves. Oh wait, Samsung does that!

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#336

Earlier quoted context omitted.

I don’t know if I agree, but we are very much in a world where that would make sense. Why do drug companies deserve justice for developing and pushing heroin-analogues, but not tech companies? Our work has real consequences.

And here we have it, the endgame of safety fascism. Do you have a loicense for that compiler?

Do you call building codes and bridge engineering standards "safety fascism" as well?

The stakes aren't any lower for us.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#337
post #93
post #50

Dear Undersigned, I have an APK I would like you to install on your personal phones. No, I won't tell you who I am. Please let me know when you are comfortable with this.

sure, point me to the fdroid page for it

Or at point me to a git repo.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#338

Earlier quoted context omitted.

If I want to run a piece of software on my phone, I shouldn't need to go ask google whether they're cool with it

This is already true if you want to run a piece of software on an iPhone, on MacOS, on Windows, on any video game console.

[delayed]

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#339

The judge told Google that Apple is not anti-competitive because Apple has no competitors on it's platform (this all stemming from the Epic lawsuits). Google listened. Blame the judge for one of the worst legal calls in recent history. Google is a monopoly and Apple is not. Simple fix for Google... Same comment I made a few days ago, I feel it bears repeating as much as possible until it's really driven home how detr…

> Same comment I made a few days ago..

This! I was about to reply that you have already posted this comment four days ago: https://news.ycombinator.com/item?id=47092480

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#340

Earlier quoted context omitted.

Developer registration doesn't prevent this problem. Stolen ID can be found for a lot less money than what a day in a scam farm's operation will bring in. A criminal with access to Google can sign and deploy a new version of their scam app every hour of the day if they wish. The problem lies in (technical) literacy, to some extent people's natural tendency to trust what others are telling them, the incompetence of in…

My guess is that Android 17 will show the registered name of the developer of the app you're trying to install. With stolen IDs you can only get accounts for individual developers not for organisations. When a scammer pretending to be your bank tells you to install an app for verification and it says "This app was created by John Smith" even grandma will get suspicious and ask why it doesn't show the bank's name.

When someone is getting scammed by "special agent John Smith of the Federal Banking Enforcement Commission", the name "John Smith" won't cause any suspicion.

This trick only works if the general public is aware of what the app developer label does, what it is used for, what it protects against, and what it's supposed to say. However, if that's the case, you already have all the info you need to deduce that you shouldn't be installing APKs sent by a guy over the phone anyway.

Post reply on HN