Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

341–350 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#341
post #165

Earlier quoted context omitted.

Sorry, which exact ruling are you referring to? How did the court arrived at this finding (that seems irrelevant, false)?

It is a non-sensical ruling. But IIRC the reason was basically that while Apple and Google did basically the same shit, only Google kept a written record of their monopolistic behaviour, so only Google was found guilty. However, there is a relevant court case here. The one about Samsung's "Auto Blocker" ( https://arstechnica.com/gadgets/2025/07/samsung-and-epic-gam... ). Epic Games sued because Samsung made it too ha…

thanks for replying!

the Samsung case is very interesting, haven't bumped into that one before.

... as far as I understand the really nasty part of "contemporary" jurisprudence of antitrust enforcement is that the standard is to show that things would be cheaper for the consumers

(though I don't know why developers are not considered consumers of the app marketplace services, after all for them bringing their own payments and whatnot would be much more cost effective... well, anyway, unfortunately the courts are mostly locked to this very inefficient path-dependent way of regulating anything through super expensive arguments, which is an obvious (?) dysfunction of legislation)

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#342

Earlier quoted context omitted.

So they'll have a lead time building up a set of verified developers. These scams are pulled by organized crime syndicates, using human trafficking and beatings to keep their call centers manned with complicit workers. Now they'll need to pay off a local mailman to give them all of Google's letters with an address in an area they control so they can register a town's worth of addresses, big whoop. It'll cost them a b…

> Now they'll need to pay off a local mailman to give them all of Google's letters with an address in an area they control so they can register a town's worth of addresses, big whoop. It'll cost them a bit more than the registration fee, but I doubt it'll be enough to solve the problem. Yeah, this is a huge amount more work than, like, nothing.

Laundering millions is a huge amount of work already. You need to hide your criminal activity from banks investigating fraud. Presuming the banks are doing their jobs right, at least, but if they don't, then that'd be the place to start solving this problem.

People are already effectively faking addresses for something as stupid as Amazon reviews. Apparently it's that cheap to fake an address, because those crapware spam stores that rotate their name/products/listings aren't exactly the size of the mob.

What this will probably do is raise the bar for scams a little so that dumb "mom-and-pop" criminals can no longer get started with a guide and a software kit they buy on Telegram, clearing the field for "professionals" while at the same time making identity fraud, address fraud, and (money) mules more lucrative.

All of that to shift away the blame from banks, public institutions, education, and to some extent people's personal financial responsibilities.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#343

Earlier quoted context omitted.

Do you need Google to compel the author to start a business relationship with them, which they can cut off at any time? Or would you be OK knowing that Thunderbird you downloaded from https://thunderbird.net/ is signed by the thunderbird.net certificate owner?

Typo squatting is a thing, and so are Unicode homographs. The permissions approach isn't bad. I may trust Thunderbird for some things, but permission to read SMS and notifications is permission to bypass SMS 2FA for every other account using that phone number. It deserves a special gate that's very hard for a scammer to pass. The exact nature of the gate can be reasonably debated.

They are, but this the next-layer-up problem. Most people don't type memorise and type URLs into their browser bar, they use a search engine result, browser history or browser bookmark.

It's therefore on their choice of search engine, or choice of app store, to lead them from "thunderbird" to "The app downloadable from https://thunderbird.net/", which can then be validated as signed by the verified owner of the same domain.

I'm not proposing changing the permissions system.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#344

Earlier quoted context omitted.

Do you need Google to compel the author to start a business relationship with them, which they can cut off at any time? Or would you be OK knowing that Thunderbird you downloaded from https://thunderbird.net/ is signed by the thunderbird.net certificate owner?

should I be confident that thunderbird.net is the real one, or could it be hosted at thunderbird.org, thunderbird.com, or thunderbird.mozilla.org?

That's a search engine / reputation problem and it's also present even in Daddy Google's and Daddy Apple's walled gardens.

If you search any web search engine for "thunderbird", https://thunderbird.net/ is the top result. You can choose your preferred search engine, you should be able to choose your own app store, and your level of confidence stems from your own estimation of that entity's past competence.

If you do search Google Play for "thunderbird", you'll find it lists an app with internal name "net.thunderbird.android" as the top result (along with lots of other mail clients). What I'm proposing is that if your choice of search engine or app store shows you https://thunderbird.net/ as the place to download Thunderbird, and you do, PKI can then verify that the app was independently signed by the owner of the matching domain, and that the certificate was issued to them by a CA who regularly validates they control that domain.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#346
post #321
post #310

Earlier quoted context omitted.

To add to that, I think it's important to point out that the problem of people not understanding how to safely use their devices is in big part caused by technology companies racing to get widest adoption everywhere, both in terms of location and in terms of industries. I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence. We shouldn't now let them pick the most convenient…

I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence. how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence) how is a UI designed that doesn't fuel incompetence? i have a hard time imagining what design aspects matter here, and how to improve upon them.

> how is a UI designed that doesn't fuel incompetence?

I'm specifically talking about UX ("how a user interacts with and experiences a product, system, or service"), not necessarily UI.

> how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence)

tl;dr We have a product, we want to make money, we need people to use the product. One of the things that stand in the way, is people not understanding how to use our product. We will make sure they can get started as fast as possible, and not mention how they may hurt themselves with the product, that would scare them away. Hurting yourself with our product is in the broad "don't do stupid things" category. We will never explain the "framework" (in case of an OS I mean apps, that apps can interact with each other and your data, how you can or cannot, control that), even in broad terms. Just click this button and get your solution.

It started with PCs and people not understanding how to not lose their documents. Now that every device is connected to the internet, the problem became worse.

You can now say that "sideloading" is stupid anyway, but this is not the only problem. Another thing that people still usually learn by painful experience is backups. There are fake apps, on both stores. Another thing, in-band signaling. You cannot trust email, phones, whatsapp, messenger... Even if your friend you often chat with is messaging you, they could've just been hacked. Try to explain that you also cannot trust websites and that even technical people don't have a good way of telling if an email of a website is real.

But at least enrollment is fast and adoption metrics are growing. Since we are already in "move fast and break things" mindset, we will think about fixing such issues when it actually becomes a problem.

To be clear, I'm not saying that making technology easy is always bad, that you should always expose the user to "the elements" and expect them pipe commands in the shell. But I think that often the focus is on only making enrollment fast. "Get started"

What if we actually expected people to understand something about technologies they want to use?

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#347
post #333

Earlier quoted context omitted.

>The play store and apple app store both contain malware Wow, that a major claim. What apps are malware, exactly? >This is still not a root cause solution, it's just a mitigation. Requiring signed apps solves the issue though, as it provides identification of whoever is running the scam and a method for remuneration or prosecution.

https://peabee.substack.com/p/everyone-knows-what-apps-you-u... This has been going on for years, Google knows about it, and intentionally leaves it unfixed. > Out of 47 Indian apps I randomly analyzed, 31 of them used the "ACTION_MAIN" filter - giving them access to see all the apps on your phone without any disclosure. That's 2 out of 3 apps. Of course there's hundreds of other variants of malware, this is just one…

>giving them access to see all the apps on your phone without any disclosure.

That is not true, as those apps declare that they collect app activity data in their Play Store page though.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#348
post #299

Earlier quoted context omitted.

> I agree that mandatory developer registration feels too heavy handed, but I think the community needs a better response to this problem than "nuh uh, everything's fine as it is." Why would the community give a different response? Everything is fine as it is. Life is not safe, nor can it be made safe without taking away freedom. That is a fundamental truth of the world. At some point you need to treat people as adul…

the problem is that in developing countries smart phones are a massive technology jump for people who lack the education to even have a clue whats going on. treating people as adults does not work if they don't have the education needed for that. these people aren't gullible. they are ignorant (in the uneducated sense). they are not making bad decisions. they are not even aware that there is a decision to be made. an…

> Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies. The robber baron's cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience

-- C.S. Lewis

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#349
post #312

Earlier quoted context omitted.

I really don't think that's a cultural difference. I also grew up and live in the EU. What Google wants just does not solve the problem in any way. And it's also not actual regulation, just new TOS from a company many are basically forced to interact with.

It might not "solve" the problem, but I'd expect it to significantly address the problem no? I've heard much criticism of it being too heavy-handed, but I don't think I understand criticism that it won't improve security. Could you expand on that?

No. You seem to be implicitly arguing that that unsigned apps are inherently less trustworthy than PlayStore apps. That's a claim that needs to be proven first. And based on the huge amount of documented data exfiltration performed by Google-approved apps, I'm going to say that claim is false.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#350
post #300

Earlier quoted context omitted.

its crazy that different things, like knives and app stores, have different rules. maybe thats why the quip about the knife sounded super cool but fell apart as an analogy for this scenario when thought about for more than 5 seconds? the point of my comment was that the state does implement a lot of rules (read: "is a nanny"), despite the claim otherwise.

Yes, the strawman version of an analogy falls apart if you poke it. You didn't actually engage the analogy at all.

[deleted]
Post reply on HN