Live data from Hacker News

Open Letter to Google on Mandatory Developer Registration for App Distribution

keepandroidopen.org

351–360 of 392 posts

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#351

Earlier quoted context omitted.

And here we have it, the endgame of safety fascism. Do you have a loicense for that compiler?

Do you call building codes and bridge engineering standards "safety fascism" as well? The stakes aren't any lower for us.

Me being allowed to publish hobby software is just as high stakes as a fscking bridge? Get a grip, man.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#353

Earlier quoted context omitted.

Do you call building codes and bridge engineering standards "safety fascism" as well? The stakes aren't any lower for us.

Me being allowed to publish hobby software is just as high stakes as a fscking bridge ? Get a grip, man.

You’re moving the goal posts. You can build all the hobby bridges you want. It would be deeply irresponsible to ask the public to cross them, though.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#354

Earlier quoted context omitted.

Or make sideloading available only after 24 hours since enabling it. I would enable it on my new devices and wait 24 hours before installing F-Droid and other apps. Not a problem. Scammers might wait one day too but it decreases the chances of success because friends and family members can interfere. But I'm afraid that this is security theater and the true goal is to protect revenues by making it hard or impossible…

> But I'm afraid that this is security theater and the true goal is to protect revenues by making it hard or impossible to install apps that impact Alfabet bottom line (eg third party YouTube clients.) It's not just them. Every other SaaS, from banks to media providers to E2EE[0] chat clients to random apps whose makers feel insecure, or are obsessed with security [theater] best practices, just salivate at the though…

In the case of most of those business it's only because they must mark checkboxes on a regulation compliance sheet and/or deflect blame on someone else. The problem is that this is a never ending spiral of regulation after regulation and new ways to deflect blame so after device attestation will fail to solve all of their problems they'll end up pushing something else.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#355

The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…

I am the author of the letter and the coordinator of the signatories. We aren't saying "nuh uh, everything's fine as it is." Rather, we are pointing out that Android has progressively been enhanced over the years to make it more secure and to address emerging new threat models. For example, the "Restricted Settings"¹ feature (introduced in Android 13 and expanded in Android 14) addresses the specific scam technique o…

This is what I was able to find with some quick searching:

- From Dec 2024 there's https://www.bangkokpost.com/business/general/2915570/state-g... and https://theinvestor.vn/thai-govt-collaborates-with-google-to... which list some efforts done in “collaboration between the Digital Economy and Society (DES) Ministry [of Thailand] and Google”. It mentions “The initiative started in April, providing the Google Play Protect feature”, which “blocked attempts by criminals to install apps more than 4.8 million times on more than 1 million Android devices”. And https://www.nationthailand.com/blogs/business/tech/40036973 is from earlier (Apr 2024), about the introduction of the Google Play Protect feature.

- From April 2025 there's https://blog.google/company-news/inside-google/around-the-gl... a blog post from a “VP, Government Affairs & Public Policy”, which mentions “people in Asia Pacific feel it acutely, having lost an estimated $688 billion in 2024” (I think this may be across all scams?) and ends with “Combatting evolving online fraud in Asia-Pacific is critical” after listing a bunch of random things (unrelated to Android) Google is/was doing. This suggests to me that Google was under some criticism/pressure from governments for enabling scams, and eager to say “see, we're doing something”.

- The developer verification announcement came four months later in August 2025: https://android-developers.googleblog.com/2025/08/elevating-...

> In early discussions about this initiative, we've been encouraged by the supportive initial feedback we've received. In Brazil, the Brazilian Federation of Banks (FEBRABAN) sees it as a “significant advancement in protecting users and encouraging accountability.” This support extends to governments as well, with Indonesia's Ministry of Communications and Digital Affairs praising it for providing a “balanced approach” that protects users while keeping Android open. Similarly, Thailand’s Ministry of Digital Economy and Society sees it as a “positive and proactive measure” that aligns with their national digital safety policies.

This shows that it was a negotiation with the governments/agencies in Brazil, Indonesia, Thailand that were breathing down on Google to do something.

- The fourth country where this developer verification is rolling out first is Singapore, and https://www.channelnewsasia.com/singapore/android-malware-sc... is from Sep 2023 while https://www.channelnewsasia.com/singapore/google-android-dev... is from Feb 2024 which mentions that a certain upgrade to Google Play Protect (blocking apps if they “demands suspicious permissions such as access to restricted data like SMSes and phone notifications”) was first rolling out in Singapore.

- And the most recent https://android-developers.googleblog.com/2025/11/android-de... from November 2025 (which promised the “students and hobbyists” account type and the “experienced users” flow “in the coming months”) also has a “Why verification is important” section that mentions the “consistently acted to keep our ecosystem safe” and “common attack we track in Southeast Asia” and “While we have advanced safeguards and protections to detect and take down bad apps, without verification, bad actors can spin up new harmful apps instantly”.

The overall picture I get is less of “Google to suddenly abandon these iterative security improvements” but more like: under pressure from governments to stop scams, Google has been doing various things like the things you mentioned, and scammers have also been evolving and finding new ways to carry out scams at scale (like “impersonating developers”), and the latest upcoming change requiring developer verification on “certified Android devices” is simply the next step of the iteration. It sucks and feels like a wholesale lock-down, yes, but it does not seem a jarring disconnect from the previous steps in the progression of locking things down.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#356

Earlier quoted context omitted.

Me being allowed to publish hobby software is just as high stakes as a fscking bridge ? Get a grip, man.

You’re moving the goal posts. You can build all the hobby bridges you want. It would be deeply irresponsible to ask the public to cross them, though.

I never mentioned building critical software like medical diagnosis software, software for industrial equipment, etc.

If I write a trash library for a random project and someone else starts using it to run their nuke plant, that isn’t my fault. Read the license. NO WARRANTY.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#357
post #348
post #299

Earlier quoted context omitted.

the problem is that in developing countries smart phones are a massive technology jump for people who lack the education to even have a clue whats going on. treating people as adults does not work if they don't have the education needed for that. these people aren't gullible. they are ignorant (in the uneducated sense). they are not making bad decisions. they are not even aware that there is a decision to be made. an…

> Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies. The robber baron's cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience -- C.S.…

this is not about moral busybodies. it's not even a moral issue. it's an existential issue. this is about demands from the population to be safe from scams. those scammers ruin lives. do you think those people really prefer to be scammed and lose their life savings?

the correct solution is of course education, but education takes time. we can educate today's children so that they can protect themselves in the future. but that's the next generation. for the current generation that kind of education is to late.

the proposed solution is a stopgap measure. do you have a better idea how to solve the problem? (maybe putting more effort into persecution, but that costs money. or making banks responsible for covering the loss. but then you'll get banks demanding the protection. tyranny of the banks then? is that any better? that's actually happening in europe now.)

not doing anything will hurt a lot of people and make them unhappy. as a government you really don't want that either.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#358
post #119

Earlier quoted context omitted.

No luck needed. Linux based phones are starting to become viable as daily drivers. [0] They are even coming with VM Android in case an application is needed that does not have a Linux equivalent. I am interested in how Google's gatekeeper tactics are going to affect Android like platforms such as /e/os and GrapheneOS. [1] [0] http://furilabs.com/ [1] https://murena.com/america/products/smartphones/

> > Good luck with that. > No luck needed. Linux based phones are starting to become viable as daily drivers. Then please tell me, which non-Android Linux-based phone can I buy here in Brazil (one of the first places where Android would have these new restrictions)? I'd love to know (not sarcasm, I'm being sincere). Keep in mind that only phones with ANATEL certification can be imported, non-certified phones will be…

Only way is to get the laws to change by electing other officials or civil disobedience.

I do not know all International laws. Nor do I respect countries and politicians that force such restrictive laws that prevent reuse of good devices that are now unsupported by the original manufacture.

Secondly if that law was enacted in the US ... I would buy a product that has a known bug to allow for loading a custom OS. In court I would push for jury-nullification too.

Authoritative governments suck at all fronts ... not just phone restrictions.

Would you mind pointing me to the ANATEL certification process? I am wondering if the voice of the law is worded to prevent competition ... sounds like something Google would of helped push through.

Are you allowed old school non-smart phones? That is how I would do it. Laptop and dumb phone.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#359
post #346
post #321

Earlier quoted context omitted.

I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence. how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence) how is a UI designed that doesn't fuel incompetence? i have a hard time imagining what design aspects matter here, and how to improve upon them.

> how is a UI designed that doesn't fuel incompetence? I'm specifically talking about UX ("how a user interacts with and experiences a product, system, or service"), not necessarily UI. > how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence) tl;dr We have a product, we want to make money, we need people to use the product. One of the th…

What if we actually expected people to understand something about technologies they want to use?

but that's what we have now, and it's not working.

the implied question is: what if we don't allow people to use technology unless they can demonstrate that they understand it?

is that really something we want to do? this sounds like gatekeeping, elitism, and anti-innovation because if if less people are going to use a technology, then there is less motivation to build it.

remember, i think it was someone at IBM that said that the potential for computers is some small number? and then it grew beyond anyone's wildest expectations?

do you think that would have happened if we had required understanding before we let anyone buy a home computer?

besides education, i don't know how to approach this issue.

Re: Open Letter to Google on Mandatory Developer Registration for App Distribution

#360
post #318
post #313

Earlier quoted context omitted.

Sure, but I don't think decreasing chances of scam-by-app on Android by some minuscule amount is in any way comparable to prescription drugs.

I do? It's a trivially comparable thing? I'm not even talking about ALL prescription drugs. I'm talking about the fact that some have interactions that can kill you. Having "life savings gone" consequences from a random app install is that level of danger. A non-trivial number of people should probably have to go see a specialist before being able to unlock sideloading in my opinion... which means we probably all wou…

I have a hard time with this because it's the world we've lived in forever. Everyone knows installing an "app" installs an executable.

Doesnt android require a specific permission to be user-accepted for an installed app to read notifications? I think it's separate from the post-notifications permission.

This seems to be an issue of user literacy. If so, doesn't it make more sense for a user to have the option to opt into "I'm tech illiterate, please protect me" than destroy open computing as we know it?

Post reply on HN