Earlier quoted context omitted.
> Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies. The robber baron's cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience -- C.S.…
this is not about moral busybodies. it's not even a moral issue. it's an existential issue. this is about demands from the population to be safe from scams. those scammers ruin lives. do you think those people really prefer to be scammed and lose their life savings? the correct solution is of course education, but education takes time. we can educate today's children so that they can protect themselves in the future.…
Open Letter to Google on Mandatory Developer Registration for App Distribution
361–370 of 392 posts
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#362Earlier quoted context omitted.
https://peabee.substack.com/p/everyone-knows-what-apps-you-u... This has been going on for years, Google knows about it, and intentionally leaves it unfixed. > Out of 47 Indian apps I randomly analyzed, 31 of them used the "ACTION_MAIN" filter - giving them access to see all the apps on your phone without any disclosure. That's 2 out of 3 apps. Of course there's hundreds of other variants of malware, this is just one…
>giving them access to see all the apps on your phone without any disclosure. That is not true, as those apps declare that they collect app activity data in their Play Store page though.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#363Earlier quoted context omitted.
> how is a UI designed that doesn't fuel incompetence? I'm specifically talking about UX ("how a user interacts with and experiences a product, system, or service"), not necessarily UI. > how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence) tl;dr We have a product, we want to make money, we need people to use the product. One of the th…
What if we actually expected people to understand something about technologies they want to use? but that's what we have now, and it's not working. the implied question is: what if we don't allow people to use technology unless they can demonstrate that they understand it? is that really something we want to do? this sounds like gatekeeping, elitism, and anti-innovation because if if less people are going to use a te…
My entire point is that education is the opposite of what we have now. That users are not expected to understand or know anything about IT technologies they use. Not the case with cars, recreational and prescription drugs...
> the implied question is: what if we don't allow people to use technology unless they can demonstrate that they understand it?
It's not exactly my point, but in extreme cases, maybe. I genuinely think that nobody has even tried to educate people about computers. Like, have you seen IT classes in schools? Assuming you are lucky enough for the classes to have any content, you will probably get some lessons in Word and Excel. Maybe some programming. Maybe Paint. But actually using the computer? Dangers of the internet, importance of backups, trusting websites, applications and emails? The concept of application and difference between applications and websites? And those technologies are not "developing" like they were 20 years ago, they are probably here to stay.
> is that really something we want to do? this sounds like gatekeeping, elitism, and anti-innovation because if if less people are going to use a technology, then there is less motivation to build it.
And the alternative Google and Apple present is giving them paternalizing control over the most popular computing device. The say over what people can do with their devices. After they made sure that these devices are embedded into our lives. I would much rather we slowed down with innovation for a second and resolved such issues first, because the way I see it, it's literally manipulation (also see: dark patterns).
As for the gatekeeping and etilism - Assuming we want a "computing license" (not necessarily what I'm arguing for), is "driving license" also gatekeeping and etilism? Or maybe some amount of gatekeeping is good?
As for anti-innovation - I genuinely think we might have had just enough innovation in the field and it may be time to slow down a little, take a step back and evaluate the results. And I honestly don't see much innovation in apps/computers/web space besides maybe AI, and governments are already working on regulating that.
> do you think that would have happened if we had required understanding before we let anyone buy a home computer?
Home computers were very harmless before the internet, but that's an aside. Assuming the tech is actually useful, not just slightly more convenient than "traditional" alternatives, then yes, I'm sure it would have still grown to sizes it has grown to today. Maybe a bit slower.
> besides education, i don't know how to approach this issue.
Same, I generally do think this whole situation needs more consideration.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#364Earlier quoted context omitted.
You can add 5 layers of "are you sure you want to do this unsafe thing" and it just adds 5 easy steps to the scam where they say "agree to the annoying popup"
then make the unlock cost money relatively easy for devs, but hard to scale for scammers
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#365The appeals to people in Southeast Asia being scammed reminds me of a blog by Cory Doctorow last year: Every complex ecosystem has parasites [1]
The gist of it is that technology can be useful, but that usefulness comes with a price: sometimes bad actors are going to commit fraud or other undesirable actions.
As an example, you can reduce the amount of banking app scams to 0% by simply denying any banking apps on phones. But because of banking apps' usefulness we're not going to do that, so there will be some non-zero risk that you will get scammed.
As a technical user I chose Android for its usefulness, accepting that there may be a (minute) chance that I get scammed, but it is a risk I am willing to take, and Google will unilaterally take this choice away from me.
Still, I don't believe Google's security concerns are sincere, so I think I just wasted my time typing all of this
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#366The most controversial claim in this letter is in the section that "Existing Measures Are Sufficient." In Google's announcement in Nov 2025, they articulated a pretty clear attack vector. https://android-developers.googleblog.com/2025/11/android-de... > For example, a common attack we track in Southeast Asia illustrates this threat clearly. A scammer calls a victim claiming their bank account is compromised and uses…
I don’t want to be too flippant, but I think there is a real trade off across many aspects of life between “freedom” and “safety”. There is a point at which people have to think critically about what they are doing. We, as a society, should do our best to protect the vulnerable (elderly, mentally disabled, etc) but we must draw the line somewhere. It’s the same thing in the outside world too - otherwise we could make…
Yes, one could imagine some kind of mental test and if you fail you don't get to use your bank online, you have to walk to the physical location to make transactions. But this can obviously be abused to shut out people from banking based on political and other aspects. Generally democracies are wary of declaring too broad sets of people as incapable of acting independently without some guardian. Obviously beyond a certain threshold of mental incapacitation, dementia etc. it kicks in, but just imagine declaring that you're too easy to influence and scam and we can't let you handle your money,... But somehow we can rely on you using sane judgment when voting in elections. Or should we strip election rights too?
We rely on polite fictions around the abilities of the average person. The contradictions sometimes surface but there is no simple way to resolve it without revising some assumptions.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#367Earlier quoted context omitted.
> The status quo may not be perfect but it is the best we can do. Nope. We could, for example, ask developers to register with their legal identity to release apps.
the open source community should ask for their own install key and that's it Play store can be fast and verification based and the F/OSS stores can be slower, reputation and review based. ... But fundamentally the easiest thing is to ask people to pay to unlock the phone's security barriers, this makes it harder and costlier for scammers.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#368Earlier quoted context omitted.
Codes arrive via SMS, which is available to all apps with the READ_SMS permission. This isn't an OS vuln. It is a property of the fact that SMS messages are delivered to a phone number and not an app. On the Play store there is a bunch of annoying checking for apps that request READ_SMS to prevent this very thing. Off Play such defense is impossible.
If they restricted sideloaded apps from sniffing SMS then I wouldn't mind all that much.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#369Earlier quoted context omitted.
>giving them access to see all the apps on your phone without any disclosure. That is not true, as those apps declare that they collect app activity data in their Play Store page though.
No they don't? The whole article is about the fact that they're using a loophole. I just checked Zomato's Play Store page, it doesn't say it collects "other installed apps", which is what it should be saying. For example, one of the other listed apps does have this. That's what it should be listing: "Installed apps".
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#370Earlier quoted context omitted.
I have a radical solution - it should not be possible to contact someone unsolicited. All phone calls, SMS, emails, and instant messages should be blocked unless the other party is in my contacts or I have reached out to them first (plus opt-in contact from contacts of contacts, etc). Ideally, cryptographically verified. I would argue this is the real solution to spam and scamming - why on earth are random people all…
How are you going to reach out to someone first if all communication is blocked because they don't already know you?
I think practically you'd want to be able to create time-limited, otherwise uncorrelated invite tokens/addresses that you could freely give out and deactivate later.