Earlier quoted context omitted.
I never said it was a sole check, I said it was a check. The reality is that app is not thoroughly tested and, even if it was, this would not catch all malware because, again, it's trivial to write malware that can pass a review period and flip on later. First Google search https://www.malwarebytes.com/blog/news/2025/08/77-malicious-... Here's 77 found by researchers and then removed. Relying on researchers to find m…
That is actually hilarious, did you actually read the MO of those Apps? >The core payload has been updated to incorporate a new keylogger variant of Anatsa. Additionally, the malware utilizes a well-known Android APK ZIP obfuscator for enhanced evasion. The DEX payload is concealed within a JSON file, which is dynamically dropped at runtime and promptly deleted after being loaded. I wonder if there is anything that G…
Open Letter to Google on Mandatory Developer Registration for App Distribution
381–390 of 392 posts
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#382Earlier quoted context omitted.
No. You seem to be implicitly arguing that that unsigned apps are inherently less trustworthy than PlayStore apps. That's a claim that needs to be proven first. And based on the huge amount of documented data exfiltration performed by Google-approved apps, I'm going to say that claim is false.
I'm arguing that a curation process that includes security review is likely to produce a more secure set of software. Admittedly it might be completely ineffective, but I think that's an unreasonable assumption. So some review is more secure than no review. Now I'm not saying "better", you could argue it's a false sense of security, but it's still more security.
I actually totally agree! There is no external entity users can rely on to make sure apps they download are legitimate. I read the thread from root to this comment and I don't see it mentioned, so I'm not sure if you know this and are just arguing something else but...
There is actually nothing about testing or verifying apps themselves in the announcement made by Google. It's just about enforcing developer verification in some Google service and "registering the apps".
https://support.google.com/android-developer-console/answer/... https://android-developers.googleblog.com/2025/11/android-de...
EDIT: I checked your profile, and I now see that you actually work at Google, on Android... Is there something I misunderstood about these announcements?
> you could argue it's a false sense of security, but it's still more security
Well here I don't agree, I would much rather be aware of the dangers than think I'm safe when I'm actually not.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#383Earlier quoted context omitted.
That is actually hilarious, did you actually read the MO of those Apps? >The core payload has been updated to incorporate a new keylogger variant of Anatsa. Additionally, the malware utilizes a well-known Android APK ZIP obfuscator for enhanced evasion. The DEX payload is concealed within a JSON file, which is dynamically dropped at runtime and promptly deleted after being loaded. I wonder if there is anything that G…
If you're wondering, I didn't read the link at all. The fact that malware exists on the play store is undisputed and I think everyone, except you, agrees with me. So I don't feel it requires much, if any, research on my part.
What a quote. My word.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#384Earlier quoted context omitted.
What if we asked users if they want extra protection? I think that would be nice..
This is the status quo. APK installation is disabled by default, and there is a warning when you go to enable it.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#385Earlier quoted context omitted.
If you're wondering, I didn't read the link at all. The fact that malware exists on the play store is undisputed and I think everyone, except you, agrees with me. So I don't feel it requires much, if any, research on my part.
>I didn't read the link at all. What a quote. My word.
It's a big repository, it's a lot of code, and Google has read approximately 0% of it. Fucking obviously there's malware, it's not rocket science.
My biggest mistake is humoring people who either play stupid or are so stupid that they can barely function. Why do I do this? Is this a form of masochism? Is there a medicine for this? And, if so, is it in-network?
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#386Earlier quoted context omitted.
Why do you expect another app store to be different? At what scales do the dynamics of what you have described change?
F-Droid does not contain malware. There were cases of maintainers going rogue, such as Simple apps being bought by an adware firm, which resulted in a timely takedown, directing users to a maintained fork Fossify. Like a distro repository, the user safety comes not from reactive moderation but active curation. Meanwhile my parents are getting hammered by inescapable malvertisements from Google, a TTS voice ordering t…
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#387Earlier quoted context omitted.
If the actual bank app does that, or is even easy to fool into doing that, then the bank should be responsible. That's the world "regular people" want and it's the world as it should be. If random malware the user chose to install does that, then that is not the bank's fault . The bank is no more involved than anybody else. And no, I don't think "regular people" want to make that the bank's fault.
The legal infrastructure for banking and securities ownership has long had defaults for liability assignment. For securities, if I own stock outright, the company has to indemnify if they do a transfer for somebody else or if I lack legal capacity. So transfer agents require Medallion Signature Guarantees from a bank or broker. MSGs thereby require a lengthy banking relationship and probably showing up in person. For…
Perhaps programmers have a clear idea of what's given up when you do things your way.
I'm not sure you do.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#388Earlier quoted context omitted.
then make the unlock cost money relatively easy for devs, but hard to scale for scammers
It is unreasonable to require a payment for people to use their own phone the way they want
Developers want developer phones, non-developers want safe phones that are resistant to their and their shitty bank's goddamn fucking stupidity. (Because banks UX is so so so so bad that most of the time the phishing attack seems like just a normal part of the bank's UX.)
But it's hard to separate people on a webshop, if a shop runs out of non-developer phones they'll happily sell the developer phones to non-developers.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#389Earlier quoted context omitted.
> Now they'll need to pay off a local mailman to give them all of Google's letters with an address in an area they control so they can register a town's worth of addresses, big whoop. It'll cost them a bit more than the registration fee, but I doubt it'll be enough to solve the problem. Yeah, this is a huge amount more work than, like, nothing.
Laundering millions is a huge amount of work already. You need to hide your criminal activity from banks investigating fraud. Presuming the banks are doing their jobs right, at least, but if they don't, then that'd be the place to start solving this problem. People are already effectively faking addresses for something as stupid as Amazon reviews. Apparently it's that cheap to fake an address, because those crapware…
It's not really clear that this is money that needs to be laundered, it's often irreversible transfers that are legit.
> People are already effectively faking addresses for something as stupid as Amazon reviews. Apparently it's that cheap to fake an address, because those crapware spam stores that rotate their name/products/listings aren't exactly the size of the mob.
I already responded to this below. Those don't involve scammer controlled addresses. If I send you a piece of physical mail with an OTP code, you can't use a random faked address.
> clearing the field for "professionals" while at the same time making identity fraud, address fraud, and (money) mules more lucrative.
The majority of this kind of fraud is already organized. That's why raising the cost is impactful, see my comments below. It's a tool to raise the cost of revenues to an ideally unsustainable amount.
Re: Open Letter to Google on Mandatory Developer Registration for App Distribution
#390Earlier quoted context omitted.
But the proposal here, requiring developers to register their identities, doesn't actually impact consumers at all. They still have the ability to make the decision about whether or not to trust someone.
Yes it does, especially when you remember the fact that developers are also consumers. But even if they (we) weren't, it would still impact consumers. I, android user who's completely ignorant when it comes to android development or even mobile in general, would be heavily impacted by this. My custom youtube clients would never be approved by google. My (free) apps for watching anime and reading manga would never get…
Google isn't approving apps though. A developer provides identity verification and a set of apps (apk names & keys) they are responsible for. There is no verification process or approval from google. The entire process as outlined in https://developer.android.com/developer-verification is that you prove you own signing keys for an apk name.