Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

471–480 of 694 posts

Re: Android developer verification: Early access starts

#471
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

> F-Droid couldn't know either

F-Droid is not just a repository and an organization providing the relevant services, but a community of like-minded *users* that report on and talk about such issues.

Re: Android developer verification: Early access starts

#472
post #120

The key question for me is whether this "advanced flow" will allow the practical use of entirely separate app stores (like F-Droid) or if they're going to throw up tons of barriers for every individual app install.

If I were designing the advanced flow, I'd require the decision to be made at phone setup time. Changing your mind later requires a factory reset. Real sideloaders (F-Droid users, etc.) know at setup time that that's how they'll be using their phone, so it works for them. But ordinary users who are targets for sideloading malware will become a lot less attractive if attackers must convince them to wipe their phone to…

> Real sideloaders (F-Droid users, etc.)

When using F-Droid, I don't think of myself as a "sideloader". I'm using an app store (F-Droid), not installing some random APKs.

(Yes, the F-Droid store app had to be "sideloaded". Once. It updates itself. If or when Google allows alternate store apps in their store app, even that would no longer be necessary.)

Re: Android developer verification: Early access starts

#473

Earlier quoted context omitted.

Google wants 0 friction for apps to display ads.

What incentive is there for OEMs to not add this option though? Does Google refuse to veriy their firmware if they offer this feature?

Well, apart from the OEM violating the Android Compatibility Definition Document (CDD), failing the Compatibility Test Suite (CTS) and thus not getting their device Play-certified (so not being able to preload all the Google services, there is an economical impact as well:

As OEM you want Carriers to sell your device above everything else, because they are able to sell large volumes.

Carriers make money using network traffic, Google is paying Revenue-Share for ads to Carriers (and OEMs of certain size). Carriers measure this as part of the average revenue per user (ARPU).

--> The device would be designed to create less ARPU for the Carrier and Google and thus be less attractive for the entire ecosystem.

Re: Android developer verification: Early access starts

#474
While we are at it, please also reject the framing of "sideloaded" apps. This framing pushes the use of legitimately installed, often high-quality, software to the periphery. This framing is an essential step in extinguishing our computing freedoms, as "sideloaded" apps are easily cast aside.

Recently I wanted to find a good app to manage my shopping lists as well as keep an ordering of this list so that I could run through the supermarket more efficiently. I really hate backtracking the supermarket to get some item on my list that I forgot was in a spot I'd already been. Of course, it had to work offline-first and I didn't mind a bit of configuration.

Everything on Google Play Store was some cloud-integrated garbage app. The only app that came even close was an app on F-droid called Aisleron, which lets you manage both your home stock and supermarkets in terms of "aisles" of products, flipping easily between what is in stock and what is needed and then managing an aisle-based sorting of these products per supermarket that I frequent.

Great App! However, I worry that this app would never have been released had Google considered actively blocking the author from creating legitimate and highly useful pieces of software like Aisleron.

Re: Android developer verification: Early access starts

#475
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

> without requiring Google's authorization for app publication. funnily enough, I am installing google drive for computers right now (macOS), I had to download a .pkg and basically sideload the app, which is not published on the Apple Store Why the double standard, dear Google?

>I had to download a .pkg and basically sideload the app, which is not published on the Apple Store

You mean install the app? The fact that Apple and Google wish to suggest that software from outside their gardens is somehow subnormal doesn't mean other people need to adopt their verbiage.

Re: Android developer verification: Early access starts

#476
post #391

Earlier quoted context omitted.

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

If an app updates to require new permissions, or to suddenly require network access, or the owner contact details change, Google Play should ideally stop that during the update review process and let the users know. But that wouldn't be good for business.

An update can become malicious even without change in permissions.

E.g. my now perfectly fine QR reader already has access to camera (obvious), media (to read QR in an image file or photo) and network (enhanced security by on-demand checking the URL for me and showing OG etc so I can more informed choose to open the URL)

But it could now start sending all my photo's to train an LLM or secretly make pictures of the inside of my home, or start mining crypto or whatnot. Without me noticing.

Re: Android developer verification: Early access starts

#477
post #7

From the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” s…

Considering phone scammers often convince their victims to: - install remote desktop software - run commands in the windows terminal - withdraw cash from the bank - lie to the bank teller about their purpose - insert their cash into a bitcoin ATM at a gas station - ignore warnings about scams which appear on the screen of the ATM - insert the scammers bitcoin address into the machine It isn't a stretch to imagine the…

A change google made to android earlier this year prevents you from allowing unknown sources and installing apks while you are on a phone call.

I'm surprised they didn't think of doing that sooner.

Re: Android developer verification: Early access starts

#478

Earlier quoted context omitted.

What if there is a 12-hour delay to unlock "power user mode", and during that entire 12-hour unlock period, the phone keeps displaying various scam education information to help even an unsophisticated user figure out what's going on? Surely Google can devote a few full-time employees to keeping such educational materials up to date, so they ideally contain detailed descriptions of the most common scams a user is goi…

This would help for sure. Ideally, the phone should stay in "expert mode" for a limited time only, like 1 hour. However, there is still a danger that scammers will call after 12 hours, and they will be more convincing than educational material (or the user may not have read it).

> However, there is still a danger that scammers will call after 12 hours

It is unlikely it will work. Scammers are talking all the time and creating a sense of urgency, people have issues to think and listen at the same time, and they tend to drop thinking completely when in a haste. 12 hours of a break will give the victim time to think at least. Probably it will give time to talk about it with someone, or to google things.

Re: Android developer verification: Early access starts

#479
post #101

Earlier quoted context omitted.

I would like a world where buying something means you get final say over how it operates even if you might do something dangerous/harmful/illegal.

I would like a world where I have the final say over whether I should have a final say. One way to achieve this is to only allow sideloading in "developer mode", which could only be activated from the setup / onboarding screen. That way, power users who know they'll want to sideload could still sideload. The rest could enjoy the benefits of an ecosystem where somebody more competent than their 80-year-old nontechnica…

This becomes a problem when someone asks me for help with their phone and I want to point them to some apps from F-Droid to reduce their exposure to surveillance marketing.

Of course that's a side effect Google probably wouldn't be sad about.

Re: Android developer verification: Early access starts

#480
post #342

I want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like R…

> > Keeping users safe on Android is our top priority. Somebody tell them that I do not want to be kept safe by Big Brother.

Your personal data will be kept safe on our servers, citizen, whether you like it or not.
Post reply on HN