What do the OEMs have to say about this? A lot of them, including Samsung, have their own app stores. Surely they'd not be willing to cede control?
Answering questions about Android developer verification
51–60 of 128 posts
Re: Answering questions about Android developer verification
#52I'm not an android developer, so I'm missing some context and key information. But I have a question: When Google is asking developers to "register" their apps as part of this new program, are they just trying to keep a mapping from some code signing key to a government ID? Or are they trying to do a code review process that is similar to submitting to an app store? I know both are objectionable in their own way, but…
The first one for sure, second one — to an extent. If you publish “objectionable” apps (we are told this will be used to combat malware) — your certificate will be revoked.
Re: Answering questions about Android developer verification
#53Earlier quoted context omitted.
After 15 years of professional development on Android I too am now thinking about switching my focus to something different. And it sucks. Just wished there was a viable* FOSS Linux based mobile OS project out there that I could offer my time and energy to instead.
Aren't Graphene and Lineage exactly that? I have been running Graphene on a Pixel for a while now and I don't think Linux phones are a viable alternative. The vast majority of Android apps just work on Graphene, and there are millions of them. The UI experience is polished, everything just works with the exception of apps that require Google Play Integrity. And of course these projects aren't affected by Google's res…
But GrapheneOS lives by the mercy of Google. Pixel devices being reference devices makes it so that it's unlikely that Google will close them down completely.
However, as can be seen with this verification move, Google is willing to go very far to accomplish its aims. They already delayed delivery of Android 16 images, causing GrapheneOS some headaches.
Who is to say more isn't to come.
Re: Answering questions about Android developer verification
#54Earlier quoted context omitted.
My understanding was that those packages still had to be signed with a key known to Google.
The current blog post does appear to say that you don't need to be verified to install and run apps with adb.
Re: Answering questions about Android developer verification
#55The year of the Linux Phone is coming!
There sadly isn't a single viable option for a Linux mobile phone out there. - Purism runs ancient hardware, charges way too much and has questionable business ethics. - Pine64 has equally bad hardware but reasonable prices. I don't like the Hong-Kong connection though. Not sure how the security patching environment is in practice. The only option on the table as I see it is buying from the devil and installing Graph…
Re: Answering questions about Android developer verification
#56Earlier quoted context omitted.
Taking away adb install should be the next step. It's a slippery slope
Is there any evidence that Google plan to do this?
Re: Answering questions about Android developer verification
#57Earlier quoted context omitted.
Taking away adb install should be the next step. It's a slippery slope
Is there any evidence that Google plan to do this?
If adb installing is used to circumvent their signing programm, it has to go as well.
Re: Answering questions about Android developer verification
#58No need to listen. We all know how evil the intentions are. This will kill the platform, for better or worse.
We’ve been through this route before, it doesn’t kill the platforms. It just alienates people like us, which is actually a net benefit to Google.
People become willing to do things when you throw them out in the cold that they wouldn't do when you were still supplying the bread and circuses, and those people they don't like? It's because they're stubborn and they actually care and they know how to build things, isn't it?
Re: Answering questions about Android developer verification
#59Can an non-profit LLC verify itself and submit apps on behalf or anonymous developers after vetting their code? If so, that would probably a nice middle-ground. The reaction to this change has truly changed my opinion that developer's opinions on a lot of subjects affecting the public's safety and security shouldn't be valued much (and yes, I realize I am on HN). If this is a bridge too far, then why should anyone li…
Is Google that organization? Because they themselves have decided that they are. I think what people are worried about is that Google is positioning itself to be the judge, jury, and executioner within such a licensing framework, not necessarily the licensing itself.
> This is just to address malicious code.
Yes, and if Google had shown that it's capable of identifying and rejecting malicious code distributed via its own app store, then maybe their proposed expansion of that security program to the entirety of the Android app ecosystem would carry some weight. But as it stands, their Play Store is full of user-hostile and often malicious apps[1].
> If you publish software for a private group of people, there should be no restrictions. If you're publishing it on a platform that would expose your software to billions of people, get a license after id verification
But that's exactly the opposite of what Google is doing, here, and why people are mad. Google isn't adding a new policy to their app distribution platform (the play store that grants exposure to billions of users), but rather they are forcing ID verification on any form of app distribution: If you want any regular user to be able to install your code, no matter how small the audience, you'll need to first give your identity to Google, and obtain a (paid[1]?) license. So the restrictions do apply to "a private group of people" too.
The crux, and what has people up in arms I think, is the overreach of Google's peoposed licensing policy to cover not only their own app distribution ecosystem, but all others targeting Android.
Many technical users of Android consider it to be a general purpose computing platform, and they want to retain the freedom to install and run whatever software they trust.
Google should focus their supposed concerns about regular user's safety on the user-hostile apps that they allow to exist in their own app store, rather than grasping for broader control that they'll "probably use at some point but only for good things like user security".
1: https://f-droid.org/en/2025/09/29/google-developer-registrat...
Re: Answering questions about Android developer verification
#60No need to listen. We all know how evil the intentions are. This will kill the platform, for better or worse.
We’ve been through this route before, it doesn’t kill the platforms. It just alienates people like us, which is actually a net benefit to Google.
If that goes away, might as well use apple's walled garden. There is no point for android to exist if freedom goes away.