Live data from Hacker News

Android developer verification: Early access starts

android-developers.googleblog.com

511–520 of 694 posts

Re: Android developer verification: Early access starts

#511

This is the worst of both worlds, you can spread your malware as a sideloaded apk just fine, but when it's so big that you're probably burned anyways, then you need to verify your account. I think a better compromise would have been for google to require developer verification, but also allow third party appstores like f-droid that don't require verification but still are required to "sign" the apks, instead of users…

> hobbyists can still publish apps in third party stores

I shouldn't need an internet connection just to make an app for a device I own.

Re: Android developer verification: Early access starts

#513

Earlier quoted context omitted.

> > Keeping users safe on Android is our top priority. Somebody tell them that I do not want to be kept safe by Big Brother.

Your personal data will be kept safe on our servers, citizen, whether you like it or not.

Enforcer, informing citizen on basic practices undermines citizen's delusion of being free. Please refer to room 22a for re-alignment and training.

Re: Android developer verification: Early access starts

#514

Earlier quoted context omitted.

Something I've never understood about DRM is, if the content is ultimately played on my device, what stops me from reverse engineering their code to make an alternative client or downloader? Is it just making it harder to do so? Or is there a theoretical limit to reverse engineering that I'm not getting? Do they have hardware decryption keys in every monitor, inside the LCD controller chip?

in short and simple terms, those parasites colluded with hardware manufacturers and put a special chip in your computer and monitor that runs enslavement software without opening it up physically there is no way to make it stop or get the raw stream before it's displayed

This. Some ways back I actually purchased bluray recording device only to learn that its firmware is deliberately crippled to accommodate someone's business model. There are people who do the unsung hero work, but those types of skills are not exactly common and a business asshole is a dime a dozen any century you want to pick.

Re: Android developer verification: Early access starts

#515

Earlier quoted context omitted.

I don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.

In many cases developer e-mail address changes, IP address changes, billing address changes, tax ID changes...

This exactly. Transferring ownership is a business transaction. Track that. If the new owner is trying to hide it, this is fraud, and should be dealt with in court.

Re: Android developer verification: Early access starts

#516
post #460

Earlier quoted context omitted.

What incentive is there for OEMs to not add this option though? Does Google refuse to veriy their firmware if they offer this feature?

The network permission was displayed in the first versions of Android, then removed. I heard ( hearsay alert ) at the time that it was because so many apps needed it, and they wanted to get rid of always-yes questions. IIRC this happened before the rise of in-app advertising. If people always answer yes, they grow tired and eventually don't notice the question. I've seen it happen with "do you want to overwrite the p…

As far as I'm concerned they can grant this permission by default. I just want the power to disable it.

A while ago I wanted to scan the NFC chip in my passport. Obviously, I didn't want this information to leave my device.

There are many small utility apps and games that have no reason to require network access. So "need" is not quite the right word here. They _want_ network access and they _want_ to be able to bully users into granting it.

That's a weird justification for granting it by default. But I wouldn't care if I could disable it.

Re: Android developer verification: Early access starts

#517
post #118

They didn't say no changes. They are just saying we'll address the concerns of hobbyists and students. Lets not celebrate prematurely and let us wait for more details on whats actually changing both technically and process wise. We should demand more clarity and should not wait to discover it after the implementation at which point it is hard and nearly impossible to push back against. We don't want to be in a situat…

I think you are correct. Clearly, they got spooked, but not enough to make full reversal. I am actually mildly optimistic. It has been a while since I saw a minority ( not that many people are aware of it outside HN circles ) shake a bigger company to a hesitation.

Re: Android developer verification: Early access starts

#518

Interesting. Did Google submit due to pressure? I have no idea. But if so then it shows the power people have. Perhaps we can make Google less evil if we complain a lot about things they do.

Well, this is the most naive thing I've read all week.

Re: Android developer verification: Early access starts

#519

Earlier quoted context omitted.

What changed is that Apple made the masses familiar with the concept of installing software only from a store with a vetting process. For short, the walled garden. That was mostly an alien thing in the world of software. All of us grew with the possibility of getting an installer and install it whenever we wanted. There were some form of protections against piracy but nothing else. Once Apple created the walled garde…

> So, to answer your question, Microsoft got blamed for viruses and made fun of but there wasn't a better way in the mainstream. There is one now. I don't think App Store is a better way. From my point of view, people keep mistaking the actual progress - generalised sandboxing and reduced API surface - with the major regression - controlled distribution. At the beginning of the App Store, when the sandboxing and APIs…

I'm with you and personally I boycott Apple because of the walled garden, for what it's worth. However it is a better way (a more convenient way?) for companies to make money and it gave an idea to legislators and regulators. Now they expect that the owner of the OS can decide what runs and what does not run on their OS and be made accountable for it.

Re: Android developer verification: Early access starts

#520

Earlier quoted context omitted.

That's deflection, there's Google blocking users from installing apps and there's OP insinuating that it might be because of governments coercion but there's no evidence to support this. Scammers pay Google to show ads to install apps, that's what the governments are holding Google responsible and it won't change with blocking installing apps.

Malicious app delivery goes beyond Google ads. In Singapore, most scam app installs are from social engineering, e.g. install new app to receive payment, install new app to buy something for cheap. I’m amazed at how gullible some people are but that’s how it is.

That's not how it is, Google helps scammers and make a lot of money from it so they are responsible and should pay for it
Post reply on HN