Live data from Hacker News

Answering questions about Android developer verification

android-developers.googleblog.com

61–70 of 128 posts

Re: Answering questions about Android developer verification

#61
post #23

So this is saying you have to have an Android developer account and sign the app with your identity… so a one-time $25 cost and that’s it? You can still distribute and sideload apps as long as you sign them. Microsoft does this for Windows apps if you don’t want scary warnings popping up everywhere. Apple doesn’t even let you sideload at all for iOS and for macOS they do the forced trash malware thing unless you run…

> Am I missing how this is different from what we already have on most platforms?

Most? The only platform that is like that is ios.

On linux, in any form, I can run what I want.

On a mac I can run what I want.

On windows I can run what I want.

Obviously on BSDs, Illumos, etc, I can run what I want.

On android up to now, I can run what I want.

The one and sole exception where I don't really own the device and can't run what I want it ios (therefore I don't own anything that uses ios). And now google wants to join that evil club.

Re: Answering questions about Android developer verification

#62
post #30

> We want to make sure that if you download an app, it’s truly from the developer it claims to be published from, regardless of where you get the app. Verified developers will have the same freedom to distribute their apps directly to users through sideloading or through any app store they prefer. This makes no sense at all.

Classic strawman argument and corporate tactics of shifting the conversation without addressing real concerns.

Somewhat unrelated: Do you think the UK government and Google have the same PR team?

Thought: Maybe we can organise and collectively hire this PR team to get Google, other big tech, and our governments, to look bad... And get shit done that way... If 2025 is the year of the PR spin, surely the only counter-measure is counter-spin?

Edit: Hold on, I think I just re-invented the concept of a political party.

Re: Answering questions about Android developer verification

#63
post #19

The year of the Linux Phone is coming!

There sadly isn't a single viable option for a Linux mobile phone out there. - Purism runs ancient hardware, charges way too much and has questionable business ethics. - Pine64 has equally bad hardware but reasonable prices. I don't like the Hong-Kong connection though. Not sure how the security patching environment is in practice. The only option on the table as I see it is buying from the devil and installing Graph…

There is also jolla / sailfishos built by ex Nokia engineers. The Russians forked it and are useing it in government / industry.

Re: Answering questions about Android developer verification

#64
post #60

Earlier quoted context omitted.

We’ve been through this route before, it doesn’t kill the platforms. It just alienates people like us, which is actually a net benefit to Google.

In this case, the benefit of android is that the owner of the device owns it, so can run whatever they want, in stark contrast to apple. If that goes away, might as well use apple's walled garden. There is no point for android to exist if freedom goes away.

An average person never thinks about that. That’s like not even a thing one ever thinks of while purchasing a phone.

Re: Answering questions about Android developer verification

#65

Can an non-profit LLC verify itself and submit apps on behalf or anonymous developers after vetting their code? If so, that would probably a nice middle-ground. The reaction to this change has truly changed my opinion that developer's opinions on a lot of subjects affecting the public's safety and security shouldn't be valued much (and yes, I realize I am on HN). If this is a bridge too far, then why should anyone li…

> This is just to address malicious code Where "malicious" is defined as anything that Google or the American Empire doesn't agree with.

Malicious is to cause harm and if it refuses your app because of that reason you have legal recourse.

Re: Answering questions about Android developer verification

#66

Can an non-profit LLC verify itself and submit apps on behalf or anonymous developers after vetting their code? If so, that would probably a nice middle-ground. The reaction to this change has truly changed my opinion that developer's opinions on a lot of subjects affecting the public's safety and security shouldn't be valued much (and yes, I realize I am on HN). If this is a bridge too far, then why should anyone li…

The umbrella organisation signing apps is not impossible, as far as I know. But it would need to be pretty cautious, because if Google revokes its registration, that could block all the apps it has signed at once. It's hard to see how you could get the necessary level of careful code review with just volunteer effort. But I suspect that most developers who don't want to register with Google are also unlikely to pay m…

With enough developers, revoking that cert would affect too many users, so Google would be forced to be careful. It will sort of be like devs unionizing. As far as review goes, not having the money or time to review code sounds exactly like the problem Google is trying to eradicate, because right now when your app causes problems you can just create a different account and start over without risking your reputation.

Re: Answering questions about Android developer verification

#67
post #59

Can an non-profit LLC verify itself and submit apps on behalf or anonymous developers after vetting their code? If so, that would probably a nice middle-ground. The reaction to this change has truly changed my opinion that developer's opinions on a lot of subjects affecting the public's safety and security shouldn't be valued much (and yes, I realize I am on HN). If this is a bridge too far, then why should anyone li…

> I wouldn't even be against requiring a professional certification organization for developers before they're allowed to publish software to the masses Is Google that organization? Because they themselves have decided that they are. I think what people are worried about is that Google is positioning itself to be the judge, jury, and executioner within such a licensing framework, not necessarily the licensing itself.…

> Is Google that organization?

I agree, it isn't and shouldn't be, an industry self-regulating org is needed, like the CA/B forum for browsers. Maybe one day we can transition to that.

> Yes, and if Google had shown that it's capable of identifying and rejecting malicious code distributed via its own app store,

You're making the opposite point there, they can't do a good job at scanning their appstore, so requiring devs to id themselves is a better option, so that anyone publishing malicious code might risk real-world criminal penalties. That's a better deterrent than google scanning code.

> If you want any regular user to be able to install your code, no matter how small the audience, you'll need to first give your identity to Google, and obtain a (paid[1]?) license. So the restrictions do apply to "a private group of people" too.

This applies to google certified phones, and such phones at the time of certification are sold to the public, not to a private audience. Private audiences need to buy non-google-certified phones (which exist). The question of google certification is one you need to have with phone vendors not Google. Samsung can opt to avoid google certification just fine. They have every right to demand that a phone with their stamp on it can only run apps by devs they authenticated, this is the price of their seal of approval.

> Many technical users of Android consider it to be a general purpose computing platform, and they want to retain the freedom to install and run whatever software they trust.

Yeah, for example I have an x86 android VM, it won't be affected because it isn't google certified. If you came up with a custom tablet or laptop that runs android, you can load random apps on it just fine.

> Google should focus their supposed concerns about regular user's safety on the user-hostile apps..

They can do multiple things, but this helps with that as well. the dev making user hostile apps now has to use his real name and their reputation will now follow them forever.

Re: Answering questions about Android developer verification

#68

Earlier quoted context omitted.

> This is just to address malicious code Where "malicious" is defined as anything that Google or the American Empire doesn't agree with.

Malicious is to cause harm and if it refuses your app because of that reason you have legal recourse.

Legal recourse in the American empire that just made Google block an app to warn of its armed goons approaching? Color me skeptical.

Re: Answering questions about Android developer verification

#69
post #32

Yep, it's as bad as everyone expected it to be. "We aren't taking away sideloading, we're just going to fully control it now! No Google-unapproved code on user devices! For security reasons!" Chrome isn't enough. We need Android to get clawed away from Google too.

Not really though, as you can still install apps over adb without developer verification, same as always.

Do you see the direction they're heading? They're now making it so maybe .5% of android users know how to sideload. They're clearly chipping away at it, even though they might not be making all the changes at once.
Post reply on HN