Live data from Hacker News

Answering questions about Android developer verification

android-developers.googleblog.com

71–80 of 128 posts

Re: Answering questions about Android developer verification

#71

Earlier quoted context omitted.

Malicious is to cause harm and if it refuses your app because of that reason you have legal recourse.

Legal recourse in the American empire that just made Google block an app to warn of its armed goons approaching? Color me skeptical.

Libel for calling it malicious and a tort case for malicious interference in trace/commerce. Although, fighting google's lawyers is another matter. If they blocked it without reason, it would be difficult, but if they said it was malicious and that was a lie, regardless of ToS or contracts you have a libel case as the very least. IANAL.

Re: Answering questions about Android developer verification

#72
post #61
post #23

So this is saying you have to have an Android developer account and sign the app with your identity… so a one-time $25 cost and that’s it? You can still distribute and sideload apps as long as you sign them. Microsoft does this for Windows apps if you don’t want scary warnings popping up everywhere. Apple doesn’t even let you sideload at all for iOS and for macOS they do the forced trash malware thing unless you run…

> Am I missing how this is different from what we already have on most platforms? Most? The only platform that is like that is ios. On linux, in any form, I can run what I want. On a mac I can run what I want. On windows I can run what I want. Obviously on BSDs, Illumos, etc, I can run what I want. On android up to now, I can run what I want. The one and sole exception where I don't really own the device and can't ru…

Have you used windows 11 and macOS 26? They both have malware scanning and throw up alerts or scary dialogs that you have to do cli commands or workarounds to launch unknown apps. I don’t see this as much different than Android requiring you to either root or enable developer options.

I understand this is a controversial position and I’m not in favor of this change, I just want to understand where the real differences are in an impartial way.

Of course Linux is an exception but it is also not widely used by consumers like Android and the other OSes I listed are.

Re: Answering questions about Android developer verification

#73

> We want to make sure that if you download an app, it’s truly from the developer it claims to be published from, regardless of where you get the app. Verified developers will have the same freedom to distribute their apps directly to users through sideloading or through any app store they prefer. This makes no sense at all.

Not to mention this doesn't even solve the problem. What's preventing someone from registering and then releasing an app with a similar name to a famous app? Sure, the registration means there's someone you can sue, but it doesn't allow the user to identify the publisher. A "verified publisher" field when you're installing an app would solve both issues (similar to windows[1]), and not require every app developer to register with google.

[1] https://en.wikipedia.org/wiki/File:User_Account_Control.png

Re: Answering questions about Android developer verification

#74
post #23

So this is saying you have to have an Android developer account and sign the app with your identity… so a one-time $25 cost and that’s it? You can still distribute and sideload apps as long as you sign them. Microsoft does this for Windows apps if you don’t want scary warnings popping up everywhere. Apple doesn’t even let you sideload at all for iOS and for macOS they do the forced trash malware thing unless you run…

It's not about the $25. It's about Google centralizing control. If they don't like your app, oops, no verification for you. Goodbye NewPipe. Goodbye anything that doesn't align with Google's capitalist interest or American imperial interest.

But they don’t verify each app in this case, just the developer… you get verified before you even tell them what type of app you have.

Sure, it’s possible they could retroactively ban your app, but they could do that without signing too. Just ban com.anonymous.newpipe or whatever the package name is. The signing doesn’t really change this.

Re: Answering questions about Android developer verification

#75
post #23

So this is saying you have to have an Android developer account and sign the app with your identity… so a one-time $25 cost and that’s it? You can still distribute and sideload apps as long as you sign them. Microsoft does this for Windows apps if you don’t want scary warnings popping up everywhere. Apple doesn’t even let you sideload at all for iOS and for macOS they do the forced trash malware thing unless you run…

I'm guessing Windows gets a pass because you can still fairly easily bypass the signature check - it's effectively a warning rather than a hard block. It sounds like for (mainstream) Android, the only workaround will be to plug it into a PC and use adb there to install an unsigned app, which is considerably harder. Installing a custom ROM will presumably get around it too, but that's tough, and various government and…

Is rooting the same as a custom rom nowadays? And enabling developer options won’t allow installation of unsigned apps either?

Re: Answering questions about Android developer verification

#76

More confirmation that Google is a company with too much power and should be forced to sell Android and Chrome

They’re more likely to buy out all of our members of parliaments and turn into East India Company and form their own army to protect their investment.

We’ve got to a point where corporations are bigger than some countries and getting almost unlimited powers again.

Re: Answering questions about Android developer verification

#77
post #32

Yep, it's as bad as everyone expected it to be. "We aren't taking away sideloading, we're just going to fully control it now! No Google-unapproved code on user devices! For security reasons!" Chrome isn't enough. We need Android to get clawed away from Google too.

Not really though, as you can still install apps over adb without developer verification, same as always.

Give them an inch...

Re: Answering questions about Android developer verification

#78

Look, Google. You and me both, we don't want EU bureaucracy to get involved again... (It's going to be a different group than the chat control people. If the chat control people win bigly, this would actually support what they want. Is there, like, any connection between that and the timing of these new rules?)

DMA does nothing to prevent this, Google claims it's about security which will satisfy the DMA. Same as for Apple (the EU is going after them because of the fees, not because of the complicated process). The EU is not interested in letting you run unapproved software because they want to use it for themselves with their digital wallet app and ID checks.

Re: Answering questions about Android developer verification

#79

One interesting aspect of this is that when using a personal Android with a work profile, developer options and ADB is (or at least can be) disabled. BYOD will then imply you can't sideload at all.

And nothing of value was lost. BYOD means Corporate can push whatever spyware they want onto your personal phone. I tell any employer I work for, if you really need me to be reachable by phone via an app, you can supply me a work phone. Otherwise I'll do without. I keep a bright-line distinction between personal devices and work devices, and never mix the two. My boss knows this explicitly.
Post reply on HN