Live data from Hacker News

Google will allow only apps from verified developers to be installed on Android

9to5google.com

761–770 of 1001 posts

Re: Google will allow only apps from verified developers to be installed on Android

#761
post #406

If this is a thing then the solution they offer is incorrect. A big giant red screen: “warning the identity of this application developer has not been verified and this could be an application stealing your data, etc” would have worked. What they want is to get rid of apps like YouTube Vanced that are making them lose money (and other Play Store apps)

"Displaying an angry warning message" is one of the tools we've used for decades, and never with much success.

So what's wrong with that? You get warned, you ignore the warning and get hacked, that's on you for being dumb enough to download stuff from some shady website. Plus, Android is supposed to have decent isolation and permission controls, unlike desktop OSs like Windows or Linux (not counting Snap/Flatpak) where software can read your entire disk or any arbitrary file and send it via the internet.

Plus, you are not required to do that, you can just stick to Google Play and trust what Google approves there. But no need to lock down others because of your recklessness.

Re: Google will allow only apps from verified developers to be installed on Android

#762
post #406

If this is a thing then the solution they offer is incorrect. A big giant red screen: “warning the identity of this application developer has not been verified and this could be an application stealing your data, etc” would have worked. What they want is to get rid of apps like YouTube Vanced that are making them lose money (and other Play Store apps)

"Displaying an angry warning message" is one of the tools we've used for decades, and never with much success.

Fuck em. If you ignore a warning, let nature take its course. We don't need to child-proof everyone's home.

Re: Google will allow only apps from verified developers to be installed on Android

#763
post #406

If this is a thing then the solution they offer is incorrect. A big giant red screen: “warning the identity of this application developer has not been verified and this could be an application stealing your data, etc” would have worked. What they want is to get rid of apps like YouTube Vanced that are making them lose money (and other Play Store apps)

> What they want is to get rid of apps like YouTube Vanced I think it is also very telling where they're rolling out first. Brazil, Indonesia, Thailand, and Singapore. It felt weird that the official press release was quoting entities from these countries, as if it should give confidence to the rest of the world. I can't imagine what these countries would want with apps that can be traced back to a government id... V…

Vance is just as big if not bigger problem there.

Re: Google will allow only apps from verified developers to be installed on Android

#764
Google (and Apple) want to turn the idea of a phone and computer into that of a gaming console. You use the device according to how they design it, apps are rented, the whole ecosystem is around controlling the experience and maximizing revenue from sites and services. Microsoft seems to be moving in this direction as well (but cannot quite execute for a variety of reasons.. legacy support being one)

Linux really is the only way to have an experience where the computer is your device to do what you want to do with it.

Re: Google will allow only apps from verified developers to be installed on Android

#765
Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning the device, not the user.

Android shouldn't be considered Open Source anymore, since source code is published in batches and only part of the system is open, with more and more apps going behind the Google ecosystem itself.

Maybe it's time for a third large phone OS, whether it comes from China getting fed up with the US and Google's shenanigans (Huawei has HarmonyOS but it's not open) or some "GNU/Linux" touch version that has a serious ecosystem. Especially when more and more apps and services are "mobile-first" or "mobile-only" like banking.

Re: Google will allow only apps from verified developers to be installed on Android

#767
Feels like Google is either following Apple's playbook from iPhone OS 1, or they're working together so they can argue this is standard practice in the industry... or something. Either way, no more Android gloating that they can install any app from anywhere any time without centralized approval. Not great. I'm an Apple fan, BUT I like having a fully open backup plan.

Re: Google will allow only apps from verified developers to be installed on Android

#768

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

Everything coming from China is going to be closed source as well, and it's going to be pretty hard for banks to onboard themselves on open source solutions. I think the ultimate solution is: two phones, one shitty one just for banking/trading/whatever, which only stays at home most of the time, and one Linux phone that we more or less own, for calls/texts/web browsing, which stays with us.

Re: Google will allow only apps from verified developers to be installed on Android

#769

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

I think Play Integrity is the fundamental issue here, and needs to go. That's the crux of the issue.

Allowing apps to say "we only run on Google's officially certified unmodified Android devices" and tightly restricting which devices are certified is the part that makes changes like this deeply problematic. Without that, non-Google Android versions are on a fair playing field; if you don't like their rules, you can install Graphene or other alternatives with no downside. With Play Integrity & attestation though you're always living with the risk of being cut off from some essential app (like your bank) that suddenly becomes "Google-Android-Only".

If Play Integrity went away, I'd be much more OK with Google adding restrictions like this - opt in if you like, use alternatives if you don't, and let's see what the market actually wants.

Post reply on HN