Live data from Hacker News

Google will allow only apps from verified developers to be installed on Android

9to5google.com

781–790 of 1001 posts

Re: Google will allow only apps from verified developers to be installed on Android

#781
Oh, no! This is the least thing I expected to see as the #1 in Hacker News' front page!

This is a plot twist I never thought it would happen. While the EU [1], Japan [2] , UK [3] and Australia [4] are in the process of forcing Apple to allow sideloading and alternative App Stores, Google, which was far from these obligations, had taken a totally unexpected road to limit/control how sideloading should work.

____________________

1.https://developer.apple.com/support/dma-and-apps-in-the-eu/

2.https://www.phonearena.com/news/the-world-is-changing-japan-...

3.https://www.videogameschronicle.com/news/uk-passes-bill-whic...

4.https://www.theguardian.com/technology/2025/jun/06/australia...

Re: Google will allow only apps from verified developers to be installed on Android

#782
post #407

Every day we stray farther from the premise that we should be allowed to install / modify software on the computers we own. Will once again re-up the concept of a “right to root access”, to prevent big corps from pulling this bs over and over again: https://medhir.com/blog/right-to-root-access

[deleted]

Re: Google will allow only apps from verified developers to be installed on Android

#783
post #407

Every day we stray farther from the premise that we should be allowed to install / modify software on the computers we own. Will once again re-up the concept of a “right to root access”, to prevent big corps from pulling this bs over and over again: https://medhir.com/blog/right-to-root-access

This should be a part of right to repair. The grouping would get more people with common cause together.

Re: Google will allow only apps from verified developers to be installed on Android

#785

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

I think that the answer are vendor-independent standards.

The main issue being solved here is that security relies heavily on those actors like Google and Apple. Banks, companies etc. have high security requirements (rightly so) and basically need to tick boxes. So if the only way to obtain, say, MFA, is through something only Goole/Apple provides, they will require Google or Apple devices.

If we had reasonable standards alternatives can become a reality.

Re: Google will allow only apps from verified developers to be installed on Android

#786

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

What's even the point of all the bullshit with Google play protect if in the end I can access my bank from a web browser. That stupidity is protecting no one

> access my bank from a web browser

Unless you get SMS or some normal TOTP app as 2FA, using the web page usually requires the bank's proprietary app to authorize. So you circle back to the the same issue.

Re: Google will allow only apps from verified developers to be installed on Android

#787
post #733
post #155

Even aside from the privacy implications (which aren't trivial themselves,) Doesn't this make it prohibitively difficult to do local builds of open source projects? It's been a long time since I've done this, but my recollection was that the process to do this was essentially you would build someone else's (the project's) package/namespace up through signing, but sign it locally with your own dev keys. A glance at th…

If so, then this change will likely make it illegal to distribute APKs of GPLv3 software, since the recipient couldn't run their modified version.

Nope, you could, given that no Google libraries is used.

You could always run the APK on a stock AOSP build, or any fork of it in the internet.

Re: Google will allow only apps from verified developers to be installed on Android

#788

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

Everything coming from China is going to be closed source as well, and it's going to be pretty hard for banks to onboard themselves on open source solutions. I think the ultimate solution is: two phones, one shitty one just for banking/trading/whatever, which only stays at home most of the time, and one Linux phone that we more or less own, for calls/texts/web browsing, which stays with us.

It only matters if you treat phones as a development environment.

It's tempting to have full control over everything OSS style, but the reality is you can only tenably have that for very specific parts of life.

Re: Google will allow only apps from verified developers to be installed on Android

#789

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

> "GNU/Linux" touch version that has a serious ecosystem

That is a very hard problem, unless someone with serious name recognition like Linus Torvalds starts to lead that kind of effort, or a big company like Microsoft suddenly decides that putting 1 billion towards GNU/Linux would be in their interest. With small efforts, it will remain scattered.

Crowdfunding has a lot of power if there is name recognition behind the effort. Star Citizen has already gathered $800 million with mostly enthusiasm and a good start. Who is there to lead the effort for GNU/Linux phone development?

Re: Google will allow only apps from verified developers to be installed on Android

#790

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

I think Play Integrity is the fundamental issue here, and needs to go. That's the crux of the issue. Allowing apps to say "we only run on Google's officially certified unmodified Android devices" and tightly restricting which devices are certified is the part that makes changes like this deeply problematic. Without that, non-Google Android versions are on a fair playing field; if you don't like their rules, you can i…

Id be more convinced that this was about malware and your security if you could turn it off.

I think this is mainly just an attempt to kill things like newpipe.

Post reply on HN