Live data from Hacker News

Google will allow only apps from verified developers to be installed on Android

9to5google.com

821–830 of 1001 posts

Re: Google will allow only apps from verified developers to be installed on Android

#821
post #406

If this is a thing then the solution they offer is incorrect. A big giant red screen: “warning the identity of this application developer has not been verified and this could be an application stealing your data, etc” would have worked. What they want is to get rid of apps like YouTube Vanced that are making them lose money (and other Play Store apps)

It won't work because of too many false positives. People are already trained to ignore warnings, like how they blindly accept T&C without reading.

There aren't too many false positives, it's just that most modern android software is malware.

Saying "this will steal your data" is probably correct.

So what were actually asking users is to install some malware, if it's provided by a big enough tech company, but not other malware. Of course users get confused.

Just stop downloading apps altogether and run the web views in the original web view - the web browser.

Will Google, Meta et al. do that and abandon their apps? Of course not, they need to install malware.

Re: Google will allow only apps from verified developers to be installed on Android

#822

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

Not merely a foreign third party: one operating fairly cozily within a country with a hostile and erratic government.

If Trump ordered Google, tomorrow, to put some egregious measure in place in Android (or Chrome, or Google Search), I, personally, would not want to bet that they would refuse him. And frankly, I don't know that I can even imagine the kinds of things he might try to get them to do.

We absolutely need better competition in smartphone OSes—we need it across the board in tech, really, from a wide array of countries.

Re: Google will allow only apps from verified developers to be installed on Android

#823
post #733
post #155

Even aside from the privacy implications (which aren't trivial themselves,) Doesn't this make it prohibitively difficult to do local builds of open source projects? It's been a long time since I've done this, but my recollection was that the process to do this was essentially you would build someone else's (the project's) package/namespace up through signing, but sign it locally with your own dev keys. A glance at th…

If so, then this change will likely make it illegal to distribute APKs of GPLv3 software, since the recipient couldn't run their modified version.

And thus accelerates Google's push away from APKs, preferring instead for all developers to embrace their proprietary App Bundle format. Complete with ad hoc signing performed by the Google Play store at time of download. The bundle is also customized to the device, meaning an .aab file ripped off a device won't necessarily be loadable on another device since it could have different configurations/hardware that happen to limit it.

I think anyone who works as a dev knew this was Google's endgame the moment they started circling the wagons with the app bundle stuff. It was already getting weird before that, but it was uncharacteristically out of step with historic Android.

Re: Google will allow only apps from verified developers to be installed on Android

#825

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

> Android shouldn't be considered Open Source anymore That idea died for me long ago, I had used Android since 2009 till 2020. I gave up on the dream of a Linux phone. Ubuntu had a nice sleek Phone UI they were working on. The issue is if nobody builds the phones and no carrier cares, nobody will pick it up. You need to push yourself into the market. Microsoft could fill this weird gap if they wanted to the key thing…

Amazon was hopeless even with the apps, because they had their hooks into things even worse than google. They are shameless. Most other tech companies large enough to even try would be as bad or worse.

All that type of money went to llms, who is going to spend that on a phone os now? Not who should, but who actually would? They gave up on browsers, they gave up on mobile oses. There is a real risk that the next step is the US gov takes X% of google instead of enforcing antitrust in a year or two.

Linux phones will never take off because banking and media/drm apps, and by extension social media apps, will just boycott them and kill it off. The tone has been set, this comment applies to any major player trying to break into the mobile market moving forward.

This is honestly very bleak news.

Re: Google will allow only apps from verified developers to be installed on Android

#826

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

This is the problem - many apps refusing to run on non-blesses platform.

Years ago I loved tinkering with the devices but then I wasn't able to use my bank and it was getting more and more annoying so at one point I just stopped...

The biggest problem are: 1) lack of drivers (so creating custom roms/OS for the devices is problematic), 2) locked bootloaders and 3) many apps requiring PlayServices and other stuff (mostly banks).

There is postmarketOS, it looks awesome but - device support is very lacking and there is no way to have bank and PopularApps (whatsapp/instagram/etc) running on it so it's popularity is microscopic…

Maybe another European Citizen Initiative to force makers to provide those things (bootloader and drivers)?

Re: Google will allow only apps from verified developers to be installed on Android

#827

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

realistically, the end point for moderately tech savvy folks is going to a be two-device setup. one cheap phone for basic communication , all the corpo stuff like banking and shirt-and-tie social media + a wifi hotspot. then a second "practical use" device that uses the hotspot, that you fully control and do your tinkering with. edit: coming to think of it, teaching people to have a device for the "clean stuff" and s…

Your heart is where your money. The device with the money would be the practical device for anybody except few RMS' followers.

Re: Google will allow only apps from verified developers to be installed on Android

#828

So what are our options (eg for EU citizens) for lobbying in terms of legislation or directly to Google to show disagreement with this? It looks like many in this thread are against, but I don't see suggestions for action?

I like your take, we see too many easy-to-write outrage articles on here these days, and rarely do we see a discussion or concrete list of actions that can be taken. eg. send a physical letter to this address, or boycot this or that service for 24hrs on such a date etc.

Personally I de-googled last year, but those numbers never get counted by the bean-counters, so it is not much of a protest.

In this case I dont think much can be done via legislation, since the governments work less and less for-the-people. This is just the next logical step on the KYC road, but for developers, GitHub is heading the same way, along with EU chat controls, UK age controls, Digital Euro, and the rest.

The EU right-to-privacy may as well be torched, and freedoms that were hard won, will continue to be surrendered for an easier swipe of a gadget.

Re: Google will allow only apps from verified developers to be installed on Android

#829
post #797

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

> Maybe it's time for a third large phone OS It's been that time for years . But it's easier said than done. The closest we've currently got are the various phone-targeted Linux distros out there. But they're not quite ready for serious usage for me; at least not on the Pinephone. Still, that's where to put your time & money if you're serious about wanting a change.

Is Pinephone still going? I was excited for it a few years ago, but I checked in recently and a lot of people are calling it dead. They discontinued to "pro" model and it doesn't sound like the software has much active development going on.

Re: Google will allow only apps from verified developers to be installed on Android

#830

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

Tizen already exists...where phone OS' fall down is that ALL of the cellular modems are extremely patent encumbered (althogh Hauwei has a large portion of the 5G ones) and there doesn't exist an open specification let alone open implementation of their interfaces.
Post reply on HN