Live data from Hacker News

Google will allow only apps from verified developers to be installed on Android

9to5google.com

841–850 of 1001 posts

Re: Google will allow only apps from verified developers to be installed on Android

#841

This is really bad. I think that most people on HN will agree with that. The problem is that most normal people (HN is not normal - mostly for the better) don't even understand what sideloading is - let alone actually care . How can we fix this? (aside from making people care - apathy enables so many political problems in the current age, but it's such a huge problem that this definitely isn't going to be the impetus…

In the EU, you would start a petition to the European Parliament in order to vote on that... Which is a tedious process but has seen some success in some fronts (like the Stop Killing/Destroying Games initiative).

For other countries... Well you get what you vote I guess.

Re: Google will allow only apps from verified developers to be installed on Android

#842
I think time quickly approaches when everyone will have one mobile phone for "banking/crypto" and the other for everything else.

Samsung used to have a very cool feature on their phones (perhaps they still do, I switched away from the galaxy line). It was called Knox and was basically containers for your apps.

Unfortunately it was limited to only one secure container. What I did was I had all my secure apps outside the container. And insecure inside. I had a fake address book that had only one phone number in "My Knox" and any app I installed there I could give all the file and address book permissions it wanted. As I knew it could only see what is inside.

That is what we need, but better. I never tried Graphene, but I wouldn't be surprised if there was such a feature thre already. It's kind of obvious.

Re: Google will allow only apps from verified developers to be installed on Android

#843

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

I think that the answer are vendor-independent standards. The main issue being solved here is that security relies heavily on those actors like Google and Apple. Banks, companies etc. have high security requirements (rightly so) and basically need to tick boxes. So if the only way to obtain, say, MFA, is through something only Goole/Apple provides, they will require Google or Apple devices. If we had reasonable stand…

That's not really going to fix anything here.

The reason a big company can do this is because they can absorb big liability risk and insure it appropriately.

A standard can't do that.

Re: Google will allow only apps from verified developers to be installed on Android

#845

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

> Maybe it's time for a third large phone OS, whether it comes from China getting fed up with the US and Google's shenanigans (Huawei has HarmonyOS but it's not open) or some "GNU/Linux" touch version that has a serious ecosystem. Especially when more and more apps and services are "mobile-first" or "mobile-only" like banking.

This makes me laugh. Not at you, but at the cycle. This was the convo years ago when this was possible, but getting consumers to trust a 3rd party like PalmOS (which was actually pretty darn good compared to android) is practically not possible.

Re: Google will allow only apps from verified developers to be installed on Android

#846

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

I somewhat agree with the protected systems part though. For example, handling payments. Now iOS and Android could both have 0-days that allow fraudulent payments to be made for all I know but there's a certain degree of trust there with 2 large companies.

But then again we still use visa/mastercard duopoly that allows you to make payments so long as your have their card number.

And then again x2; nothing will ever change, we live in a corporate hellscape where men in suits & ties make all the decisions, get themselves wealthier and the general public are too apathetic to band together on anything because they'd rather foot shoot than have someone not from their tribe receive a single cookie crumb.

Re: Google will allow only apps from verified developers to be installed on Android

#847
post #406

If this is a thing then the solution they offer is incorrect. A big giant red screen: “warning the identity of this application developer has not been verified and this could be an application stealing your data, etc” would have worked. What they want is to get rid of apps like YouTube Vanced that are making them lose money (and other Play Store apps)

It won't work because of too many false positives. People are already trained to ignore warnings, like how they blindly accept T&C without reading.

How about requiring the user to type into a text box "App Foo might be malware. I want to install it anyways."? And disable copy and paste for that box.

Re: Google will allow only apps from verified developers to be installed on Android

#848

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

I wouldn't use a bank that made it difficult for me to access my account. I don't know why most people do. I know why a few need to, but not most. There's a lot of unnecessary bedmaking going on in tech.

Re: Google will allow only apps from verified developers to be installed on Android

#849

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

> a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. I see where you're coming from, but companies like Google have local legal representation (e.g. in Ireland for the EU), and have to operate under EU rules if they want to do business here (just like how a EU business has to operate under US rules). If the EU says that you should be allowe…

Ok, how do I as a developer from Croatia get in touch with a legal representative from Google? And I don't mean 5 layers of indirection through AI chatbots and chatbots, forms and canned responses?

Re: Google will allow only apps from verified developers to be installed on Android

#850

Meaning to use your device you need to have a contractual relationship with a foreign (unless you are in the US) third party that decides what you can or cannot do with it. Plus using GrapheneOS is less of an option every day, since banks and other "regulated" sectors use Google Play Protect and similar DRMs to prevent you from connecting from whatever device you want. Client-side "trust" means the provider owning th…

> Maybe it's time for a third large phone OS, whether it comes from China getting fed up with the US and Google's shenanigans (Huawei has HarmonyOS but it's not open) or some "GNU/Linux" touch version that has a serious ecosystem. Especially when more and more apps and services are "mobile-first" or "mobile-only" like banking. This makes me laugh. Not at you, but at the cycle. This was the convo years ago when this w…

It's not about consumer trust, it's the chicken-and-egg problems of users and app devs.

App devs only care about platforms with enough users, users only care about platform with enough 3rd party devs support.

Post reply on HN