Live data from Hacker News

Android Developer Verification

android-developers.googleblog.com

91–100 of 345 posts

Re: Android Developer Verification

#91

What % of Android users actually want this? Do they know or care? I've been using Android since 2010 because it was open in ways that the Apple ecosystem wasn't. I do not want this and imagine hardly any other power users (for lack of a better term) do. I'm already using a mostly deGoogled device but this really seals the deal. I have been longing for a true Linux phone for years and now seems like a good time to get…

It would be good if there was less malware and outright scams in the play store but that's really orthogonal to the developer verification issue.

Not sure why your observation was received poorly. It's true. If they actually wanted to fight bad actors they could (for example) introduce a voluntary verification program where an app cost $$$ per year to list, is permitted only a fixed number of updates per year, and the uploads are manually audited by an actual person. This would add a second tier to the app store.

Just to drive the point home. Not that you would do this but you _could_ even implement such a system fully anonymously - with uploads via tor and payments via XMR - and it should still work just as well.

Add in a third even more expensive tier for those providing source code to the auditor where google verifies a signed deterministic build the same way fdroid does. Now clearly mark the three different tiers in the app store.

And if they went this route the next logical step for highly sensitive stuff like banking and password management would be a fourth licensed and bonded tier where a verified individual located in a friendly country took on liability for any fraud or other malpractice. That tier would be the equivalent to the situation for civil engineers.

Instead we're stuck in a reality where I don't trust sourcing password managers (among other things) from the play store. Those only ever come from fdroid for me - you know, an actually secure model for how to do app distribution and verify builds.

Re: Android Developer Verification

#92
post #49

Earlier quoted context omitted.

People don't want it until they've been scammed. Then they'll complain why you didn't save them.

Do people complain about being scammed with Windows or macOS? Apparently not. So they probably also don't complain about Android. The security seems more an excuse to become more closed. Like iOS.

> Do people complain about being scammed with Windows

They do. They absolutely do. Where have you been in the last 20 years? Windows has had a reputation as an unsafe ecosystem for decades. Even amongst non-tech people. And even with the various exploits the biggest source of viruses on windows was always that, lacking a proper channel to distribute applications, they had trained their users to double click any .exe on the internet and the next>next>next in whatever installer. I don't agree with the tightening of developer account requirements, but this argument doesn't hold at all.

Re: Android Developer Verification

#93
post #60

Earlier quoted context omitted.

F-Droid is in fact what an app store concerned about user safety looks like. Nobody gets hoodwinked into installing apps that track them or sell their data or otherwise abuse them on F-Droid.

This is non-technical. F-Droid is horrible. https://privsec.dev/posts/android/f-droid-security-issues/#5... F-Droid has not meaningfully improved since that piece was written, either. No one should use F-Droid.

That article's premise is that the Android security model is something that I want. It really isn't.

The F-Droid model of having multiple repositories in one app is absolutely perfect because it gives me control (rather than the operating system) over what repositories I decide to add. There is no scenario in which I wish Android to question me on whether I want to install an app from a particular F-Droid repository.

Re: Android Developer Verification

#94
post #60

Earlier quoted context omitted.

F-Droid is in fact what an app store concerned about user safety looks like. Nobody gets hoodwinked into installing apps that track them or sell their data or otherwise abuse them on F-Droid.

This is non-technical. F-Droid is horrible. https://privsec.dev/posts/android/f-droid-security-issues/#5... F-Droid has not meaningfully improved since that piece was written, either. No one should use F-Droid.

[deleted]

Re: Android Developer Verification

#95
> Android is for everyone. It’s built on a commitment to an open and safe platform. Users should feel confident installing apps, no matter where they get them from.

This intro immediately tells me that whatever comes after will be horrible for users and developers. Surprise surprise, I was right. Software to "verify" side loaded apps is a bad, anti user idea.

Re: Android Developer Verification

#96

Earlier quoted context omitted.

Good of a reason as any to go google-less on my Graphene pixel, I guess. But man it sucks, mostly for all the people who can't. I can manage my financials and 2FA from my laptop, that was my last real reason to have google play installed, but it's just a convenience. (I know it's mandatory for others.) I wonder how that sys app will be handled in GrapheneOS's google play sandbox?

It'll probably always confirm it's been verified. GOS have already said users won't be impacted by this clampdown.

So F-Droid will be installable without sacrificing livestock?

Re: Android Developer Verification

#97
At this point, I think I would prefer to carry a dumb flip phone for SMS and phone calls, and a smartphone-shaped generic touchscreen linux computer for everything else. It's becoming disturbingly impossible to find the former, and practically impossible (IME) to find the former.

Does anyone here have experience using Ubuntu Touch? That's the closest thing I've seen to "generic touchscreen linux" for mobile phone hardware. I'd love a device that works for multimedia, navigation, web browsing, and a handful of APKs like various chat apps (and really anything can can arbitrarily use the hardware), but it seems like tying a cellular modem to this ends up fucking up the whole dream because of carrier and manufacturer motivations/compensations.

Re: Android Developer Verification

#98
post #23

Hey boss: “40M users are running a cracked version of YouTube premium on mobile, what can we do ?”

I pay for YouTube Premium and I have an alt app on my phone because the user experience is just better. You're supposed to have background play in the regular YouTube app, but videos regularly pause until you return to the yt app to reload.

It all worked perfectly fine back on my iPod touch, pre-premium bs. Tech is regressing.

I'm on a family plan (cheap) and I use it for the music player for the inevitable question of why I'm doing this.

Re: Android Developer Verification

#99
post #2

from https://9to5google.com/2026/03/30/android-developer-verifier... - > Starting in April, Android Developer Verifier will be installed on devices. so they're rolling out a system app that will call home to check whether any sideloaded apps have been "verified" with the developer's government ID? and this process will happen regardless of whether the user has enabled the "advanced flow" in Developer settings?

That essay about being licensed to use a debugger was supposed to be an absurdist over-extrapolation for the sake of making a deeper point about software freedoms ... right? Seems more like they're using it as an instruction manual.

Re: Android Developer Verification

#100
post #23

Hey boss: “40M users are running a cracked version of YouTube premium on mobile, what can we do ?”

Exactly this.

And that launch country list is most likely the countries where cracked YouTube Premium is most common.

App piracy is huge by copying around modded APK's, and everyone's grandma is doing it.

Post reply on HN