Android developer verification: Balancing openness and choice with safety

News and insights on the Android platform, developer tools, and events.

Android Developers Blog

The part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google.

I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give users one allowed attempt at installing an app, after which it's another 24 hour waiting period for you. Then ask the user to verify themselves as a developer if they want to install whatever they want. Whatever helps them turn people away from alternatives and shrink the odds of someone dislodging their monopoly, they will do. Anything to drive people to Google Play only.

Pay verification fee to continue
>"PLEASE DRINK VERIFICATION CAN TO CONTINUE"

Context: https://files.catbox.moe/eqg0b2.png

I think they later made a Black Mirror episode along these lines. "Resume viewing... Resume viewing..."

That meme was 13 years ago.
Fiften Million Merits. The one where advertisers literally torture a man with loud high pitched noises because he refused to view ads and didn't have enough money to skip them.
Every one of BM's episodes is extremely good. Fifty Million Merits has so many parts that show precisely how evil technology can be.

Common People is utterly terrifying. Woman falls into a coma, so startup uploads her mind to the cloud so it can stream her mind back to her. Then they start to enshittify the poor woman's life. Can't even sleep because they're using her brain as a CPU. She gets mercy killed while blurting out ads for antidepressants to the person doing it.

Metalhead is also among my favorites. Those kill bots put Skynet to shame.

I think the last 2(?) seasons lost the essence of what made Black Mirror great but the older ones are excellent. Older episodes often felt directly applicable to the evils of technology we use today but these newer ones seem to be more generic Sci-Fi, season 6 didn't feel like Black Mirror at all to me.
I haven't actually watched the last two seasons yet but the first ones are amongst the best stuff I've ever watched on a screen. So thank you for the heads up.
so Apple then? They require you to pay the $99 yearly fee to sideload for more than 7 days

Which increases the limit to whatever time is left on your current payment period. After which the app will stop working and need to be reinstalled by an authenticated developer who has a current Apple Developer Subscription.

EDIT: Edited the above which previously said 90 days incorrectly. Not sure where my brain pulled that from but I posted the correct details here prior: https://news.ycombinator.com/item?id=45743615

Notably if you install a month before your subscription expires you need to reinstall the app in 1 month.

Free provisioning: If you do not pay the developer fee an app installed via Xcod... | Hacker News

> Which increases the limit to 90 days

It increases to 365 days, no? At least thats the longest I can sign my app and I use a personal but paid Apple Developer Account

Oops yes you're correct. Edited post and put a note about the correction and a link to my previous post describing the correct details.

But it's only 365 days if you install the app on day 1 of your $99 subscription period.

Apple was clear that they were offering the safety of a walled garden from the start.

Apple didn't lie about supporting a user's freedom to run anything they like, only to execute a rug pull after they successfully drove the other open options out of the marketplace.

If Google actually takes away the ability to run unsigned code, my next phone will be an iPhone. And I rarely even run unsigned code.

Honestly, it might finally result in me fully exiting the Google ecosystem.

Buy a cheap unlocked smartphone and run GrapheneOS[0]. I want my smartphone to be like my linux computers where I run them for as long as the hardware works and is still relevant. My iPhone 12 is getting close to its end of life support, yet it is still working well. We should expect better from trillion dollar companies. So I'm not supporting them with dollars wherever I can afford not to. That and I think it's more enjoyable to run something off the beaten path. I like to explore the space a little.

I swapped out my MBP for an Asus Pro Art running linux last year and that's been working out pretty well. Hopefully my cheap motorola phone will be supported by GrapheneOS soon and that will work out too.

https://news.ycombinator.com/item?id=47241551

Motorola GrapheneOS devices will be bootloader unlockable/relockable | Hacker News

> Buy a cheap unlocked smartphone and run GrapheneOS

Note that this needs to be a Pixel at the moment.

It doesn't have to be Graphene; LineageOS works on a lot more devices
GrapheneOS will support future Morotola phones that meet a subset of their requirements, rather than existing phones. Less likely to be budget lines for now.
The cheap Motorola phones won't support GrapheneOS because they are missing some of the security features that GrapheneOS requires. The Motorola partnership is for some new phones: hopefully at a lower price bracket, but likely to be flagships or 2nd tier.

> If Google actually takes away the ability to run unsigned code, my next phone will be an iPhone. And I rarely even run unsigned code.

Same here. If I must be in a walled garden, then I will choose the better kept garden and it sure as hell isn't one of Google's crappy platforms.

The only reason to put up with the shittiness of Android is freedom. The same freedom they keep eroding with their constant, never ending attempts to force remote attestation and sideloading limits.

GrapheneOS is the last hope for Android as far as I'm concerned. Hopefully Google won't find ways to screw that up.

> it might finally result in me fully exiting the Google ecosystem

Don't wait for them to push you away. Start exiting now. Setting up mail on my own domain and distancing myself from gmail is one of the best things I've ever done. Highly recommended.

I've noticed with GrapheneOS, that more recent builds are exhibiting weird issues. This isn't their fault, it's upstream ASOP issues. For example, just in the last few weeks:

* The date has now gone missing from my lockscreen, only showing the time.

* I can no longer see signal strength on my phone for mobile, if wiki is off. I turn wifi on, and now I can. I use a larger font, but it used to be just fine.

There are all sorts of little changes like this I've noticed recently.

It makes me wonder if Google is slowly mangling default ASOP so projects like GrapheneOS will have a crappier daily build experience.

And GrapheneOS doesn't have time to manage features changes like this, they focus on their key security improvements and fixes. If Google is doing this on purpose, it has real potential to seriously degrade ASOP as usable without lots of fixes and changes.

They already rug-pulled security updates or whatever it was a few months back.

And it really seems like the sort of sneaky, underhanded way Google would handle things.

Odd, I don't have those issues (date is on the lock screen, network signal strength when wifi is off is there). Played around with font settings but that changed nothing. Up to date stable version of Graphene on an 8a. Are these beta versions? Or maybe it's phone dependent.

Do you have 'Receive security preview updates' on?

Google stopped publishing any info about security updates until (I think) quarterlies come out. GrapheneOS had to sign some sort of non-disclosure for them, in order to roll them into updates.

If you don't have that on, then you're not fully up to date with security updates. This could be the difference.

> GrapheneOS had to sign some sort of non-disclosure for them, in order to roll them into updates.

So doesn't this mean GrapheneOS is effectively controlled by Google now?

Also, how is keeping anything secret under NDA possible at all if you want to know what's in a security update and be actually able to build that update yourself from source?

Controlled? No. It's about security updates being patched before disclosure.

That said. it is indeed annoying, and there was a lot of uproar when it happened.

For the nuance of it, I'd suggest GrapheneOS docs, you'll get more accurate info.

https://discuss.grapheneos.org/d/27068-grapheneos-security-p...

GrapheneOS security preview releases - GrapheneOS Discussion Forum

GrapheneOS discussion forum

GrapheneOS Discussion Forum
One walled garden to a bigger walled garden.

Just to switch to an even more aggressively monitored and tightly controlled walled garden?

People sometimes act as if the one would be an viable alternative to the other. Even both are effectively the exact same shit for the exact same reasons.

How about we move instead to open systems?

Why not a GrapheneOS phone?

> Apple didn't lie about supporting a user's freedom to run anything they like, only to execute a rug pull after they successfully drove the other open options out of the marketplace.

They did execute a rugpull, and they aren't offering safety anymore.

The rug pull is ads in the app store. If I go to the app store now and search for my bank's name, the first result is a different bank. If I search for 'anki', the first 3 results are spam ad-ware tracking-cookie trash.

If I search "password store" I get 4 results before the "password store" app.
I had a family member try to install one of the google-docs suite of apps, and the first result was some spamware that opened a full-screen ad, which on click resulted in a phishing site.

My family can't safely use the app store anymore because they click the first result, and the first result for most searches is now adware infested crap because of apple's "sponsored results".

What's the point of charging huge overhead on the hardware, and then an astounding 30% tax, and also a $100/year developer fee, if you then double-dip and screw over the users who want your app by selling user's clicks to the highest bidder?

Don't forget that Apple is spying on their users even more then Google does (which is gross in its own). Apple controls much more user data then Google does.

At the same time Apple keeps telling their users some fairy-tales about "privacy".

No, Apple isn't honest. Definitely not.

Sources needed.
The question is how much of that data do they sell to data brokers.

Google also "Doesn't sell your data to data brokers"

Because they sell "insights" or "access" or "marketing" or whatever.

> Apple was clear that they were offering the safety of a walled garden from the start.

This is a red herring. Is Google a hypocrite for lying about it first? Sure. But suppose Android dies and gets replaced by something that never claimed to be open. Or gets replaced by nothing so there is only iOS. Is that fine then?

Of course not, because the problem is the lack of alternatives, and having your choice glued to an entire ecosystem full of other choices so that everything is all or nothing and the choices you would make the other way are coerced by them all being tied together into something with a network effect.

No. Apple's phones started out with only web apps. They only add the walled garden later.

hahahahaha 'walled garden'

repeating marketing speak.

Apple got you.

Walled Prison. Look at all those people suffering with iMessage trying to use openclaw.

It's a garden right up until the point you try to leave. Then it's a jail you're trying to break out of.

Most sories with this plot, the prisoner gets free and gets to see the garden for what it really is. Famous example: The Matrix

You can refresh them. SideStore[1] does that automatically out of the box (no computer needed) but there are Shortcuts to do that too.

[1] https://docs.sidestore.io/docs/faq#what-is-sidestore

Frequently Asked Questions | SideStore Docs

A section on the most frequently asked questions for SideStore.