

Discussion summary
Discussions revolve around app verification, malware sources, and security measures on Android, with some skepticism about the effectiveness of stricter controls.
What the discussion says
- Most malware comes from unverified developers or preinstalled apps.
- Google's verification process is not foolproof, and malware still spreads.
- Sideloading is already restricted, but users can bypass warnings.
- Malware often results from social engineering rather than app stores alone.
“99% of malware with real-world consequences is from unverified developers.”
“More verification won't stop all malware, especially from social engineering.”
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- I'm going to say something that probably will get me down votes:
Why do we have to beg Google to keep Android open? Seriously. So many open source projects have risen out of real and concrete needs and successfully made their way into our every day lives.
A new platform needs to rise that breaks out completely from Google. I've given PostmarketOS a go (with a PinePhone) and while today I can't say it isn't a daily driver for everyone it is certainly the route that needs to be taken.
I'm still unable to use it because is not easy to break away from Android, but is a platform that I think about almost every day, because I do not want to use Android anymore and I'm willing to sacrifice certain aspects to have an open and friendly platform on my hands. And if it is not PostmarketOS then let it be another project.
We need these kind of projects, not kneeling down to a company like Google and begging for Android to be open. Effort needs to be put elsewhere. That's how major projects like Linux, BSDs and open source projects have flourished and taken the world.
by liendolucas - Android has not been really open for a long time now.
- Many APIs have been moved to Google Play Services (which is not open source), and many apps have come to rely on them. You can emulate it partially but not fully, see second point below.
- Some features like device attestation / SafetyNet fail on non-"official" devices, for example many banking or government ID apps refuse to work on open source os like GrapheneOS
by ajnin - Oh, the irony. I still remember how in the early days of Android vs iOS discussions, the main point was "but it's OPEN!". The word "open" was used as a comma by Google people. It was The Thing. The Difference. Good vs Evil and all that.by jwr
- Back in the 2007 or when it came out in Sweden I bought the iPhone and started developing for it. This was cool, new and exciting and it was fine as long as my company was paying the $100 fee every year. But then I switched jobs and worked at a company which produced mostly open source code. Suddenly I would have to pay $100 every year just to be able to put my own software on the phone ...
This is why I switched to Android, just for Google now to pull the rug from under my feet again ...
by jeena - This is doubleplusungood. The war on General Purpose Computing is the death of innovation and a direct attack on digital freedom.
If you're in the US, UK or EU, please contact your government.
by layfellow - As I said in the other thread:
Australian users of alternative app stores should make a complaint to the ACCC: https://www.accc.gov.au/about-us/contact-us-or-report-an-iss...
In the past, they forced Steam to implement proper refund policies, and they are currently suing Microsoft about the way subscribers were duped into paying more for "AI features" they didn't want.
by endgame - No matter how this turns out, I'm sure GrapheneOS will make a smart effort. https://grapheneos.org/
But long-term, Android is such a massive code base, and was designed more for surveillance and consumption, than for privacy&security and the user's interests.
I think getting mainline Linux on viable and sustainable on multiple hardware devices is warmer, fuzzier foundation. (Sort of a cross between Purism's work on the Librem 5, and PostmarketOS's work on trying to get mainline Linux viable on something else.)
by neilv - Before buying a smartphone I tried to find an inexpensive model that supports open source OS, but I couldn't. What open OS support is ether expensive Pixels, or outdated models.
The solution, I think, would be a regulation that forbids manufacturers of any chip or device CPU from making obstacles to reprogramming the device (using fuses, digital signatures, encryption etc). So if you buy a device with CPU and writable memory, you should be able to load your own program and manufacturer may not use technical measures to stop you. The goal of regulation would be preventing of creating digital waste, vendor locks and allow reusing the hardware.
Of course, features like theft prevention won't work, so the user should be able to waive this right.
by codedokode