Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • While I understand the reasons behind this campaign, I have mixed feelings about it.

    As an iPhone user, I find it frustrating that deploying my own app on my own device requires either reinstalling it every 7 days or paying $100 annually. Android doesn't have this limitation, which makes it simpler and more convenient for personal use.

    However, when it comes to publishing apps to the store, I take a different view. In my opinion, stricter oversight is beneficial. To draw an analogy: NPM registry has experienced several supply chain attacks because anyone can easily publish a library. The Maven Central registry for Java libraries, by contrast, requires developers to own the DNS domain used as a namespace for their library. This additional requirement, along with a few extra security checks, has been largely effective in preventing—or at least significantly reducing—the supply chain attacks seen in the NPM ecosystem.

    Given the growing threat of such attacks, we need to find ways to mitigate them. I hope that Google's new approach is motivated by security concerns rather than purely economic reasons.

  • The threat of such attacks is not growing
  • Litmus test: Can you get NewPipe or other Youtube clients onto an Android phone? This is non-malicious software that users want to run but could reduce YouTube's profits.
  • > Maven Central registry for Java libraries, by contrast, requires developers to own the DNS domain used as a namespace

    What are the requirements around domain renewal?

  • I don't understand how you can have mixed feelings about this.

    > However, when it comes to publishing apps to the store,

    This isn't about publishing apps to the Play Store. If that's all this was about, we wouldn't give a shit. The problem is that this applies to all stores, including third party stores like F-Droid, and any app that is installed independently of a store (as an apk file).

    > Given the growing threat of such attacks, we need to find ways to mitigate them.

    How about the growing threat of right-wing authoritarian control? How do we mitigate that when the only "free" platform is deciding the only way anybody can install any app on their phone is if that app's developer is officially and explicitly allowed by Google?

    Hell, how long until those anti-porn groups turn their gaze from video games and Steam onto apps, then pressure MasterCard/Visa and in turn Google to revoke privileges from developers who make any app/game that's too "obscene" (according to completely arbitrary standards)?

    There's such a massive tail of consequences that will follow and people are just "well, it's fine if it's about security". No. It's not. This is about arbitrary groups with whatever arbitrary bullshit ideology they might have being able to determine what apps are allowed to be made and installed on your phone. It's not fucking okay.

  • If the manufacturer wants to offer verification of developers, this should be an optional feature allowing the user to continue the installation of applications distributed by unverified developers in a convenient way.

    Making this verification mandatory is an absolute non-starter, ridiculous overreach, and a spit in the face of regulators who are trying to break Google and Apple's monopoly on mobile app distribution.

  • > In my opinion, stricter oversight is beneficial.

    I agree; stricter oversight is beneficial for the official app store. It should not be necessary (and neither should Google's (or Apple's, or Microsoft's, or the government's, etc) verification be necessary) for stuff you install by yourself.

    > The Maven Central registry for Java libraries, by contrast, requires developers to own the DNS domain used as a namespace for their library.

    This means that you will need to have a domain name, and can verify it for this purpose. (It also has a problem if the domain name is later reassigned to someone else; including a timestamp would be one way to avoid that problem (there are other possibilities as well) but I think Java namespaces do not have timestamps.)

    > I hope that Google's new approach is motivated by security concerns rather than purely economic reasons.

    Maybe partially, but they would need to do it a better way.

  • Android already has this strict oversight, in theory, in the form of the Play Store. And yet.

    Personally I feel much more safe and secure downloading a random app from F-Droid, than I do from Google, whose supposed watchful eyes have allowed genuine malware to be distributed unimpeded.

  • It's a lost cause. We need to focus on pmOS: https://postmarketos.org/

    With both Android and Chromium, we're ultimately at Google's mercy.

    btw, does anyone know if Huawei is following along with this in their fork?

  • > btw, does anyone know if Huawei is following along with this in their fork?

    They are moving to their own completely proprietary OS called HarmonyOS NEXT.

  • Linux on mobile is fun, but really I want AOSP and its superior security model and SDK.

    Now I hate Google as much as the next person, but I also hate all the other Android manufacturers who just don't do better.

    Ideally, major manufacturers would all contribute to AOSP to make sure that it runs well with their devices. And then we could install the "AOSP distro" we want, be it GrapheneOS or LineageOS or whatever the fuck we want.

    > does anyone know if Huawei is following along with this in their fork?

    They suck like all the other manufacturers: they forked as a quick solution, and then decided to go with their own proprietary codebase. If nobody else contributes, why would they make it open source?

    What I see from the Linux experience is that the only way it works is to have a copyleft licence and a multitude of contributors. That way it belongs to everybody, and it moves too fast for one single entity to write a proprietary competitor on their own. But AOSP is not that: first it's a permissive licence, and only Google meaningfully contributes to it.

  • JBQ redeemed: https://www.greenbot.com/jbq-is-quitting-aosp/ (yes, 2013)

    I regret having wasted a good part of my career supporting Google with the Android enterprise. They had some very good (technically and intentionally) people there, but it all got thoroughly corrupted.

    With hindsight the only thing that kept them remotely honest was the Andy Rubin vs Sundar Pichai turf war, which at the time manifested as Android vs Chrome. Once that had a decided winner it was a recipe for serious trouble.

    The only viable way forward for an open mobile OS is to fork Android as is. This is the only way to carry over anything resembling existing app support or all the work that goes into making a mobile OS actually work up to the level users expect. i.e. cameras through to hardware media CODECs and total system stability.

  • This feels similar to Sony and their OtherOS feature.[0]

    Many people bought Android phones because of the open capability. Even if you don't use it, just knowing you have an out is important.

    And now Google is "altering the terms".

    [0]:https://en.wikipedia.org/wiki/OtherOS

  • I'm going to say something that probably will get me down votes:

    Why do we have to beg Google to keep Android open? Seriously. So many open source projects have risen out of real and concrete needs and successfully made their way into our every day lives.

    A new platform needs to rise that breaks out completely from Google. I've given PostmarketOS a go (with a PinePhone) and while today I can't say it isn't a daily driver for everyone it is certainly the route that needs to be taken.

    I'm still unable to use it because is not easy to break away from Android, but is a platform that I think about almost every day, because I do not want to use Android anymore and I'm willing to sacrifice certain aspects to have an open and friendly platform on my hands. And if it is not PostmarketOS then let it be another project.

    We need these kind of projects, not kneeling down to a company like Google and begging for Android to be open. Effort needs to be put elsewhere. That's how major projects like Linux, BSDs and open source projects have flourished and taken the world.

  • Because we can't install that on phones and even if we did, we need to use Android apps to do basic daily things.

    Phones are not like PCs, you can't "just install a different OS". You also can't just build a phone from parts like you can with a PC, it comes locked in with the OS, with proprietary drivers and advanced cryptographic DRM measures.

    And even if we did get things to the level of desktop Linux, we can't run any of the apps we need for everyday life. Most of these things on desktop are web-based, so you can use them on Linux, but this isn't the case for mobile and many things only come in mobile. Bank apps, government services, digital identification, mandatory companion apps for other devices...

    If nothing else, we need to keep Android as open as possible because it makes it easier to port those things to other platforms and maybe one day have a proper alternative.

    Oh, and it's not like we have a good alternative. The current Linux stack is completely inadequate for mobile use. An average phone has something like 50 apps the need to be able to react to any of a few dozen different local or remote events at any moment, yet also need to use approximately zero CPU cycles to do that. We need a brand new app paradigm if we want mobile Linux to succeed and it's not looking like that's going to happen any time soon.

  • I don't understand why individuals expect a corporation like Google, driven by profits, to give a sh*t. I would expect no less of Apple with IOS.

    Individuals should look for and support alternatives. I'm currently working on a desktop running Ubuntu because I want an alternative to the duopoly of Windows and macOS.

    Additionally, we should support open-source alternatives with our donations. I personally donate money every year to Ubuntu, the Gnome foundation, and Tor.

  • For another platform to rise, there needs to be some heavy market shift. There already were opensource mobile OS: Maemo/meego/Tizen. Heck! I'd even throw phosh and ubports in the pot. But those are about as rare a sight in the wild as lightphones.

    Phones have become essential to daily lives and the catch22 is: companies won't support niche platforms for their apps and users won't switch until the apps are there. Android happened to get adopted before everyone started relying on mobile devices as computer substitutes. Unless a major player pulls out a Valve move and does with waydroid what Valve did with wine, I can't imagine the market changing significantly.

  • > Why do we have to beg Google to keep Android open?

    Because Google and Apple have put themselves between us and everything else.

    Until we manage to replace them (by lobbying to everything including governments against them, and by working towards making the alternatives usable), we unfortunately have to resort to this. I'd even say we are entitled to this because we never asked for Google and Apple to become compulsory, they decided this.

    I would personally be able to switch to Linux mobile today because I don't rely on anything proprietary (except the interrail app occasionally, damn them - but possibly waydroid would work for this)… if only there was usable and reliable hardware that could run the mainline kernel: decent battery life, decent picture quality, decent GPS, decent calls (especially emergency calls even if I haven't needed to actually make one so far, finger crossed, and Signal would do for most other situations actually).

    I've daily-driven the PinePhone for a year. Call quality is awful and calls are awfully unreliable, and SMS are quite unreliable as well. Too bad for a phone. Unfortunately the phone took a big rain and now its modem is unreliable and doesn't come back up very often, but that's something a phone will likely endure in its life. Pictures are awful. GPS never worked well on my regular PinePhone. It somewhat worked on the Pinephone Pro until it died because it overheated. Linux hardware support is okayish, it was nice to run completely free software which was my main motivation for trying it but the hardware is crap to the point of being unusable serious.

    The FP5 can apparently run PostmarketOS quite well. It would make an awesome Linux mobile. Camera and calls only partially work though [1]. And that's the main features of a phone.

    Linux mobile itself it becoming quite decent (if one can do without the proprietary apps), what we really need is good hardware running it. Then we can begin to imagine a world with it having a decent usage share.

    [1] https://wiki.postmarketos.org/wiki/Fairphone_5_(fairphone-fp...

  • > Why do we have to beg Google to keep Android open?

    We don't! Instead, we go to regulators. Though I suspect your question really is "Why bother with salvaging Android at all?"

    Mobile platforms are hard - famously, Microsoft failed to make Windows phone a viable platform, and John Carmack successfully argued that Meta didn't need a custom OS. Mozilla's Mobile OS that had OEM partners making real phones spluttered out, and nor for the lack of trying. Both Firefox OS and Postmarket rely on an Android foundation for HAL/drivers, IIRC. Device bring-up is hard, and negotiating with OEMs is harder still, and that comes "free" with Android-supporting devices.

    Logistically, the vast majority of people who install apps from non-Play-Store sources do so ok their daily-driver phone, which is running the stock operating system. They are not tech savvy at all

  • Legislation is required at this point. Infrastructure companies (including finance and transportation) should be required to provide web apps that have feature parity with proprietary apps. (Enforcement is simple: ban distribution of the proprietary app for 5 years).

    I think we going the other way though.

    For instance, this recently proposed bipartisan bill would force all (even locally installed) AI apps to repeatedly run age checks on end users, and also adds $100,000 penalties each time the AI screws up when a minor is involved, even for bugs. I don’t see any safe harbor provisions, or carve outs for locally installed / open source / open weight projects, so it’d end up handing a monopoly to ~ 1 provider that’s too big to prosecute:

    https://news.ycombinator.com/item?id=45741862

    The most important thing you can do right now is get the democrats to actually field a candidate in 2028 that will restore the rule of law and free markets in the US.

  • > Why do we have to beg Google to keep Android open? Seriously.

    Because the market has failed, and we have a duopoly. There are many reasons for that, but, this is the exact sort of time a govt must step in - when something becomes a utility, it needs to be regulated as such.

    I agree, I don't really want to enshrine Google/Apple into law, however if they are makers of an operating system that is used like a common utility, they should be regulated as such.

  • Answer: bank/financial apps, enterprise apps, government apps and copyrighted media (music, video, games, books, ...).

    Those are the players that demand excessive control over end-user devices, and thus the ultimate driver behind the problem we're discussing.

    It's not that a new mobile platform couldn't possibly succeed. It's an open platform that cannot, because aforementioned players don't want it, and without them, mobile devices lose 90%+ of their usefulness, dooming them to become mere gadgets instead of (crappy, toylike) tools for everyday use.

  • Android has not been really open for a long time now.

    - Many APIs have been moved to Google Play Services (which is not open source), and many apps have come to rely on them. You can emulate it partially but not fully, see second point below.

    - Some features like device attestation / SafetyNet fail on non-"official" devices, for example many banking or government ID apps refuse to work on open source os like GrapheneOS

  • Android dev at a large company - I've been talking with the folks at Graphene about options for attestation without using Google's API and it looks like there's actually a lot I can do for attestation without them, as long as I add their cert chain to a backend service.

    It's a bit of a pain because Google just does that for me normally, but we _can_ support it. It's probably only a sprint of effort give or take. But we're deeply undermanned so it's hard to get done.

  • Oh, the irony. I still remember how in the early days of Android vs iOS discussions, the main point was "but it's OPEN!". The word "open" was used as a comma by Google people. It was The Thing. The Difference. Good vs Evil and all that.
    by jwr
  • And after the change Google is doing now, it will still be more open than iOS.
  • It looks like eventually any company will start squeezing customers for what they are worth.

    But only once the company is powerful enough. We don't call Google a monopoly, because there is Apple, but taken together they certainly behave as one. Both create expectations, create expected momentum in a certain direction, people build (companies, lives) on those assumptions and boom, you can't get out and now the company changes the deal.

    Is it just our assumptions that get us in trouble? Or do we need to do more?

    I'm not sure how to regulate this, other than to stimulate open source, as the "for the people by the people" solution. But also that will just lead to poor expensive solutions (the market created some nice FOSS though). So the law it should be... And we're back to the problem of lobbying...

    Perhaps there should be contracts: Google advertises Android as open: They should sign a contract: For how long will Android be open? Define "Open". The contract can be enforced. Or perhaps we, the people, sue now, for false advertising, although that will just make them flex their legal and lobbying muscles... And they didn't sign any contracts.

  • Back in the 2007 or when it came out in Sweden I bought the iPhone and started developing for it. This was cool, new and exciting and it was fine as long as my company was paying the $100 fee every year. But then I switched jobs and worked at a company which produced mostly open source code. Suddenly I would have to pay $100 every year just to be able to put my own software on the phone ...

    This is why I switched to Android, just for Google now to pull the rug from under my feet again ...

  • I totally agree with your sentiment, but can't you still do that with Android?

    IIUC, you can still load apps directly via adb. Is that not correct?

  • You don't need a paid dev account to build and run on your own iPhone. I didn't have one most of the time