Does anyone here actually support Google’s Developer Verification?

I don’t. I’ve put a warning about it in my repo because I’m against policies like sideloading restrictions, forced ID verification.

Curious what other devs here think. Is Play Store still worth the hassle?

  • ViatorOmnium@piefed.social
    link
    fedilink
    English
    arrow-up
    98
    ·
    10 days ago

    I think if Google (or Apple for that matter) wants to play this game, then everyone from the reviewer to the CEO should be held legally responsible when malware ends up not only verified but distributed by them. And by legally I mean also as accessory to the crime.

  • forbiddencherry@lemmy.today
    link
    fedilink
    arrow-up
    36
    ·
    10 days ago

    I paid the fee for a dev account near the beginning of Android. Haven’t had any apps published in over a decade, but from what I understand my account is grandfathered in so I don’t have to jump through as many hoops to get something published if I chose to, compared to newer accounts. Anyhow, since I have an account I suppose I’m unaffected by this decision. Still, it goes against the original spirit of Android as a free and developer-centric platform and I condemn it.

  • artyom@piefed.social
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    1
    ·
    10 days ago

    Is Android Studio forcing you to register?

    Does anyone here actually support Google’s Developer Verification?

    At best some are indifferent but I’ve never heard of anyone who actively supports this.

    Is Play Store still worth the hassle i?

    Never has been 🔫

  • thingsiplay@lemmy.ml
    link
    fedilink
    arrow-up
    13
    arrow-down
    1
    ·
    10 days ago

    Does that mean this app won’t be available on app store, but can be installed from other places? I know there are on going changes regarding this topic, but I’m not fully informed. And researching will bring probably ton of Ai generated articles I’m not willing to look into. Could F-Droid still be used on a “regular” Android?

    • lime!@feddit.nu
      link
      fedilink
      arrow-up
      17
      ·
      10 days ago

      they’re going to make it more difficult too. you basically need to enable dev mode a second time, then for every application that can install ap, you need to re-approve then wait 24 hours.

    • artyom@piefed.social
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      2
      ·
      10 days ago

      No it means you won’t be allowed to install the app on any certified devices at all. Regardless of where it’s obtained.

  • lil_tank [any, he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    11
    ·
    10 days ago

    Is Play Store still worth the hassle?

    If you’re a for-profit business yeah more or less, if not hell no just publish on f-droid or something

    • Little1Lost@gehirneimer.de
      link
      fedilink
      arrow-up
      4
      ·
      9 days ago

      f-droid needs the app to be foss. maybe something like codebergXobtainium will work for closed source. There is also itch.io with the inofficial mitch client which could be worth a upload pipeline but i dont know

      • Remy@lemmy.today
        link
        fedilink
        arrow-up
        4
        ·
        9 days ago

        Are there any relevant/common reason to keep an app closed source if its NOT for profit?

          • Remy@lemmy.today
            link
            fedilink
            arrow-up
            1
            ·
            7 days ago

            I am not so much into programming, but what extra skill is required to add a license and make the repo public? Maybe if you have a closed source dependency and would need to replace it, then it would be a skill issue.

      • Swedneck@discuss.tchncs.de
        link
        fedilink
        arrow-up
        1
        ·
        8 days ago

        you can always just host your own fdroid repo, there’s nothing magical about it and it’s trivial for users to add it to their client.

  • HiddenLayer555@lemmy.ml
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 days ago

    Is there any way to build Android apps for Linux if you have the source code? I know Waydroid is a thing but that’s basically just a VM of Android. I was told Jetpack compose is supposed to be cross platform so there should be a way migrate it right?

    • jksalcedo@lemmy.mlOP
      link
      fedilink
      arrow-up
      5
      ·
      9 days ago

      Yes. Jetpack Compose is multiplatform. If you have the source code of an android app, you can port it to your preferred platform, but you have to adjust most of the code depending on the functionality since APIs are platform-specific unless it’s JVM only.

  • vapeloki@lemmy.world
    link
    fedilink
    arrow-up
    6
    arrow-down
    55
    ·
    edit-2
    10 days ago

    Yes I am.

    I spend a long time of my career in IT Sec.

    80% of android users will freely install whatever APK from wherever.

    Info stealer infected fake apps are a massive risk to a huge part of the user base.

    Yes, it will get a little bit more complicated to sideload. But nobody is prevented from it.

    And everybody that is against user protection (and yes, this is fucking user protection, just not for you) is invited next Christmas to de-worm the android devices of my family without wiping them.

    EDIT for all those that only read the memes. Sideloading will NOT be disabled. You have to jump though extra hoops.

    Yes, the way they do this is not even testable yet and we can argue over details.

    I support the principal idea, as someone who had to live with the fallout of people who installed “it support apps” because someone told them to

      • vapeloki@lemmy.world
        link
        fedilink
        arrow-up
        1
        arrow-down
        6
        ·
        10 days ago

        Because I think we should protect people that are not tech savvy. I am open for a debate

        • thingsiplay@lemmy.ml
          link
          fedilink
          arrow-up
          10
          ·
          10 days ago

          Total control and taking away freedom is not negotiable. Not literally, but: “Maybe we should ban programming languages on Windows and Linux too, because it could be used to program viruses. We should protect the not so tech savvy.” See what I mean? Instead we should look forward to a better way of helping them. The proposed way of Google is not acceptable.

        • dubyakay@lemmy.ca
          link
          fedilink
          arrow-up
          7
          ·
          10 days ago

          Your heart is in the right place, but your mind is not.

          Google et.al. is pushing for IDV in every segment due to lobby pressure from meta to build REAL user database for advertisement purposes in the age of LLM drivel. Every “protect the *” has meta’s government lobbyists behind it.

          There could be alternative approaches, but meta’s goals just so happens to align well with a fascist government’s that thinks they need to stamp out dissenting voices and anonymity.

          • vapeloki@lemmy.world
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            10 days ago

            Not denying that there could be better ways, and also, that was never the question .

    • lime!@feddit.nu
      link
      fedilink
      arrow-up
      19
      ·
      10 days ago

      so the real-world id requirement is also user protection? play store is basically an info stealer at this point.

    • Cassa@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      14
      ·
      10 days ago

      so your family’s devices get their apps from outside the play store?

      people are effectivly prevented from sideloading. not “just a little more complicated”

      • iByteABit@lemmy.ml
        link
        fedilink
        arrow-up
        12
        arrow-down
        1
        ·
        10 days ago

        of course nana uses adb exclusively to install apps on her smartphone, after all this is a totally real story about user protection right?

    • hneerqe@lemmy.world
      link
      fedilink
      arrow-up
      10
      arrow-down
      1
      ·
      10 days ago

      80% of android users will freely install whatever APK from wherever.

      I should care because? Do they care about me not wanting google shoved in every aspect of my life?

          • vapeloki@lemmy.world
            link
            fedilink
            arrow-up
            2
            arrow-down
            2
            ·
            10 days ago

            How about an apple phone?

            Or how about that: projects like Linux and Ubuntu phones died because there was no interest in it, because there was Google. And now, everybody wants an alternative.

            They are out there, you can use opensource Android forks, you don’t have to use Google

            • hneerqe@lemmy.world
              link
              fedilink
              arrow-up
              7
              arrow-down
              1
              ·
              10 days ago

              Android forks

              Soon to be locked out from participating in society because of play integrity, digital IDs and age verification. The EU is very likely to use strictly Apple/Google, the very monopolists they “despise”. Don’t give me the “just go to the post office by foot”… I could also “technically” live in a cave, I guess. Man stfu, your bullshit doesn’t stick here.

              • vapeloki@lemmy.world
                link
                fedilink
                arrow-up
                2
                arrow-down
                2
                ·
                10 days ago

                Ah another myth “the EU App”, I will not go I to detail, but each member state must implement its own app. Yes, the reference implementation uses Google services currently, but there is not a single , working , published app! Not one.

                • hneerqe@lemmy.world
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  9 days ago

                  So I’ll be back at the end of the year, be proven right and you got your pay and your karma anyway.

    • TrickDacy@lemmy.world
      link
      fedilink
      arrow-up
      9
      arrow-down
      1
      ·
      10 days ago

      80% of android users will freely install whatever APK from wherever.

      A ridiculous and absurd lie. 90% have zero clue what one is, let alone go into the developer settings (there are one, maybe two settings you have to enable) to change the settings to even make that possible. Why are you lying about this? It’s weird.

      • vapeloki@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        5
        ·
        10 days ago

        I am lying? OK, so is:

        I have over 2 decades of background in hardcore IT-Sec, i know my stuff. And you? What is your qualification, where are your sources?

        • TrickDacy@lemmy.world
          link
          fedilink
          arrow-up
          6
          arrow-down
          1
          ·
          10 days ago

          I have over 2 decades of background in hardcore IT-Sec, i know my stuff. And you? What is your qualification, where are your sources?

          I wonder if a statement like this ever once convinced anyone of anything. My guess would be it nearly always has the opposite effect. You basically told me that whatever I know doesn’t matter because “trust me bro”. For all I know, you’re the worst source ever for literally every topic. Your articles didn’t back you up. Why do people bother with shit like this? “I’m an expert so what I say goes” is idiotic and in no way addresses the common sense point I was making: the average person definitely doesn’t know or install apks because of fucking course they don’t. If you said 80% would if scammed, that’s at least plausible but I’m not even sure I could believe that. The well is poisoned now in any case so you’re not convincing anyone here after this… Whatever masturbatory shit this was. Or just shilling for a corporation? Who the fuck knows

            • TrickDacy@lemmy.world
              link
              fedilink
              arrow-up
              3
              arrow-down
              1
              ·
              10 days ago

              You do, actually.

              I have over 2 decades of background in hardcore IT-Sec, i know my stuff. And you? What is your qualification, where are your sources?

              This translates to anyone who isn’t you to:

              I know a lot, you know very little. Trust me, not you.

              And again if you’re going to make this 80% claim and then say you sourced it, don’t link shit that’s sort of related but in no way backing up that claim. No one here is saying malware isn’t a problem. You’re getting downvoted for making specific claims which are absurd.

              • vapeloki@lemmy.world
                link
                fedilink
                arrow-up
                3
                arrow-down
                1
                ·
                10 days ago

                That is a general issue of online debates.

                I can not squash 20 years of daily learning into a comment.

                I can point you to sources where you can verify it our self. Social engineering studies, blog post about campaigns from other researchers.

                Placing m credentials there is my kind of saying “I have insight, ask”, but how do you think should something like this communicated.

                We have a highly sensitive topic, with a lot of obsolete or just misinformation.

                It is a highly complex topic that can not be simply understood by most persons, but social media opens a place for debate anyways.

                There are many other examples for this happening and it is bad. Very bad.

                Another example Google wants to get rid of third party cookies. Instead they want to to adspace action on your local system. In our browser, protected. But bad, because Google. Firefox could implement the same API on better, but no, bad because Google.

                Google is not the good guy. But just throwing out every fucking Idea because Google Had it (or was forced into it, allowing sideloading again was because of pressure) is just not what we need

                • TrickDacy@lemmy.world
                  link
                  fedilink
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  10 days ago

                  This is so much beating around the bush. Somehow you’ve managed to ignore the 15 times I’ve pointed it out: most users do not install apks. That’s all. You claimed they did and I said that was dumb. So anything else is just a distraction from the point I was trying to make. Google is pretty shitty but you might have a point that not everything they do is shitty… But that’s not what the conversation started as. And I don’t really care to change the subject at this point.

        • TrickDacy@lemmy.world
          link
          fedilink
          arrow-up
          3
          arrow-down
          1
          ·
          10 days ago

          Given that your first article says nothing about 80% I’m not continuing to click your links.

          I was being generous when I said 90%.

          Source: I have ever spoken to another human.

          • vapeloki@lemmy.world
            link
            fedilink
            arrow-up
            2
            arrow-down
            2
            ·
            10 days ago

            Because people do not know what apps are and that they can be installed via sideloading, faked appstores and more, they are vulnerable.

            If I ask a “normal” person if the ever drunk di-hydrogen-monoxid they would say no, because they have no idea this is water

            • TrickDacy@lemmy.world
              link
              fedilink
              arrow-up
              3
              arrow-down
              2
              ·
              10 days ago

              Okay either you’re trolling or clueless. Because you just made my argument for me. How exactly are people who don’t know what an app is going to enable side loading and then do it? That makes no sense whatsoever.

    • Pollo_Jack@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      10 days ago

      At least make it a toggle, like you need to request access for your account for your phone.

      Kneecapping everyone because idiots exist is idiotic.

      • Pika@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        10 days ago

        It is a toggle. they just locked said toggle behind a 24 hour time lock. It’s ridiculous. I think if they kept it the way it was without said time lock it wouldn’t be anywhere near as controversial.

        • thingsiplay@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          9 days ago

          I don’t want Google to control how many and often I install apps or update them. Imagine having this 24 hour time lock on your PC. Do you know how many people get scammed or malware on PC? Should this be adopted everywhere, because its a good solution? Off course its ridiculous. 24 hour time lock is not acceptable solution. The is literally the worst toggle I have seen in my life.

          That’s not even the only issue. Developers have to give their identity / pass to Google. That alone is a multi-worm-level of issue. Google doesn’t care about its users, they only care about controlling the market and everyone.

    • Avid Amoeba@lemmy.ca
      link
      fedilink
      arrow-up
      5
      ·
      10 days ago

      for all those that only read the memes.

      For someone who possibly considers themselves better informed than others, you’re seem to be missing the fact that Google’s plan had no option for sideloading unverified apps until a sizeable outcry from us (a lot of professional developers and users). Unverified app installation was only allowed (via new hoops) after this action. For now. The fact that Google’s plan did not have an option for installing unverified apps shows us what they really want. Therefore it won’t be surprising if they make it increasingly difficult or impossible in the future.

      • loutr@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        10 days ago

        I’m pretty sure they originally planned to allow sideloading through ADB, but I might be mistaken.

        • Avid Amoeba@lemmy.ca
          link
          fedilink
          arrow-up
          2
          ·
          10 days ago

          I think I recall the same. Otherwise development would be a nightmare. But then again, that isn’t remotely equivalent to sideloading (as colloquially understood) and would still kill F-Droid. Not saying you’re saying it’s equivalent.

          • forestbeasts@pawb.social
            link
            fedilink
            arrow-up
            1
            ·
            9 days ago

            What Apple does is they give you a temporary certificate that expires in like a week.

            Works for development. Makes actually using your own apps impossible.

            – Frost

    • curbstickle@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      10 days ago

      So with your career in ITSec, you’re aware of the massive amount of malware found in the play store? That it has historically been the main distribution vector for malware?

      You have to jump though extra hoops.

      You are downplaying the hoops here by a lot. To install software on my own phone.

      Stop calling installing software “side loading”. Its nonsense.

      • vapeloki@lemmy.world
        link
        fedilink
        arrow-up
        2
        arrow-down
        2
        ·
        10 days ago

        I k ow that the Playstore is also full of crap, I don’t deny this.

        But, just because our back window does not close correctly, do you leave the front entrance open?

        Not the best analogy maybe, but a visual one

        • curbstickle@anarchist.nexus
          link
          fedilink
          English
          arrow-up
          3
          ·
          10 days ago

          Except you have it backwards. The play store is the primary vector. The play store is also pre-installed on Android devices, and even without the whole verification nonsense, you still need to allow a different app repository to install.

          Not cleaning their own play store up first means it has nothing to do with what they are claiming. And lets be candid - they have absolutely not.

          The analogy is bad specifically because its not reflecting the issues anywhere near accurately. This is closing a window on the second floor while the front door is wide open with a sign that says “Come on in!”.

          • vapeloki@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            10 days ago

            That assumes that Google does not do anything about the appstore and that is objectively not true.

            Is it enough? No ideas, but still, it does not change the need for better endpoint security.

            • curbstickle@anarchist.nexus
              link
              fedilink
              English
              arrow-up
              3
              ·
              10 days ago

              I firmly disagree. The issue has nothing to do with the endpoint. They have done very little with the play store relative to this massively impactful change to installation practices in creating a walled garden - precisely the reason many, myself included, chose not to go with iOS in the first place.

              So the very idea that this is an endpoint security issue rather than an app store issue is, to me, laughable at best.

              • vapeloki@lemmy.world
                link
                fedilink
                arrow-up
                1
                ·
                10 days ago

                Then we agree to disagree.

                I think we are manly on the same page, but different opinions on priority and that’s fine.

                I declare both as a risk.

                From my perspective, with this change, we could make Google directly reliable for malware in the appstore.

                While this started as a very anti consumer change, as long as sideloading stays possible, this is a good measure.

                • curbstickle@anarchist.nexus
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  10 days ago

                  we could make Google directly reliable for malware in the appstore.

                  There is no reason they shouldn’t be now. Developer verification for the play store is one thing. Developer verification for installing an application on your own device is wholly separate.

                  I declare both as a risk.

                  And one is substantially higher risk than the other. Namely, the play store. As we recently saw with tens of millions of downloads from just a handful of apps in the play store. Does requiring this developer verification on a device resolve that problem? No. Not even remotely, does it?

                  While this started as a very anti consumer change

                  As long as it impacts the device use (it does), it still is.

                  I’m leaving Android over this. I doubt I’ll be the only one.