Gareth321
4 hours ago
MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.
setgree
3 hours ago
And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
rock_artist
an hour ago
We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors.
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
echelon
12 minutes ago
Sandbox, ACL, scan, sign, revoke bad actors.
We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.
Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.
Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
yacthing
39 minutes ago
Do people not remember the days of viruses destroying computers?
They were a massive issue before, and now they're barely a thought for most people.
These review processes have been good for the general population.
rock_artist
4 minutes ago
I believe people in HN also remember the days before we had MMUs.
And I'm sure everyone remembers ransomware.
No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.
I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
bronson
22 minutes ago
What review processes on computers?
pflenker
9 minutes ago
I didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access.
Even though review processeses generally do not exist for computers, they are part of that same trend.
nekooooo
8 minutes ago
mac app store / windows app store
duskdozer
2 hours ago
That's a tangential issue.
1. don't force auto-updates
2. still review apps uploaded to Google Play, but don't force users to use Google Play
If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
MRtecno98
2 hours ago
> If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
So this doesn't solve the issue pointed in the OP.
> don't force auto-updates
I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
8note
33 minutes ago
> I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing
Forgeties79
2 hours ago
>So this doesn't solve the issue pointed in the OP.
Yes it does. This is their point:
> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.
It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
cogman10
an hour ago
> It’s my hardware
I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.
We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.
rpdillon
an hour ago
The app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.
yosef123
3 hours ago
And what do windows / linux / macos do about apps getting hacked to billions of pc's simultaneously? How is that a new problem?
Frieren
3 hours ago
If libraries didn't exist could not be created today. People tend to say that "it is impossible" when it actually only needs to be well organized.
Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
no-name-here
an hour ago
> macos
MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.
> Windows
I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
Maskawanian
3 hours ago
How about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.
NorthSouthNorth
2 hours ago
I don't know. Literally every single person I help with tech support makes me doubt this is possible. People do not care in the slightest and treat suggestions to learn basic digital hygiene as if you've asked them to a computer science degree in its entirety.
Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
osmukka
an hour ago
IMO in that case its their own fault. After all they have free will and can use it against their own good if they so choose. Let them get pwned a few times and see if they learn.
diegolas
22 minutes ago
that's so dumb on so many levels... should we strip cars from active safety measures and let drivers who are not super good at driving just kill themselves on the road?
myaccountonhn
a minute ago
Maybe a drivers license should be needed to have a phone.
chipsrafferty
an hour ago
A shocking number of people have passwords like "shovel"
esikich
an hour ago
I've worked with dozens of businesses over the years and you can't even get businesses with real money and consequences on the line to follow basic security practices. My current project is updating dozens of windows domain controllers that are still on 2012 R2. Aka critical infrastructure that hasn't been getting updates for years.
pjmlp
3 hours ago
Many of us have routinely cleaned computers from adults that installed several Ask Jeeves and Yahoo toolbars.
compass_copium
3 hours ago
At some point computers need to stop being treated as magical boxes that no reasonable person can learn how to use safely. We expect people who use cars to learn how to use them safely, we expect people who use lawnmowers to not stick their fingers in them. Computers have been a part of daily life for normies for decades at this point, it's infantilizing to suggest that average, non-tech savvy people can't learn to use (not necessarily build, repair, etc.) them properly and need to be protected from them.
pjmlp
3 hours ago
People have to successfully get through a state exam in order to drive cars in first place, can be jailed, get fined when not driving them safely, or forbidden for life to ever drive again.
People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
voakbasda
2 hours ago
Do you hate open source and want only projects where their authors can afford liability insurance and are willing to put themselves in the firing line of a legal system that can be both arbitrary and capricious? Because that’s what you seem to want.
pjmlp
an hour ago
Even people selling on the street or doing charity work have to account for liability of their actions.
Lets stop talking about open source as special snowflakes where everything is excused.
voakbasda
41 minutes ago
And that’s how you prevent bake sales, lemonade stands, and more. You create a barrier to entry that gets raised little by little until only the biggest players can afford the game. Software liability would end all small open source projects.
pjmlp
28 minutes ago
Bake sales and lemonade stands are perfectly fine as long as people don't land on hospital urgency, due to careless work on preparing them with spoiled ingredients or lack of hygiene.
Lets strive for quality in software.
esikich
40 minutes ago
The problem is it's literally speech. Selling something isn't speech, you do not have the right to do charity work or run a business. It goes even beyond speech, it's closer to pure math/logic and I feel very uncomfortable about regulating that. I also think it's literally impossible.
pjmlp
26 minutes ago
Speech is subject to laws in most jurisdictions.
dml2135
2 hours ago
>People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
Anyone is allowed to sue the lawnmower company. Did they win?
lightedman
an hour ago
The amount of "Do not put hands here" labels I've seen on lawnmowers would suggest that, yes, someone did sue and win (or at the least got a settlement) and thus the lawyers forced the companies to put disclaimers and warnings on the lawnmower, directly on the top of the deck in plain sight.
close04
2 hours ago
On power tools, appliances, etc. the safety features are at the user's latitude to bypass. They are usually a hint (don't microwave your dog), not a hard barrier ("I'm sorry, Dave. I'm afraid I can't do that"). A spinning blade is covered by a grill you can trivially remove without permission from anyone.
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
pjmlp
an hour ago
Yes, and when they fail to do so, there are laws in place for liability of third party, or when their own irresponsible actions affects others.
misnome
2 hours ago
Using a computer wrong doesn't kill people.
jprjr_
2 hours ago
Yes and no.
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
esikich
39 minutes ago
I'm sure you can think of many examples where it does though.
pjmlp
2 hours ago
Depends on what those computers are responsible for.
m4rtink
2 hours ago
anonymars
an hour ago
> "One [software fault] was when the operator incorrectly selected X-ray mode then in 8 seconds quickly changing to electron mode, which allowed the electron beam to be set for X-ray mode without the X-ray target being in place"
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
marcosdumay
2 hours ago
Well, computers first stop being magical machines that no person can learn how to use safely, then.
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
sunaookami
2 hours ago
And e.g. browsers cracked down on it, removed toolbar support and powerful add-on support AND enforced signing meaning everything goes through their gatekept extension store and these problems still persist (e.g. addons changing the search provider, new tab page or homepage). Locking everything down does not help.
no-name-here
an hour ago
> does not help
Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
pjmlp
an hour ago
More a problem of those stores still not being properly validated rather a dumping ground for extensions, than anything else.
bigfishrunning
2 hours ago
20 years of being tech support for countless family members and acquaintances says that nothing can possibly make people care about "digital hygiene". An iPad, Chromebook, or similar inflexible device is perfect for most people, and marketing more flexible devices to them has been a mistake since the beginning.
nik282000
2 hours ago
You expect people to treat devices with respect and responsibility? The VAST majority of people use their phones to stream an infinite sequence of clickbait, ai slop, and conspiracies for 6 to 8 hours a day.
pjc50
3 hours ago
I wonder if people would be happy replacing the "Google approves developers" system with a "government requires your ID and address on file so you can be held liable for your apps" system. I suspect not.
Frieren
3 hours ago
That is already a requirement in any civilized country. You cannot run a business without a registered ID, address, etc. for tax purposes.
For free (like for real no microtransactions) that is different. For the rest, they already have that.
everforward
2 hours ago
The only part that would really be novel is the liability.
I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).
zzril
2 hours ago
If you don't agree with a decision made by your government, you can vote for someone else next time. If you don't agree with a decision made by Google, what do you do?
freedomben
2 hours ago
The people I vote for never win. Am I really any more empowered with the government than I am with Google? At least with Google I can de-google my life (with some significant losses of convenience, but it is doable)
zzril
2 hours ago
Personally, I find it easier to live with a decision I don't support if I was simply out-numbered in a fair vote, rather than out-powered by some random company on some random continent.
As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
BiteCode_dev
3 hours ago
It's virtually the case, google and apple accounts require ID verification, which in turn can be requested by the gov in case of an investigation.
drdexebtjl
3 hours ago
What for? Malicious actors have no shortage of stolen identities.
lovasoa
3 hours ago
We could force Google to operate its app review service independently. Users could use it and pay for it, or alternatives. Currently Google forces everyone to use their own mediocre service and pay for it without knowing exactly where and how much you pay.
basilikum
2 hours ago
People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes.
Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.
Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.
The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
bluefirebrand
an hour ago
> People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes
People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually
People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
gmueckl
3 hours ago
Regulation is already addressing that. I encourage you to read up on the Cyber Resilience Act.
Buttons840
2 hours ago
How about the same thing we do when companies leak half-the-nation's personal data twice a month. Nothing.
When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
post-it
3 hours ago
How would a reviewer catch that?
miroljub
2 hours ago
> And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
howunfortunate
44 minutes ago
The push to involve the legal system and the government is ironic.
It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked.
The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.
toxik
19 minutes ago
Haha, oh the poor mega tech companies?! As if. Google sees a market, it wants to capture it. Same as Apple did.
pavlov
3 hours ago
> "Apple and Google are WELL past due for regulation in this space."
There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere.
The current US government won't do anything to follow suit, but hopefully a future one might.
graemep
3 hours ago
> There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores
So does that mean:
1. People in the EU can continue to use F-Droid etc. exactly as they have in the past, permanently? No Google verification of developers needed? 2. People are free to install apps from any APK they choose?
lern_too_spel
an hour ago
Yes. Even beyond that, people outside the EU are free to install apps from any APK they choose.
sunaookami
an hour ago
The EU is not interested in liberating phone operating systems because it goes against their digital wallet push which forces everyone to use an attested, Google/Apple sanctioned device and operating system.
cute_boi
3 hours ago
Yea, but apple and google keep finding out loopholes and unfaithful compliance, it is time for EU to have some backbone.
shevy-java
3 hours ago
The US government acts here in favour of a monopoly market. Trump violates free market principles; quite interesting how Trump works against core capitalistic means, in favour of personal corruption.
ivl
3 hours ago
Your complaint about Android .apk install is... similar to unsigned software installs on Windows in some cases (not a great argument, I know, but the same as the vast majority of users would be used to).
As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.
microtonal
3 hours ago
For the former there is: https://github.com/privacyguides/verified-apps-android
Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money:
https://www.macrumors.com/2026/07/27/apple-app-store-fake-bi...
skobes
3 hours ago
The main difference is that signing a Windows binary doesn't require any third party review of the app content.
lern_too_spel
2 hours ago
Signing an APK also doesn't require third party review of the app content.
skobes
2 hours ago
But the context of this discussion is the difficulty of installing an APK from outside the Play Store.
lern_too_spel
an hour ago
This is the first time I've seen a complaint about giving permission to an app to install another app. The SmartTubeNext issue was due to the developer's keys being stolen. If you want to keep an app with stolen keys, you can disable Play Protect. If Play Protect uninstalled apps that Google disliked instead of apps with known vulnerabilities, people would mass disable Play Protect, which would defeat its purpose.
pjmlp
3 hours ago
Nintendo, Playstation, XBox,...
drdexebtjl
3 hours ago
… should also be open, but that’s irrelevant to the discussion.
pjmlp
3 hours ago
It is quite relevant as computing systems.
And yes, they also have apps besides games on their stores, and support external keyboards and mices.
drdexebtjl
3 hours ago
Sorry, I think I misunderstood your argument as whataboutism.
surajrmal
3 hours ago
Security at its core comes down to trusting the supply chain that provides the software that runs on your hardware. There are many alternative secure supply chain models, but ultimately users often are incapable of making great choices on what is trustworthy. It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.
Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.
LanceH
3 hours ago
I'm not sure how much manual review in these stores is for security rather than content and enforcement of business rules.
I imagine nearly all the security review is automated scans, and not the source of the delays.
chii
3 hours ago
> It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.
this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.
I dont trust it.
The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.
malwrar
3 hours ago
Hard to find better solutions when we have no agency to enact them. The “arrangement” was one-sided from the start.