The Google Play app review process now regularly takes longer than a week
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
The Google Play app review process now regularly takes longer than a week
Unofficial Hacker News client; not affiliated with Y Combinator.
Gareth321 · · focus · HN ↗
And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.
[deleted] · · focus · HN ↗
[deleted]
setgree · · focus · HN ↗
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
post-it · · focus · HN ↗
gmueckl · · focus · HN ↗
Maskawanian · · focus · HN ↗
pjmlp · · focus · HN ↗
compass_copium · · focus · HN ↗
pjmlp · · focus · HN ↗
People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
voakbasda · · focus · HN ↗
pjmlp · · focus · HN ↗
Lets stop talking about open source as special snowflakes where everything is excused.
voakbasda · · focus · HN ↗
pjmlp · · focus · HN ↗
Lets strive for quality in software.
Dylan16807 · · focus · HN ↗
pjmlp · · focus · HN ↗
Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.
Dylan16807 · · focus · HN ↗
But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.
pjmlp · · focus · HN ↗
- <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32019R0881" rel="nofollow">https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
- <a href="https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement" rel="nofollow">https://www.nsa.gov/Press-Room/News-Highlights/Article/Artic...
And I could keep listing several other world regions.
esikich · · focus · HN ↗
pjmlp · · focus · HN ↗
dml2135 · · focus · HN ↗
Anyone is allowed to sue the lawnmower company. Did they win?
lightedman · · focus · HN ↗
close04 · · focus · HN ↗
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
pjmlp · · focus · HN ↗
marcosdumay · · focus · HN ↗
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
compass_copium · · focus · HN ↗
If computers aren't safe enough that a reasonably competent user, who doesn't open random files they found online and obvious spear-phishing emails, can't use one without losing their 401k, then maybe we need to just reevaluate modern life and go back to bank tellers.
misnome · · focus · HN ↗
jprjr_ · · focus · HN ↗
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
pjmlp · · focus · HN ↗
m4rtink · · focus · HN ↗
anonymars · · focus · HN ↗
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
[deleted] · · focus · HN ↗
[deleted]
misnome · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
esikich · · focus · HN ↗
sunaookami · · focus · HN ↗
pjmlp · · focus · HN ↗
sunaookami · · focus · HN ↗
pjmlp · · focus · HN ↗
Yes you can check every single program out there, when digital stores are the only acquisition mechanism.
Or as alternative, signed binaries.
Coupled with liability like anything else in our societies.
no-name-here · · focus · HN ↗
Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
sunaookami · · focus · HN ↗
bigfishrunning · · focus · HN ↗
NorthSouthNorth · · focus · HN ↗
Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
osmukka · · focus · HN ↗
diegolas · · focus · HN ↗
myaccountonhn · · focus · HN ↗
diegolas · · focus · HN ↗
preg_match · · focus · HN ↗
If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.
fauigerzigerk · · focus · HN ↗
I don't really understand why a well designed sandbox and permissions system doesn't solve the problem.
osmukka · · focus · HN ↗
chipsrafferty · · focus · HN ↗
gvurrdon · · focus · HN ↗
nik282000 · · focus · HN ↗
esikich · · focus · HN ↗
lovasoa · · focus · HN ↗
yosef123 · · focus · HN ↗
Frieren · · focus · HN ↗
Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
no-name-here · · focus · HN ↗
MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.
> Windows
I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
oblio · · focus · HN ↗
Yet life in Windows land is perfectly fine in 2026 and has been for at least 2 decades.
If Windows, which started at the bottom of the barrel security wise can make it, surely we can have more modern OSes that make freedom bearable?
pjc50 · · focus · HN ↗
drdexebtjl · · focus · HN ↗
Frieren · · focus · HN ↗
For free (like for real no microtransactions) that is different. For the rest, they already have that.
BiteCode_dev · · focus · HN ↗
zzril · · focus · HN ↗
freedomben · · focus · HN ↗
zzril · · focus · HN ↗
As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
myaccountonhn · · focus · HN ↗
If you're banned from Google? Good luck, you're fucked.
everforward · · focus · HN ↗
I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).
duskdozer · · focus · HN ↗
1. don't force auto-updates
2. still review apps uploaded to Google Play, but don't force users to use Google Play
If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
MRtecno98 · · focus · HN ↗
So this doesn't solve the issue pointed in the OP.
> don't force auto-updates
I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
Forgeties79 · · focus · HN ↗
Yes it does. This is their point:
> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.
It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
cogman10 · · focus · HN ↗
I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.
We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.
Forgeties79 · · focus · HN ↗
8note · · focus · HN ↗
this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing
basilikum · · focus · HN ↗
Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.
Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.
The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
bluefirebrand · · focus · HN ↗
People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually
People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
basilikum · · focus · HN ↗
[1] General purpose computing
Buttons840 · · focus · HN ↗
When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
miroljub · · focus · HN ↗
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
rock_artist · · focus · HN ↗
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
yacthing · · focus · HN ↗
They were a massive issue before, and now they're barely a thought for most people.
These review processes have been good for the general population.
bronson · · focus · HN ↗
pflenker · · focus · HN ↗
Even though review processeses generally do not exist for computers, they are part of that same trend.
nekooooo · · focus · HN ↗
dazgjkyfedbu · · focus · HN ↗
rock_artist · · focus · HN ↗
And I'm sure everyone remembers ransomware.
No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.
I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
oblio · · focus · HN ↗
Even on desktops... where there are no such review processes. Apparently we've found other mechanisms to reduce those issues, without app stores everywhere.
tredre3 · · focus · HN ↗
Anecdotally, at least once a month for the past several years, I notice a youtube channel in my feed get hacked. Their usual content gets replaced with crypto, Roblox, or Elon/SpaceX spam. Big channels, small channels, it happens to them all.
There's usually a post-mortem when they manage to regain control. Every time the infection happened through a virus attached to an email or by following a link on their discord.
This kind of attack simply cannot happen on mobile (unless your phone is rooted and you have disabled all warnings).
echelon · · focus · HN ↗
We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.
Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.
Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
ignoramous · · focus · HN ↗
Vulnerabilities aren't intentional.
> reviewed apps that were used for fraud or access as bad actors
The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".
GuB-42 · · focus · HN ↗
And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.
As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.
If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.
rpdillon · · focus · HN ↗
charcircuit · · focus · HN ↗
rpdillon · · focus · HN ↗
As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.
Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.
fsflover · · focus · HN ↗
surajrmal · · focus · HN ↗
Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.
LanceH · · focus · HN ↗
I imagine nearly all the security review is automated scans, and not the source of the delays.
chii · · focus · HN ↗
this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.
I dont trust it.
The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.
malwrar · · focus · HN ↗
pjmlp · · focus · HN ↗
drdexebtjl · · focus · HN ↗
pjmlp · · focus · HN ↗
And yes, they also have apps besides games on their stores, and support external keyboards and mices.
drdexebtjl · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
ivl · · focus · HN ↗
As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.
microtonal · · focus · HN ↗
Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money:
<a href="https://www.macrumors.com/2026/07/27/apple-app-store-fake-bitcoin-wallet-lawsuit/" rel="nofollow">https://www.macrumors.com/2026/07/27/apple-app-store-fake-bi...
skobes · · focus · HN ↗
lern_too_spel · · focus · HN ↗
skobes · · focus · HN ↗
lern_too_spel · · focus · HN ↗
nchmy · · focus · HN ↗
[dead]
cyanydeez · · focus · HN ↗
Anyone can put up a PWA. The only org that hates this is Apple.
The complaint is about a shared resource, which would require governments to adopt open source policies and _pay_ for it just like they do the post office.
But ya'll hate government, so here we are.
nchmy · · focus · HN ↗
nozzlegear · · focus · HN ↗
nchmy · · focus · HN ↗
This is all documented in great detail in the links i shared
ocdtrekkie · · focus · HN ↗
Paradoxically, as long as WebKit is mandatory on iOS, the open web is safe: Websites have to build for a lowest common denominator standard instead of building for Chrome proprietary APIs.
nchmy · · focus · HN ↗
[dead]
tavavex · · focus · HN ↗
johnecheck · · focus · HN ↗
nicoburns · · focus · HN ↗
azuanrb · · focus · HN ↗
[dead]
ls-a · · focus · HN ↗
[dead]
pavlov · · focus · HN ↗
There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere.
The current US government won't do anything to follow suit, but hopefully a future one might.
graemep · · focus · HN ↗
So does that mean:
1. People in the EU can continue to use F-Droid etc. exactly as they have in the past, permanently? No Google verification of developers needed? 2. People are free to install apps from any APK they choose?
lern_too_spel · · focus · HN ↗
cute_boi · · focus · HN ↗
shevy-java · · focus · HN ↗
sunaookami · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
howunfortunate · · focus · HN ↗
It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked.
The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.
toxik · · focus · HN ↗
howunfortunate · · focus · HN ↗
viktorcode · · focus · HN ↗
oblio · · focus · HN ↗
To-may-to, to-mah-to. The AppStore is basically identical in most aspects people care about.
killerstorm · · focus · HN ↗
Do you want to bring back those glorious days?
Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.
braiamp · · focus · HN ↗
Code signing with warnings about non-signed apps is enough
killerstorm · · focus · HN ↗
I remember in Bitcoin community ~10 years ago, standard recommendation was than an iOS wallet was secure enough (I don't recall even a single case where wallet was stolen via malware), but any private keys on Windows were strongly discouraged, as most cases of stolen wallets were on Windows.
I'd say popularity of iPhone shows which way people prefer, but you do you - what prevents you from voting with your wallet and buying a Linux phone?..
mrguyorama · · focus · HN ↗
The reason is because Bill Gates put out a memo because it was fucking embarrassing that you could trivially smash the stack on default open API endpoints for services that consumers never used and shouldn't have been trivially routable from the open web in the first place.
Meanwhile in app stores, you don't have to hack anything, because consumers just download your botnet software willingly and directly.
42% of all apps on LG smart TVs turned your TV into a "residential proxy" botnet participant. 30% on Samsung TVs. There is no "hacking" in the world of apps because it's completely normalized for whatever app you build to also for some reason include remote control functionality from like 6 different companies. All of those apps pass review no problem.
killerstorm · · focus · HN ↗
Does it happen on Google Pixel phones?
Obviously, the quality of the walled garden depends on the maintainer. Google's quality standards are lower than Apples, but higher than LGs.
fsflover · · focus · HN ↗
This is exactly why I use a GNU/Linux phone that runs a desktop operating system with no artificial restrictions. Debian repositories are good enough to save me from malware, aren't they?
AdityaK_9999 · · focus · HN ↗
dwaite · · focus · HN ↗
It could also be asking for it to help advertisers build a robust behavioral profile about you.
This is not a systems permission, nor is it something that billions of users can judge the ramifications of each potential privacy impacting decision. Privacy is a systems property, not a technical property enforced with ACLs. ACLs can only keep the door from being wide open, they can't prevent access which has been granted from being abused or help the user understand ramifications of granting access.
We need privacy to be a regulatory concern with actual enforcement via an international framework. Until then, it is a business concern of Apple/Google - because they are in the business of having consumers feel confident that a weather app isn't reporting their behavior to anyone willing to pay for it.