‹ BackHN Continuity

Thread

The Google Play app review process now regularly takes longer than a week

374 points · 352 comments · inputmice

  1. Gareth321 · · focus · HN ↗
    MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.

    And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.

    1. setgree · · focus · HN ↗
      And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?

      I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.

      1. rock_artist · · focus · HN ↗
        We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors.

        My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.

        1. yacthing · · focus · HN ↗
          Do people not remember the days of viruses destroying computers?

          They were a massive issue before, and now they're barely a thought for most people.

          These review processes have been good for the general population.

          1. bronson · · focus · HN ↗
            What review processes on computers?
            1. pflenker · · focus · HN ↗
              I didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access.

              Even though review processeses generally do not exist for computers, they are part of that same trend.

            2. nekooooo · · focus · HN ↗
              mac app store / windows app store
              1. dazgjkyfedbu · · focus · HN ↗
                And outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.
          2. rock_artist · · focus · HN ↗
            I believe people in HN also remember the days before we had MMUs.

            And I'm sure everyone remembers ransomware.

            No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.

            I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.

          3. oblio · · focus · HN ↗
            > They were a massive issue before, and now they're barely a thought for most people.

            Even on desktops... where there are no such review processes. Apparently we've found other mechanisms to reduce those issues, without app stores everywhere.

            1. tredre3 · · focus · HN ↗
              They're still very much a thing on desktop. You're not wrong that Windows got better at protecting itself, but I suspect the reason you don't hear about them is just that few people use desktops anymore (other than developers who, for obvious reasons, are typically less prone to be infected).

              Anecdotally, at least once a month for the past several years, I notice a youtube channel in my feed get hacked. Their usual content gets replaced with crypto, Roblox, or Elon/SpaceX spam. Big channels, small channels, it happens to them all.

              There's usually a post-mortem when they manage to regain control. Every time the infection happened through a virus attached to an email or by following a link on their discord.

              This kind of attack simply cannot happen on mobile (unless your phone is rooted and you have disabled all warnings).

        2. echelon · · focus · HN ↗
          Sandbox, ACL, scan, sign, revoke bad actors.

          We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.

          Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.

          Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?

        3. ignoramous · · focus · HN ↗
          > We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps)

          Vulnerabilities aren't intentional.

          > reviewed apps that were used for fraud or access as bad actors

          The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".

        4. GuB-42 · · focus · HN ↗
          Just because there are known vulnerabilities don't mean we should drop other security features, this is the opposite in fact. Defense in depth, an OS-level vulnerability cannot be exploited if the attacker cannot access that part of the OS.

          And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.

          As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.

          If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.