11 ms·
Petition to stop Google from restricting sideloading and FOSS apps
As Google will allow only apps from verified developers to be installed on Android (previous discussion): https://news.ycombinator.com/item?id=45017028
A developer started a petition to stop Google from limiting app installation on Android devices unless developers provide personal identity documents.
Even though Google has not revoked similar controversial policies in the past, we do our best as much as we can. This change particularly threatens the freedom to build, share, and use software without giving away sensitive personal information. It affects independent developers, FOSS contributors, and even regular users who want to install apps outside of Google Play.
``Just imagine giving sensitive personal, government-issued ID to a corporation to install an app outside Google Play``
Let’s stand together to protect our freedom to create and use software without handing over personal information to a corporation. Every signature, share, and voice counts here
Support the petition here: https://chng.it/MsHzSXtJnw
- Zephanyah 1y agoHello, I'm Connor Murphy, a student at gsu Atlanta GA. I have had android since the first came out, don't make me an apple guy please.
- fc417fc802 1y agoApple has been doing this exact thing since day one though ... ?
- ferguess_k 1y agoDoes Google ever care about petitions? Maybe stop using Google products is a better start.
- throaway920181 1y agoSo what phone manufacturer should we go to? Apple, who has always heavily restricted software installation on their devices?
- speedgoose 1y agoDid a petition ever worked ?
- mdrzn 1y agochange.org is useless
- ath3nd 1y agoI agree with the spirit of the petition and I will sign it but I think it's better to be a petition to the EU to force google to stop their adversarial interoperabilty. EU have done it with Apple and their trash lightning cable, forcing them to adopt the USB c standard. EU fined Meta and Google for mishandling our personal data (like all the time), and forced (kinda) both Google and Apple to allow alternative stores. This bs will not fly in the EU. I will not tell you to stop using Google products and Android, since you are most likely a dev or FOSS on the Android ecosystem. But yeah, Google are pretty evil. - sent from my Android - /s
- ForHackernews 1y agoOnly government intervention will matter, petition EU regulators instead, perhaps: https://www.europarl.europa.eu/petitions/en/home https://www.europarl.europa.eu/petitions/en/home
- spacebacon 1y agoBuild for the web. App stores are overrated. They will continue to make the same mistakes until they are irrelevant. Eventually.
- sanex 1y agoHow would this work with say my syncthing fork or DJI fly? Web doesn't really work here.
- jeroenhd 1y agoRe DJI Fly: a combination of WebBluetooth, WebRTC, the normal location API, offline web pages (through managed caches), regular browser video features, and a bunch of other web technologies. Re SyncThing: there's the File System Access API. You can ask the user for a folder and then operate on the files and directories inside it. Also from a locally cached offline copy, of course. Serviceworkers are there to run in the background, though I'm not 100% sure if the FS API and service workers can be combined to be honest. It'll need as much effort or maybe even more to port it to the web as it has taken to develop the Android app, but it's almost definitely possible, at least on Chrome. As part of Google's attempt to break free from the iOS app store, they accidentally invented an alternative to their own draconic measures.
- cosmic_cheese 1y agoFS API is Chrome only though, and a lot of people use Firefox for Android for access to real uBO since Chrome for Android conveniently never gained support for extensions.
- nicce 1y agoIt is a social problem which is hard to reverse. People use app stores because they are used for artificially worsened web pages. They are used to find apps with similar properties from app store. And Google search is artificially so bad that they won’t even try it to find some apps. And most won’t use other search engines.
- christkv 1y agoDon't hold your breath for the EU this aligns with the Chat Control being pushed. Banning people from side loading keeps you from escaping their plan of always listening.
- JumpCrisscross 1y agoThese online petitions are worse than useless. They don’t do anything because they fail to communicate either conviction to a cause or the relevance of the signers. And they may take someone who would otherwise do something useful, like call their elected or participate in public comment, and make them complacent. An open letter from the lead developers and decision makers of top-rated apps in the Play Store would be useful. But that takes work, unlike an online petition.
- dmix 1y agoThey are placebos to make people feel better. https://en.wikipedia.org/wiki/Slacktivism https://en.wikipedia.org/wiki/Slacktivism
- deleted 1y ago[deleted]
- janice1999 1y agoPetitioning EU lawmakers would be better. American control of European data is already a bit issue at the moment in the face of US threats over Digital taxes and Microsoft being used to punish ICJ members.
- jeroenhd 1y agoHonestly, I'll be surprised if this plan doesn't break the DMA/DSA already. Someone will need to collect the necessary resources to bring the fight to the courts, though.
- gjsman-1000 1y agoThe EU is almost ready to sign off on Apple's DMA compliance as sufficient, despite sideloading being similarly restricted, and despite 15-20% commissions remaining. The DMA was never written to allow completely anonymous sideloading, or even commission-free sideloading, another law is needed for that. https://www.reuters.com/sustainability/boards-policy-regulation/apple-set-stave-off-daily-fines-eu-accept-app-store-changes-sources-say-2025-07-22/ https://www.reuters.com/sustainability/boards-policy-regulat...
- goda90 1y agoI think the biggest impact we can have, besides getting government regulation involved, is building the market share of an alternative.
- elric 1y agoThat, and staying away from anything that funnels money to Google.
- rchaud 1y agoYes. A decision like this creates the impetus to move to alternatives like Jolla OS that have an Android-compatible layer. 20 years in, the so-called "smartphone" duopoly have jointly converged towards a "dumb terminal" strategy, where almost nothing can be done without cloud-based authentication from a centralized third party. And this was the case prior to the AI horse manure they're baking into the OS. I use the Fossify forks of Simple Mobile Tools apps (Gallery, File Manager, Calculator) because these can be installed via APK files and just be left alone. My Google Calculator app on the other hand seems to want to download new updates every single month.
- monegator 1y agoAnd what alternative would that be? iOS? hah. Hardware and vendor lock in. AOSP / Graphene, or the equivalent of linux on a smartphone would be a better chance, but first and foremost you need hardware support. Something is happening like eos, pinephone and the like but we are a long, long way toward that goal.
- egorfine 1y agoPlease bear in mind that Google was perfectly aware how much negative feedback they will receive from developers and they are completely and fully prepared for it. In other words, this decision was made with full awareness that developers and "screeching voices of minority" won't like it.
- SiempreViernes 1y agoDo you have evidence that they have accurate estimates of the potential for backlash? It is not that uncommon that people in power take decisions without thinking them though properly
- egorfine 1y agoI've got no evidence that they have an estimation of the volume or scale of the feedback. But I reckon we can all make an educated guess that they did anticipate negative feedback.
- j4hdufd8 1y ago[dead]
- JumpCrisscross 1y ago> delegitimize developer criticism before addressing its substance. This attacks the critics rather than engaging with their actual concerns It’s a petition, not a debate. Who is speaking is absolutely relevant. Tens of thousands of tiny developers with a few million collective users aren’t relevant to Google. > Appeal to Corporate Omniscience This is not a logical fallacy. You may be thinking of appeal to improper authority. But in that case the criticism is that we don’t know Google anticipated this. Not what you wrote, which is technically ad hominem, since you conclude adversely based on Google being a corporation. > ignores the possibility that feedback could be legitimate even if anticipated No, it does not. It says such a petition brings no new information to the decision makers at Google. If Google (note: this is OP’s hypothesis, not a fact) anticipated small developers complaining. Small developers are complaining. That doesn’t make the complaints wrong. But it would make them practically irrelevant.
- ulrikrasmussen 1y agoI thought the Digital Markets Act in the EU would make it illegal for Apple and Google to prevent people from sideloading apps. Is there some kind of loophole that allows Google to do this anyway?
- c0wb0yc0d3r 1y agoFrom what I’ve read Google’s new process sounds much like Apple’s app notarization process. Apple is still in complete control the user just isn’t required to go through the App Store.
- ulrikrasmussen 1y agoI am not an iOS user, so I wasn't aware of how it worked. In that case the DMA is completely worthless.
- immibis 1y agoIsn't Apple already getting sued for having that process?
- weirdpickles 1y ago[dead]
- stockresearcher 1y agoThe EU has lots of laws, including some that were made after the DMA. One of them is the CRA, which says that by the end of 2027 all app marketplaces are required to provide developer contact info to people who download software. If the contact info is fake or wrong, the app marketplace can face fines. So the app marketplace should probably verify the contact info, right? Would you take on that kind of risk to protect the anonymity of some rando you’ve never met and will never give you any money? I wouldn’t.
- cryptonym 1y agoI don't understand how side-loading would impact information marketplaces should provide. If it's side-loaded, that's no longer marketplace responsibility.
- derelicta 1y agoThat's nice, but they won't care
- deleted 1y ago[deleted]
- aussieguy1234 1y agoI'll switch my Pixel over to GrapheneOS if this happens
- c0wb0yc0d3r 1y agoWhy wait? I’ve never installed many apps on my phone, but I don’t have any problems using graphene. My bank nor credit card apps have any problem.
- aussieguy1234 1y agoIt's mainly the lack of emergency services support in my country. Every time I called the operator can't see where I am through GPS, first question asked was what state im in.
- lawn 1y agoThat might be because GrapheneOS by default scrambles your GPS location but I think you should be able to turn that off?
- throaway920181 1y agoI used GrapheneOS for about half a year as my primary phone OS. It does not scramble your GPS in any way (it has the same course/fine-grained GPS permissions as regular Android), but it does allow you to block a lot more app permissions. It's more likely that they haven't set the correct permission(s) for that information to bubble through to emergency services. I would also be surprised if there weren't cell phone system-based fallbacks for emergency services. The carriers have a good idea of where you're at based on the towers you're connected to. There are plenty of situations where GPS doesn't work.
- sneak 1y agoWhy would you kneecap yourself on hardware and get a Pixel over an iPhone if not to install Graphene as the very first action post-unboxing? Graphene is the only reason I own any pixel devices.
- deleted 1y ago[deleted]
- hofrogs 1y agoBy utilizing anti-user language like "sideloading" you are already submitting to their desire to own all hardware.
- briandear 1y ago> Just imagine giving sensitive personal, government-issued ID to a corporation to install an app outside Google Play In Spain, I have to give my NIE (National ID number) and show my government ID just to send or receive a package from FedEx. Why should I have to give up sensitive information just to receive a package?
- arnaudsm 1y agoIt's too late. As a developer, I'm pulling all my Android apps away from the Play Store. If Google is hostile to me an my users, I prefer to dedicate my volunteer time to respectful plateforms instead.
- olejorgenb 1y agoWhich platform though?
- arnaudsm 1y agoWeb and GNU/Linux
- gooob 1y agojust making sure you understand the proposal correctly. you'd still be able to distribute the app through whatever means you want; the app just has to be signed with a key tied your identity that is verified by google, if trying to install on a "certified device" (which will be most devices). i still disagree with the move. but it's not as bad as it could be. maybe there's a way to "unlock" a certified device (similar to unlocking the bootloader)?
- vorpalhex 1y agoDe-anonymization is being done for the same reason manifest v3 was - to help their youtube revenue.
- Springtime 1y agoI think there are a few main contentions: - The requirement, unless I'm mistaken, would tie a real-world identity of the developer to an app, who may wish to keep that separate from a pseudonym they may normally release things with. - Unwillingness to give Google PII or just not tie a particular pseudonymous identity to that PII on Google. - It puts absolute control in Google's hands for whether any app is allowed to run on most devices. There may be concerns about the types of decisions that may arise from this, not merely from recognized malware. Certain governments may ask Google to regulate apps allowed on such devices via this approach. - Once this globally rolls out in 2027 it will mean the audience for apps from devs who don't agree to this will shrink dramatically. Only those presumably with AOSP based custom ROMs will be able to use those apps which may have a knock-on effect for dev motivation.
- notepad0x90 1y agoCan someone articulate for me why everyone seems to be opposed to this? You can sideload apps on non-google-certified android builds/installs just fine right? If you're going to publish an app that literally be installed on billions of devices, is this not a sensible measure? Long overdue even? Why isn't Windows and Linux distros enforcing this as well is my question! Do you guys understand that people's lives are being ruined by malware? and the most popular way of deploying malware on the most popular platform (android) is sideloading apps! This is a similar situation as "Freedom of speech isn't freedom of reach". You can publish any android app you want, that doesn't give you the right to anonymously deploy those apps on everyone's personal tracking devices (phones). I get a petition to allow alternative attestation and verification authorities. and honestly, I don't think Alphabet has much choice on that given EU and US anti-trust policies. I can't image the EU being ok with a US company collecting the IDs of all its developers. For about a decade now, on Windows, you are required to have an ID-verified code signing certificate so sign drivers for example. And that has dramatically reduced rootkit abuse on the platform. Don't get me wrong, I also don't want to submit my ID to anyone. But this is a very sensible measure, one that will improve security in measurable and significant ways to millions of regular people.
- moi2388 1y agoCompany details, sure. But personal details?!
- janice1999 1y ago> You can publish any android app you want, that doesn't give you the right to anonymously deploy those apps on everyone's personal tracking devices (phones). This is about users freedom to install apps on the devices they own. > non-google-certified android builds/installs Those targets are rapidly disappearing. Alternative Android ROMs are dying one by one. Look at how few modern phones are officially supported by LineageOS. And many of those are Pixels which Google is no longer releasing binaries for (making ROM builders lives harder). > Do you guys understand that people's lives are being ruined by malware? Do you have figures to back that up? There are already multiple warnings when sideload apps. > For about a decade now, on Windows, you are required to have an ID-verified code signing certificate so sign drivers for example. Drivers and applications are not the same things.
- nfriedly 1y agoClickable: https://chng.it/MsHzSXtJnw https://chng.it/MsHzSXtJnw
- bagol 1y agoI just realized how powerless we are. The situation is almost unavoidable. Majority people will just accept this. They are unaware how restricted they are, thus they don't care.
- gooob 1y agoare there enough devs to make "non-certified" phones? also i wonder if you'll be able to disable the verification check similar to bootloader unlocking.
- rchaud 1y agoNon-certified phones won't be sold in Western markets. This whole scheme has one goal only, and that's to snuff out DRM-unfriendly third party apps like alternative Youtube clients, videogame emulators and P2P file sharing apps.
- gooob 1y agowhat i'm saying is it's time to make a new company. this is a matter of maintaining good technology and avoiding enshitification so it's quite important.
- rchaud 1y agoThat's my point. Who is going to create a company to compete with Google and Apple on the smartphone front? They already ran everybody else out of business (Palm WebOS, BlackberryOS, Windows Phone). The alternatives are already here but they don't operate in North America (Huawei HarmonyOS, Jolla OS, Pinephone).
- bryan_w 1y agoWhy not you? The beauty of open source is that you don't need to wait to make something happen if you really want it to happen.
- zokier 1y agoWhen I was back there in Seminary School There was a person there Who put forth the proposition That you can petition the Lord with prayer Petition the Lord with prayer Petition the Lord with prayer You cannot petition the Lord with prayer! If you truly want to protect your rights then don't petition Google, but instead petition FTC and other antitrust agencies. Petitioning Google just establishes that they have a choice here.
- Chinjut 1y agoI agree, but under the current administration, the FTC isn't going to do anything to impede a megacorporation's profits. We're fucked, at least for the time being.
- dvh 1y agoSave your effort and invest it in making alternative OS better.
- onetokeoverthe 1y ago[dead]
- deleted 1y ago[deleted]
- rep_lodsb 1y ago"Almost completely boiled frog petitions against raising the water temperature another degree" It's great to see that some more people who were previously complacent are outraged about this move. But let's look back a bit: In the early 1990s, Linus Torvalds started writing an OS kernel for 386-class PCs. He didn't need the approval of some corporation to allow him to run code on his own machine, or distribute it for others to run on theirs. The code didn't have to run as an "app" in some restricted sandbox under Microsoft's OS (not that back then, DOS or Windows were even in any way locked down the way modern operating systems are). Documentation for all the "standard" hardware like video, keyboard, hard disks, etc. was openly available, so it didn't have to rely on proprietary drivers. This is how it was at one time, and what should have remained the standard today, but instead it's turned into some utopian dream that those who grew up with "smart" devices can't even conceive as possible anymore. Google has taken what became of this code, and turned it into an "open" system that is pretty much designed to track every aspect of people's lives in order to more effectively target them with psychological manipulation, which is what advertisements really are. And you're not really getting "free stuff" in return for this invasion either, since pretty much everything you buy includes a hidden "tax" that goes to support this massive industry. "A supercomputer in everyone's pocket"? Yes, but it's not yours, nor can you even know what it does. Even the source code that is available is millions of lines that you couldn't inspect in all your lifetime. Online 24/7, with GPS tracking your every move and a microphone that listens to what you say. Every URL you visit is logged. Your photos uploaded to "the cloud" and used to train AI. The only solution is to no longer accept any of this, even if almost everyone else does. Even if it means giving up some convenience. Google has to be destroyed.
- kogasa240p 1y ago>Google Apple too, they're the ones who normalized smartphones.
- danaris 1y agoApple showed the world that a smartphone that was enjoyable to use was possible. I know it's hard to remember today, but in 2007, Apple was still the perennially-"beleaguered" underdog whose only big success story in marketshare terms was the iPod. If the public had not loved the iPhone, it never could have "normalized" anything. There are definitely aspects of the iPhone that it is fair to criticize Apple for. The rest of the world's wholesale embrace of its design—to the point of slavishly copying it, for several manufacturers at different points in time—can only be blamed on their lack of imagination and willingness to take risks, and on the public's unwillingness to give up the benefits of the iPhone just to get the much-less-obvious benefits of something more "open" or different.
- ozim 1y agoWas it prevent side loading fully or was it just publishing on Play store will require verification?
- progval 1y agoFrom the OP: "It affects independent developers, FOSS contributors, and even regular users who want to install apps outside of Google Play"
- 0xbadcafebee 1y agoI am actually super exited about Google's decision. I only used Android because it was the least-worst option. I always hated how restrictive its OS is, and the Play Store, the locking-down of tethering, etc. But I never had enough reason to try a totally open-source smartphone. Until now. I'm so excited that I might even jump back into open source development to make a new OS that isn't as bloated and slow as Android. There is a need for an OS that only gives you minimum capabilities, to run on cheaper, simpler, smaller devices. I would love to help make that a reality.
- dreamcompiler 1y agoMe too. The idea of not being forced to write apps in shitty languages like Java or shitty IDEs like Xcode makes me positively giddy.
- biggedyb 1y agoWell I signed the petition, not holding my breath. If anything this just gives me more reasons to seriously look at linux phone options.
- kogasa240p 1y agoThis whole debacle is going to make me buy a dumbphone, there is literally no reason to buy a modern smartphone if you can't sideload apps.
- Speedy218 1y agoLuckily you can't enshittify something that is already shit (not necessarily but you get what I mean) .
- SirMaster 1y agoDo you really have to give personal details, or can't it just be company details? What would a company fill in for these details for the developer deployment account they are using to deploy the apps made by their software team? Is the account that publishes Spotify or Facebook app etc really going to be personal information for some person? I highly doubt that.
- Speedy218 1y agoI think it can be company details if you're an actual company, but they'll probably still have you list some kind of primary point of contact (e.g. head developer or something).
- UnKnowNisDeaD 1y ago[dead]
- UnKnowNisDeaD 1y ago[dead]
- akashjangir 1y agoGoogle ki ma ki chut
- throaway920181 1y agoIt's frustrating and sad to see the road that Google is headed down with Android and Pixels. The recent AOSP changes were a big red flag, now this. I've had many Nexus and Pixel devices because I like the freedom that they offer me. I don't use Apple devices because they're so locked down and I can't use the hardware and software in ways that I'd like to use it. Google's about to be added to that shitlist, and there aren't really many alternatives.
- butz 1y agoBetter start a kickstarter or something to collect enough funds to build true open source mobile operating system. Someone will reply that's impossible, but I say it is just a matter of keeping scope small. Basic OS, few most important apps - phone, sms, maybe calendar or alarm, and let users build everything else themselves.
- DanOpcode 1y agoThe users are gonna build replacements for Uber, car parking apps, bank apps, etc?
- butz 1y ago"Your App Should Have Been A Website", and banks at least in EU are providing open banking API, so it should be doable. More incentive for everyone to build APIs again.
- beeflet 1y agopostmarketOS is already there. You need hardware support to make it happen
- bitwize 1y agoGoogle is realizing that Apple is right: Curated is better for end users. Android has had a far worse malware problem than iOS; from a security standpoint, authoritative allowlisting is the only thing proven to have significant mitigating effect against malware attacks. Nerds are getting big mad now that Google is demanding the slightest modicum of accountability from them -- nowhere near as comprehensive as the system that helped make the iPhone the premier pick of privacy-conscious folks. Professional developers stand behind their code with their real names. If you are unwilling to do that much, you should not be able to release software to billions of users on the Android platform. That phone is not a Commodore 64. It is people's link to financial, health, educational, and government services. Compromise can have severe consequences. Just as we lock down corporate PCs to avoid leaking corporate information, phones should be locked down to avoid leaking personal information.
- fc417fc802 1y agoAn utterly vacuous argument. Nothing is preventing Google from better curating the Play store, either with or without attestation of developer PII. The vast majority of malware is not coming from "sideloaded" apps. The vast majority of users are unwilling to install apps from the internet at large precisely because of the risks.
- aldousd666 1y agoGoogle probably feels they need to implement this restriction because too many people are installing apps that bypass their data collection tools and ad tech. Why they would take such a stance in the middle of an anti-trust litigation is beyond me. It makes them look even more like monopolists in light of Apple's recent App-store related foibles. (Aside, I don't personally feel that they are a monopoly, but you have to play the cards you are dealt.)
- jasonvorhe 1y agoPetitions to big corporations are a waste of time. You're just keeping change.org alive. Good luck regardless.
- dreamcompiler 1y agoThis whole episode sounds like a great opportunity for somebody to start a truly open source phone company. Smart phones have been around for over 15 years. Surely there's enough hardware expertise out there now for a startup to make a mass-market phone that runs Linux.
- DanOpcode 1y agoThere has been a dozen attempts already.
- deleted 1y ago[deleted]
- pollofire23 1y agoThis is exactly why I'm against Google's new sideloading restrictions: Broken promises: Android was supposed to be about open software and user choice False security narrative: They claim it's "for our safety" when it's clearly about control and revenue One-size-fits-all approach: Why force restrictions on users who understand the risks? Give us the option to enable sideloading with proper warnings. Don't treat informed users like children. If this goes through, rooting becomes the only way to maintain actual ownership of our devices.
- Speedy218 1y agoThe privacy and control implications this has is absolutely insane, they are control freaks just like almost every other big corporation. I'd fully argue that what they are doing to us is worse than the supposed stuff that happens to children that "Google" aims to protect them from. I'm sure our children would be thrilled to know that they are going to live a reality in the 1984 book where Google and major governments are big brothers. The "security" reasoning was just an afterthought in this so that they have a leg to stand on in court. ROOT YOUR ANDROIDS IF YOU STILL CAN!! Google is rapidly pressuring manufacturers to permanently lock bootloaders, I know all of this trips play integrity which means lots of apps stop working, but quite frankly it's a bad hand and it's all we've got.
- Self_Mad_Man 1y agoInstead of removing an entire feature that is a core part of your identity, is it really that hard to move it in the developer options, where the people who know what they are looking for will go to activate it??
- breezk0 1y agoI honestly don’t see a problem with that, why would you want to publish something anonymously to the App Store in the first place? Only scenario I can think of is something fishy. If it’s legitimate you don’t need to hide your identity imho.
- babban010 1y agoThe only reason one uses android is cos of the side loading feature. Google is digging its own grave. Don't try it.