4 ms·
None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale o
by Taterr 6mo ago
None of the comments here seem to discuss or even mention how this situation looks from googles perspective? I feel like HN readers are not aware of the scale of the problem they face or their motivation behind these changes.
If you look at the rate of growth of the call/text scam industry I think it's entirely possible that android owners are getting scammed out of more money than google themselves makes on the android platform as a whole. It's at least not that far off. Which doesn't even account for the humanitarian issues which they probably feel partially responsible for.
- schubidubiduba 6mo agoWhy does nobody ever think of the poor megacorporation? I mean maybe you're even right and they care a little bit about people being scammed. But if you believe that the scamming thing is any more than a pretense for further establishing Google's absolute control over the Android ecosystem, that is just very naive. Their goal is to make money. Apps installed outside of Google mean less money for them. Ergo, consumer's right to install what they want on their devices must go.
- Taterr 6mo agoI understand usually the megacorporation is simply being anti-consumer with these kinds of changes, and who knows maybe this is the same. But I think this might be an actual exception. They seem to be actually implementing a lot of high effort scam protection features recently in android so unless they did all of that just as an excuse to make side loading harder then they've fooled me. https://security.googleblog.com/2026/02/strengthening-android-lead-in-scam-protection.html https://security.googleblog.com/2026/02/strengthening-androi... https://blog.google/innovation-and-ai/technology/safety-security/how-were-using-ai-to-combat-the-latest-scams/ https://blog.google/innovation-and-ai/technology/safety-secu... For more context, the the "reason" they're increasing the friction in sideloading is to prevent one extremely specific scam where someone instructs you over the phone to download a malicious android app, which then steals your banks 2 factor verification code from your notifications and sends it to the scammers. The 24 hour limitation does seem specifically designed to prevent that so I'm inclined to believe them.
- procaryote 6mo agoIt's pretty easy to make up a reasonable sounding excuse for something you do for your own profit as a company. If they don't even provide any statistic on how frequent these scams are, it can be just words Also, if your bank 2fa code is in your notifications, you should switch 2fa methods to something other than sms, or switch banks.
- Taterr 6mo agoSo we should just accept that all apps must treat android notifications as a compromised communication channel? The scammers will find some other way to abuse the very generous permissions allowed by an android app if you prevent the notification attack.
- MarsIronPI 6mo ago> So we should just accept that all apps must treat android notifications as a compromised communication channel? Look, that's an OS issue, not an app distribution issue. If I could use the trusted, vetted software from F-Droid I wouldn't need to worry about this sort of attack.
- sunaookami 6mo agoDo you also believe mass surveillance is necessary to protect children?
- eloox 6mo agoThat may be, but I think you are missing the point of the outrage: this solution is not good.
- izacus 6mo agoSo let's discuss a good solution instead of this boring repetitive outrage.
- TuringTest 6mo agoThe problem with that thought is that Goole isn't creating a good solution, it's creating this specific one.
- vanviegen 6mo agoLook at the attack vectors that are actually being used, and address them specifically, with minimally invasive measures. If the problem is apps that allow remote control of your device, that people can be socially engineered into installing, put up barriers to gaining just that permissions. That approach would actually help motivate the problem (as scammers can now just use Google-approved apps for such things). If the problem is ads that are pushing scams, Google could start with eradicating them from their own network. They seem to be the primary source. And, god forbid, perhaps even offer an ad blocker integrated in Android. (Yeah, I know.) If the problem is scammers pretending to be a friend or family member in need of help though social apps, Google could force these apps to help users identify these cases (using local privacy friendly heuristics is course) for inclusion in the Play Store. And no, they wouldn't be able to demand the same from apps installed from elsewhere, but that should be firmly outside of their sphere of responsibility. And casual users would be extremely like to stick with the default app store anyhow. Note that all three of these proposals provide a measure of safety from the problems they are addressing much larger than what Google is attempting by banning all non-Google-authorized applications.
- Taterr 6mo agoI am quite genuinely curious what you think the best solution to prevent someone instructing a tech illiterate person over the phone to click through every permission warning about a malicious app they're installing is? No amount of scary menus will work. I feel like they only have 2 options, which is to limit some permissions without any exceptions (making their platform more closed), or make it harder to install apps as a whole. Do you have a better idea?
- xigoi 6mo agoGoogle’s perspective is that they don’t want people to install NewPipe so that the CEO can buy more yachts.
- ChocolateGod 6mo agoI would bet the amount of people getting scammed is probably higher than those installing NewPipe.
- xigoi 6mo agoThe difference is that Google doesn’t mind scam apps being on the Play Store.
- lucb1e 6mo agoBecause we hear so many stories where the scammer directed their target to install an app so that their scam works I know a lot more people that install newpipe than people that got scammed by any means, and have never heard of anyone being asked to install an app by a scammer
- tosti 6mo agoBut I was scammed by newpipe! It said I can watch YouTube, but there aren't any ads! Now I don't know what to buy. It even had CCC Media, so now my videos are informative and insightful. Where's my influencers?!
- goku12 6mo agoTheir solution to every problem is to take away more control of the smartphones each time from the users who own them. Meanwhile, I have much less problems with scam and security issues and more freedom with software off FDroid. Makes you wonder if the actual problem is perhaps the one coming up with these solutions and their malevolent intentions behind a thin veil of laughable PR. Besides, I don't get people's habit of justifying trillion dollar corporations that can't seem to come up with any non-dystopian solutions.
- realusername 6mo agoGoogle's perspective is that they want full control on Android. If they really care about scams, the first result when I search for chatgpt is a fake app with a fake logo. Maybe they should start by tackling the scams on the play store as the play store is the far west.
- fredgrott 6mo agomy bias former android and java dev.... Google choose an OS using a VM by design is insecure by default.... ITS NOT US USERS FAULT!
- rpdillon 6mo agoI don't find the assertion credible that people are getting scammed out of more money than the entire platform is worth. But given that Google does not make the revenue for Android public, what kind of numbers do you think you're talking about here? Also, I think it's disingenuous to say that scams are predominantly powered by sideloading. I think the vast majority of the scams that are perpetrated use apps directly from the Play Store.
- Taterr 6mo agoGoogles total revenue in 2025 was about $400 billion across their entire company. It's hard to estimate how much money scammers steal in general but if you take an estimate[1] that each of the 300,000 forced laborers generates $300-400/day then you end up at a figure of 40 billion in scams, and considering android has most of the market in the regions the scammers target you can be pretty sure those are android owners being scammed through android devices. They're also growing rapidly, so those numbers might already be double in 2026 1. https://www.theguardian.com/technology/2025/dec/02/scam-state-multi-billion-dollar-industry-south-east-asia https://www.theguardian.com/technology/2025/dec/02/scam-stat...
- rpdillon 6mo agoThese numbers aren't credible. Total credit card fraud globally is projected to reach $43 billion in 2026. You're arguing that fraud on Android alone is equivalent to that. Doesn't smell right.
- Taterr 6mo agoThey've been claiming since 2023 that sideloading has been a favored attack vector. "The Global Scam Report also found that scams were most often initiated by sending scam links via various messaging platforms to get users to install malicious apps and very often paired with a phone call posing to be from a valid entity." https://security.googleblog.com/2023/10/enhanced-google-play-protect-real-time.html https://security.googleblog.com/2023/10/enhanced-google-play... https://security.googleblog.com/2024/02/piloting-new-ways-to-protect-Android-users-from%20financial-fraud.html https://security.googleblog.com/2024/02/piloting-new-ways-to... https://blog.google/intl/en-in/products/launching-enhanced-fraud-protection-pilot-in-india/ https://blog.google/intl/en-in/products/launching-enhanced-f...