37 ms·
MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past d
by Gareth321 19d ago
MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.
- deleted 19d ago[deleted]
- setgree 19d agoAnd what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously? I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
- post-it 19d agoHow would a reviewer catch that?
- Maskawanian 19d agoHow about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.
- pjmlp 19d agoMany of us have routinely cleaned computers from adults that installed several Ask Jeeves and Yahoo toolbars.
- compass_copium 19d agoAt some point computers need to stop being treated as magical boxes that no reasonable person can learn how to use safely. We expect people who use cars to learn how to use them safely, we expect people who use lawnmowers to not stick their fingers in them. Computers have been a part of daily life for normies for decades at this point, it's infantilizing to suggest that average, non-tech savvy people can't learn to use (not necessarily build, repair, etc.) them properly and need to be protected from them.
- pjmlp 19d agoPeople have to successfully get through a state exam in order to drive cars in first place, can be jailed, get fined when not driving them safely, or forbidden for life to ever drive again. People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company. What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
- voakbasda 19d agoDo you hate open source and want only projects where their authors can afford liability insurance and are willing to put themselves in the firing line of a legal system that can be both arbitrary and capricious? Because that’s what you seem to want.
- pjmlp 19d agoEven people selling on the street or doing charity work have to account for liability of their actions. Lets stop talking about open source as special snowflakes where everything is excused.
- gmueckl 19d agoRegulation is already addressing that. I encourage you to read up on the Cyber Resilience Act.
- lovasoa 19d agoWe could force Google to operate its app review service independently. Users could use it and pay for it, or alternatives. Currently Google forces everyone to use their own mediocre service and pay for it without knowing exactly where and how much you pay.
- yosef123 19d agoAnd what do windows / linux / macos do about apps getting hacked to billions of pc's simultaneously? How is that a new problem?
- Frieren 19d agoIf libraries didn't exist could not be created today. People tend to say that "it is impossible" when it actually only needs to be well organized. Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
- no-name-here 19d ago> macos MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc. > Windows I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
- oblio 18d ago> but I don't think there's much people would point to as a positive regarding Windows’ approach to app security. Yet life in Windows land is perfectly fine in 2026 and has been for at least 2 decades. If Windows, which started at the bottom of the barrel security wise can make it, surely we can have more modern OSes that make freedom bearable?
- pjc50 19d agoI wonder if people would be happy replacing the "Google approves developers" system with a "government requires your ID and address on file so you can be held liable for your apps" system. I suspect not.
- drdexebtjl 19d agoWhat for? Malicious actors have no shortage of stolen identities.
- Frieren 19d agoThat is already a requirement in any civilized country. You cannot run a business without a registered ID, address, etc. for tax purposes. For free (like for real no microtransactions) that is different. For the rest, they already have that.
- BiteCode_dev 19d agoIt's virtually the case, google and apple accounts require ID verification, which in turn can be requested by the gov in case of an investigation.
- zzril 19d agoIf you don't agree with a decision made by your government, you can vote for someone else next time. If you don't agree with a decision made by Google, what do you do?
- freedomben 19d agoThe people I vote for never win. Am I really any more empowered with the government than I am with Google? At least with Google I can de-google my life (with some significant losses of convenience, but it is doable)
- zzril 19d agoPersonally, I find it easier to live with a decision I don't support if I was simply out-numbered in a fair vote, rather than out-powered by some random company on some random continent. As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
- duskdozer 19d agoThat's a tangential issue. 1. don't force auto-updates 2. still review apps uploaded to Google Play, but don't force users to use Google Play If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play. But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
- MRtecno98 19d ago> If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play. So this doesn't solve the issue pointed in the OP. > don't force auto-updates I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
- Forgeties79 19d ago>So this doesn't solve the issue pointed in the OP. Yes it does. This is their point: > The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians. It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it. It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
- basilikum 19d agoPeople accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes. Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs. Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods. The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
- bluefirebrand 19d ago> People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
- basilikum 19d agoYes, hold people accountable for their actions. Don't take away their freedom. We may prohibit individual actions that involve a general tool when they harm others. That is compatible with a free society. We may not prohibit fundamental tools¹ That is fundamentally incompatible with a free society. Especially when that tool forms the infrastructure for the flow of information and free speech. [1] General purpose computing
- Buttons840 19d agoHow about the same thing we do when companies leak half-the-nation's personal data twice a month. Nothing. When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
- miroljub 19d ago> And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously? "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
- rock_artist 19d agoWe already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors. My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
- yacthing 19d agoDo people not remember the days of viruses destroying computers? They were a massive issue before, and now they're barely a thought for most people. These review processes have been good for the general population.
- bronson 19d agoWhat review processes on computers?
- pflenker 19d agoI didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access. Even though review processeses generally do not exist for computers, they are part of that same trend.
- nekooooo 19d agomac app store / windows app store
- dazgjkyfedbu 19d agoAnd outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.
- rpdillon 19d agoThe app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.
- charcircuit 19d agoJust because something is not perfect that does not mean it's worthless. Most things security things operate this way where it's impossible to stop all malware or attacks.
- rpdillon 19d agoWhen analyzing whether something is a net good for society, I look not only at the value it brings, but the cost that it brings. The mobile ecosystem normalizing the idea that the vendor that sold you your everyday computing device is the sole arbiter of what can run on that device is of enormous cost to society, but anytime anyone brings that up, there's an immediate retort bringing fear, uncertainty, and doubt about software obtained outside of those centralized silos. As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from. Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.
- fsflover 19d agohttps://news.ycombinator.com/item?id=49731273 https://news.ycombinator.com/item?id=49731273
- surajrmal 19d agoSecurity at its core comes down to trusting the supply chain that provides the software that runs on your hardware. There are many alternative secure supply chain models, but ultimately users often are incapable of making great choices on what is trustworthy. It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain. Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.
- LanceH 19d agoI'm not sure how much manual review in these stores is for security rather than content and enforcement of business rules. I imagine nearly all the security review is automated scans, and not the source of the delays.
- malwrar 19d agoHard to find better solutions when we have no agency to enact them. The “arrangement” was one-sided from the start.
- chii 19d ago> It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain. this position of privilege is what the OS vendor (google in this case) wants, because it spells profit. I dont trust it. The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.
- pjmlp 19d agoNintendo, Playstation, XBox,...
- drdexebtjl 19d ago… should also be open, but that’s irrelevant to the discussion.
- pjmlp 19d agoIt is quite relevant as computing systems. And yes, they also have apps besides games on their stores, and support external keyboards and mices.
- drdexebtjl 19d agoSorry, I think I misunderstood your argument as whataboutism.
- deleted 19d ago[deleted]
- ivl 19d agoYour complaint about Android .apk install is... similar to unsigned software installs on Windows in some cases (not a great argument, I know, but the same as the vast majority of users would be used to). As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.
- microtonal 19d agoFor the former there is: https://github.com/privacyguides/verified-apps-android https://github.com/privacyguides/verified-apps-android Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money: https://www.macrumors.com/2026/07/27/apple-app-store-fake-bitcoin-wallet-lawsuit/ https://www.macrumors.com/2026/07/27/apple-app-store-fake-bi...
- skobes 19d agoThe main difference is that signing a Windows binary doesn't require any third party review of the app content.
- lern_too_spel 19d agoSigning an APK also doesn't require third party review of the app content.
- skobes 19d agoBut the context of this discussion is the difficulty of installing an APK from outside the Play Store.
- lern_too_spel 19d agoThis is the first time I've seen a complaint about giving permission to an app to install another app. The SmartTubeNext issue was due to the developer's keys being stolen. If you want to keep an app signed with stolen keys, you can disable Play Protect. If Play Protect uninstalled apps that Google disliked instead of apps with known vulnerabilities, people would mass disable Play Protect, which would defeat its purpose.
- nchmy 19d ago[flagged]
- cyanydeez 19d agowe have an open web. no ones pays for it. Anyone can put up a PWA. The only org that hates this is Apple. The complaint is about a shared resource, which would require governments to adopt open source policies and _pay_ for it just like they do the post office. But ya'll hate government, so here we are.
- nchmy 19d agowhy invest in developing a PWA if a significant portion of (particularly wealthy) users cant use it?
- nozzlegear 19d agoHow are iOS users not able to use a PWA? Because it takes a few taps to add it to the homescreen? I have several PWAs on my iPhone and I can use them quite well.
- nchmy 19d agoit is significantly more complicated - especially for the average user - to install them than on other browsers. other browsers also let developers ask the browser to prompt the user to install the app. This is all documented in great detail in the links i shared
- ocdtrekkie 19d agoOpen Web Advocacy's goal is Chrome on all platforms, which just means the Play Store problem gets even worse. The moment OWA wins, the open web dies. These are people with a truly bad astroturfy goal, clothed in charitable nonprofit status. Paradoxically, as long as WebKit is mandatory on iOS, the open web is safe: Websites have to build for a lowest common denominator standard instead of building for Chrome proprietary APIs.
- ls-a 19d ago[dead]
- pavlov 19d ago> "Apple and Google are WELL past due for regulation in this space." There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere. The current US government won't do anything to follow suit, but hopefully a future one might.
- graemep 19d ago> There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores So does that mean: 1. People in the EU can continue to use F-Droid etc. exactly as they have in the past, permanently? No Google verification of developers needed? 2. People are free to install apps from any APK they choose?
- lern_too_spel 19d agoYes. Even beyond that, people outside the EU are free to install apps from any APK they choose.
- cute_boi 19d agoYea, but apple and google keep finding out loopholes and unfaithful compliance, it is time for EU to have some backbone.
- shevy-java 19d agoThe US government acts here in favour of a monopoly market. Trump violates free market principles; quite interesting how Trump works against core capitalistic means, in favour of personal corruption.
- sunaookami 19d agoThe EU is not interested in liberating phone operating systems because it goes against their digital wallet push which forces everyone to use an attested, Google/Apple sanctioned device and operating system.
- deleted 19d ago[deleted]
- howunfortunate 19d agoThe push to involve the legal system and the government is ironic. It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked. The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.
- toxik 19d agoHaha, oh the poor mega tech companies?! As if. Google sees a market, it wants to capture it. Same as Apple did.
- howunfortunate 18d agoYou're misreading me. Regulation helps boost Apple and Google at the expense of anyone trying to compete with them on app stores.
- viktorcode 19d agoThis case has nothing to do with "gatekeepers". It is about the Play Store, operated by Google.
- oblio 18d ago> This case has nothing to do with "gatekeepers". It is about the Play Store, operated by Google. To-may-to, to-mah-to. The AppStore is basically identical in most aspects people care about.
- killerstorm 19d agoBack in early 2000s, pretty much all Windows machines were infested with malware. Do you want to bring back those glorious days? Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.
- braiamp 19d agoPeople still can install/run whatever they like on their PCs, so why further restrictions needed or am I missing something? Also, further restrictions doesn't seem to work on the mobile/TV market where actual malware still infects iOS/Android/TV devices despite all the "hops" that it has too go through. Code signing with warnings about non-signed apps is enough
- killerstorm 19d agoHmm? Malware on iOS is extremely rare. I remember in Bitcoin community ~10 years ago, standard recommendation was than an iOS wallet was secure enough (I don't recall even a single case where wallet was stolen via malware), but any private keys on Windows were strongly discouraged, as most cases of stolen wallets were on Windows. I'd say popularity of iPhone shows which way people prefer, but you do you - what prevents you from voting with your wallet and buying a Linux phone?..
- mrguyorama 19d agoThe reason that modern computers are no longer filled with malware has nothing to do with completely irrelevant locked garden app stores on phones. The reason is because Bill Gates put out a memo because it was fucking embarrassing that you could trivially smash the stack on default open API endpoints for services that consumers never used and shouldn't have been trivially routable from the open web in the first place. Meanwhile in app stores, you don't have to hack anything, because consumers just download your botnet software willingly and directly. 42% of all apps on LG smart TVs turned your TV into a "residential proxy" botnet participant. 30% on Samsung TVs. There is no "hacking" in the world of apps because it's completely normalized for whatever app you build to also for some reason include remote control functionality from like 6 different companies. All of those apps pass review no problem.
- fsflover 19d ago> operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all This is exactly why I use a GNU/Linux phone that runs a desktop operating system with no artificial restrictions. Debian repositories are good enough to save me from malware, aren't they?
- AdityaK_9999 19d agoI am on an Android 10 system... gate keeping wasn't this bad during the Android 10 times...so i fairly use software stores like f-droid... simpmusic is one app I use frequently from f droid....no application so far has been deleted automatically. I guess Google has been upping the gatekeeping with newer systems as they come out
- dwaite 19d agoA weather app could be asking for your location to give you more convenient local forecasts. It could also be asking for it to help advertisers build a robust behavioral profile about you. This is not a systems permission, nor is it something that billions of users can judge the ramifications of each potential privacy impacting decision. Privacy is a systems property, not a technical property enforced with ACLs. ACLs can only keep the door from being wide open, they can't prevent access which has been granted from being abused or help the user understand ramifications of granting access. We need privacy to be a regulatory concern with actual enforcement via an international framework. Until then, it is a business concern of Apple/Google - because they are in the business of having consumers feel confident that a weather app isn't reporting their behavior to anyone willing to pay for it.