HN user

plst

74 karma
Posts0
Comments40
View on HN
No posts found.

Another problem, AI allows many people to submit PRs that may look viable with very low effort. So you get a lot more code to review, often submitted by people who are not actually familiar with the codebase. So they may not even be able to make requested changes to their patches. Combine that with AI's verbosity. The maintainers drown in noise.

You mention nuance and good faith, but on your profile, and on your website, you claim to work on Android at Google. Previously on Google Play. I don't see that mentioned in your comments about this issue, I do think it matters a lot.

This side however seems to stick its head in the sand over security, "I wouldn't fall for it therefore it's not a problem"

Which is also a total misrepresentation of the arguments made on the website, and made by many people opposing these changes. Again, since you mention good faith and nuance.

By all means push back on security being a concern,

The website does not seem to push back on security being a concern in general, if I'm reading it right. It does however push back on the idea that changes made by Google will actually increase security of the users.

but the numbers don't support this.

Can I see these numbers? I would seriously love to.

I don't really understand your argument here, isn't Google's announcement also entirely one sided? I also don't see any "discussion" of disadvantages of their solution in their announcements. For example, the "over 50 times more malware" stat is stated without any source at all, same with "Most of your users’ download experience will not change at all" (inb4 I don't care about power users at all). Not to mention stats about scam-by-sideloaded app, anything that would suggest that the proposed solution is going to work.

The point of "keepandroidopen.org", in my understanding, is to be a quick PSA on why the author of the website thinks this is a problem with some call-to-action. It's not supposed to be a place for discussion, it's at best a discussion starter, one of the sides of the discussion to consider. Obviously they present their side, as Google has presented their side.

And anyway, how are users supposed to hold this "reasonable discussion" with a corporation? I know that Google had some sort a feedback form about this, and that they made some changes, but that is not a discussion. I didn't really actually see any "reasonable discussion" being held on this topic ever, anywhere, ever, nor do I really see how it would happen. I don't even really see a good reason for Google to hold such a discussion. It's a decision made by a corporation, about their product, after all.

Could you present your how you see this "reasonable discussion" being had? Where? How?

They then end up paying more by buying five awful low-range phones that each last a year instead of one mid-range that will last more. No, I would rather everyone paid more for a phone. I find it hard to believe that the difference in price will make it impossible for them to buy it, if so, that's a separate problem. This + mandated software support may finally make it viable to just buy a used phone, too.

Yet somehow they are not too dumb to get a driving license or operate a gas stove. I would argue that operating a car is much more complicated than operating a smartphone.

At some point, if you are unwilling to learn basic facts about your environment, and you don't have a guardian, then you will get hurt. I don't necessarily mean by a computer. I think that's fine and I don't think a patronizing solution by a corporation that clearly wants more control over society is a necessary help.

I think Google is trying to solve the problem at the wrong level - people do not really understand their computing devices enough to understand the risks, they never had to learn or were taught how to use such devices, they were only told it's easy and to not ask questions. The interfaces are designed in a way that allows them to get by with almost no understanding of anything. Which is why such solutions may also be bypassed by a determined attacker. Such scams only really expose this fact. So there is no good way to differentiate between the two groups.

My solution is educating about smartphones and computers first. Not in an in-depth way, but people need to understand what "application", "verified" means and what are the risks. I think android cleaned up the abstraction enough to make this possible.

Being able to tell if an app came from a trusted company or not is a good thing, but I would rather such a solution be managed in an OS-independent way, not controlled by Google. Applications not authenticated by a company should not be second-tier citizens, but there should be a clear warning (and the users should already know the difference before even seeing this warning).

I think the scams and phishing also expose another important problem that nobody tried to tackle yet - you can't authenticate calls, sms messages or emails. There is no good way of telling if it's actually your bank calling you, or if it's just a scammer.

In the end, we also need to accept that not all scams can be prevented, at some point if someone is calling as a friend of your family member, and is asking to urgently transfer money to an unknown account, and you fall for this... I really can't think of a technological measure that would've helped, it's only you and your common sense.

Why the snark? Did I misread? I don't often buy a new car, do you? I really don't understand what your last sentence means.

I don't even think this a fair comparison, it's more like keeping the old car just in case or for other family members. But I think I specified enough what I'm arguing already, yes this is unlikely, just not impossible.

How many people are gullible enough right now to plug a phone to a laptop over USB and execute an exe on an operating system with no sandboxing at all? ADB even seems to work over webusb. (at that point you may as well give up on hacking the phone, but I digress). That's exactly why I believe the problem is more complicated and why Google's solution is not really fixing anything, not for the users.

What do you mean by impossible in this case? Can't you just have the coin-operated parking meters back? Where I live, in EU, parking meters even take cards.

EDIT: I guess "just" is doing some heavy-lifting, so I won't argue this further, but "impossible" isn't the word I would use either. The city could revert this decision, definitely if enough people wanted them to (that's... I know, the hardest part). I just agree with the OP that we technically could go back to slightly less-digital society.

because you are annoyed about some temporary problems

I mean, all problems are temporary, time is money etc. etc. And there are signs that suggest that some of these problems (namely freedom to run your own software) are not going to get resolved soon. Is there something deeper in your thought that I missed?

These kind of posts get a lot of upvotes, but they do nothing to change corporate behavior.

I don't understand, we are on a discussion forum. Of course writing comments here does not influence what Apple does, that's not what HN is for, I think (I hope) that everyone already assumes that. Why do you feel the need to point that out?

I'm arguing that a curation process that includes security review is likely to produce a more secure set of software

I actually totally agree! There is no external entity users can rely on to make sure apps they download are legitimate. I read the thread from root to this comment and I don't see it mentioned, so I'm not sure if you know this and are just arguing something else but...

There is actually nothing about testing or verifying apps themselves in the announcement made by Google. It's just about enforcing developer verification in some Google service and "registering the apps".

https://support.google.com/android-developer-console/answer/... https://android-developers.googleblog.com/2025/11/android-de...

EDIT: I checked your profile, and I now see that you actually work at Google, on Android... Is there something I misunderstood about these announcements?

you could argue it's a false sense of security, but it's still more security

Well here I don't agree, I would much rather be aware of the dangers than think I'm safe when I'm actually not.

but that's what we have now, and it's not working.

My entire point is that education is the opposite of what we have now. That users are not expected to understand or know anything about IT technologies they use. Not the case with cars, recreational and prescription drugs...

the implied question is: what if we don't allow people to use technology unless they can demonstrate that they understand it?

It's not exactly my point, but in extreme cases, maybe. I genuinely think that nobody has even tried to educate people about computers. Like, have you seen IT classes in schools? Assuming you are lucky enough for the classes to have any content, you will probably get some lessons in Word and Excel. Maybe some programming. Maybe Paint. But actually using the computer? Dangers of the internet, importance of backups, trusting websites, applications and emails? The concept of application and difference between applications and websites? And those technologies are not "developing" like they were 20 years ago, they are probably here to stay.

is that really something we want to do? this sounds like gatekeeping, elitism, and anti-innovation because if if less people are going to use a technology, then there is less motivation to build it.

And the alternative Google and Apple present is giving them paternalizing control over the most popular computing device. The say over what people can do with their devices. After they made sure that these devices are embedded into our lives. I would much rather we slowed down with innovation for a second and resolved such issues first, because the way I see it, it's literally manipulation (also see: dark patterns).

As for the gatekeeping and etilism - Assuming we want a "computing license" (not necessarily what I'm arguing for), is "driving license" also gatekeeping and etilism? Or maybe some amount of gatekeeping is good?

As for anti-innovation - I genuinely think we might have had just enough innovation in the field and it may be time to slow down a little, take a step back and evaluate the results. And I honestly don't see much innovation in apps/computers/web space besides maybe AI, and governments are already working on regulating that.

do you think that would have happened if we had required understanding before we let anyone buy a home computer?

Home computers were very harmless before the internet, but that's an aside. Assuming the tech is actually useful, not just slightly more convenient than "traditional" alternatives, then yes, I'm sure it would have still grown to sizes it has grown to today. Maybe a bit slower.

besides education, i don't know how to approach this issue.

Same, I generally do think this whole situation needs more consideration.

how is a UI designed that doesn't fuel incompetence?

I'm specifically talking about UX ("how a user interacts with and experiences a product, system, or service"), not necessarily UI.

how does it do that? (i am not getting hung up on "intuitive", i just mean you argue that the currently used design fuels incompetence)

tl;dr We have a product, we want to make money, we need people to use the product. One of the things that stand in the way, is people not understanding how to use our product. We will make sure they can get started as fast as possible, and not mention how they may hurt themselves with the product, that would scare them away. Hurting yourself with our product is in the broad "don't do stupid things" category. We will never explain the "framework" (in case of an OS I mean apps, that apps can interact with each other and your data, how you can or cannot, control that), even in broad terms. Just click this button and get your solution.

It started with PCs and people not understanding how to not lose their documents. Now that every device is connected to the internet, the problem became worse.

You can now say that "sideloading" is stupid anyway, but this is not the only problem. Another thing that people still usually learn by painful experience is backups. There are fake apps, on both stores. Another thing, in-band signaling. You cannot trust email, phones, whatsapp, messenger... Even if your friend you often chat with is messaging you, they could've just been hacked. Try to explain that you also cannot trust websites and that even technical people don't have a good way of telling if an email of a website is real.

But at least enrollment is fast and adoption metrics are growing. Since we are already in "move fast and break things" mindset, we will think about fixing such issues when it actually becomes a problem.

To be clear, I'm not saying that making technology easy is always bad, that you should always expose the user to "the elements" and expect them pipe commands in the shell. But I think that often the focus is on only making enrollment fast. "Get started"

What if we actually expected people to understand something about technologies they want to use?

To add to that, I think it's important to point out that the problem of people not understanding how to safely use their devices is in big part caused by technology companies racing to get widest adoption everywhere, both in terms of location and in terms of industries. I'm not against "intuitive UX design" in general, but at it's extreme, it just fuels incompetence. We shouldn't now let them pick the most convenient option, the option that just happens to also increase their powers over the users, as a way to "fix" the problem.

Assuming the owner gave the shop the pin. If so, the shop can already steal a lot of data from the phone. Why bother with persistent malware at this point?

You already have to trust the repair shop with your data. Installing persistent malware on phones is already illegal. What's the point of this extra software protection in this case? To prevent a 0.00001% chance hack? The type of hack that would put the repair men in jail?

Not to even mention that modern phones are basically unfixable.

I don't find the laws unjust in any way. Apple did everything they could to take half of the smartphone market, and to me it's totally understandable that the EU government may want to limit their power over this market.

in this case, it really seems to me like the EU is harming consumers who benefit from the coherently-designed, safe (as compared to androland) walled garden in favor of some fairly overtly xenophobic power play against incumbents local champions cannot compete with on the merits. IMO this type of action directly invites retaliation against European companies and interests abroad.

Apple consumers will still be able to benefit from this amazing walled garden by choosing not to buy non-Apple devices. Other consumers will be able to choose other vendors that will be able to fully interoperate with Apple devices. I don't see any loses for current Apple consumers.

As for the retaliation. Maybe. Remains to be seen. Introducing any regulations brings risk.

in the related cases of airdrop interop and alternate stores, it is certainly being required that apple release its proprietary IP to competitors

What proprietary IPs?

there are plenty of hungry competitors in the smartphone market beyond apple and google including Samsung huawei and scores of others.

In terms of operating systems you have these two. I don't think Huawei counts, aren't they sanctioned still? Harmony OS has a very small share in EU either way.

Their rights to license stuff they sell should not be unlimited, that's the entire point.

I understand that your second sentence refers to the fact, that the limitation is only in EU. Businesses have to respect local laws. Laws often mentioned in the thread (DMA, GDPR, although we can only suspect that these are the reasons for this lock) apply equally to everyone who wants to do business in Europe. If Apple does not want to respect these laws, they are free to leave. Even better, they can make changes to their devices that work only in EU and leave it as it already is in other countries. Said "competitors" do not necessarily need to be EU citizens, I'm sure many US companies would use that opportunity too.

Local regulations are not foreign to Apple, apparently similar laws are in force in Japan.

As for "some chunks" - interfaces are not protected by copyright, even in the US. Assuming DMA is the problem, nobody is asking for Apple to release details of their implementation, just for them to remove artificial software restrictions that lock apps from other vendors from doing (a small subset!) of stuff only Apple can do.

Smartphones are general computing devices. Apple and Google are a duopoly in the smartphone market, while restricting what users can do with their devices more than Microsoft ever restricted what Windows users can do with Windows. If we continue allowing these companies to go in that direction, we will end up with computers that are as limited as game consoles are, Apple and Google will be the only beneficiaries of that situation.

I replied to someone else in the same vein but having had a garmin watch in the home there was nothing that it would have done better if it was able to work with Apple's proprietary stuff

Maybe to you. Garmin watches cannot respond to notifications on Apple devices, for example. Detailed article about restrictions on iOS from Pebble: https://ericmigi.com/blog/apple-restricts-pebble-from-being-...

If random devices of unknown provenance were able to freely connect with Apple devices then the security of Apple's ecosystem would take a hit. This would be bad.

Random devices are not able to connect over bluetooth to your device without your consent. Then, the bluetooth device can only get as much information as the companion app will allow it to get.

Besides, we have that on Android (and PCs) and the security of these "ecosystems" is not worse because of it.

Can't reference a leak or incident specifically, but when Foxconn (a massive company with 3/4 million employees) had workers jumping from their dormitories and installed "suicide nets" the headlines were always "Apple factory..." - and I checked multiple sites at the time. Even though quite literally every single piece of major western technology is assembled in Foxconn factories.

Apple chose Foxconn. It won't get to choose the third parties implementing alternative translation apps. That's the point.

I see that I wasn't specific, but I thought it's obvious given the context.

And about 3rd party translation AI systems. Of course _I_ won't install suspicious ones, but how do you make sure Auntie Liz won't?

I think you are switching topics from allowing other vendors to use Apple-only APIs to "sideloading".

Educate her. (yes, that's not Apple's responsibility, and they don't even try. We need people to understand what applications can do when installed on a smartphone or a computer. It's a national education issue IMO). If she can't take care of herself anymore - parental controls.

I see the point in having some entity verify legitimacy of applications, but it does not need to be only Apple/Google, like with TLS.

So basically all the stuff that makes apple devices actually measurably better has to be opened up so that some rando can make a half hacked together attempt at compatibility?

Only the interfaces and protocols. This is not the interesting or expensive part, unlike the implementation. Apple can still have the best implementation of the protocol, and a lot of people will believe that this is the case.

For what?

So that people are not locked into the ecosystem when they buy the device. The price for the phone is what they pay, not what they will be forced to pay later, for example by only being able to choose airpods or apple watch for full experience later. For example.

I don't want random bluetooth earbuds from the petrol station to be able to access an API that lets them send transcripts of my calls anywhere they like

First, don't buy them, you don't have to. Second, technically, the API exposed by the device will first need to allow them to connect somewhere online and send any data. That's a separate issue. Not to mention that, hypothetically, if bluetooth airbuds were able to send data somewhere by themselves, a malicious airbud manufacturer could still use the protocols by reverse engineering them. Not necessarily the case with legit manufacturers. Such lockin only stops legitimate, non-malicious actors.

and I definitely don't want a low barrier to entry for devices that can airdrop me stuff or paste to my macbook if I'm out and about.

Allowing everyone and anyone to airdrop you stuff is a bad idea anyway. The protocol was reverse engineered too.

I'd be happy because I have never once bought a non-apple device that I care about connecting to my phone. I'd have to buy a new monitor but that's ok.

And a lot of other Apple users wouldn't be happy.

All consumer tech right now is literally rebadges or mild modificatioins of stuff from AliExpress and I don't want that in my nice clean ecosystem.

A lot is not. Again, just don't buy it, you have to choose to let such devices to connect to your device.

If these competitors want to actually compete then how about they make something that's actually better in some way instead of just hamfistedly copying whatever Apple comes up with?

A lot of the time they legitimately want to, but Apple locks them out of certain features. For example, AFAIK, Garmin watches (legitimate company! with an original take on a smartwatch, definitely not copying Apple) are locked from accessing certain iOS features Apple Watch can access.

EU has defined Apple (but not Google(!)) as a "digital gatekeeper"

Could you explain what you mean? The following article lists Alphabet as a gatekeeper.

https://digital-markets-act.ec.europa.eu/gatekeepers_en

So if they bring this system in, something which is listening to people real time and using online AI models to translate things, EU might force them to let _any_ 3rd party AI replace it.

If you allow the third party to do that, yes.

And when someone installs TotallyHonest Co. AI to replace it and there's a massive data leak where they just stored every conversation as-is in an open S3 bucket, who gets the PR flak on HN?

I see this argument often, as often as I hear about leaks. Do you have an instance where Apple was blamed for a leak from a third party? I never heard anybody blaming Apple for Tea app leaks for a recent example, and it is still available on App Store.

Also, an alternative translation app does not have to be provided by a totally random third party vendor. Companies that to me are just as trustworthy as Apple surely will provide alternatives too - Google, OpenAI, Meta, Microsoft or Anthropic.

So I really don't see what's your point here. Don't install the alternatives if you don't trust them.

And it really shouldn't be this way. Everyone is tricked into believing that they own devices they bought. And we are somehow supposed to accept that the abilities of the device can be reduced after we bought it just because the vendor said so. Same with (lack of) right to repair. It's really not ok, nobody (especially here) should accept that.

Can someone who actually understands the topic explain to me (or link good resources) why/if what they do is useful to anyone? Or are they literally just in the business of making money? (anyone except themselves of course. I'm serious, any hints of irony are unintended)