Rendered at 20:14:49 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
greysonp 7 hours ago [-]
With Signal, the biggest issue we have is that review times are extremely inconsistent. Sometimes it's 4 hours, sometimes it's 5 days, and there's no visibility as to why. Our working theory is that there's automated and manual queues, and occasionally, for whatever reason, we fall into the manual queue. But when you work on an app that has weekly updates, randomly getting hit with a review time of several days really throws off your groove. And it can obviously be terrible for moments where you're fixing a critical issue.
elijahciali 6 hours ago [-]
I can imagine Apple probably has an automated review of a diff, and probably makes a manual review anytime a system API call changes
LilBytes 7 hours ago [-]
Thank you for Signal <3
joshuakcockrell 3 hours ago [-]
I agree with this. I had a production Play Store submission approved within 4 hours last week. It feels so random.
busymom0 6 hours ago [-]
Has it ever happened where your submission goes to review and then just sits in the "In Review" state for many days? I am talking 4-5 days? or sometimes longer than a week? And then it gets approved?
That's been happening randomly to me.
davidmurdoch 7 hours ago [-]
I'm partly to blame. I accidentally ran an illegal unregulated money transference service over Google Play.
It let users cash out their Google Play Credits for real cash, which I automatically wired them.
Someone then hacked in to a major bookstore chain, stole piles of Google Play Gift cards, activated them using their access, and used my app to get cash for them.
Luckily, the whole thing blew up on me before I got in serious trouble, rightfully so, and the app was removed by Google, then an investigation followed. A ton of copycat apps popped up immediately after, then a few months months later Google announced their app review process.
DrammBA 6 hours ago [-]
I love how casually you're dropping this incredible piece of internet lore as if somebody asked you how's the weather.
davidmurdoch 6 hours ago [-]
Haha. I used to have some blog posts detailing things a bit more, but I let it die when Heroku cancelled their original free tier years ago.
eks391 4 hours ago [-]
A domain is only ~$12/year if you don't buy it through a scammy site like godaddy that adds fake fees or quadruples the cost after a year. WordPress is easy for blogs, or you can just vibe code something in an afternoon if you don't care to have comments. Even embedding forms or an emailing tool can be done statically. Heck, there's probably a free option out there for simple posting that I don't know about.
When you "spend" Google Play Credits in an app, Google Play treats those credits the same as if you paid with real money: they took 30% (their take isn't so steep today), I took 10%, and then I sent the user/buyer the remaining 60% directly from my bank account (I used Dwolla back then).
It was risky because I didn't actually receive any money from Google until about a month later.
skeptic_ai 2 hours ago [-]
What you did was money laundering. And big chance for getting in trouble if let’s say ton of credits come from fraud/stolen and then google pays out to you and then crawl back once they realize is fraud.
I’m curious how you didn’t get into money laundering problems.
davidmurdoch 2 hours ago [-]
Technically it was an unregulated money transference service without KYC. The user that stole the cards from the bookstore was the one doing the money laundering part. I just enabled it (which is probably worse, legally).
I was investigated and cooperated fully.
Edit: I just remembered, the bank I used for the transference did do KYC for all users who were sent funds. This makes it more like "money dirtying", since the account is tied directly to a real identity.
nemomarx 2 hours ago [-]
> It let users cash out their Google Play Credits for real cash, which I automatically wired them.
I really want to know what the intended design or use case was for this? This is why people usually only let you turn credits into in app balances right
IshKebab 3 hours ago [-]
How did you "accidentally" do something that was so obviously not allowed?
davidmurdoch 2 hours ago [-]
I didn't know what a "money transference service" was, and certainly didn't know this service that I didn't know about was highly regulated.
I only created it because I had Google Play Credits that were gifted to me. I built an app to "convert" them to cash for myself. I had never built an app before. I was proud of it and tried to make it pretty and professional and useful for others, and used it as a learning experience. The listing on the Play Store was clear about what it was.
I had to answer questions about what the API was being used for when I signed up for Dwolla (an actual regulated money transference service). I answered honestly. They approved it.
The app sat unused with no downloads for years before someone on Reddit's `r/churning/` posted about it.
IshKebab 2 hours ago [-]
Right but... You've used gift cards before right? The whole point is that you can't convert them to cash. Not only that but Google/Apple gift cards are notorious for being used in fraud.
I guess if you're young...
davidmurdoch 1 hours ago [-]
Sure.
I created it back in 2011 or 2012.
It wasn't a gift card that personally motivated me to make this. It was credits from an online referral program I was gifted. I guarantee I did not read the fine print at that time.
MichaelZuo 1 hours ago [-]
Most people dont read the fine print on the back of gift cards. So I can easily see someone never running into a situation where it’s actually explained that is not allowed face to face.
leetrout 2 hours ago [-]
He accidentally got caught.
kulahan 1 hours ago [-]
I’ll never understand people so desperate to find villains in the world.
davidmurdoch 2 hours ago [-]
I responded to others with more details if you're interested
abricq 7 hours ago [-]
By the way, the same is happening for the Apple Store.
In the last month, I had to go through the review process twice, and twice I needed to contact them personally after waiting for 1 week of waiting. It did however helped, after every human contact I was reviewed within a few hours.
I got this explanation from them...
> We are currently experiencing a higher-than-normal amount of inquiries and have been unable to respond in the time frame that we would prefer. During these periods of high volume, the app review time will take longer than average, and we cannot currently provide a concrete timeline for when your specific app(s) will be finished with the process
I'm guessing, AI slots invading the store.
JamesSwift 21 minutes ago [-]
> I'm guessing, AI slots invading the store.
Well, same as my lack of sympathy for github and their "inability" to deal with "unprecedented AI generated traffic", I dont buy it. Seems really simple to setup an algorithm of "existing app from pre-AI is submitting another update gets put in the priority queue while everyone else gets the shared queue".
hbn 6 hours ago [-]
I'm sure submissions have absolutely skyrocketed with model advancements since the beginning of the year. I'd be curious to see the numbers.
I know Github's commit numbers have been pretty staggering YoY.
trymas 1 hours ago [-]
Yup, my bets are on this. It’s not only github that gets ~order of magnitude more PRs and commits, but probably app stores too.
Wonder how it will change app stores for the future.
techterrier 6 hours ago [-]
theres's hordes of sloppycats in every vertical. Check out how many birding apps have come out in the last 12 months for example
chrisandchris 39 minutes ago [-]
Or just developer/mansgement slop? I don't understand why every app needs to be updated every second day (at least it feels like that).
The easiest way to count how many apps you have is to turn off automated updates and wait a week. The number of updates equals the number of apps.
SkiFire13 2 hours ago [-]
> usually within 24 hours
I have never seen Apple approving within 24 hours
busymom0 7 hours ago [-]
I've had same experience. Brand new iOS apps are taking weeks. My latest all took 3 weeks to get reviewed and approved. Updates to existing apps are fast though (1-2 days).
Also, sometimes, apps will go in review and then just stay in that state for 3-4 days before approval. No idea why.
This is the reason I never made a mobile version and all mobile users use it in a browser.
The biggest problem (bug) with this approach is that iOS limits the RAM usage to 2 GB per website. I have to tell many of my users to ditch their $1000 iPads and get a used $150 Macbook for better experience.
If you are the photopea developer, you are a true hero. Thank you for your work!
IvanK_net 3 hours ago [-]
Thank you! :)
egeozcan 3 hours ago [-]
I created a much more basic version of photopea (https://egeozcan.github.io/ketchup/) because I didn't even know it existed. This is very cool and fast!
IvanK_net 27 minutes ago [-]
Nice! :)
david_allison 8 hours ago [-]
AnkiDroid (~17 years old) submitted our latest alpha on Sept 03, 2026, 4:40 am. Still pending review.
ryantgtg 3 hours ago [-]
We have about a 16 year old app, and our Google Play app review consistently takes between 30 minutes to 1 hour.
Apple consistently takes about 36 hours for us.
RugnirViking 8 hours ago [-]
thanks for your app! using it for learning danish and finding it very useful.
david_allison 8 hours ago [-]
Team effort, but thank you!! I've just taken the next month and a half off to work on things full time. I'm excited!
The next update won't be huge, (Google required us to make all screens 'edge to edge'[0], which took up most of my time last month). I'm hoping for some solid improvements now that's out the way, once the release pipeline has returned to normal.
Feel free to get in touch if you fancy contributing.
If you can get your agent of choice to run up the app in an emulator and navigate the whole thing taking screenshots then tasks like edge-to-edge can be pretty hands off.
The way I did it was to firstly get accessibility identifiers on everything. Then have it record everything I do on an emulator to navigate the entire app. Then left it for a while to work out how to actually use the app via the emulator. Once you have this sort of baseline. A lot of changes are really quite pleasant. I often ask for an HTML gallery of screenshots covering a few device sizes as the step before I bother running it on a device myself.
david_allison 8 hours ago [-]
We use Roborazzi[0], which is an excellent screenshot library, but:
* We target minSdk 24
* We're still using XML views
* We target a large variety of form factors
* We have a lot of screens, and these have a lot of configuration options.
I really wish it was "point an agent at it, and walk away", but many screens ended up being hours of iteration with Fable driving my phone/an emulator to produce an acceptable outcome.
Given that my Pixel 9 Pro has system screens which are still broken under edge to edge, it's not an easy change, and takes up time which could have been going towards feature development.
Gotta love that Google enforces rules on developers that it won’t even enforce on itself. Such a great look.
AstralSerenity 6 hours ago [-]
You guys are awesome, thank you.
jbaber 7 hours ago [-]
Thank you for Ankidroid!
bbx 6 hours ago [-]
I just released a game [1] on both iOS and Android.
The Google Play process is more thorough. There are a lot of steps and you need to clear them one by one. This means waiting several days between each step. The Play Console dashboard is quite well documented to be honest but can be overwhelming. The main obstacle is that you need to find at least 12 testers to play your game for 2 weeks straight. I ended up paying a service to test my app.
On iOS, the process is a bit more obscure. It's fairly easy to submit an app, but then you don't really know what's happening. You can only see a status like "Pending review". And then one day, you are approved.
Overall, the iOS process felt easier for me. As long as your build succeeds and you provide the correct information, your game can be live within a week. The Android process took more than a month in total.
Finding 12 testers was a struggle for my app [1]. Had to use a mix of LinkedIn begging, work colleagues, friends, and people from random Whatsapp groups I was in.
Once you get over that hurdle for your first release, at least you don't have to do it for every update.
The Play Console is a bit fiddly and I'm always getting random warnings that I need to comply with some new rule by an arbitrary date or my app will get delisted.
That's an understatement and a half. It's massively over engineered and complicated, especially when compared with (say) the dashboard on Itch.
Aulig 24 minutes ago [-]
I've published hundreds of apps over the past 6 years and Google's review times had a similar spike during covid. It took a very long time to recover but now it's back to being bad, I can confirm that.
Hang on. You've published hundreds of apps? As in the same thing slightly modified several times?
fhub 8 hours ago [-]
Some reviews are clearly automated, some get a light human review, and some involve a human really looking hard. New apps seem to get a more rigorous human review for their first 2-4 submissions. Or at least humans looking over automated test screenshots etc. One reviewer apparently only looked at screenshots because they missed something that would be blindingly obvious on the prior screen if they did it themselves.
The explosion in LLM app development has clearly created a bottleneck at the human review steps. Not only delays but much more “dumb” rejections from likely over-stressed humans.
vesterde 36 minutes ago [-]
Still trying to get a Play Store page with stats onto my AI Impact page, but if their numbers are anything like Apple's (and they're likely much higher), then it's a tough life for them right now:
Yeap latest CoMaps update took ~16 days to review (the longest wait for us so far) and two support tickets (submitted first after ~9 days and got "we have expedited it", 5 days later still in review, so submitted one more ticket).
Before that we had a hotfix update (a very small change) and still it took longer than a week and a support ticket (after which it had been approved in a day)...
mrjeeves 8 hours ago [-]
Our app includes Android Auto, which I think is what causes it for us. Submitted 4 Sept, still in review.
Was only 48-72 hours until this year, where it randomly jumped to 2 weeks or longer like it still is.
It's really frustrating, and makes it very difficult to develop with, let alone reliably release features across platforms.
rnotaro 4 hours ago [-]
I suspect the same issue; I added Android Auto to my application on the latest release and the version I pushed on Sept 3th is still under review.
deminature 6 hours ago [-]
Maybe I'm just incredibly lucky, but my reviews on Google Play take roughly an hour and appear to be entirely automated. My initial review was about a week, but everything after that has been 1hr. My Apple reviews are still around a day and my initial review was one month. The Google process is painless and is almost as easy as a web deploy, the Apple process feels much less certain that it will go smoothly and Apple actually regularly opens the app even months after release. This is presumably to check for problematic UGC, but feels rather unnerving.
ryantgtg 3 hours ago [-]
Exact same situation for us.
Google just seems to fly through and fill out a bunch of forms (we had to include a condition where if the google tester credentials logs in, we switch the app to the staging API). And then it's live within the hour.
Gareth321 8 hours ago [-]
MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.
setgree 7 hours ago [-]
And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
rock_artist 5 hours ago [-]
We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors.
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
GuB-42 2 hours ago [-]
Just because there are known vulnerabilities don't mean we should drop other security features, this is the opposite in fact. Defense in depth, an OS-level vulnerability cannot be exploited if the attacker cannot access that part of the OS.
And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.
As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.
If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.
echelon 4 hours ago [-]
Sandbox, ACL, scan, sign, revoke bad actors.
We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.
Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.
Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
yacthing 5 hours ago [-]
Do people not remember the days of viruses destroying computers?
They were a massive issue before, and now they're barely a thought for most people.
These review processes have been good for the general population.
rock_artist 4 hours ago [-]
I believe people in HN also remember the days before we had MMUs.
And I'm sure everyone remembers ransomware.
No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.
I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
bronson 4 hours ago [-]
What review processes on computers?
pflenker 4 hours ago [-]
I didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves.
In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access.
Even though review processeses generally do not exist for computers, they are part of that same trend.
nekooooo 4 hours ago [-]
mac app store / windows app store
dazgjkyfedbu 4 hours ago [-]
And outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.
ignoramous 4 hours ago [-]
> We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps)
Vulnerabilities aren't intentional.
> reviewed apps that were used for fraud or access as bad actors
The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".
duskdozer 6 hours ago [-]
That's a tangential issue.
1. don't force auto-updates
2. still review apps uploaded to Google Play, but don't force users to use Google Play
If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
MRtecno98 6 hours ago [-]
> If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
So this doesn't solve the issue pointed in the OP.
> don't force auto-updates
I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
8note 5 hours ago [-]
> I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing
Forgeties79 6 hours ago [-]
>So this doesn't solve the issue pointed in the OP.
Yes it does. This is their point:
> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.
It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
cogman10 5 hours ago [-]
> It’s my hardware
I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.
We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.
Forgeties79 3 hours ago [-]
Agree, what I'm saying is "it is mine and we should treat it as mine, same as my laptop/desktop." We both agree the current status quo is not that, I'm saying what it should be.
yosef123 7 hours ago [-]
And what do windows / linux / macos do about apps getting hacked to billions of pc's simultaneously? How is that a new problem?
Frieren 7 hours ago [-]
If libraries didn't exist could not be created today. People tend to say that "it is impossible" when it actually only needs to be well organized.
Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
no-name-here 5 hours ago [-]
> macos
MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.
> Windows
I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
Maskawanian 7 hours ago [-]
How about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.
NorthSouthNorth 6 hours ago [-]
I don't know. Literally every single person I help with tech support makes me doubt this is possible. People do not care in the slightest and treat suggestions to learn basic digital hygiene as if you've asked them to a computer science degree in its entirety.
Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
chipsrafferty 5 hours ago [-]
A shocking number of people have passwords like "shovel"
osmukka 5 hours ago [-]
IMO in that case its their own fault. After all they have free will and can use it against their own good if they so choose. Let them get pwned a few times and see if they learn.
diegolas 4 hours ago [-]
that's so dumb on so many levels... should we strip cars from active safety measures and let drivers who are not super good at driving just kill themselves on the road?
fauigerzigerk 3 hours ago [-]
I agree, but what I disagree with is the idea that everyone must be prevented from freely installing software on their own devices to make sure unskilled people cannot be tricked into doing it.
I don't really understand why a well designed sandbox and permissions system doesn't solve the problem.
preg_match 4 hours ago [-]
Well cars kill people, granny using the password “password” does not. We can’t prevent all levels of stupidity and carelessness.
If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.
myaccountonhn 4 hours ago [-]
Maybe a drivers license should be needed to have a phone.
esikich 5 hours ago [-]
I've worked with dozens of businesses over the years and you can't even get businesses with real money and consequences on the line to follow basic security practices. My current project is updating dozens of windows domain controllers that are still on 2012 R2. Aka critical infrastructure that hasn't been getting updates for years.
pjmlp 7 hours ago [-]
Many of us have routinely cleaned computers from adults that installed several Ask Jeeves and Yahoo toolbars.
compass_copium 7 hours ago [-]
At some point computers need to stop being treated as magical boxes that no reasonable person can learn how to use safely. We expect people who use cars to learn how to use them safely, we expect people who use lawnmowers to not stick their fingers in them. Computers have been a part of daily life for normies for decades at this point, it's infantilizing to suggest that average, non-tech savvy people can't learn to use (not necessarily build, repair, etc.) them properly and need to be protected from them.
pjmlp 6 hours ago [-]
People have to successfully get through a state exam in order to drive cars in first place, can be jailed, get fined when not driving them safely, or forbidden for life to ever drive again.
People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
voakbasda 6 hours ago [-]
Do you hate open source and want only projects where their authors can afford liability insurance and are willing to put themselves in the firing line of a legal system that can be both arbitrary and capricious? Because that’s what you seem to want.
pjmlp 5 hours ago [-]
Even people selling on the street or doing charity work have to account for liability of their actions.
Lets stop talking about open source as special snowflakes where everything is excused.
voakbasda 5 hours ago [-]
And that’s how you prevent bake sales, lemonade stands, and more. You create a barrier to entry that gets raised little by little until only the biggest players can afford the game. Software liability would end all small open source projects.
pjmlp 4 hours ago [-]
Bake sales and lemonade stands are perfectly fine as long as people don't land on hospital urgency, due to careless work on preparing them with spoiled ingredients or lack of hygiene.
Lets strive for quality in software.
Dylan16807 3 hours ago [-]
Now do that again without careless work or spoiled ingredients. Do you still want them punished or facing so much regulation they can't exist? Because you'll definitely get that with software; even really good development will have flaws, and single flaws can lead to a thousand or million hacks.
pjmlp 2 hours ago [-]
All humans face scrutiny in their interactions with others.
Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.
Dylan16807 1 hours ago [-]
I dunno, people seem to accept most kinds of tool being fussy or flaky.
But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.
esikich 5 hours ago [-]
The problem is it's literally speech. Selling something isn't speech, you do not have the right to do charity work or run a business. It goes even beyond speech, it's closer to pure math/logic and I feel very uncomfortable about regulating that. I also think it's literally impossible.
pjmlp 4 hours ago [-]
Speech is subject to laws in most jurisdictions.
dml2135 6 hours ago [-]
>People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
Anyone is allowed to sue the lawnmower company. Did they win?
lightedman 5 hours ago [-]
The amount of "Do not put hands here" labels I've seen on lawnmowers would suggest that, yes, someone did sue and win (or at the least got a settlement) and thus the lawyers forced the companies to put disclaimers and warnings on the lawnmower, directly on the top of the deck in plain sight.
close04 6 hours ago [-]
On power tools, appliances, etc. the safety features are at the user's latitude to bypass. They are usually a hint (don't microwave your dog), not a hard barrier ("I'm sorry, Dave. I'm afraid I can't do that"). A spinning blade is covered by a grill you can trivially remove without permission from anyone.
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
pjmlp 5 hours ago [-]
Yes, and when they fail to do so, there are laws in place for liability of third party, or when their own irresponsible actions affects others.
misnome 6 hours ago [-]
Using a computer wrong doesn't kill people.
jprjr_ 6 hours ago [-]
Yes and no.
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
pjmlp 6 hours ago [-]
Depends on what those computers are responsible for.
> "One [software fault] was when the operator incorrectly selected X-ray mode then in 8 seconds quickly changing to electron mode, which allowed the electron beam to be set for X-ray mode without the X-ray target being in place"
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
1 hours ago [-]
misnome 2 hours ago [-]
You are right! Computer use should be taught, tested and licensed exactly the same way of steering several tons of metal at 70mph are!
esikich 5 hours ago [-]
I'm sure you can think of many examples where it does though.
marcosdumay 6 hours ago [-]
Well, computers first stop being magical machines that no person can learn how to use safely, then.
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
sunaookami 5 hours ago [-]
And e.g. browsers cracked down on it, removed toolbar support and powerful add-on support AND enforced signing meaning everything goes through their gatekept extension store and these problems still persist (e.g. addons changing the search provider, new tab page or homepage). Locking everything down does not help.
no-name-here 5 hours ago [-]
> does not help
Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
pjmlp 5 hours ago [-]
More a problem of those stores still not being properly validated rather a dumping ground for extensions, than anything else.
bigfishrunning 6 hours ago [-]
20 years of being tech support for countless family members and acquaintances says that nothing can possibly make people care about "digital hygiene". An iPad, Chromebook, or similar inflexible device is perfect for most people, and marketing more flexible devices to them has been a mistake since the beginning.
nik282000 5 hours ago [-]
You expect people to treat devices with respect and responsibility? The VAST majority of people use their phones to stream an infinite sequence of clickbait, ai slop, and conspiracies for 6 to 8 hours a day.
rpdillon 5 hours ago [-]
The app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.
charcircuit 4 hours ago [-]
Just because something is not perfect that does not mean it's worthless. Most things security things operate this way where it's impossible to stop all malware or attacks.
rpdillon 2 hours ago [-]
When analyzing whether something is a net good for society, I look not only at the value it brings, but the cost that it brings. The mobile ecosystem normalizing the idea that the vendor that sold you your everyday computing device is the sole arbiter of what can run on that device is of enormous cost to society, but anytime anyone brings that up, there's an immediate retort bringing fear, uncertainty, and doubt about software obtained outside of those centralized silos.
As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.
Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.
pjc50 7 hours ago [-]
I wonder if people would be happy replacing the "Google approves developers" system with a "government requires your ID and address on file so you can be held liable for your apps" system. I suspect not.
Frieren 7 hours ago [-]
That is already a requirement in any civilized country. You cannot run a business without a registered ID, address, etc. for tax purposes.
For free (like for real no microtransactions) that is different. For the rest, they already have that.
zzril 6 hours ago [-]
If you don't agree with a decision made by your government, you can vote for someone else next time.
If you don't agree with a decision made by Google, what do you do?
freedomben 6 hours ago [-]
The people I vote for never win. Am I really any more empowered with the government than I am with Google? At least with Google I can de-google my life (with some significant losses of convenience, but it is doable)
zzril 6 hours ago [-]
Personally, I find it easier to live with a decision I don't support if I was simply out-numbered in a fair vote, rather than out-powered by some random company on some random continent.
As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
myaccountonhn 4 hours ago [-]
You probably have some sort of legal rights and ability to challenge decisions made by your government.
If you're banned from Google? Good luck, you're fucked.
everforward 6 hours ago [-]
The only part that would really be novel is the liability.
I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).
BiteCode_dev 7 hours ago [-]
It's virtually the case, google and apple accounts require ID verification, which in turn can be requested by the gov in case of an investigation.
drdexebtjl 7 hours ago [-]
What for? Malicious actors have no shortage of stolen identities.
lovasoa 7 hours ago [-]
We could force Google to operate its app review service independently. Users could use it and pay for it, or alternatives. Currently Google forces everyone to use their own mediocre service and pay for it without knowing exactly where and how much you pay.
Regulation is already addressing that. I encourage you to read up on the Cyber Resilience Act.
basilikum 6 hours ago [-]
People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes.
Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.
Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.
The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
bluefirebrand 5 hours ago [-]
> People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes
People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually
People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
basilikum 2 hours ago [-]
Yes, hold people accountable for their actions. Don't take away their freedom. We may prohibit individual actions that involve a general tool when they harm others. That is compatible with a free society. We may not prohibit fundamental tools¹ That is fundamentally incompatible with a free society. Especially when that tool forms the infrastructure for the flow of information and free speech.
[1] General purpose computing
post-it 7 hours ago [-]
How would a reviewer catch that?
Buttons840 6 hours ago [-]
How about the same thing we do when companies leak half-the-nation's personal data twice a month. Nothing.
When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
miroljub 6 hours ago [-]
> And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
dwaite 2 hours ago [-]
A weather app could be asking for your location to give you more convenient local forecasts.
It could also be asking for it to help advertisers build a robust behavioral profile about you.
This is not a systems permission, nor is it something that billions of users can judge the ramifications of each potential privacy impacting decision. Privacy is a systems property, not a technical property enforced with ACLs. ACLs can only keep the door from being wide open, they can't prevent access which has been granted from being abused or help the user understand ramifications of granting access.
We need privacy to be a regulatory concern with actual enforcement via an international framework. Until then, it is a business concern of Apple/Google - because they are in the business of having consumers feel confident that a weather app isn't reporting their behavior to anyone willing to pay for it.
pavlov 7 hours ago [-]
> "Apple and Google are WELL past due for regulation in this space."
There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere.
The current US government won't do anything to follow suit, but hopefully a future one might.
graemep 6 hours ago [-]
> There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores
So does that mean:
1. People in the EU can continue to use F-Droid etc. exactly as they have in the past, permanently? No Google verification of developers needed?
2. People are free to install apps from any APK they choose?
lern_too_spel 5 hours ago [-]
Yes. Even beyond that, people outside the EU are free to install apps from any APK they choose.
sunaookami 5 hours ago [-]
The EU is not interested in liberating phone operating systems because it goes against their digital wallet push which forces everyone to use an attested, Google/Apple sanctioned device and operating system.
cute_boi 6 hours ago [-]
Yea, but apple and google keep finding out loopholes and unfaithful compliance, it is time for EU to have some backbone.
shevy-java 6 hours ago [-]
The US government acts here in favour of a monopoly market. Trump violates free market principles; quite interesting how Trump works against core capitalistic means, in favour of personal corruption.
howunfortunate 5 hours ago [-]
The push to involve the legal system and the government is ironic.
It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked.
The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.
toxik 4 hours ago [-]
Haha, oh the poor mega tech companies?! As if. Google sees a market, it wants to capture it. Same as Apple did.
AdityaK_9999 3 hours ago [-]
I am on an Android 10 system... gate keeping wasn't this bad during the Android 10 times...so i fairly use software stores like f-droid... simpmusic is one app I use frequently from f droid....no application so far has been deleted automatically.
I guess Google has been upping the gatekeeping with newer systems as they come out
viktorcode 4 hours ago [-]
This case has nothing to do with "gatekeepers". It is about the Play Store, operated by Google.
killerstorm 4 hours ago [-]
Back in early 2000s, pretty much all Windows machines were infested with malware.
Do you want to bring back those glorious days?
Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.
braiamp 3 hours ago [-]
People still can install/run whatever they like on their PCs, so why further restrictions needed or am I missing something? Also, further restrictions doesn't seem to work on the mobile/TV market where actual malware still infects iOS/Android/TV devices despite all the "hops" that it has too go through.
Code signing with warnings about non-signed apps is enough
killerstorm 2 hours ago [-]
Hmm? Malware on iOS is extremely rare.
I remember in Bitcoin community ~10 years ago, standard recommendation was than an iOS wallet was secure enough (I don't recall even a single case where wallet was stolen via malware), but any private keys on Windows were strongly discouraged, as most cases of stolen wallets were on Windows.
I'd say popularity of iPhone shows which way people prefer, but you do you - what prevents you from voting with your wallet and buying a Linux phone?..
mrguyorama 1 hours ago [-]
The reason that modern computers are no longer filled with malware has nothing to do with completely irrelevant locked garden app stores on phones.
The reason is because Bill Gates put out a memo because it was fucking embarrassing that you could trivially smash the stack on default open API endpoints for services that consumers never used and shouldn't have been trivially routable from the open web in the first place.
Meanwhile in app stores, you don't have to hack anything, because consumers just download your botnet software willingly and directly.
42% of all apps on LG smart TVs turned your TV into a "residential proxy" botnet participant. 30% on Samsung TVs. There is no "hacking" in the world of apps because it's completely normalized for whatever app you build to also for some reason include remote control functionality from like 6 different companies. All of those apps pass review no problem.
8 hours ago [-]
ivl 7 hours ago [-]
Your complaint about Android .apk install is... similar to unsigned software installs on Windows in some cases (not a great argument, I know, but the same as the vast majority of users would be used to).
As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.
Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money:
The main difference is that signing a Windows binary doesn't require any third party review of the app content.
lern_too_spel 6 hours ago [-]
Signing an APK also doesn't require third party review of the app content.
skobes 6 hours ago [-]
But the context of this discussion is the difficulty of installing an APK from outside the Play Store.
lern_too_spel 5 hours ago [-]
This is the first time I've seen a complaint about giving permission to an app to install another app. The SmartTubeNext issue was due to the developer's keys being stolen. If you want to keep an app signed with stolen keys, you can disable Play Protect. If Play Protect uninstalled apps that Google disliked instead of apps with known vulnerabilities, people would mass disable Play Protect, which would defeat its purpose.
6 hours ago [-]
fsflover 3 hours ago [-]
> operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all
This is exactly why I use a GNU/Linux phone that runs a desktop operating system with no artificial restrictions. Debian repositories are good enough to save me from malware, aren't they?
pjmlp 7 hours ago [-]
Nintendo, Playstation, XBox,...
drdexebtjl 7 hours ago [-]
… should also be open, but that’s irrelevant to the discussion.
pjmlp 7 hours ago [-]
It is quite relevant as computing systems.
And yes, they also have apps besides games on their stores, and support external keyboards and mices.
6 hours ago [-]
drdexebtjl 7 hours ago [-]
Sorry, I think I misunderstood your argument as whataboutism.
ls-a 7 hours ago [-]
[dead]
nchmy 7 hours ago [-]
[flagged]
tavavex 7 hours ago [-]
Web apps can't fully replace native apps. This would be a bandaid fix, we need a fully open ecosystem for apps, like what is available on PCs. Native apps can run offline, they can be much more deeply integrated into the OS (you can't have a web app Android launcher, for instance), and they have a performance overhead due to having more layers between them and the hardware, which is important for games or anything complex.
johnecheck 6 hours ago [-]
Web apps can run offline. Google could figure out web app android launchers if they wanted to. The performance overhead exists but is slight. It doesn't matter to 90+% of applications, including many games.
nicoburns 6 hours ago [-]
I have high hopes for the Rust UI ecosystem in this regard. It's implementing pretty much everything from scratch, which means that it should be able to support a standalone GUI ecosystem that doesn't depend on a system GUI toolkit being available (while also being able to target existing OS's).
cyanydeez 7 hours ago [-]
we have an open web. no ones pays for it.
Anyone can put up a PWA. The only org that hates this is Apple.
The complaint is about a shared resource, which would require governments to adopt open source policies and _pay_ for it just like they do the post office.
But ya'll hate government, so here we are.
nchmy 6 hours ago [-]
why invest in developing a PWA if a significant portion of (particularly wealthy) users cant use it?
nozzlegear 4 hours ago [-]
How are iOS users not able to use a PWA? Because it takes a few taps to add it to the homescreen? I have several PWAs on my iPhone and I can use them quite well.
nchmy 3 hours ago [-]
it is significantly more complicated - especially for the average user - to install them than on other browsers. other browsers also let developers ask the browser to prompt the user to install the app.
This is all documented in great detail in the links i shared
ocdtrekkie 7 hours ago [-]
Open Web Advocacy's goal is Chrome on all platforms, which just means the Play Store problem gets even worse. The moment OWA wins, the open web dies. These are people with a truly bad astroturfy goal, clothed in charitable nonprofit status.
Paradoxically, as long as WebKit is mandatory on iOS, the open web is safe: Websites have to build for a lowest common denominator standard instead of building for Chrome proprietary APIs.
nchmy 6 hours ago [-]
[flagged]
azuanrb 6 hours ago [-]
[dead]
surajrmal 7 hours ago [-]
Security at its core comes down to trusting the supply chain that provides the software that runs on your hardware. There are many alternative secure supply chain models, but ultimately users often are incapable of making great choices on what is trustworthy. It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.
Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.
LanceH 7 hours ago [-]
I'm not sure how much manual review in these stores is for security rather than content and enforcement of business rules.
I imagine nearly all the security review is automated scans, and not the source of the delays.
chii 7 hours ago [-]
> It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.
this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.
I dont trust it.
The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.
malwrar 7 hours ago [-]
Hard to find better solutions when we have no agency to enact them. The “arrangement” was one-sided from the start.
JimDabell 8 hours ago [-]
The Google Play review process has been slower and more painful than the App Store review process for 5+ years at this point. At least you get to communicate with real people at Apple; it’s all bot-driven with Google.
flerchin 5 hours ago [-]
What are bots doing for two weeks
jimmydoe 6 hours ago [-]
If you know how many get rich quick guru online are teaching people vibes code and submit apps and faceshift to other apps later, you won’t be surprised the App Store model is no longer sustainable.
wiradikusuma 7 hours ago [-]
Yea I noticed that as well. Even longer than Apple's.
FYI Samsung's is even worse.. 6-8 weeks. Hope you get it right the first time you submit your app.
I submitted Signage Sync (https://signagesync.app) last year, still on my third review. Fingers crossed:)
sanitycheck 4 hours ago [-]
Yep, I always expect 2-3 months to get an app onto Samsung TVs and those are just variants of a white-label base which already passed their QA multiple times. LG is even worse for the initial review but they accept redirects to hosted apps so at least there's no need to ever deal with them again after launch.
hnisjafx40 8 hours ago [-]
F-Droid's great but their build queue has had multi week waits too, difference is you can see exactly where your build is stuck instead of guessing.
collabs 8 hours ago [-]
You can also choose to host your own repositories like futo and new pipe do.
account42 8 hours ago [-]
Part of the value of F-Droid is the curated distribution model that hopefully catches the worst behaving developers that think they have a god given right to your data though.
skeledrew 8 hours ago [-]
Hopefully the process is straight forward so others can easily pick it up.
wklm 7 hours ago [-]
Strong argument in favor of web vs native apps. If you need bluetooth on iOS checkout the web bluetooth iOS safari extension i've been working on recently: https://beacio.com
nchmy 7 hours ago [-]
Yes, a truly Open Web is the solution that we need. It already works everywhere with a single codebase, and is more secure and private than native apps.
But Apple prevents that by forcing all browsers to use terrible WebKit on iOS.
Note that Alex Russell is a Blink partisan, currently supporting Blink at Microsoft and formerly having done so at Google. Folks like that don't take kindly to the idea that a Blink monoculture might not be a great thing, and definitely do not share the opinion that it's critical to the open web that Apple not cede the open web to Blink.
Remember, Blink began as Google's 2013 fork of WebKit. They've embraced and extended it, but thankfully the "extinguish" step is taking longer than they thought. This makes the "open web, as long as it's my engine" people upset.
Safari's PWA support is not as complete as Chrome's today, but it's as good as Firefox's support and perfectly capable of supporting rich, standards-based apps. https://pwascore.com/
nchmy 5 hours ago [-]
The fact that your "argument" rests upon baseless ad hominem, I'm mostly inclined to not even respond.
I'll simply say that if you bothered reading anything (let alone objectively), you'd clearly see that no one is arguing for a blink monoculture. They're arguing for allowing everyone to choose whichever browser and browser engine that you want. Safari included.
The math isnt mathing on that site... And, no, safari is NOT capable of PWAs - which is the primary point of contention (not obscure APIs, though safari generally lags in all of that as well). They deliberately hobble PWAs and make them very difficult to install.
edit: also, your site is just obviously biased/poorly done, because there exist many better comparisons of web features, which show how vastly far behind Safari is, often even of Firefox. This is unsurprising given your chosen style of rhetoric
It's not ad hominem since I'm critiquing their position, not their character. Their positions are public and well-documented, which is why it's important to point out the bias of what you linked to.
> And, no, safari is NOT capable of PWAs…
Incorrect, see my link. PWA installation on iOS is simple and idiomatic, and the same as it is for all websites: Share > Add to Home Screen.
nchmy 4 hours ago [-]
It is rare that someone voluntarily exposes their lack of insight and integrity so thoroughly... Kudos..?
your argument amounts to "this person is incapable of being objective, let alone decent, because they work at xyz". Moreover, you literally didn't address a single thing presented in either link that i shared - which directly refute your nonsense. Pure ad hominem, and worse.
You are not a serious person if you think that PWA installation is "simple and idiomatic on iOS". It is buried multiple menus, taps, drags etc... deep. Most chromium browsers present a button right in the address bar or at least conspicuously in the main menu. Moreover, they allow developers to ask for the ability to prompt users to install the app.
> Incorrect, see my link. PWA installation on iOS is simple and idiomatic
> Share > Add to Home Screen.
Are you sure "share" is idiomatic here?
Also calling a 6 steps process simple is laughable. One-click prompt to install is simple and part of PWA API that safari doesn't implement.
CharlesW 3 hours ago [-]
> edit: also, your site is just obviously biased/poorly done
If you can offer recommendations for data-based improvements, I'd sincerely appreciate it! It was made without any concern for Safari "winning", as is probably obvious since it has the lowest score. Methodology described here: https://pwascore.com/about
nchmy 3 hours ago [-]
lol, not after you behaved so disgracefully here. at the very least, fix the math as i said more than once
CharlesW 3 hours ago [-]
The math is correct, see /about for methodology and this summary from the "How Scores Work" panel.
About PWA Scores:
• The main score shown is weighted for feature importance
• Only stable (non-experimental) features are counted
• Tap or hover any score to see:
– Raw scores (simple % of supported features)
– Experimental feature scores
nchmy 2 hours ago [-]
background capabilities is 0 for all browsers. there were other weird inconsistencies as well. We can completely leave to the side that your weighting scheme is surely arbitrary or perhaps even biased.
CharlesW 2 hours ago [-]
Because they're experimental. Since that's confusing even with a key, it may be better to hide experimental features/categories by default.
> We can completely leave to the side that your weighting scheme is surely arbitrary or perhaps even biased.
Hover on any number to see both "raw" and "with experimental/non-standard features" scores. If you do this to the overall score, you'll see that Firefox benefits the most from this.
wklm 5 hours ago [-]
True that. Apple has strong economic incentives to nerf PWAs, and I don't share their privacy concerns about web bluetooth. If anything, forcing users who need bluetooth to install shady third-party browsers creates way more risk. Based on beacio's download numbers, quite a few people would rather have web bluetooth available in their default browser.
mig39 4 hours ago [-]
>safari is NOT capable of PWAs...
> They deliberately hobble PWAs and make them very difficult to install.
Hit the share button, "Add to Home Screen" is very difficult to install?
adamddev1 6 hours ago [-]
I just pulled a PWA app off the app store and I am going to keep it a pure PWA. It's installable, offline-first. I know I feel like I'm swimming against the current but I would love people to try to push for awareness of PWA installs more.
rnotaro 4 hours ago [-]
I personally have a TrustedWebActivity. Most update doesn't need a review because I only need to update server-side. Behave like a PWA while being an Android App. (And you can implement Android Auto, other native stuff)
It allows the users to discover my web app through the Google Play Store.
My app was also available as a PWA but I mostly push the TWA currently.
nosioptar 5 hours ago [-]
I'd love to see people distribute their apks directly.
Itch.io is an option for people who don't want to set up a site or handle payments. While they focus on games, they're cool with distributing non-games:
I think inconsistency is really annoying. Hard to rely on it. Most of our reviews clear with a couple hours, but sometimes it gets stuck for days.
Frieren 7 hours ago [-]
This is why goverments have appeal processes and layers of tribunals.
To be judged and found guilty by a corporation takes away all your rights.
robocat 3 hours ago [-]
Do you happen to live in a country where your government departments are known for rapid processing? (not weeks of delay like we're talking about here).
I generally see my legal system create severe delays (regardless of how much that victimises or costs everyone involved)
Frieren 3 hours ago [-]
> I generally see my legal system create severe delays
Better a delay that getting your account closed without recourse. But you are right, years of conservative governments have starved the government and its services are slower than they should around the west world.
calyhre 8 hours ago [-]
Not sure how it works behind the scene, but our app (present on the store since 2018) is taking a couple hours at best with Google, and usually less than 24h with Apple.
Very much likely an automated triage based on code change or complexity.
masonwan 1 hours ago [-]
If developers want to get the same processing speed, are we ready to pay as much as we pay for Apple App Store?
habosa 4 hours ago [-]
Making Android apps was my introduction to publishing software. I remember in ~2011-2012 you could upload an APK and it would be published immediately and the Android Market had a "New" page which was just a chronological feed of recently published or updated apps. Just uploading your app update was an easy way to get ~500 free downloads which I found very exciting.
At the time I couldn't imagine paying $99 for an Apple Developer account and waiting a week to publish my app...
bilalq 6 hours ago [-]
FWIW, this has not been my experience. Google Play usually approves within 24 hours for me still. Apple has been taking over a week though.
When Shopify announced their shift from React Native, this is actually what was on top of mind for me. Week+ delays for critical bugfixes is insane. Being able to patch things with OTA updates is tablestakes at this point.
tzone 6 hours ago [-]
This is one part where it should really just be done by AI for 99% of the cases. Just have a security focused AI model that is biased towards flagging things a bit more conservatively.
Only apps that get flagged by the AI reviewer then have to go through a separate, slower human review process.
corentin88 2 hours ago [-]
In the opposite, Google Chrome extensions are now reviewed in a few hours, sometimes less than one hour.
jmkni 8 hours ago [-]
I've noticed this
Google Play is regularly slower now than App Store Connect, which never used to be the case
Pr0Ger 8 hours ago [-]
Longer than an average App Store review (which is heavily criticized for being too long)? Hilarious
gyomu 8 hours ago [-]
I believe the App Store has switched to automated reviews, at least for updates. I've had my app updates approved in <1h on a regular basis starting this summer.
hobofan 7 hours ago [-]
From what I was able to see from the outside, App Store has had semi-automated reviews for updates in basically forever (+ some random spot checks), presumably based on some introspection that only triggers a human review if a new system API was used.
h14h 4 hours ago [-]
This is a big part of why React Native (and especially EAS) is still my preferred native development platform. The ability to ship OTA updates directly without depending on platform reviews & rollout schedules is a killer feature I'm not sure I could live without.
maelito 5 hours ago [-]
Meanwhile, the Web is ever more powerful. But now Android and iOS users expect to find things in the App store only.
lecarore 8 hours ago [-]
The google review process is the best advertising for f-droid there could ever be.
allthetime 5 hours ago [-]
I have three apps on the Play Store, they all take a couple hours to pass review and their auto-testing/review systems often catch little bugs I didn't almost immediately.
Getting a new app on the store is a bit cumbersome, but it should be.
guzik 7 hours ago [-]
We push updates for our app pretty frequently and they've been passing review in an average time of 1 hour (around 7 updates in the last 60 days). Hope it stays that way.
Shywim 5 hours ago [-]
I think that the app targeting Android Auto should be pointed out. Google Play reviews are mostly automated and it shouldn't take more than a few hours. Android Auto is heavily curated for good reasons.
gadders 6 hours ago [-]
Can confirm. Took about 8 days for my last app update, and about 5 or 6 for the Play Store listing update.
As someone new to the app publishing world I am surprised at how strict the requirements are, given the absolute dross you can find published.
p2detar 6 hours ago [-]
We should write more web apps, more PWAs and have some sort of a way to distribute those without proprietary app stores. It's true not every mobile app can be a web app, but for a lot of cases web apps work great.
postsantum 4 hours ago [-]
Depends on how trusted account/apps are. I have some old apps that are reviewed in 2-3 hours every time
shimfish 6 hours ago [-]
Anecdata: I've pushed out dozens of small code fixes to My PlayHome Plus over the past month and none of them took more than a few hours to be reviewed.
BIGFOOT_EXISTS 7 hours ago [-]
I'm not familiar with this space (new to Android), could someone explain why there hasn't been additional "app stores" appear that people can use?
rnotaro 4 hours ago [-]
It's coming soon. Android have been pushed to accept third-party app stores.
There have been, but most non-technical users don't care or don't go through the hassle of using them.
BIGFOOT_EXISTS 6 hours ago [-]
Is there any that I should be looking into?
jprjr_ 6 hours ago [-]
F-droid is the biggest one
freedomben 6 hours ago [-]
Check out droidify or neo store for a better front end to f-droid
nosioptar 5 hours ago [-]
I use Foxy Droid.
It's unfortunate the official f-droid client is an unusable mess. (I stopped using it years ago, maybe they fixed it.)
There's also f-droid classic, can't remember why I use foxy droid over it.
charcircuit 4 hours ago [-]
The Huawei AppGallery is hundreds of times bigger.
bpx51 6 hours ago [-]
Interestingly, I published a completely new app yesterday, and it was reviewed and published in less than 2 hours.
dminor 7 hours ago [-]
Our app rarely takes longer than a day, but it doesn't have Android Auto support so maybe that's the difference?
nixarn 7 hours ago [-]
I know this is quite the controversial idea. But I'd personally love a fee per app, just to counter spam, say 100usd/app.
tehlike 8 hours ago [-]
Huh.
On the flip side, googles release infra provides much more functionality for apps that already has scale. I wish apple were more production oriented too.
mococa 6 hours ago [-]
IMO/IME (as former mobile developer) mobile app development is obliterated.
This is fight for big dogs now.
6 hours ago [-]
jadar 7 hours ago [-]
I haven't pushed an update since June, but this has not been my recent experience...
abroszka33 7 hours ago [-]
You would think that with the AGI that these companies are hyping the review happens in minutes. Weird.
pintxo 7 hours ago [-]
Guess both are excused for not having up to the par approaches available.
torutofu 7 hours ago [-]
A week-plus review queue basically kills any chance of a quick hotfix for a free app.
zoobab 8 hours ago [-]
A public FTP server is next app store.
gman83 8 hours ago [-]
This isn't my experience. My updates usually get accepted within hours. Apple takes days usually.
shevy-java 7 hours ago [-]
Why do people still want to make Google more powerful? I don't get it. Legislation must allow for break up of monopolies such as google play.
BigBalli 3 hours ago [-]
not my experience... I have most updates go through in <24h.
tnolet 7 hours ago [-]
That's quick. The Slack App review takes 10+ weeks.
NickHirras 6 hours ago [-]
Sometimes several weeks in my recent submissions.
polotics 8 hours ago [-]
yeah my 'promptly AI' alarm clock almost always spends 7 days, as soon as the binary changes, even descriptions changes take several days
21.37.42-SECONDARY is an interesting version number, don't they like final-final2 in their version numbers?
eviks 8 hours ago [-]
It took the whole year before v21 was finally approved, so seems only fair they publish minor v21 revisions multiple times a day!
joshstrange 7 hours ago [-]
Apple's App Review has also been slipping over the past few months. I have multiple apps that have taken days, up to a week to be approved.
What's most galling is that if you use CapacitorJS or similar you can ship app updates instantly to your users but if you write native first-class OS citizen apps you are penalized.
There is nothing quite so annoying as having a fix for a bug people are running into and have zero control over when it will get out to them.
8 hours ago [-]
m00dy 5 hours ago [-]
I just submitted an open source android passive income app [0]. It's been two weeks and I'm still waiting. It's my first app though.
In fact, I'd support Google with this policies if they'd also take full accountability if my phone gets hacked. Do they? No, so it's unfair and a bad authoritarian way to create another walled garden.
okokwhatever 6 hours ago [-]
This will only change once a new player rises. We live in a world full of blind consumers that won't look out of the Google and Apple walled gardens.
micromacrofoot 7 hours ago [-]
Everyone that ingests code is seeing an order of magnitude more of it thanks to LLMs, even existing apps are producing more updates. It's the same sort of thing github keeps failing to keep up with.
basisword 8 hours ago [-]
For all the complaining about Apple's store, the Play Store has always been worse imo. You can't even release an app without first doing a beta test with at least a dozen people.
joshstrange 7 hours ago [-]
> You can't even release an app without first doing a beta test with at least a dozen people.
Perhaps I'm misunderstanding what you are saying here but less than a month ago I released a brand new app with no beta period, direct to production (white labeled app, which is why I didn't need a beta)
sync 6 hours ago [-]
As an individual that 'dozen people beta test' is required. It's not required if you're a business. Also depends on when your account was created.
Same happened to me yesterday, I published a new app and it was reviewed and published within a few hours without any beta testing. but I think this is why I see people ready to buy old playstore accounts for real money, maybe this only affects new accounts
brewtide 6 hours ago [-]
I'm just working on my first app (thanks to AI...) and if you have a new dev account created sometime after 2023 they are making you do a 12 person, 14 day beta run before anything else occurs, apparently.
joshcartme 16 minutes ago [-]
It gets worse! If Google decides the people in your test don't engage enough and/or you didn't respond to their feedback, they may not give you production access. I've got a game that's available on iOS, I released there first and did lots of testing to deal with the low-hanging bugs. After doing the 14 day test Google emailed me:
Possible reasons why your production access could not be granted include:
- Testers were not engaged with your app during your closed test
- You didn't follow testing best practices, which may include gathering and acting on user feedback through updates to your app
Jyaif 8 hours ago [-]
I just updated 2 dormant apps for the first time in 10 years;
It took 2 days, and the apps were approved on a sunday.
myko 1 hours ago [-]
Google's review is complete horseshit. It has been darkly funny to watch them try to compete with Apple by adding strict review (way stricter than Apple's) and still terrible applications make it in while legitimate ones have trouble.
Just go back to the way it was before, and scan the apps with static analysis tools. This security theater is stupid and always was (for Apple and Google).
skeledrew 8 hours ago [-]
Sounds like a clear "find another store" message to me.
RicoElectrico 9 hours ago [-]
Same happened for CoMaps (which unfortunately does not have 12+ years of presence going for it)
okasaki 4 hours ago [-]
> AI is becoming part of how people experience the web every day. We want to make sure that doesn’t mean people are chained to one company’s self-serving pipeline.
Ah yes, the extremely diverse offering of OpenAI, Google, Anthropic, Microsoft, and Mistral (a fake "euro" chatbot). Mozilla is truly a "people's" company.
bryanwexler 7 hours ago [-]
[dead]
NeoByte 4 hours ago [-]
[dead]
flcikfinder 4 hours ago [-]
[flagged]
0dayman 8 hours ago [-]
[dead]
Unified-Mentor 7 hours ago [-]
[dead]
surcap526 7 hours ago [-]
[dead]
carlosjobim 8 hours ago [-]
Why can't you wait for a week? That doesn't sound like a long time.
randyrand 8 hours ago [-]
For a critical bug fix, a week can be a very long time.
cute_boi 6 hours ago [-]
with ai agents and everything even hours can be a long time. I think google playstore should be responsible for all the damages...
tehlike 8 hours ago [-]
For apps with a scale, it's a long time
carlosjobim 8 hours ago [-]
Because? People wait far longer for much more important things in real life.
tehlike 7 hours ago [-]
Speed is money. Yes people wait for 9 months for having a baby, doesn't mean you should wait 9 months for an app release. That is not a sound logic.
carlosjobim 7 hours ago [-]
Yes, but one week to wait for your app is nothing to complain about.
tehlike 6 hours ago [-]
You should want higher speed and quality of service from your vendors. In this case, apple is paid wonderfully for it.
doc_ick 5 hours ago [-]
Apple has some “trust” for vetting things, and with the wave of slop-apps it fine with a slight delay so the App Store doesn’t become riddled with slop like the android store.
tehlike 4 hours ago [-]
Review speed and slopness are related but not exclusive to each other.
jprjr_ 6 hours ago [-]
let's say you have a bug that makes your app unusable. If you can't get an update our for a week - people are going to just stop using your app.
carlosjobim 6 hours ago [-]
You shouldn't have shipped that bug in the first place, I would say. If the bug comes from an Android update, I assume that developers have had access to betas long before the system update is rolled out.
5 hours ago [-]
tehlike 5 hours ago [-]
Why do you think apple has point releases that fix... Bugs every time? Not necessarily new features but bugs.
Lesson in there.
carlosjobim 4 hours ago [-]
Do you mean that these point releases introduce bugs that break third party software?
tehlike 4 hours ago [-]
I decided not to engage with you. Not productive.
tehlike 5 hours ago [-]
And you know 100% all the bugs are visible at all times.
cute_boi 6 hours ago [-]
Sometime there are 0 days etc.. So, maybe you should have broader view on things instead of simple assumption.
voakbasda 6 hours ago [-]
I hope someone will sue the ever-loving shit out of Apple when their foot dragging prevents a critical update from going out in time to prevent a 0-day from being widely exploited.
neilv 5 hours ago [-]
Interesting. And all the history of Kafkaesque review interactions that various developers have had could be subpoenaed, as evidence of a pattern: that delays aren't necessarily due to excellence and good faith.
voakbasda 5 hours ago [-]
Given the sibling reply, I can imagine them claiming national security prevents them from releasing those records. But that’s okay; I am fairly certain we can find enough developers willing to tell their tales.
Shywim 5 hours ago [-]
You can request an expedite review from Apple. We already did this, and our app was up in the next 1-2 hours.
6 hours ago [-]
wouldbecouldbe 8 hours ago [-]
For new accounts yes, for older accounts it's much faster in my experience.
Apple has it's own issues, they often just answer with a random question so they can kick the review down the line. "Are you sure this is your pricing?" "Can you confifrm you have not selected that country" and then you have to wait another 2 days.
account42 8 hours ago [-]
TFA is a post from an established developer and showing a screenshot for the submission of an update to a longstanding app (Conversations XMPP chat client).
That's been happening randomly to me.
It let users cash out their Google Play Credits for real cash, which I automatically wired them.
Someone then hacked in to a major bookstore chain, stole piles of Google Play Gift cards, activated them using their access, and used my app to get cash for them.
Luckily, the whole thing blew up on me before I got in serious trouble, rightfully so, and the app was removed by Google, then an investigation followed. A ton of copycat apps popped up immediately after, then a few months months later Google announced their app review process.
It was risky because I didn't actually receive any money from Google until about a month later.
I’m curious how you didn’t get into money laundering problems.
I was investigated and cooperated fully.
Edit: I just remembered, the bank I used for the transference did do KYC for all users who were sent funds. This makes it more like "money dirtying", since the account is tied directly to a real identity.
I really want to know what the intended design or use case was for this? This is why people usually only let you turn credits into in app balances right
I only created it because I had Google Play Credits that were gifted to me. I built an app to "convert" them to cash for myself. I had never built an app before. I was proud of it and tried to make it pretty and professional and useful for others, and used it as a learning experience. The listing on the Play Store was clear about what it was.
I had to answer questions about what the API was being used for when I signed up for Dwolla (an actual regulated money transference service). I answered honestly. They approved it.
The app sat unused with no downloads for years before someone on Reddit's `r/churning/` posted about it.
I guess if you're young...
I created it back in 2011 or 2012.
It wasn't a gift card that personally motivated me to make this. It was credits from an online referral program I was gifted. I guarantee I did not read the fine print at that time.
Their review process is advocated as usually within 24 hours (and heavily advertised by Apple as such, see https://developer.apple.com/distribute/app-review/) and it is taking now much longer.
In the last month, I had to go through the review process twice, and twice I needed to contact them personally after waiting for 1 week of waiting. It did however helped, after every human contact I was reviewed within a few hours.
I got this explanation from them...
> We are currently experiencing a higher-than-normal amount of inquiries and have been unable to respond in the time frame that we would prefer. During these periods of high volume, the app review time will take longer than average, and we cannot currently provide a concrete timeline for when your specific app(s) will be finished with the process
I'm guessing, AI slots invading the store.
Well, same as my lack of sympathy for github and their "inability" to deal with "unprecedented AI generated traffic", I dont buy it. Seems really simple to setup an algorithm of "existing app from pre-AI is submitting another update gets put in the priority queue while everyone else gets the shared queue".
I know Github's commit numbers have been pretty staggering YoY.
Wonder how it will change app stores for the future.
The easiest way to count how many apps you have is to turn off automated updates and wait a week. The number of updates equals the number of apps.
I have never seen Apple approving within 24 hours
Also, sometimes, apps will go in review and then just stay in that state for 3-4 days before approval. No idea why.
This is the reason I never made a mobile version and all mobile users use it in a browser.
The biggest problem (bug) with this approach is that iOS limits the RAM usage to 2 GB per website. I have to tell many of my users to ditch their $1000 iPads and get a used $150 Macbook for better experience.
I think Apple does it on purpose https://bugs.webkit.org/show_bug.cgi?id=268816
Apple consistently takes about 36 hours for us.
The next update won't be huge, (Google required us to make all screens 'edge to edge'[0], which took up most of my time last month). I'm hoping for some solid improvements now that's out the way, once the release pipeline has returned to normal.
Feel free to get in touch if you fancy contributing.
[0] https://developer.android.com/develop/ui/views/layout/edge-t...
The way I did it was to firstly get accessibility identifiers on everything. Then have it record everything I do on an emulator to navigate the entire app. Then left it for a while to work out how to actually use the app via the emulator. Once you have this sort of baseline. A lot of changes are really quite pleasant. I often ask for an HTML gallery of screenshots covering a few device sizes as the step before I bother running it on a device myself.
* We target minSdk 24
* We're still using XML views
* We target a large variety of form factors
* We have a lot of screens, and these have a lot of configuration options.
I really wish it was "point an agent at it, and walk away", but many screens ended up being hours of iteration with Fable driving my phone/an emulator to produce an acceptable outcome.
Given that my Pixel 9 Pro has system screens which are still broken under edge to edge, it's not an easy change, and takes up time which could have been going towards feature development.
[0] https://github.com/takahirom/roborazzi/
The Google Play process is more thorough. There are a lot of steps and you need to clear them one by one. This means waiting several days between each step. The Play Console dashboard is quite well documented to be honest but can be overwhelming. The main obstacle is that you need to find at least 12 testers to play your game for 2 weeks straight. I ended up paying a service to test my app.
On iOS, the process is a bit more obscure. It's fairly easy to submit an app, but then you don't really know what's happening. You can only see a status like "Pending review". And then one day, you are approved.
Overall, the iOS process felt easier for me. As long as your build succeeds and you provide the correct information, your game can be live within a week. The Android process took more than a month in total.
[1] https://jgthms.com/hopera/
Once you get over that hurdle for your first release, at least you don't have to do it for every update.
The Play Console is a bit fiddly and I'm always getting random warnings that I need to comply with some new rule by an arbitrary date or my app will get delisted.
[1] https://play.google.com/store/apps/details?id=com.gads.hamil...
That's an understatement and a half. It's massively over engineered and complicated, especially when compared with (say) the dashboard on Itch.
I wrote about it a while ago, might be time to upsate that post. https://webtoapp.design/blog/time-to-publish-apps
The explosion in LLM app development has clearly created a bottleneck at the human review steps. Not only delays but much more “dumb” rejections from likely over-stressed humans.
https://vester.si/ai-impact/appstore/
Before that we had a hotfix update (a very small change) and still it took longer than a week and a support ticket (after which it had been approved in a day)...
Was only 48-72 hours until this year, where it randomly jumped to 2 weeks or longer like it still is.
It's really frustrating, and makes it very difficult to develop with, let alone reliably release features across platforms.
Google just seems to fly through and fill out a bunch of forms (we had to include a condition where if the google tester credentials logs in, we switch the app to the staging API). And then it's live within the hour.
And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.
As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.
If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.
We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.
Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.
Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
They were a massive issue before, and now they're barely a thought for most people.
These review processes have been good for the general population.
And I'm sure everyone remembers ransomware.
No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.
I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
Even though review processeses generally do not exist for computers, they are part of that same trend.
Vulnerabilities aren't intentional.
> reviewed apps that were used for fraud or access as bad actors
The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".
1. don't force auto-updates
2. still review apps uploaded to Google Play, but don't force users to use Google Play
If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
So this doesn't solve the issue pointed in the OP.
> don't force auto-updates
I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing
Yes it does. This is their point:
> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.
It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.
We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.
Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.
> Windows
I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
I don't really understand why a well designed sandbox and permissions system doesn't solve the problem.
If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.
People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
Lets stop talking about open source as special snowflakes where everything is excused.
Lets strive for quality in software.
Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.
But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.
Anyone is allowed to sue the lawnmower company. Did they win?
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.
Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.
For free (like for real no microtransactions) that is different. For the rest, they already have that.
As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
If you're banned from Google? Good luck, you're fucked.
I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).
Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.
Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.
The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually
People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
[1] General purpose computing
When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
It could also be asking for it to help advertisers build a robust behavioral profile about you.
This is not a systems permission, nor is it something that billions of users can judge the ramifications of each potential privacy impacting decision. Privacy is a systems property, not a technical property enforced with ACLs. ACLs can only keep the door from being wide open, they can't prevent access which has been granted from being abused or help the user understand ramifications of granting access.
We need privacy to be a regulatory concern with actual enforcement via an international framework. Until then, it is a business concern of Apple/Google - because they are in the business of having consumers feel confident that a weather app isn't reporting their behavior to anyone willing to pay for it.
There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere.
The current US government won't do anything to follow suit, but hopefully a future one might.
So does that mean:
1. People in the EU can continue to use F-Droid etc. exactly as they have in the past, permanently? No Google verification of developers needed? 2. People are free to install apps from any APK they choose?
It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked.
The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.
Do you want to bring back those glorious days?
Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.
Code signing with warnings about non-signed apps is enough
I remember in Bitcoin community ~10 years ago, standard recommendation was than an iOS wallet was secure enough (I don't recall even a single case where wallet was stolen via malware), but any private keys on Windows were strongly discouraged, as most cases of stolen wallets were on Windows.
I'd say popularity of iPhone shows which way people prefer, but you do you - what prevents you from voting with your wallet and buying a Linux phone?..
The reason is because Bill Gates put out a memo because it was fucking embarrassing that you could trivially smash the stack on default open API endpoints for services that consumers never used and shouldn't have been trivially routable from the open web in the first place.
Meanwhile in app stores, you don't have to hack anything, because consumers just download your botnet software willingly and directly.
42% of all apps on LG smart TVs turned your TV into a "residential proxy" botnet participant. 30% on Samsung TVs. There is no "hacking" in the world of apps because it's completely normalized for whatever app you build to also for some reason include remote control functionality from like 6 different companies. All of those apps pass review no problem.
As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.
Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money:
https://www.macrumors.com/2026/07/27/apple-app-store-fake-bi...
This is exactly why I use a GNU/Linux phone that runs a desktop operating system with no artificial restrictions. Debian repositories are good enough to save me from malware, aren't they?
And yes, they also have apps besides games on their stores, and support external keyboards and mices.
Anyone can put up a PWA. The only org that hates this is Apple.
The complaint is about a shared resource, which would require governments to adopt open source policies and _pay_ for it just like they do the post office.
But ya'll hate government, so here we are.
This is all documented in great detail in the links i shared
Paradoxically, as long as WebKit is mandatory on iOS, the open web is safe: Websites have to build for a lowest common denominator standard instead of building for Chrome proprietary APIs.
Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.
I imagine nearly all the security review is automated scans, and not the source of the delays.
this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.
I dont trust it.
The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.
FYI Samsung's is even worse.. 6-8 weeks. Hope you get it right the first time you submit your app.
I submitted Signage Sync (https://signagesync.app) last year, still on my third review. Fingers crossed:)
Endless more information on all of this at
https://infrequently.org/series/browser-choice-must-matter/
https://open-web-advocacy.org
Remember, Blink began as Google's 2013 fork of WebKit. They've embraced and extended it, but thankfully the "extinguish" step is taking longer than they thought. This makes the "open web, as long as it's my engine" people upset.
Safari's PWA support is not as complete as Chrome's today, but it's as good as Firefox's support and perfectly capable of supporting rich, standards-based apps. https://pwascore.com/
I'll simply say that if you bothered reading anything (let alone objectively), you'd clearly see that no one is arguing for a blink monoculture. They're arguing for allowing everyone to choose whichever browser and browser engine that you want. Safari included.
The math isnt mathing on that site... And, no, safari is NOT capable of PWAs - which is the primary point of contention (not obscure APIs, though safari generally lags in all of that as well). They deliberately hobble PWAs and make them very difficult to install.
edit: also, your site is just obviously biased/poorly done, because there exist many better comparisons of web features, which show how vastly far behind Safari is, often even of Firefox. This is unsurprising given your chosen style of rhetoric
https://wpt.fyi/
https://webstatus.dev/
> And, no, safari is NOT capable of PWAs…
Incorrect, see my link. PWA installation on iOS is simple and idiomatic, and the same as it is for all websites: Share > Add to Home Screen.
your argument amounts to "this person is incapable of being objective, let alone decent, because they work at xyz". Moreover, you literally didn't address a single thing presented in either link that i shared - which directly refute your nonsense. Pure ad hominem, and worse.
You are not a serious person if you think that PWA installation is "simple and idiomatic on iOS". It is buried multiple menus, taps, drags etc... deep. Most chromium browsers present a button right in the address bar or at least conspicuously in the main menu. Moreover, they allow developers to ask for the ability to prompt users to install the app.
https://adactio.com/journal/18252
https://adactio.com/journal/22757
Apple forces their employees to debase themselves in order to defend this status quo. eg:
https://github.com/w3ctag/design-reviews/issues/1245
https://github.com/WebKit/standards-positions/issues/619
Take care. And keep that math not mathing!
> Share > Add to Home Screen.
Are you sure "share" is idiomatic here?
Also calling a 6 steps process simple is laughable. One-click prompt to install is simple and part of PWA API that safari doesn't implement.
If you can offer recommendations for data-based improvements, I'd sincerely appreciate it! It was made without any concern for Safari "winning", as is probably obvious since it has the lowest score. Methodology described here: https://pwascore.com/about
> We can completely leave to the side that your weighting scheme is surely arbitrary or perhaps even biased.
Hover on any number to see both "raw" and "with experimental/non-standard features" scores. If you do this to the overall score, you'll see that Firefox benefits the most from this.
Hit the share button, "Add to Home Screen" is very difficult to install?
It allows the users to discover my web app through the Google Play Store. My app was also available as a PWA but I mostly push the TWA currently.
Itch.io is an option for people who don't want to set up a site or handle payments. While they focus on games, they're cool with distributing non-games:
https://itch.io/blog/32835/itchio-isnt-just-for-games-check-...
I generally see my legal system create severe delays (regardless of how much that victimises or costs everyone involved)
Better a delay that getting your account closed without recourse. But you are right, years of conservative governments have starved the government and its services are slower than they should around the west world.
Very much likely an automated triage based on code change or complexity.
At the time I couldn't imagine paying $99 for an Apple Developer account and waiting a week to publish my app...
When Shopify announced their shift from React Native, this is actually what was on top of mind for me. Week+ delays for critical bugfixes is insane. Being able to patch things with OTA updates is tablestakes at this point.
Only apps that get flagged by the AI reviewer then have to go through a separate, slower human review process.
Google Play is regularly slower now than App Store Connect, which never used to be the case
Getting a new app on the store is a bit cumbersome, but it should be.
As someone new to the app publishing world I am surprised at how strict the requirements are, given the absolute dross you can find published.
A new era for choice and openness : https://android-developers.googleblog.com/2026/03/a-new-era-...
It's unfortunate the official f-droid client is an unusable mess. (I stopped using it years ago, maybe they fixed it.)
There's also f-droid classic, can't remember why I use foxy droid over it.
On the flip side, googles release infra provides much more functionality for apps that already has scale. I wish apple were more production oriented too.
This is fight for big dogs now.
What's most galling is that if you use CapacitorJS or similar you can ship app updates instantly to your users but if you write native first-class OS citizen apps you are penalized.
There is nothing quite so annoying as having a fix for a bug people are running into and have zero control over when it will get out to them.
[0]: https://github.com/proxybasehq/proxybase-gui
Perhaps I'm misunderstanding what you are saying here but less than a month ago I released a brand new app with no beta period, direct to production (white labeled app, which is why I didn't need a beta)
https://support.google.com/googleplay/android-developer/answ...
Possible reasons why your production access could not be granted include:
Just go back to the way it was before, and scan the apps with static analysis tools. This security theater is stupid and always was (for Apple and Google).
Ah yes, the extremely diverse offering of OpenAI, Google, Anthropic, Microsoft, and Mistral (a fake "euro" chatbot). Mozilla is truly a "people's" company.
Lesson in there.
Apple has it's own issues, they often just answer with a random question so they can kick the review down the line. "Are you sure this is your pricing?" "Can you confifrm you have not selected that country" and then you have to wait another 2 days.