Hacker News new | ask | show | jobs
by ysnp 30 days ago
Can Android OEMs, bundling Google Mobile Services for Android certification, choose different trust roots for verification?

>The correct thing to complain about is requiring developer mode for unverified installs, which doesn't seem necessary

I had assumed the friction was to dissuade developers from not going through ADV. Isn't it partly for making malware distribution more traceable and campaigns easier to halt on GMS/certified Android systems?

1 comments

> Can Android OEMs, bundling Google Mobile Services for Android certification, choose different trust roots for verification?

They can already install additional system app stores, so it would surprise me if they can't allow additional verifiers.

> Isn't it partly for making malware distribution more traceable

Enabling developer mode does not make malware distribution more traceable.