Re: GR -- Sign open letter to keep allowing users to install apps on android

Simon Richter <[email protected]>
Newsgroups gmane.linux.debian.devel.vote
Message-ID <[email protected]>
Hi,

On 4/4/26 01:14, Salvo Tomaselli wrote:

> So my proposal is for Debian to sign this, since it could add some weight
> https://keepandroidopen.org/open-letter/

We'll probably need some sort of a resolution text to vote on, so that 
if the press picks this up, they have something to quote -- and also for 
formal as well as developer laziness reasons, the resolution text should 
probably be self contained.

So, a possible full resolution text would be below, feel free to suggest 
improvements, as this is really barebone.

     Simon

----- 8< -----

The Debian project signs the "Keep Android Open" open letter to Google, 
which can be found at https://keepandroidopen.org/open-letter/ and is 
reproduced here for reference:

We, the undersigned organizations representing civil society, nonprofit 
institutions, and technology companies, write to express our strong 
opposition to Google’s announced policy requiring all Android app 
developers to register centrally with Google themselves in order to 
distribute applications outside of the Google Play Store, set to take 
effect worldwide in the coming months.

While we do recognize the importance of platform security and user 
safety, the Android platform already includes multiple security 
mechanisms that do not require central registration. Forcibly injecting 
an alien security model that runs counter to Android’s historic open 
nature threatens innovation, competition, privacy, and user freedom. We 
urge Google to withdraw this policy and work with the open-source and 
security communities on less restrictive alternatives.
Our Concerns

1. Gatekeeping Beyond Google’s Own Store

Android has historically been characterized as an open platform where 
users and developers can operate independently of Google’s services. The 
proposed developer registration policy fundamentally alters that 
relationship by requiring developers who wish to distribute apps through 
alternative channels — their own websites, third-party app stores, 
enterprise distribution systems, or direct transfers — to first seek 
permission from Google through a mandatory verification process, which 
involves the agreement to Google’s terms and conditions, the payment of 
a fee, and the uploading of government-issued identification.

This extends Google’s gatekeeping authority beyond its own marketplace 
into distribution channels where it has no legitimate operational role. 
Developers who choose not to use Google’s services should not be forced 
to register with, and submit to the judgement of, Google. Centralizing 
the registration of all applications worldwide also gives Google 
newfound powers to completely disable any app it wants to, for any 
reason, for the entire Android ecosystem.

2. Barriers to Entry and Innovation

Mandatory registration creates friction and barriers to entry, 
particularly for:

     Individual developers and small teams with limited resources
     Open-source projects that rely on volunteer contributors
     Developers in regions with limited access to Google’s registration 
infrastructure
     Privacy-focused developers who avoid surveillance ecosystems
     Emergency response and humanitarian organizations requiring rapid 
deployment
     Activists working on internet freedom in countries that unjustly 
criminalize that work
     Developers in countries or regions where Google cannot allow them 
to sign up due to sanctions
     Researchers and academics developing experimental applications
     Internal enterprise and government applications never intended for 
broad public distribution

Every additional bureaucratic hurdle reduces diversity in the software 
ecosystem and concentrates power in the hands of large established 
players who can more easily absorb such compliance costs.

3. Privacy and Surveillance Concerns

Requiring registration with Google creates a comprehensive database of 
all Android developers, regardless of whether or not they use Google’s 
services. This raises serious questions about:

     What personal information developers must provide
     How this information will be stored, secured, and used
     Whether this data could be subject to government requests or legal 
processes
     To what extent developer activity is tracked across the ecosystem
     What this means for developers working on privacy-preserving or 
politically sensitive applications

Developers should have the right to create and distribute software 
without submitting to unnecessary surveillance or scrutiny.

4. Arbitrary Enforcement and Account Termination Risks

Google’s existing app review processes have been criticized for opaque 
decision-making, inconsistent enforcement, and limited appeal 
mechanisms. Extending this system to all Android certified devices 
creates risks of:

     Arbitrary rejection or suspension without clear justification
     Automated systems making consequential decisions with insufficient 
human oversight
     Developers losing their ability to distribute apps across all 
channels due to a single un-reviewable corporate decision
     Political or competitive considerations influencing registration 
approvals
     Disproportionate impact on marginalized communities and 
controversial but legal applications

A single point of failure controlled by one corporation is antithetical 
to a healthy, competitive software ecosystem.

5. Anticompetitive Implications

This requirement allows Google to collect intelligence on all Android 
development activity, including:

     Which apps are being developed and by whom
     Alternative distribution strategies and business models
     Competitive threats to Google’s own services
     Market trends and user preferences outside of Google’s ecosystem

This information asymmetry provides Google with significant competitive 
advantages, allows it to preempt, copy, and undermine competing products 
and services, and may open many questions about antitrust.

6. Regulatory concerns

Regulatory authorities worldwide, including the European Commission, the 
U.S. Department of Justice, and competition authorities in multiple 
jurisdictions, have increasingly scrutinized dominant platforms’ ability 
to preference their own services and restrict competition, demanding 
more openness and interoperability. We additionally note growing 
concerns around regulatory intervention increasing mass surveillance, 
impeding software freedom, open internet and device neutrality.

We urge Google to find alternative ways to comply with regulatory 
obligations by promoting models that respect Android’s open nature 
without increasing gatekeeper control over the platform.
Existing Measures Are Sufficient

The Android platform already includes multiple security mechanisms that 
do not require central registration:

     Operating system-level security features, application sandboxing, 
and permission systems
     User warnings for applications that are directly installed (or 
“sideloaded”)
     Google Play Protect (which users can choose to enable or disable)
     Developer signing certificates that establish software provenance

No evidence has been presented that these safeguards are insufficient to 
continue to protect Android users as they have for the entire seventeen 
years of Android’s existence. If Google’s concern is genuinely about 
security rather than control, it should invest in improving these 
existing mechanisms rather than creating new bottlenecks and 
centralizing control.
Our Petition

We call upon Google to:

     Immediately rescind the mandatory developer registration 
requirement for third-party distribution.
     Engage in transparent dialogue with civil society, developers, and 
regulators about Android security improvements that respect openness and 
competition.
     Commit to platform neutrality by ensuring that Android remains a 
genuinely open platform where Google’s role as platform provider does 
not conflict with its commercial interests.

Over the years, Android has evolved into a critical piece of 
technological infrastructure that serves hundreds of governments, 
millions of businesses, and billions of citizens around the world. 
Unilaterally consolidating and centralizing the power to approve 
software into the hands of a single unaccountable corporation is 
antithetical to the principles of free speech, an affront to free 
software, an insurmountable barrier to competition, and a threat to 
digital sovereignty everywhere.

We implore Google to reverse course, end the developer verification 
program, and to begin working collaboratively with the broader community 
to advance security objectives without sacrificing the open principles 
upon which Android was built. The strength of the Android ecosystem has 
historically been its openness, and Google must work towards restoring 
its role as a faithful steward of that trust.

----- 8< -----
OpenPGP_signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEEtjuqOJSXmNjSiX3Tfr04e7CZCBEFAmnQnOMACgkQfr04e7CZ
CBHfUggAnRa362zxH5BmuxdB+zZ0wg2uCTUd3xY39GqV0lZjBznBNBogb2woKLLD
nidkv2sKL18wEErYyUV28JE5k8F5UMEIgSSGlN32z6G/4P6fifmXAzj+IH3WhOns
u06gV996IRSbFtU8iY0AGitgvpHstsQJtCJmsPEYp3okNPaMTJJ9EWFiFivjW4xW
xrfWT/sIZFsWlxWxCRAmyQv+lWQa3CuRHt/rqwuk/5F9WMClWzRfCz5TT3LAoMGm
mVGC7xaika67wlPTPhfaUFcybQmMIvEjVPn0OqrfygpaqtlE/4kAUxlD46XAZLBV
5wwQTNCi+wpzQhmpJJoeyGANwQrjsQ==
=sITP
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.