Re: GR -- Sign open letter to keep allowing users to install apps on android
Simon Richter <[email protected]>
| Newsgroups | gmane.linux.debian.devel.vote |
|---|---|
| Message-ID | <[email protected]> |
Hi,
On 4/4/26 01:14, Salvo Tomaselli wrote:
> So my proposal is for Debian to sign this, since it could add some weight
> https://keepandroidopen.org/open-letter/
We'll probably need some sort of a resolution text to vote on, so that
if the press picks this up, they have something to quote -- and also for
formal as well as developer laziness reasons, the resolution text should
probably be self contained.
So, a possible full resolution text would be below, feel free to suggest
improvements, as this is really barebone.
Simon
----- 8< -----
The Debian project signs the "Keep Android Open" open letter to Google,
which can be found at https://keepandroidopen.org/open-letter/ and is
reproduced here for reference:
We, the undersigned organizations representing civil society, nonprofit
institutions, and technology companies, write to express our strong
opposition to Google’s announced policy requiring all Android app
developers to register centrally with Google themselves in order to
distribute applications outside of the Google Play Store, set to take
effect worldwide in the coming months.
While we do recognize the importance of platform security and user
safety, the Android platform already includes multiple security
mechanisms that do not require central registration. Forcibly injecting
an alien security model that runs counter to Android’s historic open
nature threatens innovation, competition, privacy, and user freedom. We
urge Google to withdraw this policy and work with the open-source and
security communities on less restrictive alternatives.
Our Concerns
1. Gatekeeping Beyond Google’s Own Store
Android has historically been characterized as an open platform where
users and developers can operate independently of Google’s services. The
proposed developer registration policy fundamentally alters that
relationship by requiring developers who wish to distribute apps through
alternative channels — their own websites, third-party app stores,
enterprise distribution systems, or direct transfers — to first seek
permission from Google through a mandatory verification process, which
involves the agreement to Google’s terms and conditions, the payment of
a fee, and the uploading of government-issued identification.
This extends Google’s gatekeeping authority beyond its own marketplace
into distribution channels where it has no legitimate operational role.
Developers who choose not to use Google’s services should not be forced
to register with, and submit to the judgement of, Google. Centralizing
the registration of all applications worldwide also gives Google
newfound powers to completely disable any app it wants to, for any
reason, for the entire Android ecosystem.
2. Barriers to Entry and Innovation
Mandatory registration creates friction and barriers to entry,
particularly for:
Individual developers and small teams with limited resources
Open-source projects that rely on volunteer contributors
Developers in regions with limited access to Google’s registration
infrastructure
Privacy-focused developers who avoid surveillance ecosystems
Emergency response and humanitarian organizations requiring rapid
deployment
Activists working on internet freedom in countries that unjustly
criminalize that work
Developers in countries or regions where Google cannot allow them
to sign up due to sanctions
Researchers and academics developing experimental applications
Internal enterprise and government applications never intended for
broad public distribution
Every additional bureaucratic hurdle reduces diversity in the software
ecosystem and concentrates power in the hands of large established
players who can more easily absorb such compliance costs.
3. Privacy and Surveillance Concerns
Requiring registration with Google creates a comprehensive database of
all Android developers, regardless of whether or not they use Google’s
services. This raises serious questions about:
What personal information developers must provide
How this information will be stored, secured, and used
Whether this data could be subject to government requests or legal
processes
To what extent developer activity is tracked across the ecosystem
What this means for developers working on privacy-preserving or
politically sensitive applications
Developers should have the right to create and distribute software
without submitting to unnecessary surveillance or scrutiny.
4. Arbitrary Enforcement and Account Termination Risks
Google’s existing app review processes have been criticized for opaque
decision-making, inconsistent enforcement, and limited appeal
mechanisms. Extending this system to all Android certified devices
creates risks of:
Arbitrary rejection or suspension without clear justification
Automated systems making consequential decisions with insufficient
human oversight
Developers losing their ability to distribute apps across all
channels due to a single un-reviewable corporate decision
Political or competitive considerations influencing registration
approvals
Disproportionate impact on marginalized communities and
controversial but legal applications
A single point of failure controlled by one corporation is antithetical
to a healthy, competitive software ecosystem.
5. Anticompetitive Implications
This requirement allows Google to collect intelligence on all Android
development activity, including:
Which apps are being developed and by whom
Alternative distribution strategies and business models
Competitive threats to Google’s own services
Market trends and user preferences outside of Google’s ecosystem
This information asymmetry provides Google with significant competitive
advantages, allows it to preempt, copy, and undermine competing products
and services, and may open many questions about antitrust.
6. Regulatory concerns
Regulatory authorities worldwide, including the European Commission, the
U.S. Department of Justice, and competition authorities in multiple
jurisdictions, have increasingly scrutinized dominant platforms’ ability
to preference their own services and restrict competition, demanding
more openness and interoperability. We additionally note growing
concerns around regulatory intervention increasing mass surveillance,
impeding software freedom, open internet and device neutrality.
We urge Google to find alternative ways to comply with regulatory
obligations by promoting models that respect Android’s open nature
without increasing gatekeeper control over the platform.
Existing Measures Are Sufficient
The Android platform already includes multiple security mechanisms that
do not require central registration:
Operating system-level security features, application sandboxing,
and permission systems
User warnings for applications that are directly installed (or
“sideloaded”)
Google Play Protect (which users can choose to enable or disable)
Developer signing certificates that establish software provenance
No evidence has been presented that these safeguards are insufficient to
continue to protect Android users as they have for the entire seventeen
years of Android’s existence. If Google’s concern is genuinely about
security rather than control, it should invest in improving these
existing mechanisms rather than creating new bottlenecks and
centralizing control.
Our Petition
We call upon Google to:
Immediately rescind the mandatory developer registration
requirement for third-party distribution.
Engage in transparent dialogue with civil society, developers, and
regulators about Android security improvements that respect openness and
competition.
Commit to platform neutrality by ensuring that Android remains a
genuinely open platform where Google’s role as platform provider does
not conflict with its commercial interests.
Over the years, Android has evolved into a critical piece of
technological infrastructure that serves hundreds of governments,
millions of businesses, and billions of citizens around the world.
Unilaterally consolidating and centralizing the power to approve
software into the hands of a single unaccountable corporation is
antithetical to the principles of free speech, an affront to free
software, an insurmountable barrier to competition, and a threat to
digital sovereignty everywhere.
We implore Google to reverse course, end the developer verification
program, and to begin working collaboratively with the broader community
to advance security objectives without sacrificing the open principles
upon which Android was built. The strength of the Android ecosystem has
historically been its openness, and Google must work towards restoring
its role as a faithful steward of that trust.
----- 8< -----
OpenPGP_signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEtjuqOJSXmNjSiX3Tfr04e7CZCBEFAmnQnOMACgkQfr04e7CZ CBHfUggAnRa362zxH5BmuxdB+zZ0wg2uCTUd3xY39GqV0lZjBznBNBogb2woKLLD nidkv2sKL18wEErYyUV28JE5k8F5UMEIgSSGlN32z6G/4P6fifmXAzj+IH3WhOns u06gV996IRSbFtU8iY0AGitgvpHstsQJtCJmsPEYp3okNPaMTJJ9EWFiFivjW4xW xrfWT/sIZFsWlxWxCRAmyQv+lWQa3CuRHt/rqwuk/5F9WMClWzRfCz5TT3LAoMGm mVGC7xaika67wlPTPhfaUFcybQmMIvEjVPn0OqrfygpaqtlE/4kAUxlD46XAZLBV 5wwQTNCi+wpzQhmpJJoeyGANwQrjsQ== =sITP -----END PGP SIGNATURE-----