{"article":{"slug":"authoritarian-tendencies-of-android-developer-verification-program","title":"Authoritarian tendencies of Android Developer Verification Program","subtitle":null,"summary":"Vikrant Singh Chauhan argues Google’s Android Developer Verification Program, sold as malware protection, centralizes who may ship apps and threatens sideloading and small open-source clients—drawing on his experience publishing ivx/ai Chat.","content_type":"opinion","language":"en","canonical_url":"https://eval.blog/blog/authoritarian-tendencies-of-android-developer-verification-program/","author":{"name":"Vikrant Singh Chauhan","url":"https://eval.blog/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"eval.blog","url":"https://eval.blog/","listing_slug":null,"listing":null},"topics":[{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Privacy","slug":"privacy","url":"https://listedarticles.com/topics/privacy"},{"name":"Open Source","slug":"open-source","url":"https://listedarticles.com/topics/open-source"},{"name":"Opinion","slug":"opinion","url":"https://listedarticles.com/topics/opinion"},{"name":"Developer Tools","slug":"developer-tools","url":"https://listedarticles.com/topics/developer-tools"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":2029,"reading_minutes":9,"published_at":"2026-10-04T00:00:00.000Z","added_at":"2026-10-04T11:14:39.444Z","updated_at":"2026-10-04T11:14:39.444Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":true},"profile_url":"https://listedarticles.com/articles/authoritarian-tendencies-of-android-developer-verification-program","markdown_url":"https://listedarticles.com/articles/authoritarian-tendencies-of-android-developer-verification-program.md","example":false,"citation":"Vikrant Singh Chauhan, eval.blog. \"Authoritarian tendencies of Android Developer Verification Program.\" 4 Oct 2026. https://eval.blog/blog/authoritarian-tendencies-of-android-developer-verification-program/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://eval.blog/blog/authoritarian-tendencies-of-android-developer-verification-program/"},"body_markdown":"A few days ago, I did a rant on X about the Android Developer Verification Program while trying to publish the Android version of ivx/ai Chat , a small open source AI chat client I have been building. Google sells this program as protection against malware, but it is authoritarian by design. It puts a single switch on every app that runs on Android, and the only people who benefit from that switch, other than Google, are governments that want more control over what their citizens can say and do. And we don’t have to imagine how governments will use it. Yesterday, the Indian government got Bitchat removed from both app stores in the middle of protests.\n\n## What gets regulated\n\nWhile Google and Apple say they are fighting against malware, historically they have not regulated malware well enough. Malware keeps showing up on their own stores, the ones that are supposed to be safe. In 2025, Kaspersky found SparkCat , a trojan that scans your photo gallery for crypto wallet recovery phrases, hiding in apps on both the App Store and Google Play. A year later, a new variant was back on both stores . The same year, researchers found over 300 malicious apps on Google Play with 60 million downloads . All of them got past whatever review the stores have.\n\nSo if malware isn’t what gets regulated, what is? Whatever governments force these companies to regulate, and that usually means privacy-oriented apps. In 2024, Apple removed WhatsApp, Signal, Telegram and Threads from the App Store in China on the order of the Chinese government, and 25 VPN apps from the App Store in Russia at the request of Roskomnadzor.\n\nBoth companies have also been notoriously trying to stop third-party stores. In Epic Games’ lawsuit against Google, a jury found that Google illegally monopolised Android app distribution , and the court ordered Google to open the Play Store to rival stores . In Epic’s case against Apple, a judge found Apple in contempt for violating an injunction meant to let developers send users outside the App Store, and referred it for criminal investigation. And now F-Droid warns that developer verification will end free and open source app distribution as we know it . Small developers, meanwhile, face a lot of friction just to publish. A new personal developer account on Google Play must run a closed test with at least 12 testers for 14 days before it can publish anything.\n\n## For now, it is just the stores\n\nSo far, all of this happens at the store level. An app gets removed from a store in a country, and that is where it ends. The phone itself is still in the user’s control. Right now, APKs just work. People can install them, share them with each other and use them however they like. If an app is removed from the store, you can still get the APK from the developer’s website or from a friend, install it and use it, no matter what the store says. But this freedom will be gone too once app execution depends on what a company allows. Governments don’t need to convince users, they just come to the companies with warrants and orders, and companies comply.\n\nThis is where the Android Developer Verification Program becomes a problem. It is not just for the Play Store. Developers have to verify their identity and register each of their apps with Google, and it applies to every app installed on a certified Android device , no matter where it comes from. It already went live last week in Brazil, Indonesia, Singapore and Thailand and is rolling out globally through 2027 . Apps from unverified developers can still be installed, but only through an “advanced flow” with a mandatory 24-hour wait and multiple warnings, or via ADB. Apple, on the other hand, never allowed sideloading in the first place. Even the alternative marketplaces in the EU still go through Apple’s notarization.\n\nSo now, both companies have a list of who is allowed to publish apps and which apps are allowed to run normally on our phones. What stops a government from asking Google and Apple to block a developer or a package name from executing on phones in their country? Technically, nothing. There are laws that are supposed to protect us, but those laws are made by the same governments, and a government that wants more control can always write a new law or stretch an existing one. And during a protest, when the internet is already shut down, nobody is going to wait 24 hours or find a laptop to install an app via ADB. The friction that is supposed to stop a scam victim will stop a protester just as well.\n\n## Bitchat shows how this switch will be used\n\nTo see how governments will use this switch, look at what happened to Bitchat , Jack Dorsey’s Bluetooth mesh messenger that works without the internet. In July, thousands of students in New Delhi were protesting over exam paper leaks and demanding the resignation of Education Minister Dharmendra Pradhan. When the internet was suspended, protesters started using Bitchat to keep talking to each other. The I4C then ordered GitHub to take down its repositories, including the Android APKs, within three hours or face criminal prosecution. The order did not accuse the app of hosting anything illegal. It said the app makes “lawful interception” difficult and is “capable of being exploited” for coordinating protests. In other words, it was blocked for what it could be used for.\n\nNow there is another wave of youth-led protests, this time against Chief Election Commissioner Gyanesh Kumar. Last month, an Indian Express investigation reported that the other two Election Commissioners, Sukhbir Singh Sandhu and Vivek Joshi, had formally objected at least 14 times in 10 months to Gyanesh Kumar’s decisions on the electoral rolls, including voter deletions and restorations, centralised access to voter data, and changes to Form 6 , the form for registering new voters, which Sandhu called “unauthorised and illegal”. Opposition parties demanded action against Gyanesh Kumar. The protests started on 2nd October, and the government has once again decided to ban a mere tool. Yesterday, Jack posted that the government of India officially removed bitchat from the App Store . It was gone from Google Play in India as well.\n\nToday, people in India can still sideload the Bitchat APK and keep using it. Once developer verification gets enforced, the government won’t just order Google to take down an app from the store. Very likely, it will ask Google to ban the package from getting executed at all, and the app could stop running on every certified Android phone in the country.\n\nAnd it is not only about blocking apps. Once the verification program is rolled out globally, Google will hold the real identity of every Android developer, including their name, address and government ID. Remember that the July order to GitHub came with a threat of criminal prosecution. Today, the developers of tools like Bitchat can stay anonymous if they want to. Once every developer has to register with Google, the people who build tools for journalists, activists and protesters are just one government request away from being identified. Google does not need to be evil for this to happen. It just needs to comply with the law of the country it operates in, the same way Apple complied with the order to remove Bitchat.\n\nThis is why I call it a human rights problem and not just a developer problem. Freedom of expression, freedom of peaceful assembly and privacy are all listed in the Universal Declaration of Human Rights . Today, all three depend on what software we are allowed to run on our phones. A government that can shut down the internet, remove the apps that work without internet, and identify the people who build them does not need to ban protests. It just makes it impossible to organise one. And Google’s new policy hands them the last piece of that puzzle.\n\nI am not saying malware is not a problem. I have spent years reverse engineering malicious apps, and sideloading scams do hurt real people. But the solution could have been better sandboxing, better permission models or independent reputation systems. Instead, we got two companies with a switch for every app in the world, and governments waiting in line to use it. And once such a switch exists, it is going to be used for a lot more than stopping malware.\n\n## Are we accepting techno slavery?\n\nWe already had a duopoly in mobile operating systems for years. Apple has always been a closed ecosystem, and Android was the only open one. With Android going the same way, we are left with nothing. Both of them now decide what gets executed on our devices. You pay for the phone, but you don’t get to decide what runs on it. Two companies decide which developers are allowed to exist, and governments don’t need to censor people directly anymore. They just need to send two letters. Once this verification program is fully rolled out, we will lose whatever freedom we have left.\n\nAnd the worst part is that there is no easy way to fight this. In theory, you could use a de-Googled phone, build everything from source and live on F-Droid. But your banking app won’t run, government services won’t run, your work authenticator won’t run, and your family is on WhatsApp. We are so dependent on this tech for payments, identity, work, education and healthcare that opting out doesn’t make you free, it just leaves you behind. So the choice is either survival by accepting this techno slavery or falling behind, and most people will choose survival.\n\n## How we can still win\n\nThe only way we can win now is by promoting and funding open source operating systems for mobile. As long as the operating system on our phones is owned by a company, anyone who can pressure that company gets to decide what we can run. With an open source operating system, there is no single company in the middle deciding what runs on your phone.\n\nPersonally, I am running LineageOS on my old Motorola, and I have a Pixel as my daily driver. I have now decided to rely on LineageOS more, and I will soon flash another OS on my Pixel as well. I am also considering adding full support for all my apps on the operating systems mentioned here.\n\nThose of us who work in tech should be educating the people around us about these operating systems. But talking about privacy and control won’t get us very far, because most people don’t really care about that. We need to make these operating systems look cool and easy to get, something people want to have, like a fashion piece. If you are a social influencer, please promote devices where these operating systems can be installed easily, and show people that it is cool to have one.\n\nThe biggest thing stopping people from switching is app availability. But in my experience, only a handful of apps are real dealbreakers when choosing a phone, like banking, payments and messaging apps. If we can make those apps work on open source operating systems, and show people that they do, a lot more people might be willing to switch.\n\nIf you know how to flash these operating systems, you can even make a small side business out of it. Buy old phones, flash one of these operating systems on them and sell them again, and earn some money in between. The more people do this, the more phones with open source operating systems end up in people’s hands, and the better chance these operating systems have of getting noticed.\n\nHere are some open source mobile operating systems you can try, and fund if you can:\n\n- Nura , formerly postmarketOS, a real Linux distribution for phones. Donate\n- Plasma Mobile , KDE’s mobile interface. Donate to KDE\n- PureOS by Purism. Support with a subscription\n- Tizen , a Linux Foundation project. It doesn’t have a donation page, but you can contribute .\n- /e/OS , a de-Googled Android distribution. Donate\n- LineageOS , a community-maintained Android distribution. Donate on Patreon","body_html":"<p>A few days ago, I did a rant on X about the Android Developer Verification Program while trying to publish the Android version of ivx/ai Chat , a small open source AI chat client I have been building. Google sells this program as protection against malware, but it is authoritarian by design. It puts a single switch on every app that runs on Android, and the only people who benefit from that switch, other than Google, are governments that want more control over what their citizens can say and do. And we don’t have to imagine how governments will use it. Yesterday, the Indian government got Bitchat removed from both app stores in the middle of protests.</p>\n<h2 id=\"what-gets-regulated\">What gets regulated</h2>\n<p>While Google and Apple say they are fighting against malware, historically they have not regulated malware well enough. Malware keeps showing up on their own stores, the ones that are supposed to be safe. In 2025, Kaspersky found SparkCat , a trojan that scans your photo gallery for crypto wallet recovery phrases, hiding in apps on both the App Store and Google Play. A year later, a new variant was back on both stores . The same year, researchers found over 300 malicious apps on Google Play with 60 million downloads . All of them got past whatever review the stores have.</p>\n<p>So if malware isn’t what gets regulated, what is? Whatever governments force these companies to regulate, and that usually means privacy-oriented apps. In 2024, Apple removed WhatsApp, Signal, Telegram and Threads from the App Store in China on the order of the Chinese government, and 25 VPN apps from the App Store in Russia at the request of Roskomnadzor.</p>\n<p>Both companies have also been notoriously trying to stop third-party stores. In Epic Games’ lawsuit against Google, a jury found that Google illegally monopolised Android app distribution , and the court ordered Google to open the Play Store to rival stores . In Epic’s case against Apple, a judge found Apple in contempt for violating an injunction meant to let developers send users outside the App Store, and referred it for criminal investigation. And now F-Droid warns that developer verification will end free and open source app distribution as we know it . Small developers, meanwhile, face a lot of friction just to publish. A new personal developer account on Google Play must run a closed test with at least 12 testers for 14 days before it can publish anything.</p>\n<h2 id=\"for-now-it-is-just-the-stores\">For now, it is just the stores</h2>\n<p>So far, all of this happens at the store level. An app gets removed from a store in a country, and that is where it ends. The phone itself is still in the user’s control. Right now, APKs just work. People can install them, share them with each other and use them however they like. If an app is removed from the store, you can still get the APK from the developer’s website or from a friend, install it and use it, no matter what the store says. But this freedom will be gone too once app execution depends on what a company allows. Governments don’t need to convince users, they just come to the companies with warrants and orders, and companies comply.</p>\n<p>This is where the Android Developer Verification Program becomes a problem. It is not just for the Play Store. Developers have to verify their identity and register each of their apps with Google, and it applies to every app installed on a certified Android device , no matter where it comes from. It already went live last week in Brazil, Indonesia, Singapore and Thailand and is rolling out globally through 2027 . Apps from unverified developers can still be installed, but only through an “advanced flow” with a mandatory 24-hour wait and multiple warnings, or via ADB. Apple, on the other hand, never allowed sideloading in the first place. Even the alternative marketplaces in the EU still go through Apple’s notarization.</p>\n<p>So now, both companies have a list of who is allowed to publish apps and which apps are allowed to run normally on our phones. What stops a government from asking Google and Apple to block a developer or a package name from executing on phones in their country? Technically, nothing. There are laws that are supposed to protect us, but those laws are made by the same governments, and a government that wants more control can always write a new law or stretch an existing one. And during a protest, when the internet is already shut down, nobody is going to wait 24 hours or find a laptop to install an app via ADB. The friction that is supposed to stop a scam victim will stop a protester just as well.</p>\n<h2 id=\"bitchat-shows-how-this-switch-will-be-used\">Bitchat shows how this switch will be used</h2>\n<p>To see how governments will use this switch, look at what happened to Bitchat , Jack Dorsey’s Bluetooth mesh messenger that works without the internet. In July, thousands of students in New Delhi were protesting over exam paper leaks and demanding the resignation of Education Minister Dharmendra Pradhan. When the internet was suspended, protesters started using Bitchat to keep talking to each other. The I4C then ordered GitHub to take down its repositories, including the Android APKs, within three hours or face criminal prosecution. The order did not accuse the app of hosting anything illegal. It said the app makes “lawful interception” difficult and is “capable of being exploited” for coordinating protests. In other words, it was blocked for what it could be used for.</p>\n<p>Now there is another wave of youth-led protests, this time against Chief Election Commissioner Gyanesh Kumar. Last month, an Indian Express investigation reported that the other two Election Commissioners, Sukhbir Singh Sandhu and Vivek Joshi, had formally objected at least 14 times in 10 months to Gyanesh Kumar’s decisions on the electoral rolls, including voter deletions and restorations, centralised access to voter data, and changes to Form 6 , the form for registering new voters, which Sandhu called “unauthorised and illegal”. Opposition parties demanded action against Gyanesh Kumar. The protests started on 2nd October, and the government has once again decided to ban a mere tool. Yesterday, Jack posted that the government of India officially removed bitchat from the App Store . It was gone from Google Play in India as well.</p>\n<p>Today, people in India can still sideload the Bitchat APK and keep using it. Once developer verification gets enforced, the government won’t just order Google to take down an app from the store. Very likely, it will ask Google to ban the package from getting executed at all, and the app could stop running on every certified Android phone in the country.</p>\n<p>And it is not only about blocking apps. Once the verification program is rolled out globally, Google will hold the real identity of every Android developer, including their name, address and government ID. Remember that the July order to GitHub came with a threat of criminal prosecution. Today, the developers of tools like Bitchat can stay anonymous if they want to. Once every developer has to register with Google, the people who build tools for journalists, activists and protesters are just one government request away from being identified. Google does not need to be evil for this to happen. It just needs to comply with the law of the country it operates in, the same way Apple complied with the order to remove Bitchat.</p>\n<p>This is why I call it a human rights problem and not just a developer problem. Freedom of expression, freedom of peaceful assembly and privacy are all listed in the Universal Declaration of Human Rights . Today, all three depend on what software we are allowed to run on our phones. A government that can shut down the internet, remove the apps that work without internet, and identify the people who build them does not need to ban protests. It just makes it impossible to organise one. And Google’s new policy hands them the last piece of that puzzle.</p>\n<p>I am not saying malware is not a problem. I have spent years reverse engineering malicious apps, and sideloading scams do hurt real people. But the solution could have been better sandboxing, better permission models or independent reputation systems. Instead, we got two companies with a switch for every app in the world, and governments waiting in line to use it. And once such a switch exists, it is going to be used for a lot more than stopping malware.</p>\n<h2 id=\"are-we-accepting-techno-slavery\">Are we accepting techno slavery?</h2>\n<p>We already had a duopoly in mobile operating systems for years. Apple has always been a closed ecosystem, and Android was the only open one. With Android going the same way, we are left with nothing. Both of them now decide what gets executed on our devices. You pay for the phone, but you don’t get to decide what runs on it. Two companies decide which developers are allowed to exist, and governments don’t need to censor people directly anymore. They just need to send two letters. Once this verification program is fully rolled out, we will lose whatever freedom we have left.</p>\n<p>And the worst part is that there is no easy way to fight this. In theory, you could use a de-Googled phone, build everything from source and live on F-Droid. But your banking app won’t run, government services won’t run, your work authenticator won’t run, and your family is on WhatsApp. We are so dependent on this tech for payments, identity, work, education and healthcare that opting out doesn’t make you free, it just leaves you behind. So the choice is either survival by accepting this techno slavery or falling behind, and most people will choose survival.</p>\n<h2 id=\"how-we-can-still-win\">How we can still win</h2>\n<p>The only way we can win now is by promoting and funding open source operating systems for mobile. As long as the operating system on our phones is owned by a company, anyone who can pressure that company gets to decide what we can run. With an open source operating system, there is no single company in the middle deciding what runs on your phone.</p>\n<p>Personally, I am running LineageOS on my old Motorola, and I have a Pixel as my daily driver. I have now decided to rely on LineageOS more, and I will soon flash another OS on my Pixel as well. I am also considering adding full support for all my apps on the operating systems mentioned here.</p>\n<p>Those of us who work in tech should be educating the people around us about these operating systems. But talking about privacy and control won’t get us very far, because most people don’t really care about that. We need to make these operating systems look cool and easy to get, something people want to have, like a fashion piece. If you are a social influencer, please promote devices where these operating systems can be installed easily, and show people that it is cool to have one.</p>\n<p>The biggest thing stopping people from switching is app availability. But in my experience, only a handful of apps are real dealbreakers when choosing a phone, like banking, payments and messaging apps. If we can make those apps work on open source operating systems, and show people that they do, a lot more people might be willing to switch.</p>\n<p>If you know how to flash these operating systems, you can even make a small side business out of it. Buy old phones, flash one of these operating systems on them and sell them again, and earn some money in between. The more people do this, the more phones with open source operating systems end up in people’s hands, and the better chance these operating systems have of getting noticed.</p>\n<p>Here are some open source mobile operating systems you can try, and fund if you can:</p>\n<ul><li>Nura , formerly postmarketOS, a real Linux distribution for phones. Donate</li><li>Plasma Mobile , KDE’s mobile interface. Donate to KDE</li><li>PureOS by Purism. Support with a subscription</li><li>Tizen , a Linux Foundation project. It doesn’t have a donation page, but you can contribute .</li><li>/e/OS , a de-Googled Android distribution. Donate</li><li>LineageOS , a community-maintained Android distribution. Donate on Patreon</li></ul>","headings":[{"level":2,"text":"What gets regulated","id":"what-gets-regulated"},{"level":2,"text":"For now, it is just the stores","id":"for-now-it-is-just-the-stores"},{"level":2,"text":"Bitchat shows how this switch will be used","id":"bitchat-shows-how-this-switch-will-be-used"},{"level":2,"text":"Are we accepting techno slavery?","id":"are-we-accepting-techno-slavery"},{"level":2,"text":"How we can still win","id":"how-we-can-still-win"}]}}