Google is taking what keeps them alive
Millions of people living under authoritarian governments, military occupation and drug cartels depend on apps built by people who can't send Google a passport. This month Google starts blocking them with their developer verification program.
There are apps that keep people alive every day, installed in different ways. Every one of them now needs Google's permission, not just the ones on the Play Store. I couldn't find anyone who looked at the humanitarian impact of this in real people and real numbers, so I'm going to take you on a world tour to show them to you.
Entire populations have no government willing to give them ID. Billions have no bank card Google will accept. Plenty have both and still won't connect their identity to their app, because they know what their government will do to them.
Google says this is for user safety, to stop fraud. I'll show you that checking developer ID doesn't work, and Google knows it.
We'll start with Nico Mexis, the type of person you might think of when someone says "app developer". He made StudiPassau covering a university in Bavaria. It shows what the canteen is serving, which room your seminar is in, and the campus news. He's not a student there anymore, but he still keeps it updated.
By the end of next year, Google's new policy demands he sends twenty-five dollars and a photograph of his passport. Or the cafeteria menu stops installing. I won't even ask why that's theirs to ask for. It's not the big problem.
Take the same requirement to the West Bank and hand it to whoever maintains Azmeh, a checkpoint map used by 70,000 Palestinians. It was built in 2015 by a twenty-year-old law student from East Jerusalem, taken offline for years after its creators were threatened by the Israeli military, and found its way back in 2023. When a reporter reached one of its developers last year, that developer spoke on condition of anonymity, fearing what the Israelis would do if they identified him.
"We are stranded for hours, sometimes from sunrise to sunset," Rakan Said, a minibus driver with 20 years of experience, told Rest of World. "Passengers can't reach jobs, and drivers lose their entire day's wages waiting at checkpoints."
This is not Waze telling you there's traffic on the 101. The UN counted almost a thousand checkpoints, roadblocks and other military-installed blocks at the start of the year. The WHO has logged 987 attacks on and delays to health care in the West Bank since October 2023. In July an infant died after a forty-kilometre detour at Deir 'Ammar. A woman in Sinjil died of cardiac arrest after being delayed at a closed military gate. This is what the map is for. Knowing which gate is open is the difference between reaching a hospital and not.
The Google policy: for an app to install normally, passing the new "developer verification" requires the developer to send legal name, address, government ID (more on this later), twenty-five dollars, and proof they hold the signing key, for basically every developer, on every channel, including the ones outside its own store entirely. Other app stores like F-Droid, even apps that people build and share themselves. It starts on 30 September in Brazil, Indonesia, Singapore and Thailand, and goes global in 2027.
The safety numbers just don't justify it, and what this is likely to cost is actual human lives.
Real people that Android helps keep safe and alive. Until now.
Health apps no store can carry
AndroidAPS is an open-source artificial pancreas: it reads a continuous glucose monitor, drives an insulin pump, and lets type 1 diabetics sleep through the night. It has never been on Google Play and never can be, for legal reasons its own documentation spells out. It exists because in 2013 John Costik, a software engineer at a supermarket company in upstate New York, worked out how to read the glucose monitor attached to his four-year-old son Evan, so he could watch the numbers from home while Evan was at daycare, and then posted the code publicly. A woman called Dana Lewis saw it. She'd been diagnosed with type 1 diabetes at fourteen and was frightened of going to sleep, because the alarm on her monitor was too quiet to wake her. She and Scott Leibrand built a louder one, then kept going, and ended up with an artificial pancreas. In her words:
Having a computer make adjustments while I sleep is far safer than trying groggily to make decisions in the early hours.
By 2018, more than 700 people were running one.
OpenSeizureDetector was written by Graham Jones for his son Benjamin, who has epilepsy, because the commercial monitors relied on bed sensors and Benjamin wouldn't sleep in a bed. A decade on it detects tonic-clonic seizures with a £35 watch and a cheap Android phone, no subscription and no internet connection, and wakes whoever is caring for you.
There are more out there, beyond diabetes and epilepsy. Actually, self-made apps are now a standard area of study in health care; it's a normal way for companies and universities to understand what's possible and what works.
They all start with a stranger publishing some code, asking nobody's permission, and it reaching somebody who was going to die without it.
Financial survival
In Argentina, after years of triple-digit inflation, knowing today's black-market dollar rate is the difference between spending your pesos now or losing value by tomorrow. Nobody big built that. It's covered by a scattering of solo-developers: Dólar App Argentina, running since 2019, built by someone who goes by 2nomadev; Argentina Dollar Rates, built and still maintained by Ramiro Gioia. A review of Dolar Blue Hoy, unprompted:
"I use every day to know about exchange rates."
They just built the thing their people needed, and even if an Argentinan happens to have the right kind of bank card that Google requires to sign up, $25 US dollars is a big ask to people in hyper-inflation turmoil. In simple terms, they can't afford it.
Day-to-day apps that aren't on Google Play
There are a lot of apps that aren't life-or-death but still a big part of daily life. Little apps with hundreds of users.
AmSprung gives departure times for Vienna's trams, named after a Viennese phrase for being about to leave, maintained by somebody who goes by uniqx and has never put a legal name to it.
Boky Fivavahana Anglikana is the complete Anglican prayer book for Madagascar, in Malagasy only, maintained by one person: Tsiory Rajaonirina.
Software like this is one of the reasons F-Droid exists. It holds four thousand apps, and says it cannot survive under Google's new policy. For fifteen years it has handled fraudulent apps effectively without knowing a single developer's legal name. It takes an app's published source code, builds the app itself, and signs the result with its own key, so what lands on your phone can be checked against code you can read. That's a stronger security model than Play's, because F-Droid checks every line of code rather than the paperwork of whoever uploaded a closed app file.
Google's new policy requires whoever holds the signing key to register each app. They haven't accounted for cases where multiply parties share parts of the process, like more than one developer or app stores like F-Droid that take care of the build step to protect end users. F-Droid cannot compel thousands of upstream authors to send documents to Google, and many of its contributors are pseudonymous on principle because being named for the software you write is dangerous where they live.
F-Droid's position hasn't changed since it started: a phone belongs to the person who bought it, and that person decides what runs on it. F-Droid built the answer, it works, and in fifteen years it has never asked anybody for a card.
The ones that are already disappearing
In May 2025, users of a popular app called v2rayNG noticed it had vanished from Google Play.
v2rayNG is a proxy client. It's one of the tools people in Iran, China and Russia use to reach the internet their governments have decided they shouldn't see. Its repository has over sixty thousand stars. It's made by somebody who signs their work 2dust and has never published a legal name.
Asked what had happened, 2dust answered in one sentence: 本应用无法完成认证,被 GooglePlay 下架了。 This app cannot complete the verification, so it was removed from Google Play.
It wasn't a policy violation and it wasn't malware. The developer, writing in Chinese, simply refused to identify themselves to Google.
A user in that same thread asked: when verification comes for direct installs too, what then? 2dust didn't say they would register. Mainland China had never depended on Google Play anyway; they'd see what actually arrived and deal with it then. 总是有办法的. There is always a way.
The way is a much harder way.
v2rayNG users now need three pieces of developer infrastructure. GitHub Releases, where the current build lists twenty-three separate files and the project has to link a document explaining which one you want. GPG, to check the signature and know the file wasn't swapped in transit by a mirror, an ISP or the state doing the censoring. And Obtainium, a third app that watches the release feed. Plenty of professional programmers have never set up GPG. And it's now what's advised for a school teacher in Jammu or a cook in Shanghai.
In Turkmenistan, the criminal code allows up to seven years in prison for installing circumvention software on somebody else's device. Seven years. For helping a neighbour talk to their daughter in London.
Meanwhile the state department that runs the blocking quietly sells access back, reportedly at fifty dollars a month for the basic tier or two thousand to remove the filtering entirely. Here, a minimum-wage worker already needs something like a fifth of their income on the official, censored connection.
Turkmenistan isn't alone. Iran, Russia, China, Myanmar, Belarus, Turkey, Pakistan and India all imprison people just for circumvention software, which is why v2rayNG has cousin apps everywhere.
The problems follow to apps that have nothing to do with VPNs.
Way Way Nay lists Myanmar businesses owned by the military so people can avoid buying from them. It passed 100,000 installs within ten days of launching after the coup, and its creator speaks to journalists only on condition of anonymity.
ProofMode signs a photograph as it's taken so it can later be shown not to have been altered, for the person filming something that will be denied. Briar passes messages phone to phone over Bluetooth and wifi when the network has been cut, which is the moment a government most wants you unable to talk. These are tools used by journalists and their sources. They know they need to publish on Google Play and F-Droid and a plain APK, because they can't depend on any single gatekeeper.
Except Google is now making itself the gatekeeper everywhere.
Half the world is cut out
Google's head office is in Mountain View, California. If you live there, asking for ID and a couple bucks doesn't seem like much. But actually, it cuts out half the world from registering their apps, and that means stopping half the world installing the specific community apps they need, on a phone they bought with their hard-earned money.
It's easy to assume the world's poorest people aren't technical enough to be app developers, but that's just not true if you go look. In Mumbai's Dharavi, girls built apps for communal water queues, rubbish collection and women's safety; in Havana, volunteers ran servers and modified software to keep a vast homemade network alive on improvised hardware; and in Nairobi's Mathare, residents who could not afford college learned development and began building websites and teaching coding inside the settlement. These are not exceptional people somehow escaping their surroundings; they are communities using software the same way people everywhere do: people learn to code, and write software to solve their problems.
No bank card
To put an app where the public can actually install it, a developer needs the full account. That costs twenty-five dollars, and Google mandates a government ID and a form of payment, both under your legal name. The money goes through Google Pay, which takes major card networks only and states plainly that prepaid cards are not accepted. Prepaid is what people without a bank relationship use. The World Bank's 2025 Findex counts about 6 billion adults worldwide, of whom roughly 3.3 billion own an account-linked debit card.
Half the world's adults do not have the payment instrument Google requires.
Their software can't be sent or installed normally now. And Androids are the only phones most people there can afford.
No ID
The World Bank counts about 850 million people with no ID any government will recognise, concentrated where a cheap Android phone is the only computer anyone owns. In the United States, a 2023 survey found 21.3 million citizens of voting age can't readily produce any citizenship document.
And documents now get stripped away as a political technique. India's National Register of Citizens excluded 1.9 million people in Assam state alone, with Human Rights Watch documenting that tribunals declared disproportionately more Muslims foreign and struck people off over spelling differences between documents. The Dominican Republic's Constitutional Court retroactively stripped nationality in 2013 from tens of thousands of people, mostly of Haitian descent, who had held Dominican papers their whole lives. At least a dozen more countries have done this recently, and it's becoming more common.
If you make a government ID the condition, you've made every one of those decisions yours too.
The card is a wall. Half the world's adults can't get over it, and nothing about their app or their intentions comes into it.
The institutional trick
This ID policy on Google Play has created a common workaround. If you can't register as an individual or a company, your app can be published under the account of an organisation that is already verified.
Look up Azmeh on Google Play today. The developer is now listed as Burj Al-Luqluq, a sports centre for kids in Jerusalem.
It runs football, basketball and taekwondo, kindergartens, summer camps, art rooms and psychosocial support, for around 6,500 people a year. It's a Palestinian community centre in the Bab Hutta quarter of the Old City of Jerusalem, founded in 1991 on land the neighbourhood fought to keep from a planned settlement, and its buildings have faced demolition orders. It exists legally because the Jerusalem Municipality accepts its registration as a charity.
So the arrangement that keeps a map of Israeli military checkpoints installable on Palestinian phones is that a children's sports centre, registered with the municipality of the occupying power, signs for it.
The first thing that tells us is that the workaround costs somebody else. An organisation running taekwondo for six thousand children is now the name Google holds, the name that answers a subpoena, and the name a state reads when it wants to know who to pressure about a checkpoint map. Burj Al-Luqluq didn't write a line of it.
The second thing it tells us is who can do this at all. You need an institution willing to sign, which means the app has to be big enough or known enough to be worth the risk to them.
The ones that clear that bar are the ones you might have heard of. Fogo Cruzado sends real-time gunfire alerts to over 400,000 people across Brazil; it started as a Google Docs spreadsheet kept by a journalist who couldn't find the stray-bullet statistics she needed for a story, and it now has a board and Amnesty behind it. Gershad crowdsources morality police checkpoints in Iran so a woman can walk a different street; the government blocked it within a day of launch, it spread to 100,000 people by sharing the app file anyway, and it is now reclaimed it's Play Store listing by a nonprofit outside the country. And we saw Azmeh found a youth centre.
But these are exceptions. East Jerusalem happens to carry an unusually dense layer of foreign-funded civil society, built up over decades precisely because of the political situation there. Myanmar's Sagaing region has nothing like it. Neither do the border cities of northern Mexico, or the neighbourhoods where those Argentine dollar-rate apps get made, or the island of Madagascar, where that Christian prayer book needs it.
The third thing this tells us is that the workaround defeats the stated purpose completely. Verification supposedly exists so that Google knows who built and controls an app, but it accepts an organisation that does neither. Cut off that account and the app finds another host. The problem doesn't get stopped. It gets laundered.
And more to the point, the sorting isn't between honest developers and fraudsters. It's between people who can find a legal name to stand in front of them and people who cannot. The long tail of useful apps made for small communities won't find one, and until now it didn't have to, because people could still install directly or use a niche app store. Google Play made a rule about its own shelves, and everyone who couldn't live with it used another channel. Now Google is insisting its rules apply to every channel.
This isn't a change to a listing policy.
It's a change to what you're allowed to do with a phone you own.
What your name costs you
In October last year Google removed an app called Red Dot from the Play Store. Red Dot let people report sightings of US immigration agents in their neighbourhood, anonymously, with reports expiring after five hours. The explanation was Google's own, not the government's: it told 404 Media it had not been contacted by the Department of Justice, and that it bans apps with a high risk of abuse and apps sharing the location of a vulnerable group. The vulnerable group they were talking about was ICE agents.
Red Dot is still running. If you go to its website it tells Android users to download the APK and install it themselves, because that's the only channel left. From next year, that channel closes. The party deciding whether Red Dot's developer may register is the same party that already decided the app shouldn't exist. Google.
ICEBlock's developer put his own name to his app. He was threatened with federal prosecution, the Attorney General named the app from a podium, and it was gone from Apple's App Store the same week. He is suing.
That's what happens in a country with courts, an appeals process and a still-functioning press.
Elsewhere the sequence is shorter. In the West Bank, 3,532 Palestinians are currently held under administrative detention: no charge, no trial, six-month orders renewed indefinitely, on evidence the detainee's own lawyer never sees. The UN's thematic report shows how commonly relatives are detained to force a wanted person to come in. In Iran it means the Revolutionary Guard's intelligence organisation, which detains people over social media accounts and threatens relatives inside the country to silence people outside it. In Myanmar, since the cybersecurity law took effect last July, soldiers run street phone checks for VPNs and social apps. In Kashmir, they do that too, and administering a WhatsApp group has been charged under a law carrying seven years.
The sequence from "register" to "target list" is well documented. In December 2016 Iran ordered every Telegram channel administrator with more than 5,000 members to register with the Ministry of Culture. Over 700 complied. Three months later twelve of them were arrested and their channels deleted.
And the party that wants the record isn't always a government. Mexico's Secretary of Public Security, the man who ran the federal police, was convicted in a New York court of taking millions from the Sinaloa cartel. The former president of Honduras was sentenced to forty-five years for protecting cocaine shipments while running the country. He recently got a US presidential pardon and was freed to go home. Nobody has tried the ones who weren't extradited, and they still hold their police commands and their ministries.
Turkey prosecuted people for terrorism because they had a specific messaging app on their phone: ByLock. After the failed coup in 2016, Turkish intelligence declared all of its users members of a terrorist organisation: the interior ministry charged 95,310 just for a installing chat app. Its own intelligence report, the one the courts used, said a third of them had never sent a single message with it, and 11,480 on the list hadn't even installed ByLock, but had been added by a misreading of the ISP logs that in fact proved they didn't use Bylock. Still, 75,000 were arrested, more than were already known to be innocent. Charges against those 11,480 were eventually dropped, but not before they were jailed. One man spent six months in prison and missed his son's wedding. The prosecutions continue today.
Once a list of names attached to an app exists, hostile governments gain access, and being on it becomes all the evidence they need.
Should developers be expected to trust Google?
Google is not a neutral or independent custodian of their list of developers.
On the day of Russia's parliamentary elections, it removed Alexei Navalny's tactical voting app. When India's Ministry of Home Affairs decided that Bluetooth mesh messaging was a problem during student protests this July, Google removed BitChat, Briar and Bridgefy. It spent two years building Dragonfly, a search engine for China that blacklisted terms about human rights and peaceful protest, and abandoned it only after its own staff revolted.
Mostly, though, according to Google's transparency report, it just answers lawful orders, and it is set up to do that at scale.
Following lawful orders is not the same as being required by law. Google says so itself: many of the court orders it receives do not require it to act at all, and it weighs each request and decides for itself.
The report sorts the government requests it receives into ten kinds of requester. Police is one. Military is another. So are suppression orders, which Google describes as court orders that "prohibit any discussion of the order", sometimes including the fact that it exists.
The term lawful used here is a cover. Administrative detention without charge is lawful in the West Bank. The Ministry of Culture's register was lawful in Iran. Turkey's prosecutions of ByLock users as terrorists went through its courts. Lawful or not, Google explains that it still decides if it plays ball, and we've seen how it decides.
Through all this, developers are now being required to trust that Google won't hand over their identity.
So Google forces a choice. Hand over your name and accept whatever your government does to you, or let Google kill the thing you made that people depend on.
Does it actually help the fraud victim?
The reason Google gives for doing all this is to stop fraud: a grandmother somewhere, talked into installing something that empties her bank account. That happens. But when apps are involved, it basically comes down to two ways.
The Dropper
Publish a simple, normal app to the Play Store and leave it there for months. A pink rabbit-themed calculator, a PDF reader. The app works, it gets reviewed, it gets good ratings, thousands of people install it. Then push a clean update that doesn't show up in scans, and later flip a switch on your own server, and the app fetches the code that does the stealing.
The whole scam is based on app store reputation. The store isn't the thing that stops it. The store is the thing that makes it work.
Play has required identity verification since 2023: government ID for an individual, or a D-U-N-S number for an organisation, with the legal name and address printed on the listing.
The Dropper recipe survives all of it intact. One dropper reached the top three of the US Play Store's free tools chart last year, with over 50,000 downloads, before the malicious update arrived six weeks after release. Kaspersky found more of them on Play three months ago.
The Call
The other type of app fraud doesn't depend on app-store reputation.
Here's how it runs in Bangkok. Grandma gets a text message on LINE, then a phone call from somebody claiming to be the police, or the electricity company, or a parcel service.
"There's a problem with your account."
"A delivery you didn't order."
"A money-laundering case with your name on it."
He is patient, he is helpful, and he stays on the line while he talks her through downloading a file and installing it. Once it's on the phone it asks for the accessibility service, allowing it to see the screen, read the codes and move the money while she's still saying thank you.
A purpose-built malicious app like this would be caught inside an app store with their automated checks. What does the work is a person on the phone, building trust and talking the victim through each step.
We'll call this one The Call, because the software is the smallest part of it.
Singapore's cyber security agency collaborated with Google on this a few years ago. It calls the category malware-enabled scams. The police there count where the money actually moves. In 80 percent of reported scam cases, victims made the transfers themselves. They didn't even need a malicious app. The scammers never took control of the account at all.
Their report explains it like this:
In most of these cases, the scammers didn’t gain direct control of the victims’ accounts, but manipulated victims into performing the monetary transactions by means of deception and social engineering.
Developer identity verification doesn't touch the Call, because the man on the phone directs the victim's own hands. It doesn't stop Droppers either. Google Play tried identity verification on its app store already, and it fails at the type of fraud they say they're stopping. That's the same check Google is now extending to every app on every phone, citing fraud prevention again.
Fake IDs
There's a deeper reason collecting ID doesn't work: a register only bites if identity is scarce, and it isn't. The US Department of Justice describes syndicates luring workers to Thailand with offers of well-paid technical work, seizing their identification documents, and trafficking them into scam compounds. Thailand's own Technology Crime Investigation Bureau recorded mule-account arrests rising to more than six thousand last year, and one anti-trafficking group has documented at least 961 cases of Thais taken to Cambodia and made to surrender passport, SIM and a facial scan. The UN's IOM found 300,000 people trafficked into scam compounds in South East Asia. They get the ID documents along with the captured human.
Criminal operations that can traffic humans and write apps won't have trouble getting as many ID cards as they need.
And let's be honest. Anyone who has ever watched a teenager buy beer at the corner store knows exactly how effective asking for ID works.
Google's answers
The EFF warned Google that people building Android apps to report ICE misdeeds shouldn't have to worry that Google will hand their personal information to the Department of Homeland Security. Brave explained that developers of privacy browsers, encrypted messengers, VPNs and tools for journalists in hostile environments would have to upload government ID to a company they have no reason to trust, and that many would simply stop. A coalition of more than seventy organisations put their names to an open letter making the same case.
Here's how Google answered them.
First, for hobbyists and students who can't afford the twenty-five dollars, they created the limited distribution account with no fee and, Google says, no government ID required. What it does require is a Google payments profile holding your legal name and address. And then the app goes on twenty phones. But that's not twenty people who can just grab your app and install it: each one has to authorise your app itself, through what Google calls "a secure handshake process involving QR codes or links," one phone at a time. That is really a testing allowance, not a distribution channel.
AndroidAPS has already written a help page for this, because according to Google, it's actually worse than the 20 users they imply. Each type 1 diabetic running it is the developer of their own build. Each now has to register with Google as a developer themselves, or learn ADB, to keep their insulin pump talking to their glucose monitor. That's how they keep themselves alive through the night.
Second, Google added an "advanced flow" so they could say phone owners may still install software of their choice.
In reality it's a confusing maze, designed as a deterrent. The steps: enable developer mode, which means finding a specific unlabelled option deep in your settings and tapping it seven times. (Noting it also puts your phone in an insecure state.) Confirm that nobody is coaching you. Restart the phone. Wait twenty-four hours. Reauthenticate. Then tap through another warning. Or, you know, just install some Android developer tools, learn them, then keep updating apps over a USB cable like it's 2002.
Google calls this the path for power users. Everybody who installs an app directly now has to take it. That is every v2rayNG user in China, Turkey and Turkmenistan. Everybody in the United States downloading Red Dot's APK from its website, the only channel Google left it. A teacher in Jammu, a cook in Shanghai, and every Anglican in Madagascar who wants a Christian prayer book in their own language. These are not power users. They are not technical. But this is now what they need to do to install the same app.
And grandma? The scam was always about gaining trust and patiently talking her through steps on a phone. More steps are the only thing that's been added. The man calling her has the time and the motivation. He is probably trapped in a scam compound in Cambodia, in a room with no windows and fluorescent lights. If he can already guide grandma to download an APK, enable unknown sources and install it, he can handle developer mode and a call back tomorrow.
In the end, Grandma is the reason Google gives for all this, and she's the one it doesn't save.
What Google learned from the police
Here's what gets me. Google already knows this. They've already fixed it too. Not in theory. They built the solution and ran it across Singapore, with the same Singapore police, back in 2024.
They looked at it technically: exactly which privileges do scam apps actually need? Reading your texts (READ_SMS, RECEIVE_SMS). Killing your notifications (NOTIFICATION_LISTENER). Taking over your screen (ACCESSIBILITY). So they blocked those four, specifically.
They didn't block all direct installing. Only apps that flicked those four switches.
Google had seen that over 95 percent of the malware abusing those permissions was arriving through direct installs, and once the phones started checking for that combination, 900,000 installs got stopped in six months in Singapore alone.
None of those criminals were asked to please send their ID before committing their crime. It stopped The Call because the man on the phone had nothing to say. There was no button grandma could press for him.
Google rolled it out to India and it showed the same, at thousand times the scale. Recently, India logged 2.8 million cyber-fraud complaints last year (reported there as 28.15 lakh), and a standard playbook never sends a malicious app at all.
It's a lot like the Singapore police explained. Scammers posing as Paytm support talk the victim into installing a legitimate remote-support app, like QuickSupport or AnyDesk. They use the access she grants them herself to move the money and read the codes as they arrive.
Take that in. The scammers don't even need their own app.
Every app they use already has verified developers, legal names, registered companies, everything Google is now demanding outside of the app store.
If it doesn't stop them in the app store, it won't stop them outside it.
You can block just the bad apps
The Singapore pilot, being a police collaboration, focused on fraud cases where direct installs kept getting noticed. That might be why it conflated direct installs with criminal acts at first.
What it showed Google was that it's those four system privileges that should make an app suspect, not that it was directly installed. Most regular apps, including the life-saving ones, never touch those privilege switches.
Some do: a seizure detector that has to wake a carer, a messenger built for the moment the network goes down. To block the scammers but not the good apps, there's something better to look at: app file history.
Files can have global histories, known to the whole world, using something called an append-only log. It's basically a published list that can only be added to, never quietly edited, with cryptographic cross-checking so anybody can verify nobody has rewritten it. If phones check a log of how apps were built, a phone gains facts it currently cannot obtain about a new app file: how long has this exact one been public? How many versions have there been? What permissions did each of them ask for?
Against that, the Call fails. The scam apps are usually fresh and unique, rebuilt for each victim so the file's fingerprint comes out different every time and the lists of known-bad files never match it. But with an append-only log, a phone can also see if an app has no history at all.
Combine that with a block on those four dangerous app permissions. Google can make it so an app with no public track record doesn't get any of them. Period.
There's nothing the scammer can tell grandma to do to get them. But Nico Mexis, uniqx and Tsiory Rajaonirina all get those capabilities if they need them, because their builds are old, public and unflagged. The moment an app asks for a dangerous permission it never had before, that takes a new release, and the new release is published to the log. After two years, if a PDF reader starts wanting the accessibility service to read your screen, that gets flagged immediately.
That's where the friction belongs: a delay, and the anti-coaching question, on turning on a dangerous capability. Google knew this from the Singapore pilot in 2024.
But now, it's decided to bolt all of this complication to anyone who doesn't register on Google Pay, instead of just the dangerous app permissions that actually get abused.
The hard parts
By now, a technical reader will have some good questions about these logs. How do new versions restart the access timers? What about an app that declares dangerous capabilities from day one, the way droppers already do? What about code injected at runtime, which never touches a build? What gets logged, and how do you stop the log being spammed? Should revocations be public, and if Google can issue them quietly, how is that different from Google deciding what gets blocked today?
These all have good answers, and this isn't the essay for them, because the answers aren't mine. They belong to the people who have spent a decade working on exactly this, at a conference run by a company that has already solved the same problem once, at a larger scale, for the entire web.
If you can guess which company this is, you owe me 25 bucks.
Who gets to look
Google itself built something called Certificate Transparency, a decade ago, covering every website on the internet.
Certificate Transparency requires every website certificate to be published to append-only public logs, so a bad one can't be issued quietly. It works by making mis-issuance visible to everyone, and visibility turned out to be enough: Symantec, then a major issuer of certificates on the internet, was caught issuing them improperly often enough that the browsers stopped trusting it, and it left the business. The whole project started because one certificate company, registered and well documented as it was, had issued false certificates used to break into Gmail accounts in Iran.
The part that matters here is that anyone can check the logs, not just Google. Anyone can run a monitor, and the people with the most to lose do. A company watches the logs for certificates issued in its own name and finds out within hours if somebody else has gained access to one.
Apply that to Thailand, one of the four countries where this new ID policy starts. Thai banking fraud runs on impersonation, an app wearing a real bank's name and icon. Under a public log the bank could watch for imitations of its own product: its real package names, signing keys and icon files are all in the log, so an app that has just appeared, looks almost exactly like the real one but has no history behind it -- that's something a script can find.
Google has less reason to chase Thai-language impersonation than the banks themselves, that have to reimburse the victims. The Bank of Thailand and ThaiCERT could watch the whole category, in Thai, in near real time. And that's before the cross-checking that banks, security researchers and NGOs could do across borders to catch international fraud.
It could do what it does with website security certificates, and let everyone look.
And Google made this for itself
Here's the last kicker. Once again, Google already built an append-only log system for Android apps.
In May this year Google shipped binary transparency for Android. Its own production apps, released after 1 May, now get an entry in a public append-only ledger. Google's framing: a signature is a certificate of origin, binary transparency is a certificate of intent. Google's own words on the design: it's built so that no party, including Google, can change the software authorised for your device without creating a public record.
That is the correct principle, written by Google, four months before it shipped the opposite for everybody else.
For its own software: no single party should decide unaccountably what runs on your phone, not even Google.
For everybody else's: Google decides, and the price of admission for any app developer is their passport.
Everyone else doing this
The people building these systems meet at the transparency.dev conference, which Google started and hosted at its London office in 2024.
The same idea is already protecting some of the people this policy endangers, journalists. WEBCAT comes from the Freedom of the Press Foundation, a small nonprofit who make SecureDrop. That's the system the Washington Post, the Guardian and dozens of other newsrooms use to receive documents from anonymous sources (and one I've learned a lot from on my own projects). Those newsrooms trust a handful of people to protect the identity of a source against a state that wants it. WEBCAT extends the principle to web apps: a browser checks that the code it's about to run is the code the developers signed, before running it, and can see the history of the web app. WEBCAT presented at Google's transparency summit last year.
Sigstore, a Google-backed project, is now how npm and PyPI, the two largest public collections of reusable code in the world, let a developer prove a release came from where it claims to.
Sigstore is worth a moment, because it shows the middle ground exists: it ties a signature to an identity, but that identity can be an email address or an account rather than a state document, and that link goes into a public log instead of a private database at Google.
It works, and it proves it works without giving anyone your passport.
So why is Google doing this?
Google spent six years rebuilding Chrome's extension platform, and the version that arrived can't do what a content blocker needs. uBlock Origin's forty million users lost the full version in 2024, and Google cited security. Ad blockers cost Google money. Draw your own conclusion.
I don't think this is a conspiracy. I'm sure people argued against it inside Google and lost, because commercial incentives usually win that fight. It's a company behaving the way companies behave. Google runs a store and sells advertising, and the Play Store and the other licensed stores are among its biggest money-makers: Google Services makes almost $100 billion per year. When it gains control over a distribution layer, it uses that control in ways that protect its revenue and reduce its legal exposure. Each of those decisions, once made public, comes wrapped in the language of user safety.
App stores are businesses. Governments offer access to their markets.
What's different now is that to squeeze more control out of a platform, Google has to put people's lives at risk. And this time, it can't pretend a government is forcing it.
Google has better options. It has the people who pushed Certificate Transparency into the browser, the people who shipped Binary Transparency for Android in May, and the people who host the conference on this entire class of technologies.
Google had a human rights program with oversight running up to Alphabet's board, the board the founders still sit on. In 2020 the board wrote civil and human rights explicitly into that committee's charter. In October 2025 it took it out, and told shareholders that leaving it out lets its committees be "nimble and flexible". Though almost a year later, Google's public page still says that Human Rights Program exists.
Larry Page and Sergey Brin wrote this in their founding letter to the SEC:
Google users trust our systems to help them with important decisions: medical, financial and many others. Our search results are the best we know how to produce. They are unbiased and objective... We believe it is important for everyone to have access to the best information and research, not only to the information people pay for you to see.
That describes responsibility.
Billions of people later chose Android, and paid for the hardware themselves, at a price that in much of the world is months of income. Note the phrase above: "not only to the information people pay for you to see." Now, by blocking apps they don't control, they are blocking that information.
There is still something left from this in Google's Code Of Conduct, a phrase as a final note: "...don't be evil, and if you see something that you think isn't right – speak up!"
The apps we won't see
Every app you read about here was someone writing software for a problem they were standing in themselves. Costik was a supermarket engineer whose son had diabetes. Azmeh's author was a twenty-year-old law student in a city full of checkpoints. Those girls in a Mumbai slum built a system so more people could have water. Most software like this has hundreds, maybe thousands of users, but it's most needed where nobody is counting.
The cost is that half the world loses the ability to make these apps for each other. Not just the ones they've made, the ones they will make. They have no payment method Google will take, or no ID card, or a good reason not to trust Google with it. They will have no reason to write software, because the only devices everyone in their community owns won't accept what they make.
When their apps go dark, they won't make the news. If they disappear, nobody will count them, but we can count them now. This cuts off billions of people. That's billions with a B, no matter how you spell googol.
We can't know how many lives will end at closed checkpoint gates, police raids, cartel firefights, or for that matter, late-night insulin emergencies. But consider this: Azmeh , Doroob (a similar map app), Gershad, Way Way Nay and Fogo Cruzado have close to a million users who depend on them for life-and-death decisions.
That's just five, and there are thousands more, all over the world. It's reasonable to think they protect to many, many millions of people. Until Google stops them from installing.
But who knows? Nico Mexis might send his passport, change app stores, and a university cafeteria menu app in Germany will keep working.
Then Google can tell themselves everything is fine.