Application Gatekeeping: An Ever-Expanding Pathway to Internet Censorship | Electronic Frontier Foundation
Skip to main content
AboutContact
Press
People
Opportunities
IssuesFree Speech
Privacy
Creativity and Innovation
Transparency
International
Security
Artifical Intelligence
Our WorkDeeplinks Blog
Press Releases
Events
Legal Cases
Whitepapers
Podcast
Annual Reports
Take ActionAction Center
Volunteer
Follow EFF
ToolsPrivacy Badger
Surveillance Self-Defense
Certbot
Atlas of Surveillance
Cover Your Tracks
Street Level Surveillance
apkeep
Shop
DonateDonate to EFF
Shop
Giving Societies
Sponsorships
Other Ways to Give
Membership FAQ
Email updates on news, actions,
and events in your area.
Join EFF Lists
Copyright (CC BY)
Trademark
Privacy Policy
Thanks
Electronic Frontier Foundation
Donate
If you use technology, this fight is yours.Donate today
EFFecting Change: If You Own It, Why Can't You Fix It? on July 23
Application Gatekeeping: An Ever-Expanding Pathway to Internet Censorship
DEEPLINKS BLOG
By Corynne McSherry<br>November 3, 2025
Application Gatekeeping: An Ever-Expanding Pathway to Internet Censorship
Share It
Share on Mastodon<br>Share on Bluesky<br>Share on Facebook<br>Copy link
It’s not news that Apple and Google use their app stores to shape what apps you can and cannot have on many of your devices. What is new is more governments—including the U.S. government—using legal and extralegal tools to lean on these gatekeepers in order to assert that same control. And rather than resisting, the gatekeepers are making it easier than ever.
Apple’s decision to take down the ICEBlock app at least partially in response to threats from the U.S. government—with Google rapidly and voluntarily following suit—was bad enough. But it pales in comparison with Google’s new program, set to launch worldwide next year, requiring developers to register with the company in order to have their apps installable on Android certified devices—including paying a fee and providing personal information backed by government-issued identification. Google claims the new program of “is an extra layer of security that deters bad actors and makes it harder for them to spread harm,” but the registration requirements are barely tied to app effectiveness or security. Why, one wonders, does Google need to see your driver’s license to evaluate whether your app is safe? Why, one also wonders, does Google want to create a database of virtually every Android app developer in the world?
Those communities are likely to drop out of developing for Android altogether, depriving all Android users of valuable tools.
F-Droid, a free and open-source repository for Android apps, has been sounding the alarm. As they’ve explained in an open letter, Google’s central registration system will be devastating for the Android developer community. Many mobile apps are created, improved, and distributed by volunteers, researchers, and/or small teams with limited financial resources. Others are created by developers who do not use the name attached to any government-issued identification. Others may have good reason to fear handing over their personal information to Google, or any other third party. Those communities are likely to drop out of developing for Android altogether, depriving all Android users of valuable tools.
Google’s promise that it’s “working on” a program for “students and hobbyists” that may have different requirements falls far short of what is necessary to alleviate these concerns.
It’s more important than ever to support technologies which decentralize and democratize our shared digital commons. A centralized global registration system for Android will inevitably chill this work.
The point here is not that all the apps are necessarily perfect or even safe. The point is that when you set up a gate, you invite authorities to use it to block things they don’t like. And when you build a database, you invite governments (and private parties) to try to get access to that database. If you build it, they will come.
Imagine you have developed a virtual private network (VPN) and corresponding Android mobile app that helps dissidents, journalists, and ordinary humans avoid corporate and government surveillance. In some countries, distributing that app could invite legal threats and even prosecution. Developers in those areas should not have to trust that Google would not hand over their personal information in response to a government demand just because they want their app to be installable by all Android users. By the same token, technologists that work on Android apps for reporting ICE misdeeds should not have to worry that Google will hand over their personal information to, say, the U.S. Department of Homeland Security.
It’s easy to see how a new registration requirement for developers could give Google a new lever for maintaining its app store monopoly
Our tech infrastructure’s substantial...