259 comments

[ 1.9 ms ] story [ 263 ms ] thread
Same happened for CoMaps (which unfortunately does not have 12+ years of presence going for it)
The google review process is the best advertising for f-droid there could ever be.
I have three apps on the Play Store, they all take a couple hours to pass review and their auto-testing/review systems often catch little bugs I didn't almost immediately.

Getting a new app on the store is a bit cumbersome, but it should be.

(comment deleted)
Longer than an average App Store review (which is heavily criticized for being too long)? Hilarious
I believe the App Store has switched to automated reviews, at least for updates. I've had my app updates approved in <1h on a regular basis starting this summer.
From what I was able to see from the outside, App Store has had semi-automated reviews for updates in basically forever (+ some random spot checks), presumably based on some introspection that only triggers a human review if a new system API was used.
F-Droid's great but their build queue has had multi week waits too, difference is you can see exactly where your build is stuck instead of guessing.
Now, let's compare with "google friendly" apps: https://www.apkmirror.com/uploads/?appcategory=youtube :)
It took the whole year before v21 was finally approved, so seems only fair they publish minor v21 revisions multiple times a day!
21.37.42-SECONDARY is an interesting version number, don't they like final-final2 in their version numbers?
I just updated 2 dormant apps for the first time in 10 years; It took 2 days, and the apps were approved on a sunday.
The Google Play review process has been slower and more painful than the App Store review process for 5+ years at this point. At least you get to communicate with real people at Apple; it’s all bot-driven with Google.
What are bots doing for two weeks
Huh.

On the flip side, googles release infra provides much more functionality for apps that already has scale. I wish apple were more production oriented too.

AnkiDroid (~17 years old) submitted our latest alpha on Sept 03, 2026, 4:40 am. Still pending review.
thanks for your app! using it for learning danish and finding it very useful.
Thank you for Ankidroid!
We have about a 16 year old app, and our Google Play app review consistently takes between 30 minutes to 1 hour.

Apple consistently takes about 36 hours for us.

Yeah you'd think they could use some kind of exponential back-off type algorithm for apps that have been successfully reviewed many times... :-D
Is that 2.24.1 which was successfully published on F-Droid on Sept 2? If so that's... Interesting. And useful.
Google Play rejected our 2.24.1 release (Aug 31). F-Droid is typically slower, but we don't have to worry about distribution issues.

This is regarding 2.25.0alpha4.

This isn't my experience. My updates usually get accepted within hours. Apple takes days usually.
For new accounts yes, for older accounts it's much faster in my experience.

Apple has it's own issues, they often just answer with a random question so they can kick the review down the line. "Are you sure this is your pricing?" "Can you confifrm you have not selected that country" and then you have to wait another 2 days.

TFA is a post from an established developer and showing a screenshot for the submission of an update to a longstanding app (Conversations XMPP chat client).
Some reviews are clearly automated, some get a light human review, and some involve a human really looking hard. New apps seem to get a more rigorous human review for their first 2-4 submissions. Or at least humans looking over automated test screenshots etc. One reviewer clearly only looked at screenshots because they missed something that would be blindingly obvious on the prior screen if they did it themselves.

The explosion in LLM app development has clearly created a bottleneck at the human review steps. Not only delays but much more "dump" rejections from likely over-stressed humans.

MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.

And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.

(comment deleted)
And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?

I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.

How would a reviewer catch that?
Regulation is already addressing that. I encourage you to read up on the Cyber Resilience Act.
How about treating people like adults for a start? How about starting public awareness campaigns about proper digital hygiene. Not everything has to be nanny state garbage.
20 years of being tech support for countless family members and acquaintances says that nothing can possibly make people care about "digital hygiene". An iPad, Chromebook, or similar inflexible device is perfect for most people, and marketing more flexible devices to them has been a mistake since the beginning.
I don't know. Literally every single person I help with tech support makes me doubt this is possible. People do not care in the slightest and treat suggestions to learn basic digital hygiene as if you've asked them to a computer science degree in its entirety.

Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.

IMO in that case its their own fault. After all they have free will and can use it against their own good if they so choose. Let them get pwned a few times and see if they learn.
that's so dumb on so many levels... should we strip cars from active safety measures and let drivers who are not super good at driving just kill themselves on the road?
Maybe a drivers license should be needed to have a phone.
Well cars kill people, granny using the password “password” does not. We can’t prevent all levels of stupidity and carelessness.

If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.

I agree, but what I disagree with is the idea that everyone must be prevented from freely installing software on their own devices to make sure unskilled people cannot be tricked into doing it.

I don't really understand why a well designed sandbox and permissions system doesn't solve the problem.

A shocking number of people have passwords like "shovel"
You expect people to treat devices with respect and responsibility? The VAST majority of people use their phones to stream an infinite sequence of clickbait, ai slop, and conspiracies for 6 to 8 hours a day.
I've worked with dozens of businesses over the years and you can't even get businesses with real money and consequences on the line to follow basic security practices. My current project is updating dozens of windows domain controllers that are still on 2012 R2. Aka critical infrastructure that hasn't been getting updates for years.
We could force Google to operate its app review service independently. Users could use it and pay for it, or alternatives. Currently Google forces everyone to use their own mediocre service and pay for it without knowing exactly where and how much you pay.
And what do windows / linux / macos do about apps getting hacked to billions of pc's simultaneously? How is that a new problem?
If libraries didn't exist could not be created today. People tend to say that "it is impossible" when it actually only needs to be well organized.

Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.

> macos

MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.

> Windows

I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.

> but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.

Yet life in Windows land is perfectly fine in 2026 and has been for at least 2 decades.

If Windows, which started at the bottom of the barrel security wise can make it, surely we can have more modern OSes that make freedom bearable?

I wonder if people would be happy replacing the "Google approves developers" system with a "government requires your ID and address on file so you can be held liable for your apps" system. I suspect not.
What for? Malicious actors have no shortage of stolen identities.
That is already a requirement in any civilized country. You cannot run a business without a registered ID, address, etc. for tax purposes.

For free (like for real no microtransactions) that is different. For the rest, they already have that.

It's virtually the case, google and apple accounts require ID verification, which in turn can be requested by the gov in case of an investigation.
If you don't agree with a decision made by your government, you can vote for someone else next time. If you don't agree with a decision made by Google, what do you do?
The people I vote for never win. Am I really any more empowered with the government than I am with Google? At least with Google I can de-google my life (with some significant losses of convenience, but it is doable)
You probably have some sort of legal rights and ability to challenge decisions made by your government.

If you're banned from Google? Good luck, you're fucked.

The only part that would really be novel is the liability.

I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).

That's a tangential issue.

1. don't force auto-updates

2. still review apps uploaded to Google Play, but don't force users to use Google Play

If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.

But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.

> If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.

So this doesn't solve the issue pointed in the OP.

> don't force auto-updates

I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.

>So this doesn't solve the issue pointed in the OP.

Yes it does. This is their point:

> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.

It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.

It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.

> It’s my hardware

I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.

We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.

Agree, what I'm saying is "it is mine and we should treat it as mine, same as my laptop/desktop." We both agree the current status quo is not that, I'm saying what it should be.
> I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.

this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing

People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes.

Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.

Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.

The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.

> People accidentally hurt themselves with kitchen knives every day. They are also very often used for violent crimes

People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually

People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them

Yes, hold people accountable for their actions. Don't take away their freedom. We may prohibit individual actions that involve a general tool when they harm others. That is compatible with a free society. We may not prohibit fundamental tools¹ That is fundamentally incompatible with a free society. Especially when that tool forms the infrastructure for the flow of information and free speech.

[1] General purpose computing

How about the same thing we do when companies leak half-the-nation's personal data twice a month. Nothing.

When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consume hardware to protect them from the burden of controlling their own devices. See how that works?

> And what should we do about apps' getting hacked, sending out malicious updates that get auto-updated and thereby infecting tens of millions or billions of phones simultaneously?

"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."

We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps), there were enough reviewed apps that were used for fraud or access as bad actors.

My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.

Do people not remember the days of viruses destroying computers?

They were a massive issue before, and now they're barely a thought for most people.

These review processes have been good for the general population.

What review processes on computers?
I didn’t write the previous comment, but I think the point here is that there is a long-running trend aiming to protect users both from malicious intent and to a certain extent from themselves. In the past, viruses had it easy to infect and spread computers because of both inattentive users clicking on mails claiming someone loved them, and the default access mode for any user granting them admin access.

Even though review processeses generally do not exist for computers, they are part of that same trend.

mac app store / windows app store
And outside stores we have Windows’ UAC and Mac’s annoying-but-understandable “this dmg is sus” dialogues. Granted they are review processes but they’re often what keeps common users from wrecking their devices.
I believe people in HN also remember the days before we had MMUs.

And I'm sure everyone remembers ransomware.

No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.

I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.

> They were a massive issue before, and now they're barely a thought for most people.

Even on desktops... where there are no such review processes. Apparently we've found other mechanisms to reduce those issues, without app stores everywhere.

They're still very much a thing on desktop. You're not wrong that Windows got better at protecting itself, but I suspect the reason you don't hear about them is just that few people use desktops anymore (other than developers who, for obvious reasons, are typically less prone to be infected).

Anecdotally, at least once a month for the past several years, I notice a youtube channel in my feed get hacked. Their usual content gets replaced with crypto, Roblox, or Elon/SpaceX spam. Big channels, small channels, it happens to them all.

There's usually a post-mortem when they manage to regain control. Every time the infection happened through a virus attached to an email or by following a link on their discord.

This kind of attack simply cannot happen on mobile (unless your phone is rooted and you have disabled all warnings).

Sandbox, ACL, scan, sign, revoke bad actors.

We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.

Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.

Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?

> We already had enough proof of vulnerabilities in the OS code and Manufacturers (eg. Samsung/Lenovo/etc privileged apps)

Vulnerabilities aren't intentional.

> reviewed apps that were used for fraud or access as bad actors

The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".

Just because there are known vulnerabilities don't mean we should drop other security features, this is the opposite in fact. Defense in depth, an OS-level vulnerability cannot be exploited if the attacker cannot access that part of the OS.

And like it or not, the Play Store approval process is a security feature. It limits the ability of bad actors to run code on your phone and access data or exploit vulnerabilities they wouldn't be able to otherwise. Some get through, but it makes their life harder, again, defense in depth. Something can be both an anticompetitive practice and a security feature.

As for banking in the browser, you can, but your bank probably doesn't like it. That's why they are pushing for browser attestation, or to force you to use the app. The banks would rather take that freedom away from everyone rather than giving it to everyone. And I suspect they do it for good (as in profitable) reasons, fraud costs them, it costs them more than what they would gain by being more open.

If we want security features and freedom (which is the harder option), we need competition. If Google and Apple are the only players besides an insignificant minority, it is easy to lock software to these platforms, screw that weird guy with his Linux distro. Legislation is another option if the first one fails.

The app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.
Just because something is not perfect that does not mean it's worthless. Most things security things operate this way where it's impossible to stop all malware or attacks.
When analyzing whether something is a net good for society, I look not only at the value it brings, but the cost that it brings. The mobile ecosystem normalizing the idea that the vendor that sold you your everyday computing device is the sole arbiter of what can run on that device is of enormous cost to society, but anytime anyone brings that up, there's an immediate retort bringing fear, uncertainty, and doubt about software obtained outside of those centralized silos.

As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.

Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.

Security at its core comes down to trusting the supply chain that provides the software that runs on your hardware. There are many alternative secure supply chain models, but ultimately users often are incapable of making great choices on what is trustworthy. It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.

Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.

> It does generally make sense that the OS vendor needs to play a key part in helping ensure trusted parties are involved in the supply chain.

this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.

I dont trust it.

The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.

Hard to find better solutions when we have no agency to enact them. The “arrangement” was one-sided from the start.
Nintendo, Playstation, XBox,...
Your complaint about Android .apk install is... similar to unsigned software installs on Windows in some cases (not a great argument, I know, but the same as the vast majority of users would be used to).

As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.

A truly Open Web is the solution that we need. It already works everywhere with a single codebase, and is more secure and private than native apps.

But Apple prevents that by forcing all browsers to use terrible WebKit on iOS.

Endless more information on all of this at

https://infrequently.org/series/browser-choice-must-matter/

https://open-web-advocacy.org

Web apps can't fully replace native apps. This would be a bandaid fix, we need a fully open ecosystem for apps, like what is available on PCs. Native apps can run offline, they can be much more deeply integrated into the OS (you can't have a web app Android launcher, for instance), and they have a performance overhead due to having more layers between them and the hardware, which is important for games or anything complex.
I have high hopes for the Rust UI ecosystem in this regard. It's implementing pretty much everything from scratch, which means that it should be able to support a standalone GUI ecosystem that doesn't depend on a system GUI toolkit being available (while also being able to target existing OS's).
[dead]
> "Apple and Google are WELL past due for regulation in this space."

There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere.

The current US government won't do anything to follow suit, but hopefully a future one might.

The EU is not interested in liberating phone operating systems because it goes against their digital wallet push which forces everyone to use an attested, Google/Apple sanctioned device and operating system.
(comment deleted)
The push to involve the legal system and the government is ironic.

It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked.

The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.

Haha, oh the poor mega tech companies?! As if. Google sees a market, it wants to capture it. Same as Apple did.
You're misreading me. Regulation helps boost Apple and Google at the expense of anyone trying to compete with them on app stores.
This case has nothing to do with "gatekeepers". It is about the Play Store, operated by Google.
> This case has nothing to do with "gatekeepers". It is about the Play Store, operated by Google.

To-may-to, to-mah-to. The AppStore is basically identical in most aspects people care about.

Back in early 2000s, pretty much all Windows machines were infested with malware.

Do you want to bring back those glorious days?

Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.

People still can install/run whatever they like on their PCs, so why further restrictions needed or am I missing something? Also, further restrictions doesn't seem to work on the mobile/TV market where actual malware still infects iOS/Android/TV devices despite all the "hops" that it has too go through.

Code signing with warnings about non-signed apps is enough

Hmm? Malware on iOS is extremely rare.

I remember in Bitcoin community ~10 years ago, standard recommendation was than an iOS wallet was secure enough (I don't recall even a single case where wallet was stolen via malware), but any private keys on Windows were strongly discouraged, as most cases of stolen wallets were on Windows.

I'd say popularity of iPhone shows which way people prefer, but you do you - what prevents you from voting with your wallet and buying a Linux phone?..

The reason that modern computers are no longer filled with malware has nothing to do with completely irrelevant locked garden app stores on phones.

The reason is because Bill Gates put out a memo because it was fucking embarrassing that you could trivially smash the stack on default open API endpoints for services that consumers never used and shouldn't have been trivially routable from the open web in the first place.

Meanwhile in app stores, you don't have to hack anything, because consumers just download your botnet software willingly and directly.

42% of all apps on LG smart TVs turned your TV into a "residential proxy" botnet participant. 30% on Samsung TVs. There is no "hacking" in the world of apps because it's completely normalized for whatever app you build to also for some reason include remote control functionality from like 6 different companies. All of those apps pass review no problem.

Interesting that you mention LG and Samsung TVs.

Does it happen on Google Pixel phones?

Obviously, the quality of the walled garden depends on the maintainer. Google's quality standards are lower than Apples, but higher than LGs.

> operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all

This is exactly why I use a GNU/Linux phone that runs a desktop operating system with no artificial restrictions. Debian repositories are good enough to save me from malware, aren't they?

I am on an Android 10 system... gate keeping wasn't this bad during the Android 10 times...so i fairly use software stores like f-droid... simpmusic is one app I use frequently from f droid....no application so far has been deleted automatically. I guess Google has been upping the gatekeeping with newer systems as they come out
A weather app could be asking for your location to give you more convenient local forecasts.

It could also be asking for it to help advertisers build a robust behavioral profile about you.

This is not a systems permission, nor is it something that billions of users can judge the ramifications of each potential privacy impacting decision. Privacy is a systems property, not a technical property enforced with ACLs. ACLs can only keep the door from being wide open, they can't prevent access which has been granted from being abused or help the user understand ramifications of granting access.

We need privacy to be a regulatory concern with actual enforcement via an international framework. Until then, it is a business concern of Apple/Google - because they are in the business of having consumers feel confident that a weather app isn't reporting their behavior to anyone willing to pay for it.

yeah my 'promptly AI' alarm clock almost always spends 7 days, as soon as the binary changes, even descriptions changes take several days
Sounds like a clear "find another store" message to me.
I've noticed this

Google Play is regularly slower now than App Store Connect, which never used to be the case

Not sure how it works behind the scene, but our app (present on the store since 2018) is taking a couple hours at best with Google, and usually less than 24h with Apple.

Very much likely an automated triage based on code change or complexity.

A public FTP server is next app store.
Why can't you wait for a week? That doesn't sound like a long time.
For apps with a scale, it's a long time
For all the complaining about Apple's store, the Play Store has always been worse imo. You can't even release an app without first doing a beta test with at least a dozen people.
> You can't even release an app without first doing a beta test with at least a dozen people.

Perhaps I'm misunderstanding what you are saying here but less than a month ago I released a brand new app with no beta period, direct to production (white labeled app, which is why I didn't need a beta)

Same happened to me yesterday, I published a new app and it was reviewed and published within a few hours without any beta testing. but I think this is why I see people ready to buy old playstore accounts for real money, maybe this only affects new accounts
I'm just working on my first app (thanks to AI...) and if you have a new dev account created sometime after 2023 they are making you do a 12 person, 14 day beta run before anything else occurs, apparently.
It gets worse! If Google decides the people in your test don't engage enough and/or you didn't respond to their feedback, they may not give you production access. I've got a game that's available on iOS, I released there first and did lots of testing to deal with the low-hanging bugs. After doing the 14 day test Google emailed me:

Possible reasons why your production access could not be granted include:

    - Testers were not engaged with your app during your closed test
    - You didn't follow testing best practices, which may include gathering and acting on user feedback through updates to your app
I think it only applies to newer accounts and individual rather than company accounts. To make things worse, Google doesn't allow you to switch an account from individual > company. You need to create a whole new account.
Our app includes Android Auto, which I think is what causes it for us. Submitted 4 Sept, still in review.

Was only 48-72 hours until this year, where it randomly jumped to 2 weeks or longer like it still is.

It's really frustrating, and makes it very difficult to develop with, let alone reliably release features across platforms.

I suspect the same issue; I added Android Auto to my application on the latest release and the version I pushed on Sept 3th is still under review.
Yeap latest CoMaps update took ~16 days to review (the longest wait for us so far) and two support tickets (submitted first after ~9 days and got "we have expedited it", 5 days later still in review, so submitted one more ticket).

Before that we had a hotfix update (a very small change) and still it took longer than a week and a support ticket (after which it had been approved in a day)...

I think inconsistency is really annoying. Hard to rely on it. Most of our reviews clear with a couple hours, but sometimes it gets stuck for days.
This is why goverments have appeal processes and layers of tribunals. To be judged and found guilty by a corporation takes away all your rights.
Do you happen to live in a country where your government departments are known for rapid processing? (not weeks of delay like we're talking about here).

I generally see my legal system create severe delays (regardless of how much that victimises or costs everyone involved)

> I generally see my legal system create severe delays

Better a delay that getting your account closed without recourse. But you are right, years of conservative governments have starved the government and its services are slower than they should around the west world.