20 ms·
Android developer verification: Early access starts
- erohead 11mo agoSounds like they're rolling back the mandatory verification flow: Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. We are gathering early feedback on the design of this feature now and will share more details in the coming months.
- silisili 11mo agoI feel like if safety was really their top priority, they would have done this long ago and not bothered with this mandatory signing nonsense to begin with... Still, it seems like good news, so I'll take it.
- gowthamgts12 11mo ago> Sounds like they're rolling back the mandatory verification flow absolutely no. this is for the user side. but if you're a developer who is planning to publish the app in alternative play store/from your website, you have to do verification flow. please read the full text.
- Ajedi32 11mo agoI'm a little nervous about what this advanced flow is going to look like, given that sideloading already requires jumping through a bunch of hoops to enable and even that apparently wasn't enough to satisfy Google. I'm cautiously optimistic though. I'm generally okay with nanny features as long as there's a way to turn them off and it sounds like that's what this "advanced flow" does.
- themafia 11mo ago> Keeping users safe on Android is our top priority. I highly doubt this is your "top" priority. Or if it is then you're gotten there by completely ignoring Google account security. > intercepts the victim's notifications And who controls these notifications and forces application developers to use a specific service? > bad actors can spin up new harmful apps instantly. Like banking applications that use push or SMS for two factor authentication. You seem to approve those without hesitation. I guess their "top" priority is dependent on the situation.
- boxedemp 11mo agoOnly a few things in life are for sure. Death, taxes, and corpospeak.
- _factor 11mo agoHey, sometimes the dumbest people it works on are also the ones with the decision making ability. What a world to live in.
- BrenBarn 11mo agoTheir top priority is making money.
- shirro 11mo agoMaking money and complying with the law. They are obligated to do both. In many countries laws are still enforced. Protecting their app store revenues from competition exposes them to scrutiny from competition regulators and might be counter productive. Many governments are moving towards requiring tech companies to enforce verification of users and limit access to some types of software and services or impose conditions requiring software to limit certain features such as end to end encryption. Some prominent people in big tech believe very strongly in a surveillance state and we are seeing a lot of buy in across the political spectrum, possibly due to industry lobbying efforts. Allowing people to install unapproved software limits the effectiveness of surveillance technologies and the revenues of those selling them. If legal compliance risks are pushing this then it is a job for voters, not Google to fix.
- Aachen 11mo agoEdit: be sure to read geoffschmidt's reply below /edit The buried lede: > a dedicated account type for students and hobbyists. This will allow you to distribute your creations to a limited number of devices without going through the full verification So a natural limit on how big a hobby project can get. The example they give, where verification would require scammers to burn an identity to build another app instead of just being able to do a new build whenever an app gets detected as malware, shows that apps with few installs are where the danger is. This measure just doesn't add up
- geoffschmidt 11mo agoBut see also the next section ("empowering experienced users"): > We are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified
- Aachen 11mo agoOh! I thought I had found the crucial piece finally after ~500 words, but there's indeed better news in the section after that! Thanks, I can go sleep with a more optimistic feeling now :) Also this will kill any impetus that was growing on the Linux phone development side, for better or worse. We get to live in this ecosystem a while longer, let's see if people keep damocles' sword in mind and we might see more efforts towards cross-platform builds for example
- Metacelsus 11mo agoGlad to see them being less evil.
- gblargg 11mo agoSo they can be less evil to more people rather than pushing people to a non-evil platform.
- idle_zealot 11mo agoWhat is the non-evil phone platform? Aftermarket Android ROMs?
- gblargg 11mo agoIf they had gone ahead and blocked local installs, and forced every apk to be signed by a registered developer, I'm assuming there would have been a strong push for a viable Linux on these devices.
- pwg 11mo agoSadly, less evil is still evil.
- Grimblewald 11mo agoTaking 10 steps in the direction of evil, and taking 1 step back, is not something that should save you from the gallows.
- a96 11mo agoEspecially when they're continuing on the next 10 steps ASAP.
- svat 11mo agoFrom the very first announcement of this, Google has hinted that they were doing this under pressure from the governments in a few countries. (I don't remember the URL of the first announcement, but https://android-developers.googleblog.com/2025/08/elevating-android-security.html https://android-developers.googleblog.com/2025/08/elevating-... is from 2025-August-25 and mentions “These requirements go into effect in Brazil, Indonesia, Singapore, and Thailand”.) The “Why verification is important” section of this blog post goes into a bit more detail (see also the We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer), but ultimately the point is: there cannot exist an easy way for a typical non-technical user to install “unverified apps” (whatever that means), because the governments of countries where such scams are widespread will hold Google responsible. Meanwhile this very fact seems fundamentally unacceptable to many, so there will be no end to this discourse IMO.
- Lammy 11mo agoGoogle have their own reasons too. They would love to kill off YouTube ReVanced and other haxx0red clients that give features for free which Google would rather sell you on subscription. Just look at everything they've done to break yt-dlp over and over again. In fact their newest countermeasure is a frontpage story right beside this one: https://news.ycombinator.com/item?id=45898407 https://news.ycombinator.com/item?id=45898407
- charcircuit 11mo agoYou would still be able to adb installs them. They wouldn't die.
- zb3 11mo agoI have to admit I couldn't even understand this problem, because for me the "stock OS" is already unbearable and I'd simply never be able to use it - I've never used it for more than a hour..
- IlikeKitties 11mo agoThe issue is that of network effects. Making it harder to sideload for example f-droid makes the already small market for it even smaller, leading to less apps. It also forces people developing Apps that they don't want to reveal to be developing for completly valid reasons (Imagine developing a porn app in saudi arabia or an abortion support app in the USA) to validate against google aka the US Government.
- zb3 11mo agoI'm just presenting my exotic point of view - since that developer verification would only be needed to run apps on the "stock OS" (which I consider bad), then deliberately excluding it could promote using LineageOS/GrapheneOS which would be a good thing. But of course I'm talking about non-commercial apps, but commercial app developers would already be on Google Play.
- add-sub-mul-div 11mo agoAsk yourself how relevant and interesting you'd find this comment if someone else had posted it.
- zb3 11mo agoI'd agree because I'd feel the same :) As to relevance to the article - I'm not cheering that much because if Google made "stock OS" even worse then maybe more users would flock to LineageOS/GrapheneOS which would be a great thing and make it harder to push Play Integrity.
- asadm 11mo agoi think your opinion is pretty dated.
- Sytten 11mo agoIn the end when supporting the non tech people in the family, what I would really like is to setup their device so they can install anything on Fdroid but nothing from the play store (unless approved by me) nor direct from an apk.
- gpm 11mo ago8 days ago Google and Epic announced a proposed settlement and modification of a permanent injunction that Epic won, I believe this proposed settlement would likely have prohibited Google's plan to forbid installation of third party apps (excluding app stores from the definition of apps) unless those app developers had paid google a registration fee. The proposed settlement is here [1], the relevant portion is > 13. For a period beginning on the Effective Date through June 30, 2032, Google will [...] and will continue to permit the direct downloading of apps from developer websites and third-party stores without any fees being imposed for those downloads unless the downloads originate from linkouts from apps installed/updated by Google Play (excluding web browsers). 6 days ago the court expressed skepticism as to the proposal and announced that they'd have a hearing, with testimony from expert witnesses, as to whether it would prevent the market harms that the original injunction was trying to cure [2]. Today Google announces this, effectively confirming that they're backing down from their requirement that third party app developers pay google prior to distributing their apps. Nothing (yet) is explicitly tying these together, but I can't help but suspect that this move is in large part being made to convince the court that they're actually intending to honour this portion of the proposed injunction even though Epic would have little reason to enforce it. [1] https://storage.courtlistener.com/recap/gov.uscourts.cand.364325/gov.uscourts.cand.364325.756.3_2.pdf https://storage.courtlistener.com/recap/gov.uscourts.cand.36... [2] https://storage.courtlistener.com/recap/gov.uscourts.cand.364325/gov.uscourts.cand.364325.758.0.pdf https://storage.courtlistener.com/recap/gov.uscourts.cand.36...
- dgoldstein0 11mo agoDid we read the same thing? I think Google here said there would be a $25 fee per developer (for those who can't fit in their limited distribution category). I suppose it's much better than a fee per paid install but it's not nothing.
- gpm 11mo agoSee the "Empowering experienced users" section. They announced the $25 "verification" plan awhile ago. The new part in this article is that they're going to have it remain possible to install software that didn't do that "verification". > Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified.
- bilsbie 11mo agoI don’t like to see the word “allow” in the same sentence with a device I own.
- edoceo 11mo agoIt's a device you own, sure. But you've licensed the software.
- flagos10 11mo agoWe need a free-as-in-freedom version of Android.
- wmf 11mo agoGrapheneOS
- tcfhgj 11mo agoGoogle is suppressing freedom. "Go, give money to Google, to reclaim freedom"
- rcMgD2BwE72F 11mo agoWhat's Google profit/margin on Pixel phones nowadays (hardware only)?
- a96 11mo agoGrapheneOS is also in danger.
- jhasse 11mo agoAlready exists. LineageOS, /e/OS, GrapheneOS, to name a few.
- EMIRELADERO 11mo agoThis is misleading though. There is simply no other choice if you want to use mainstream apps. It could be argued (successfully in my view) that any agreement is null and void due to its acceptance under duress. Users have an inherent legal right to unconditionally access the full advertised functionality of devices they purchase. Any agreement after that is inherently suspect and I wouldn't be surprised to find out it was ruled unconscionable by some court if it came to that.
- BrenBarn 11mo agoThe key question for me is whether this "advanced flow" will allow the practical use of entirely separate app stores (like F-Droid) or if they're going to throw up tons of barriers for every individual app install.
- NewJazz 11mo agoIf F-Droid is no longer part of the android community, then neither will I. I'm not too worried. My employer should be, though.
- andrepd 11mo agoCorrect me if I'm wrong but doesn't the EU digital markets act mandate this?
- gumby271 11mo agoIsn't Apple technically complying with this even while forcing notarization? Seems like Google could get away with the same scheme.
- gpm 11mo agoApple says they are. The EU says they aren't. They're fighting over it.
- advisedwang 11mo agoEU digital markets mandates that you can install apps through f-droid... but doesn't mandate that those apps don't to comply with Google's signing policy.
- tadfisher 11mo agoThere's a second path, whereby F-Droid registers as an "alternative app store", which is a new category of app created in the fallout of Epic Games v. Google [0]. This is interesting because it applies to all regions and will necessarily need more elevated permissions than the typical REQUEST_INSTALL_PACKAGES permission used today. No idea what requirements Google will impose on such apps. [0]: https://en.wikipedia.org/wiki/Epic_Games_v._Google https://en.wikipedia.org/wiki/Epic_Games_v._Google
- zzo38computer 11mo agoIf adb is unrestricted and can work with the Linux command shell (something I seem to remember I had read about before; you will need to enable the developer mode to use it), which is aparently a separate system but runs on the same device, although if it has the ability to communicate with the main Android system using adb (which it might be reasonable to require that to be explicitly enabled with another setting, for additional security in case you do not use adb), then this would help since you do not require another computer that would be compatible with adb in order to do it. However, I think there are other things they should do as well (in addition to the other things) if they want to improve the safety, such as looking at the apps in Google Play to check that they are not malware (since apparently some are; however, it says they do have some safeguards, so hopefully that would help), and to make the permission system to work better (e.g. to make it clear that it can intercept notificatinos; there are legitimate reasons to do this but it should require an explicit permission setting to make this clear).
- sprior 11mo agoThis brings back memories of "sure you can root your phone, but if you do secure apps like payment won't run anymore"
- spaqin 11mo agoI can only imagine that allowing "unverified" apps to run would also disable payment/banking apps. Just in case, you know. For your own good.
- lern_too_spel 11mo agoThat should be up to the bank to decide, and it already is. https://developer.android.com/privacy-and-security/safetynet/verify-apps https://developer.android.com/privacy-and-security/safetynet... None of my banks have complained to me because I'm running a patched YouTube app.
- rbits 11mo agoThat doesn't seem to have anything to do with what apps you have installed, just whether you have Play Protect enabled. I have Play Protect enabled, and I can still install apps without having to scan them first.
- lern_too_spel 11mo agoSee the listHarmfulApps() documentation on that page.
- anonymousiam 11mo ago"Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. We are gathering early feedback on the design of this feature now and will share more details in the coming months." So they haven't actually changed anything yet, but they say that they will "in the coming months."
- rbits 11mo agoThat's because developer verification outside of Google Play isn't required yet.
- wheybags 11mo ago"We have realised that boiling the frog this fast will result in it jumping out of the water. Therefore we have slowed down, but remain steadfastly devoted to seeing this frog boiled"
- DecentShoes 11mo agoNow allow individuals to release apps again.
- aboringusername 11mo agoWe really need to banish the term "sideloading". Installing apps on a terminal is just that, and for as long as I remember on windows, Linux it has always been just that. Google mentions about being on a call, and being tricked into handing over codes. So why not use signals and huristics to decide? If user is on a call, block any ability to install a shady app. Implement a cool down before that functionality is restored (say 24 hours). It can also detect where the user is based to add additional protection (such as mandating the use of play protect to scan the app before it's activated and add another cool down regardless). There's lots of ways to help protect the user but it's wrong to ultimately control them. The real world is full of scary dangers that technology is trying to solve but is actively making things worse (such as computerized safety systems in cars). Ultimately, the user is responsible and whilst it's palpable Google would want to reduce harm in this specific way, we know authoritarian governments would also love to be able to dictate what software people can run. The harm to democracy is simply too great in favor of saving a few people's money.
- sipofwater 11mo ago* "Android Developer Verification Discourse" by agnostic-apollo (https://github.com/agnostic-apollo https://github.com/agnostic-apollo), Termux app (https://github.com/termux/termux-app https://github.com/termux/termux-app) developer: https://gist.github.com/agnostic-apollo/b8d8daa24cbdd216687a6bef53d417a6 https://gist.github.com/agnostic-apollo/b8d8daa24cbdd216687a... (gist.github.com/agnostic-apollo/b8d8daa24cbdd216687a6bef53d417a6) and https://old.reddit.com/r/termux/comments/1ourtxj/android_developer_verification_discourse/ https://old.reddit.com/r/termux/comments/1ourtxj/android_dev... (old.reddit.com/r/termux/comments/1ourtxj/android_developer_verification_discourse/) * "Android Developer Verification Proposed Changes" by agnostic-apollo (https://github.com/agnostic-apollo https://github.com/agnostic-apollo), Termux app (https://github.com/termux/termux-app https://github.com/termux/termux-app) developer: https://issuetracker.google.com/issues/459832198 https://issuetracker.google.com/issues/459832198 via https://old.reddit.com/r/termux/comments/1ourtxj/android_developer_verification_discourse/ https://old.reddit.com/r/termux/comments/1ourtxj/android_dev... (old.reddit.com/r/termux/comments/1ourtxj/android_developer_verification_discourse/)
- sipofwater 11mo agoAndroid Debug Bridge (https://developer.android.com/tools/adb https://developer.android.com/tools/adb) using two Android smartphones and Termux (https://github.com/termux/termux-app https://github.com/termux/termux-app): * Search for "Smartphone-1 to Smartphone-2" "adb tcpip 5555" in "Motorola moto g play 2024 smartphone, Termux, termux-usb, usbredirect, QEMU running under Termux, and Alpine Linux: Disks with Globally Unique Identifier (GUID) Partition Table (GPT) partitioning": https://old.reddit.com/r/MotoG/comments/1j2g5gz/motorola_moto_g_play_2024_smartphone_termux/ https://old.reddit.com/r/MotoG/comments/1j2g5gz/motorola_mot... (old.reddit.com/r/MotoG/comments/1j2g5gz/motorola_moto_g_play_2024_smartphone_termux/) * Search for "termux-adb" in "Motorola moto g play 2024 Smartphone, Android 14 Operating System, Termux, And cryptsetup: Linux Unified Key Setup (LUKS) Encryption/Decryption And The ext4 Filesystem Without Using root Access, Without Using proot-distro, And Without Using QEMU": https://old.reddit.com/r/MotoG/comments/1jkl0f8/motorola_moto_g_play_2024_smartphone_android_14/ https://old.reddit.com/r/MotoG/comments/1jkl0f8/motorola_mot... (old.reddit.com/r/MotoG/comments/1jkl0f8/motorola_moto_g_play_2024_smartphone_android_14/)
- gowthamgts12 11mo agoso still distributing with f-droid is messed up? i now have to pay a fee to develop an open-source app via f-droid to everyone? this is a misleading title. they only allow side-loading unverified apps only on fewer devices.
- rbits 11mo agoDon't know if you read the whole article > Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. Or am I misreading your comment?
- zoobab 11mo ago"this is a misleading title" Marketing at work, I am not giving away my ID to publish an app on an alternative app store, like F-Droid. Google is abusing their "gatekeeper" status, like Apple does.
- xg15 11mo agoSo there was the very concrete problem that F-Droid could not continue to function with the verification requirements, because they rebuild every app and so would have to know every key. Do the changes here do anything for F-Droid?
- rbits 11mo agoWhat this probably means: to use F-Droid on your phone, you will have to first go through the new unverified app flow
- xg15 11mo agoThat would at least be an improvement to the current situation, were they wouldn't be able to operate at all. If the flow is designed such the you only have to do it once for F-Droid and then the unsigned apps would be installable from there without friction, it wouldn't even be that bad.
- 999900000999 11mo agoAhh yes,the slow boiling continues. So if I want to release a free android game my options are. A: Hope Google doesn't change course again. B: Give Google a copy of my apartment lease, Would be too hard for them to ya know actually implement sandboxing which would prevent this. Anything aside from full bootloader access means I'm renting my device. Too late now though.
- WorldPeas 11mo agoI still remember when I could give my friends an exe of the stupid little games I made, worry free. I guess that makes me a cybercriminal, doesn't it.
- seandoe 11mo agoThis is great news to me. I'm going to celebrate it. As evil as everyone thinks they are, they did the right thing here. Thanks google.
- CodeCrusader 11mo agoOver the long run this might help Android a lot
- nunez 11mo agoGlad to see Google come to their senses on this. Disabling it entirely would have basically guaranteed an exodus of power users over to iOS. If your only choices are walled gardens, you might as well pick the easiest, prettiest one.
- gowthamgts12 11mo agoit's not > "Google come to their senses on this" it's > "Google was forced to their senses on this"
- a96 11mo ago"For now."
- bilekas 11mo agoImagine you could do with your hardware what you wanted. Brave. Innovative. Revolutionary. /Old man laughing at "cloud" that is my baremetal.
- WorldPeas 11mo agoI worry that the overton window has shifted so much after over a decade and a half of most downloads being mediated by "app stores" that most people don't realize or have the means to vocalize or understand what they're missing.
- devsda 11mo agoThey didn't say no changes. They are just saying we'll address the concerns of hobbyists and students. Lets not celebrate prematurely and let us wait for more details on whats actually changing both technically and process wise. We should demand more clarity and should not wait to discover it after the implementation at which point it is hard and nearly impossible to push back against. We don't want to be in a situation where they technically make it possible but make it practically impossible to install apps outside playstore.
- A4ET8a8uTh0_v2 11mo agoI think you are correct. Clearly, they got spooked, but not enough to make full reversal. I am actually mildly optimistic. It has been a while since I saw a minority ( not that many people are aware of it outside HN circles ) shake a bigger company to a hesitation.
- deleted 11mo ago[deleted]
- uneven9434 11mo agoThere are many real-world sideloading abuse cases in China. Attackers often trick victims with plausible stories—e.g., claiming a flight is delayed—and ask them to sideload an app (a remote‑meeting or remote‑control tool) to share their screen. Once installed, the attacker can view the victim’s screen and intercept SMS 2FA codes for online banking or other sensitive accounts. Other schemes include impersonating sex workers to lure victims into nude video chats, then persuading them to install an app that harvests private content and contacts for blackmail.
- Spivak 11mo agoYes, this is called malware and isn't the fault of being able to install software on your device. If someone tricks you into handing over the keys to the kingdom, the solution isn't to remove your door.
- derbOac 11mo agoWhy should that mean anyone else should lose control of their device? Maybe at some point you have to accept that it's the user's responsibility? Maybe empower users to be aware of what the apps they install are doing, without take their control away? This is how loss of autonomy always happens in every sphere: make an argument that it's for their own safety that individuals are losing autonomy, and the entity gaining control is superior in knowing what's best, and is taking control only out of the goodness of their heart.
- Ms-J 11mo agoThese unfortunately gullible people would be tricked in many different other ways throughout their daily lives even if it wasn't for the ability to install something on a device that you paid for and outright own. We don't cater the most stupid in society.
- fulafel 11mo agoWhat's the Android situation there? Last I heard Google didn't license Android there and they were using Chinese app stores with forked AOSP Android. Which would seem to put the sideloading decision in the hands of the forked OS.
- 11mo ago
- xyzzy_plugh 11mo ago> we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. As long as this is a one-time flow: Good, great, yes, I'll gladly scroll through as many prompts as you want to enable sideloading. I understand the risks! But I fear this will be no better than Apple's flow for installing unsigned binaries in macOS. Please do better.
- lokar 11mo agoWhat if it imposed a longish (one time) cooldown period? A day?
- rbits 11mo ago1 day is not longish. That would greatly harm apps like F-Droid. You'd have to go through it every time you want to update your apps.
- huem0n 11mo agoExactly, this would greatly reduce the ability for scammers in "urgent" situations, but for power users who flip the switch on day one it would rarely be a problem. What would be terrible though ... is if Google made it require a network connection or Google approval.
- pabs3 11mo ago> When the user logs into their real banking app, the malware captures their two-factor authentication codes That seems like a severe security bug in Android APIs or sandboxing or something else. > bad actors can spin up new harmful apps instantly Why are harmful apps possible at all?
- Jyaif 11mo agoAs soon as a platform gives control to the fullscreen, harmful apps are possible. See for example Apple detecting if a user is typing on a keyboard while in a fullscreen website, and then blocking the website. Yes it's as crazy as it's sounds.
- lern_too_spel 11mo ago> That seems like a severe security bug in Android APIs or sandboxing or something else. No, this is the permissioned API that makes KDE Connect work, which makes Apple's Continuity look like a toy and that also lets me programmatically filter notifications.
- rbits 11mo agoIt's a permission the app can have. Android asks the user whether to allow it when you launch the app. It's a very useful permission for some apps that I use. But a scammer can just tell the user to accept the permission.
- Ms-J 11mo agoGoogle still hasn't changed anything but took the opportunity to again insult their customers within the first headline, titled "Why verification is important". Google goes on to say how taking away one of your last remaining rights is good for you, if you like it or not. It is clear to everyone why Google is partnering with governments around the world to remove our rights to installing apps. Laws are not on your side and must be reevaluated on an individual level to move forward. You decide your own terms, you have the power. Only we can stop this together.
- notepad0x90 11mo agoThis is the worst of both worlds, you can spread your malware as a sideloaded apk just fine, but when it's so big that you're probably burned anyways, then you need to verify your account. I think a better compromise would have been for google to require developer verification, but also allow third party appstores like f-droid that don't require verification but still are required to "sign" the apks, instead of users enabling wide-open apk sideloading. that way, hobbyists can still publish apps in third party stores, and it is a couple of more steps harder for users to fall for social engineering,because they now have to install/enable f-droid, and then find the right malicious app and download it. The apk downloaded straight from the malicious site won't be loaded no matter what. Google can then require highlighting things like number of downloads and developer reputation by 3rd party appstores, and maybe even require an inconsistent set of steps to search and find apps to make it harder to social engineer people (like names of buttons, ux arrangements, number of clicks,etc.. randomize it all). What frustrated me on this topic from the beginning is that solutions like what I'm proposing (and better ones) are possible. But the HN prevailing sentiment (and elsewhere) is pitchforks and torches. Ok, disagree with google, but let's discuss about how to solve the android malware problem that is hurting real people, it is irresponsible to do otherwise.
- lern_too_spel 11mo ago> Google can then require highlighting things like number of downloads and developer reputation by 3rd party appstores F-droid doesn't want to track number of installs because that is an invasion of privacy. > require developer verification, but also allow third party appstores like f-droid that don't require verification Now you've moved the problem from Google gatekeeping apps to Google gatekeeping app stores. We don't want either.
- notepad0x90 11mo agoThen i guess you can't publish apps? One of those issues where i should be "writing to my congressman" or whatever I guess. the problem is real and people like you are being obtuse, unwilling to find a solution or a compromise. Something as simple as number of installs is an invasion of privacy? how? it's a number, you increment a counter when someone hits download, that's it. Yeah, if google gets to have rules over what happens by apps that have their seal of approval. that's how seals of approvals work. you're not entitled to these things. you don't have the right to publish to the android platform, if Google, wary of anti-trust suits allows a 3rd party app store, it can institute reasonable requirements. If an appstore is willingly hosting malware, should Google still provide their seal of approval? That was supposed to be rhetoric, but I wouldn't be surprised if you told me that they should. This is willful ignorance, I only hope you educate yourself on the harms caused by malware and malicious actors and consider taking a practical approach to finding solutions instead of dying on every single hill.
- metadat 11mo agoAre there any entities on earth with resources to compete with a complicit global duopoly? If Android is open source, why can't/won't a community fork it? Graphene OS exists but many folks claim Netflix and banking apps do not work with it (despite allowing logins from any common desktop browser)? If all widely-accepted phone operating systems are de-facto proprietary, what does this say about the current phase of society? What choice do non-billionaire/millionaire humans have for living in a single-planet society where technology is so highly integrated (and the inherent non-consensual compromises)? What If the little people are going to get squeezed even more? Troubling questions.
- Gigablah 11mo agoWell, would the community be willing to respond to AI-submitted CVEs without funding?
- opan 11mo agoLineageOS is based on AOSP and works well. I don't understand the banking app thing either. I suspect it's a regional issue. I can log in to my credit union account via any browser, and if something needs MFA it should be able to use TOTP which works on anything. Android in practice is full of proprietary blobs, stuck on old kernel versions, and the hardware is barely supported. Lots of downstream crap from the vendors not playing nice. Most devices running Android are instantly doomed to be e-waste. You can look through devices postmarketOS supports, and anything without mainline kernel support and most stuff working is basically e-waste unless someone puts in a lot of work for that particular device. It's a little bit like how modern GPUs don't work without blobs in the kernel anymore and you have to go back to Haswell era or older for things to work with all free software, but the state of smartphones is a few steps worse than that due to their locked down nature. Pretty much any OnePlus device (other than ones still too new) seems to be a good bet for decent software support (both LineageOS and pmOS). Though annoyingly stuff like the 3G shutdown makes a lot of the earlier models unusable as actual phones these days. At least they can still be computers. Not quite e-waste.
- devsda 11mo ago
- 0xbadcafebee 11mo agoDamn. I was excited by the prospect of Google shooting themselves in the foot, inspiring people to make Android replacements that aren't privacy and process nightmares. With this (partial) capitulation, the path of least resistance will remain a proprietary, corporate-controlled, bloated walled garden.
- arunc 11mo agoSoutheast Asian scammers - they could've directly said from India/Pakistan.
- ankit219 11mo agoGoogle is about to find out the next step of this chain - give access to everyone, don't gatekeep / do checks, and yet take responsibility for anything that goes wrong. "You should open up the tool, put no restrictions, and yet ensure that it is safe and secure" is an impossible task for anyone.
- yehat 11mo agoHow it was working till now for so many years, now suddenly can't?
- ankit219 11mo agobecause they put restrictions. now they cannot. because all the restrictions meant saying no to some legit things as well - inevitably. but then they got sued, laws got passed, to not be monopolistic, and still secure the users. this is the aspect of tech saying no when the thing being asked is impossible but people assume because they dont want to do it for whatever reason.
- Seattle3503 11mo agoThe Tyranny of the Marginal User strikes again.
- lobeai 11mo agoOh thank goodness, hopefully its implemented in a way thats not annoying for pro users
- chasing0entropy 11mo agoSuper obvious move. It will probably make you type "I understand I am Gonna get haxxored" while clicking a moving dot 5 times and promising you are super power user. This would have been the end of android as a phone OS.
- sschueller 11mo agoThey will just add a flag in the SafetyNet service to let other apps know if non "verified" apps have been installed. You will not be able to use any of your banking apps without first removing all of those... We need alternatives, this will not work and is a risk to freedom/democracy for all of us. Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. However Google and Apple can just remove it, what then? [1] https://github.com/swiyu-admin-ch https://github.com/swiyu-admin-ch
- nake89 11mo agoThey won’t remove it if its been installed from their app stores.
- sschueller 11mo agoThey removed the "ICE" app and if the US government has an issue with other Apps they bend over and do it. Switzerland is currently dealing with a 39% and Brazil with a 50% tariff because Trump has a personal problem with them. It would not be far fetched for an administration to have another states app removed.
- nake89 11mo agoI just want to preface that I am not in support of Apple or Google in their closed ecosystem. I was specifically referring to you saying "Switzerland is implementing a digital ID[1]. It will be made available to the most common devices and is open source. However Google and Apple can just remove it, what then?" It seemed like you were saying that because it is open source, it will be removed. I simply disagreed with that. Plenty of opensource software exists in the app store. I'm not disagreeing that they have the ability to remove software from their app stores. They have done that before as you mention. That is a fact.
- sschueller 11mo ago> It seemed like you were saying that because it is open source, it will be removed. I simply disagreed with that. Plenty of opensource software exists in the app store. Sorry if it came across that way. It is not what I meant, I just mentioned that it is open source. ESL...
- ramshanker 11mo agoAncedotal: I used to believe in this "freedom to install". Than my Father got scammed (~$1000) in the name of Electricity recharge. The APK was sent over WhatsApp. Now I am not so sure how to implement this freedom. At the bare minimum there has to be big red warnings. One thing which can immediately improve security is forbidding SMS read access forever. Just like Apple does. No App should be able to read SMS.
- eviks 11mo ago- warning - SMS read access So you do know - inform users, increase privacy,...?
- b112 11mo agoThe built in Android SMS app seems to be horrible in every incarnation I've seen. The one that comes with the Pixel, the one Samsung has. Some may like it, but I can't stand them. I tend to install my own SMS app in each case, and I don't use computers to be locked into something I don't prefer. It's my tool. Mine. I'll do with it as I please. I agree there are issues. But preventing installs aren't the answer, just like removing all windows and doors from a house isn't the answer to neighbourhood crime. I'd be more inclined to say the problem is allowing apps to be funded by advertising. If all apps were paid apps, and using personal data in any way was immensely, "thrown in jail" illegal, then you'd find yourself approving access to contacts, SMS, Pii quite rarely. It would really stand out in such a case. "What?! I've been using my phone for 10 years, and some app wants to see my contacts. Why?? No one reputable asks for that, ever!" So much of the problem with the internet is that Pii is paying the way. On GrapheneOS, when I install anything, it flat out asks me if I want to give it internet access at all. SMS could be the same way. Off by default, try to grant it, big warnings. At a certain point, if you have big warnings saying "Are you serious?!" and people turn it on, it entirely ends up being the end user's fault.
- a2128 11mo agoThere seems to be a whole market of Google Play developer accounts and apps for sale, developers like myself regularly get emailed by scammy companies offering to buy the account or to publish an app, and malware is regularly found on Google Play[0]. There's no reason to believe that bad actors would be stopped by install restrictions if their scam is effective enough to overcome the financial hurdles [0] https://www.bleepingcomputer.com/news/security/malicious-android-apps-on-google-play-downloaded-42-million-times/ https://www.bleepingcomputer.com/news/security/malicious-and...
- DeathArrow 11mo agoI can access any website or webapp without verification. I can install any app on my PC without verification. I assume the results of my actions and I accept that if something bad is going to happen, it's my fault. I am fine with that. I want the same kind of freedom on my phone, a device I own and I payed for with my own money. I am not smarter when using the PC and dumber when using the phone. I want to be able to opt out of verification and install whatever I want.
- rbits 11mo agoDon't know if I misunderstood your comment, but that's what the article is saying. You will be able to opt out of unverified app blocking.
- p0w3n3d 11mo agoThis is the last moment we can use to move out of this platform. We've already given basically all the control on our lives to two companies. They will decide one day that government will know our each move, our WiFi password, number of appliances, our body temperature and chemical compounds of our bodily fluids - every sensor that is connected to the system. 1984 all over again but this time IRL This is old rule: you don't need to take over control of all the people, you just need to take over those two-three suppliers that are covering all the people. If for example new politician Tronald Dump will take seat in 2035 in USA and they will try to push their agenda to other countries, they will take over the LLM, phone and OS providers, namely OpenAI, MS, Apple, Google. That's all to control to have the souls ruled all over the world. If something must vanish, will vanish. Like in the Ministry of Truth
- ptrl600 11mo agoIf it doesn't require a Google account and just means jumping through a bunch of hoops the first time, maybe requiring a USB cable, OK. If it does require a Google account, or won't let you give permission to F-Droid to install stuff, I call foul.
- 11mariom 11mo agoSecurity by obscurity. That's my device, that's my decision to install whatever I want. I see here and there some comments about someone was scammed, etc… Lack of knowledge of users is not a good reason. They still will get scammed, in a different way, but outcome will be the same. On PC one can install whatever want - and nobody is blaming OS for it.
- moi2388 11mo agoGood job everybody, just don’t start complaining when your family members installed malware, their banking and health information is leaked, and you have to fix this for them.
- ImHereToVote 11mo agoWe need Linux phones stat.
- Jean-Papoulos 11mo ago> We are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified I believe they will push responsability onto OEM.
- chemicalchance 11mo ago> Google will allow users to sideload Android apps without verification Mercedes will allow drivers to carry passengers without verification. Sounds silly, doesn't it?
- tauntz 11mo agoThat blog post really downplays the issue that people have with the verification requirement and is tone-deaf. The resistance to get Google's blessing for app distribution is definitely not limited to students and hobbyists - and I don't think that's even the biggest affected group.
- chemicalchance 11mo ago> Google will allow users to sideload Android apps without verification Ford will allow drivers to carry passengers without verification. Sounds silly, doesn't it?
- pi-err 11mo agoIf 90% of passengers were scamming the drivers or hijacking the car for some nefarious purpose that affects other cars, you definitely wouldn't find that silly.
- jwitthuhn 11mo agoI would think it is pretty silly if I needed some sort of verification to drive people I personally know around because other people were getting their car hijacked after choosing to pick up strangers they found on the highway.
- rom1v 11mo agoI want to be able to install apps from alternative app stores like F-Droid and receive automatic updates, without requiring Google's authorization for app publication. Manually installing an app via adb must, of course, be permitted. But that is not sufficient. > Keeping users safe on Android is our top priority. Google's mandatory verification is not about security, but about control (they want to forbid apps like ReVanced that could reduce their advertising revenue). When SimpleMobileTools was sold to a shady company (https://news.ycombinator.com/item?id=38505229 https://news.ycombinator.com/item?id=38505229), the new owner was able to push any user-hostile changes they wanted to all users who had installed the original app through Google Play (that's the very reason why the initial app could be sold in the first place, to exploit a large, preexisting user base that had the initial version installed). That was not the case on F-Droid, which blocked the new user-hostile version and recommended the open source fork (Fossify Apps). (see also this comment: https://news.ycombinator.com/item?id=45410805 https://news.ycombinator.com/item?id=45410805)
- leoedin 11mo agoI don't really see how you can both allow developers to update their apps automatically (which is widely promoted as being good security practice) and also defend against good developers turning bad. How does Google know if someone has sold off their app? In most cases, F-Droid couldn't know either. A developer transferring their accounts and private keys to someone else is not easily detected.
- niutech 11mo agoIn many cases developer e-mail address changes, IP address changes, billing address changes, tax ID changes...
- rollcat 11mo agoThis exactly. Transferring ownership is a business transaction. Track that. If the new owner is trying to hide it, this is fraud, and should be dealt with in court.
- 11mo ago
- WhoCaresAboutIt 11mo agoIt's not "sideloading". It is "installing". Just installing the software you want, on the device you own. I am not "sideloading" applications on Windows, either. I download and install them. And before the internet, you got your software on CDs or floppies and ... installed them. This is nothing new. The term "sideloading" somehow implies you are circumventing or side stepping some mechanisms or protections in a non-sanctioned / nefarious manner. I am not. I just install software on my phone.
- mid-kid 11mo ago> Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. We are gathering early feedback on the design of this feature now and will share more details in the coming months. I don't agree that this is something that should be restricted to "advanced" users, even. One of the basic freedoms that protects users from the unilateral control of the developers, is other developers (like me) being able to patch apps and distribute them to friends and family, without making a public fork or meeting play store requirements. Take for example, youtube revanced. If I want to help my friends by making a private f-droid or obtainium repository, to save them the trouble of going through the (legal!) process of patching and updating the app themselves, right now I can do this. If this requires going through a lengthy process instead, that may or may not be detectable by apps that will then choose to cease to function (this has happened with rooting), my ability to help friends and family as someone with the know-how and experience gets reduced significantly. There's many things that don't fly on the play store, such as the completely legal NewPipe, AdAway, and Termux applications, and while I can sign up for the developer verification, it's not clear to me under what circumstances the verification can be terminated.
- shevy-java 11mo agoInteresting. Did Google submit due to pressure? I have no idea. But if so then it shows the power people have. Perhaps we can make Google less evil if we complain a lot about things they do.
- tucnak 11mo agoWell, this is the most naive thing I've read all week.
- KurSix 11mo agoTying app distribution to a verified identity definitely raises the cost for scammers. But the devil's in the implementation. If "verification" ends up being too bureaucratic or expensive, it risks pushing legit indie devs and hobbyists away from the ecosystem entirely
- v3xro 11mo agoWhat prohibits Google from offering a way to register your long-term app signing key without identity verification, publishing apps that are still verified by their automated tooling and then opting in to the usual denylisting/app store banning methods if those apps are malicious? This identity verification requirement is basically just an easy way for illiberal governments to find ways to crack down on apps they do not like (such as say, ICEBlock or whatever)
- iggldiggl 11mo agoBanning all apps signed by the same key is already possible. Requiring signing keys to be anonymously registered with Google would add some friction to simply rotating your signing keys when you get caught doing something naughty (depending on how much Google account creation and key registration can be automated against Google’s anti-bot protection, though), but definitely not as much as full identity verification and payment of 25 USD (even if that isn't foolproof, either, and has the annoying side effect of unfortunately slowing down small-scale freeware developers at the same time, too).
- benob 11mo agoGoogle's move is very good for the web. By pushing app makers away from walled platforms, you turn them to standardized, open ones such as the web.
- constantcrying 11mo ago>we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. This is exactly the right thing to do and the best possible outcome. Google is correct that arbitrary Software installation can be harmful to users, especially those with limited technical knowledge. At the same time there are many users who want to install software freely and should be able to do so. The compromise of a clear and unambiguous warning of the potential dangers, which the user is then allowed to accept, seems very good and the right thing to do.
- NooneAtAll3 11mo agohow to make people forget about your bad practices 1) announce decision that will make everything even worse 2) wait for negative opinion 3) announce walking back on the decision 4) observe general sense of relief The only way this can be stopped is to make it costly to even announce "decisions making everything worse"
- maxlin 11mo ago>This is why we announced this change early: to gather input and ensure our solutions are balanced. Sounds like just trying to save face, they didn't have a language of "we're only _MAYBE_ stopping everyone from installing non-verified apps" back then. They were quite adamant. But happy that they're dropping the craziest part of this in any case. Won't stop me from investigating Graphene OS and other options when getting my next handset though, the previous move surely caused a jolt in my interest.
- mrasong 11mo agoIf everything’s completely open, it could lead to a higher rate of malware installs.
- cubefox 11mo agoThe current title of this submission is > Google will allow users to sideload Android apps without verification Which seems to be false. As far as I understand, Google still requires verification.
- jamesbelchamber 11mo ago..does Valve wanna make a phone any time soon?
- mcherm 11mo agoGreat! Based on this, I would like to sign up to get early access to Android Developer Console (to distribute apps ONLY outside the Play store). The article explains that they will start sending out invitations to people on the waiting list. But it does not say (or I can't find it) how to JOIN the waiting list. Does anyone know how?
- Phemist 11mo agoI don't see in what world you would want to test this and help Google make this feature better, especially if you're doing it for free.
- croemer 11mo agoActual title is "Android developer verification: Early access starts now as we continue to build with your feedback" Two key announcements: > we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. > We are using your input to shape a dedicated account type for students and hobbyists. This will allow you to distribute your creations to a limited number of devices without going through the full verification requirements.
- devsda 11mo agoDoesn't it mean Google will collect the app ids of all installs on all devices whether they are signed into an account or not. I'm not naive to think its not happening today, whats probably new is them admitting to it. How long does it take them to use that info to drop ban hammer on the user accountd for using apps like newpipe and hide behind reasons like violation of TnCs.
- iggldiggl 11mo agoThe student/hobbyist account type will most likely literally only be useful for that strict purpose, i.e. very small-scale distribution to a known quantity of people. I think it was mentioned somewhere else that that account type would require manually authorising each individual installation, so it'd still be useless for small freeware developers, who are only in it for the fun, too, but want to give away their software to everybody who might find it useful.
- poulpy123 11mo agoI don't understand the title, it's exactly the reverse, they will force verification for sideloading, even if they say they would have lighter requirements for hobby apps with low install number
- yellow_lead 11mo ago> Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified.
- rcMgD2BwE72F 11mo agoaka "Trust us bros"
- arnaudsm 11mo ago@dang this post title was editorialized against the rules, and is highly misleading. Should we revert it ?
- tomhow 11mo agoReverted now, thanks!
- jonathanstrange 11mo agoThat's by far not good enough. Google's reasoning is principally flawed. First of all, there is principally no good reason why adult people should be patronized by Google or other companies and kept from installing the software they want to install. Limitation of numbers just means that I cannot publish my .apk and let users install it freely. However, anyone who is allowed to smoke, drink alcohol, or get a motorcycle, should also be allowed to install whatever application they want. It's a matter of basic individual freedom. Second, the majority of reasonable users cannot be restricted from using their device as they wish just because a small minority falls for scams. A minority of people also drink themselves to death, die in motorcycle accidents, or smoke. There is nothing wrong with taking risks and taking responsibility for one's own life. We don't need for-profit corporations to hold our hands. Third, if they believed their own arguments, then they'd make certain functions such as intercepting SMS messages and installing a custom keyboard subject to stricter requirements with potential developer verification and keep the OS open and free otherwise. This would be a piece of cake since the technical infrastructure is already there on Android. The fact that they don't clearly indicates they're hypocrites and want to control users and developers, make 3rd party app stores harder or impossible, control which apps they "allow" as part of anti-competitive behavior, and possibly extract some extra cash from developers in the future. It's a pity how private computing is destroyed and that's the reason we all have to use inferior web apps until browsers are closed down in the same way in the name of security theater.
- Hilift 11mo agoMobile is such a second class operating system platform. I look forward to doing everything with Meta eyewear that also corrects vision impairments.
- dzogchen 11mo agoI will never use the term 'sideloading' for 'installing'.
- jbb67 11mo ago> his will allow you to distribute your creations to a limited number of devices without going through the full verification requirements. Sorry, *allow*? ALLOW? I'm sorry. My device. My software. My customer or friend. You don't have the right to insert yourself into the process. Very kind of you to ALLOW me to do something you have no involvement in whatsoever. Like everything google do the real reason for the plan is to let google insert themselves unwanted into someone elses business so they can extract money from other people's work. I would bin my android phone now if the alternatives weren't even worse,
- qwertox 11mo agoI'm already annoyed by the fact that when I upgrade my own apps, self-developed and only used by me, which are installed either from Android Studio or by letting the app itself download the update from my server (with the app installation permission) and me then installing it, that I must send the app to Google for them to make a security check. It's not an option, even if they pretend it to be one: if I click the text "install without scanning", nothing happens. I must accept the big button that uploads the app for a scan. It's none of their business. ADB is no alternative for me, because it's easier for me to send a websocket command to my 9 devices (mostly dashboards) so that they download the file and start the upgrade process, so that I then only need to press the "upgrade" button manually on each device. Remove the dashboards from the walls, just to plug an USB cable in them, to upgrade the apps?
- qwertox 11mo ago> Keeping users safe on Android is our top priority. Then let me decide which apps can access the internet, and which app can access which domain names / IP addresses. Because it feels like there are a lot of DATA THIEVES out there, selling my data to companies you work with. We call them Firewalls on the PC.
- Phemist 11mo agoWhile we are at it, please also reject the framing of "sideloaded" apps. This framing pushes the use of legitimately installed, often high-quality, software to the periphery. This framing is an essential step in extinguishing our computing freedoms, as "sideloaded" apps are easily cast aside. Recently I wanted to find a good app to manage my shopping lists as well as keep an ordering of this list so that I could run through the supermarket more efficiently. I really hate backtracking the supermarket to get some item on my list that I forgot was in a spot I'd already been. Of course, it had to work offline-first and I didn't mind a bit of configuration. Everything on Google Play Store was some cloud-integrated garbage app. The only app that came even close was an app on F-droid called Aisleron, which lets you manage both your home stock and supermarkets in terms of "aisles" of products, flipping easily between what is in stock and what is needed and then managing an aisle-based sorting of these products per supermarket that I frequent. Great App! However, I worry that this app would never have been released had Google considered actively blocking the author from creating legitimate and highly useful pieces of software like Aisleron.
- malcolmxxx 11mo agoSideloading? Really? So I'm not installing stuff on my phone, but sideloading... must be something illegal, isn't?
- Noaidi 11mo agoSorry, really confused user here, so can someone ELI5 for me? I was looking to go to GrapheneOS, will this effect that at all? The title now says they will allow side-loading and it sounds like good news but everyone in here is still complaining. I do not mind this extra step and I think it is way better than what my POS iPhone 16e with Liquid@ss is offing me. "Based on this feedback and our ongoing conversations with the community, we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified. We are designing this flow specifically to resist coercion, ensuring that users aren't tricked into bypassing these safety checks while under pressure from a scammer. It will also include clear warnings to ensure users fully understand the risks involved, but ultimately, it puts the choice in their hands. We are gathering early feedback on the design of this feature now and will share more details in the coming months. "
- nirui 11mo agoExcuse me, what exactly is "sideloading"? If I wanted to run third-party code on a system through the means that's supported by the system, then it should be called "running", it's a part of normal operation. The word "sideload" made it sound like you're smuggle something you shouldn't onto the system. Subtle word tricks like this could sneak poisons into your mind, be watchful.
- aargh_aargh 11mo agonewspeak FTW!
- rollcat 11mo agoYou can't make people just stop using a word. The best course of action is to reclaim it. Look at us, we're posting on Hacker News. With a sideloaded browser.
- glenstein 11mo agoThey already did! The word was install. Or as GP noted, run. They're actually even now much more conventional and widely understood uses, and if anything it's Google attempting to swim against the stream and normalize sideload as language for software installation. Theirs is an object lesson, I think, in appropriately registering the objection and pushing us back to normal language.
- troyvit 11mo agoI keep hearing that here, and people have good reasons why they think of that but to me sideloading always meant having your phone physically next to the device you're pulling an apk from, in other words loading the app from the side.
- glenstein 11mo agoYeah, that strikes me as a familiar use also. They seem to be using it to mean not only that but any software installation that doesn't happen via the Play Store, so it's rooted in real history but also conveniently re-appropriated to imply it's veering outside of typically intended use cases.
- A4ET8a8uTh0_v2 11mo ago"Allow". This is the entirety of the problem. They are allowing things on my machine that I purchased with monies that I leased my soul for. Anyway, I am already planning for a future in which Google does not feature as prominently as did until now. Small steps so far ( grapheneOS ), but to me the writing the wall is unmistakable. Google got cold feet over feedback and now they can allow things. When negative publicity ends, they will start working towards further locking it in again. I am personally done with passively accepting it. It might be annoying, but it degoogling is a simple necessity.
- sdoering 11mo ago> I am already planning for a future in which Google does not feature This. Currently I am still a paying Google customer for a few things running my freelance side business. I am in the process of migrating my data out of Google Drive and migrating my photos out as well. Next step is taking back control over my email infrastructure. Especially as google nowadays sorts quite a relevant number of important mail to spam, while allowing more and more crap to pass into my inbox. Also they one sidedly raised the price because they now have AI included. Fuck them - I am not using their shitty AI and I did not buy that. I am using AI daily - just not the crap product Google shoved down my throat. garpheneOS/postmarketOS are next on my list. As I have a tertiary device around, I will during the dark months ahead set this up and see if it fits my needs. With Arch now my daily driver (except for the main job), I plan to use way less US tech vendor crap. There are so many beautiful and not to difficult to use OS solutions out there, easily hostable on servers inside a more sensible jurisdiction. Also currently working on a solution to get around the enshittified YouTube experience. Without it becoming an unreasonable effort to still watch the interesting things on my big screen in the living room. But automated AI audio translations did this in for me. I already find the automated title translations to be abhorrent - now, having had the absolute shit experience of starting a video and having it dubbed by an awful AI voice was just a bit too much for me.
- xandrius 11mo agoConsider UbuntuTouch, really nice ecosystem and community, you can run many Android apks.
- talkingtab 11mo ago"Keeping users safe on Android is our top priority." This is propaganda. It is a statement made to dissuade people from the real issue. The top priority is to make money. It is hard to to trust anyone who starts communication with an obvious falsehood. Users beware.
- rpdillon 11mo agoSo an interesting intellectual exercise is to try to figure out how you would create a power user toggle that is coercion resistant. The best I've been able to come up with is a timed lockout that is random in how long it takes to allow you to finally move into power user mode. So like a random value between 1 hour and 24 hours and you say I want to be a power user and then it says you have to wait 3 hours and 27 minutes before you can become a power user. Randomness because a scammer could optimize around a particular time period that was predictable. Other thoughts on how you could make a coercion resistant power user toggle? I'm very excited that Google's thinking about offering this because it gives me faith that just because I chose to be in a minority, I won't be relegated. On the flip side, I was so shaken by the original announcement that would kill off F-Droid that I've been very actively looking into building my own mobile device that runs Linux. I purchased the components for a Hackberry Pi that I'm hoping to build in the next couple of months, but knowing that Android won't kill off F-Droid entirely is heartening.
- maxloh 11mo agoThat could be done by requiring the use of ADB. Normal users would found it troublesome to setup a phone through command line. To make it even harder, they could also require a verification code from your phone manufacturer, or the package of your device, which makes it impossible to automate the switch into power-user mode.
- Gormanu 11mo agoBold move from Google — finally admitting the Play Store has a trust problem. Verification sounds great on paper, but if this turns into “prove you’re a real dev by jumping through 12 forms of bureaucracy,” it’ll just push more talent to sideloading and open platforms. Still, if Google actually nails this — transparent, fair, and fast — it could be the first time in years Android feels safer without feeling locked down. That’d be a plot twist I’d love to see.
- p1dda 11mo agoThis monopolist dictates its demands. It's pretty outrageous behaviour from a company that has grown by parasitizing Internet infrastructure built with taxpayer money. That's how far you get by bribing every US politician. It's a banana republic, a fucking shit show.
- a456463 11mo agoYou don't own that device you paid >$1000 for because google deems it so
- jMyles 11mo ago> Keeping users safe on Android is our top priority. I'm really over third parties telling me that my safety is their priority. Unless you're transporting my body (ie, airline, ride share, etc), then I really don't need you to be looking out for my safety. See the problem is: when you do look out for my safety, you do it by giving yourself control over my life that is not healthy for either of us. Let my safety be my concern, and the functionality of your product can be your top priority.
- AdmiralAsshat 11mo agoIn light of Google's recent push to eliminate this, I went and installed F-Droid to see what we'd be losing. I had thought about it for years, but always held off on doing it on my daily driver phone because I simply didn't want to open the floodgates on allowing apps to start randomly installing on my phone. But having done it, I'm actually pretty impressed with the existing security. At least on my S24, you have to both enable sideloading at the system level, and enable each specific app to be allowed to "Install other apps" (e.g. when I first tried to launch the APK that I had downloaded from Firefox, I received a notification that I would need to whitelist Firefox to be allowed to install apps. I decided no, and instead whitelisted my File Manager app and then opened the APK through that). I then installed F-Droid, allowed it to install other apps, installed NewPipe, and then toggled back off the system-level sideloading setting. NewPipe still works, and I don't think anything else can install. This satisfies my security paranoia that once the door to sideloading is opened that apps can install other apps willy-nilly. Not so. So I really don't see what this new initiative by Google solves, other than, as others have said, control. The idea that somehow all user security woes come from sideloading apps and they would somehow be safe if they simply stuck strictly to the Play Store is patently untrue, given the number of malware-laden apps currently lurking in the Play Store.
- NoGravitas 11mo agoYou can also de-whitelist your file manager app from installing apps after you install F-Droid.
- boogerfinger 11mo agoI have been an Android fan-boy since 2010 (hello HTC Evo!). Blackberry until that. Never owned an iPhone until a month ago. There really is not a benefit to owning an Android smartphone anymore if they are going to knee-cap F-Droid.
- fithisux 11mo agoIf I install Android on a Raspberry PI do I still have this restriction? Can I use FDroid?
- p0w3n3d 11mo agoI had been Android fan from the start. When first Android phones went out I was astonished by the amount of possibilities. There were linux phones available, my colleagues used to set up ssh servers and more. Samsung had Baidu at that time which at least to me appeared more closed than Android. Things have been going bad since then. Closing of root access, closing of software, youtube not working in split screen etc. All the changes make me think of Android as more and more repulsing. Recent changes like removing old software from the store because they didn't update API and now this... Google stop being evil
- oblio 11mo ago> Google stop being evil You think this is evil? :-))) Watch what happens as they can't grow by 10% per year and their share price tanks in 5-10 years.
- panny 11mo agoNo thanks. When my apps stop working, I stop carrying your phone.