26 ms·
Google confirms 'high-friction' sideloading flow is coming to Android
- ggm 9mo agoTBH this doesn't seem a particularly high friction change. It seems very like what we have to do already, or like what we do on OSX.
- 71bw 9mo ago> like what we do on OSX. ...which is so much of a complicated nuisance that most people simply give up. If this will go the way I think it will prepare to have to skip 10 things, write 3 ADB commands and submit a video of you spinning around for 30 seconds just to install your pirated game.
- Terretta 9mo ago> so much of a complicated nuisance that most people simply give up Most people should give up. The number of legitimate unsigned apps for MacOS that your grandparents should frictionlessly one-click-to-install is essentially nil. Meanwhile, they're receiving countless bullying demands a day to install keyloggers and drain their bank accounts. The threat model tradeoffs are clear.
- bigyabai 9mo agoThe threat model doesn't work. It depends on Apple doing their job, and even $99/year doesn't prevent Apple from signing a Trojan horse of your competitor: https://blog.lastpass.com/posts/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store https://blog.lastpass.com/posts/warning-fraudulent-app-imper... You want to talk about confusing Grandma? Why isn't Lastpass the first entry on the App Store when you search for it verbatim? At the going rate, installing signed software is more deceptive than searching for the official installer online.
- vee-kay 9mo agoNot sure if anyone should be installing Lastpass. It's been massively hacked in 2022 and 2024, and there's currently an ongoing attack (Jan 2026).
- fc417fc802 9mo agoA single scary warning per source (ie per new certificate that you choose to trust) would be fine. If I had to jump through a few hoops to install f-droid on a stock device that would be fine. But once I've authorized f-droid the OS needs to shut up and stay out of the way for good. No "are you sure you want f-droid installing this other thing" nonsense.
- Der_Einzige 9mo agoThis is the human death drive externalized into thought. Reject it in all of its instances with extreme prejudice.
- subscribed 9mo agoJust to install a proper call recorder or a better Work Profile manager. Turning a possibility to install software outside of the app store should be about as normal as the fact you're using a laptop or desktop to install your pirated games. Yeah, you. If someone having access to "side load" an app has it to install a pirated game, then you have your OS, where you are not limited only to Apple/Amazon/Google store, simply for installing pirated software. QED :)
- tracker1 9mo agoI absolutely HATED the first time I had to deal with it... at least now it works a little better.. but the first version didn't actually tell you that you needed to go into security settings right after to enable the install. Still not a big fan of it... though admittedly mostly just install stuff via brew/cask more than direct downloads as a result.
- saidinesh5 9mo agoThey did not specify what exactly is the new workflow is/what is high friction about it in the post no?
- faust201 9mo ago> like what we do on OSX. You are on macOS. Not others. You are following Apple. We don't.
- fc417fc802 9mo agoHow does this relate to the announcement from a while back about introducing signatures that tie back to Google? (IE trusted developer program or whatever they're calling that horse shit.)
- 3836293648 9mo agoThis is in response to all the pushback they got from that
- AlotOfReading 9mo agoGoogle's long term strategy with Android is baffling to me. Apple has had better mobile hardware for years. Apple has higher consumer trust. Apple has better app selection (for most people). Apple has been increasingly implementing the core features that differentiate Android devices, like USB-C and RCS. Every Android user lost to the increasing iOS market share is another customer Google has to pay exorbitant fees to a competitor to access. And Google's strategy is to continue removing differentiating features from Android that also help them mitigate the threat of antitrust? Surely the marginal revenue from the inconsequential number of sideloading users isn't attractive enough to justify that kind of strategic blunder.
- 3abiton 9mo agoTheir strategy is growing markets, especially in india, and africa, and of course China. It's where the chinese oem dominate. Beside chinese OEM, i think the only other player is Samsung. So google strategy seems to be to circumvent people from misusing their OS by blocking certain services (mainly ads). This is done via apps from fdroid, and rooting and what not. If google can control how people uses their devices (block vpn based adblocking, or rooting all together), they have better grip on the market. At the end of the day, Android is front for an ad platform.
- thaumasiotes 9mo ago> [Google's] strategy is growing markets, especially in india, and africa, and of course China. Really? China? Where Google services are banned and Android phones come with local OS versions that cut them out? "High-friction sideloading" won't affect anyone in China. It won't be part of their experience at all.
- londons_explore 9mo agoI think OP is suggesting that the ability to sideload is what is preventing their phones being distributed in China. If you can present a "locked down" phone to regulators, you might be more likely to get permission to sell large volumes of them - like iPhones in China.
- whyagaindavid 9mo ago> Matthew Forsyth, Director of Product Management, Google Play Developer Experience & Chief Product Explainer, said the system isn’t a sideloading restriction, but an “Accountability Layer.” And... What about accountability for hosting distributing spyware, malware loaded apps from Google Playstore and hundreds of copy cat, misleading apps? Why can't they pose a question when the phone is setup? - Yes, I want to sideload - No I dont want If the user says NO then to later enable it to allow sideload Yes, the user needs to factory reset phone. Done.
- teruakohatu 9mo ago> And... What about accountability for hosting distributing spyware, malware loaded apps from Google Playstore This is no joke. The Playstore is filled with malware that pretend to be a different app. It takes days if not weeks to remove these apps. I have twice now had to recover the devices of family members when they installed malware on Samsung phones running up to date firmware. That malware to this level is even possible is another matter.
- torginus 9mo agoA somewhat unrelated thing, is I got bombarded with ads for a 'mental health mindfulness' service on one of the major international news websites. I decided to Google the company after a few days. I was immediately confronted by thousands of reports by angry users, complaining about how after they tried the app, they got locked into a yearly subscription at exorbitant prices and it was impossible to cancel. The company itself is registered in some offshore tax haven. They used to scare us, that if we went to those shady pirate websites, somebody would steal our credit cards and steal our money. Well...
- The_President 9mo agoThis problem is significantly worse than the height of Windows XP spyware.
- e145bc455f1 9mo ago>And... What about accountability for hosting distributing spyware, malware loaded apps from Google Playstore and hundreds of copy cat, misleading apps? The rules don't apply to billion dollar corporations. Meta is showing 15 billion scam ads per day. https://www.reuters.com/investigations/meta-is-earning-fortune-deluge-fraudulent-ads-documents-show-2025-11-06/ https://www.reuters.com/investigations/meta-is-earning-fortu...
- MrDresden 9mo agoWhen this whole thing got announced, I purchased a new Pixel 9 and flashed it with GrapheneOS. I am hoping that in about 6-8 years (when I realistically need to update) the landscape might be a bit better. Or who knows, maybe I'll just continue using GrapheneOS. So far I have not had a single issues with it. Apps the rely on attestation do not work, but honestly it's only two applications out of hundreds so I can live with it. I also financially support GrapheneOS on a monthly basis (15$). This is just too important of an project not to.
- rich_sasha 9mo agoI think the EU should pile in as well. It's basically an oven-ready independent mobile OS.
- onli 9mo agoGraphene OS spends its social capital on hallucinating attacks from other projects and bullying other projects by sending their followers against them, based on those hallucinated attacks. It also has a completely intransparent project structure based around a supposedly retired mean developer, who then just did not (and still does almost all commits). That's not a project where the EU can invest money in, and the confidence users on HN tend to put into that project is baffling.
- cakealert 9mo agoYes that guy is extremely weird, he should delegate operations and community management to someone who isn't weird and stick to development.
- tazjin 9mo agoThese weird anti-Graphene posts confuse me. I use GrapheneOS, fwiw, and I believe some things the project does (like its attacks on F-Droid) are misguided for orthogonal reasons. However, it all makes sense from the perspective of Graphene not attempting to be a general purpose OS like Lineage, but explicitly a security focused OS. Security is often in conflict with what the average consumer wants, and they can go use Lineage or whatever. It's like writing lots of comments complaining about OpenBSD devs coming across as grumpy and refusing to support Bluetooth. That is part of their value proposition! You're just not the target audience and that is okay.
- n0vella 9mo agoDon't be evil
- swe_dima 9mo agoI am not very well educated when it comes to alternative stores landscape. But I do know that in Russia there's now Rustore: https://www.rustore.ru/en https://www.rustore.ru/en which functions by automatically downloading and updating APKs for you. During the APK install, however, you do see the ugly Android prompt about how this app may be dangerous. Rustore has its own app payment system, which obviously circumvents Google Play fees. This works on regular Android phones. Are there other examples of such stores? Perhaps it's Google's answer to that.
- hexfish 9mo agoF-Droid and derivatives are really popular in the FOSS community.
- swe_dima 9mo agooh, right! Didn't have my coffee yet :-) But one difference is Rustore actually has payments and subscriptions, which hurts Google more.
- necovek 9mo agoI was expecting Google has stopped doing most of the business in Russia due to sanctions. Do you still see Russian-company ads in Google Search results or Youtube? Similarly, I thought they were not selling apps or ads in Google Play store in Russia either (they might be showing ads from non-Russian companies because, well, that just increases the show-count and absolute number of clicks).
- swe_dima 9mo agoI no longer reside in Russia, so I am not being targeted by these. But I think that it mostly comes down to companies being able to pay for these ads. Mastercard / Visa payments no longer work in Russia. If a company has a way to pay (by having another business entity in another country), then it probably works.
- 9mo ago
- necovek 9mo agoI would like to see a high friction flow for installing all the crap from the Play Store to "protect and educate users". "Are you sure you want to install this app? It's only got a score of 2.8 and only 7 reviews, and will ask for all of these permissions?"
- Culonavirus 9mo agoEven if it has 4.8 and 7000 reviews it's often fake 4.8 because the reviews are botted / paid / dark patterned (e.g. when you pop up star rating on your users and beg them "rate the app plz" and when the users tap anything but 5 stars you say "k, ty" and keep those "bad" reviews for yourself)
- necovek 9mo agoThat was just an example to communicate my idea: a better way to validate authenticity of the app could and should be used. But to your point specifically, Play store and App Store have APIs to rate from within the app: when the pop up shows, app author does not have an option to avoid getting a 1-star rating (they are also time-restricted, eg. at most once every 180 days for Apple IIRC). What devs do though, is to preempt it with "Are you enjoying our app?", and only giving you a formal rating pop-up if you answer "Yes".
- kotaKat 9mo agoThe hilarious part in all of this is watching Epic Games sue Google over how bad the "high friction" flow was for them to sideload their hefty bundle of Google Play violations and win the rights to be back in the Play Store. It's OK now that Epic can have a one-click download for Fortnite to shove all the friction back into the sideloading experience.
- _ink_ 9mo agoAnd I want to see transparent price structures. Hey, this app is free. Installed. Only works with subscription. I hate it. Edit: to clarify, I don't hate subscription, I hate that I cannot search for free apps in the store.
- 9mo ago
- p0w3n3d 9mo agoI heard that the frog boiling is a myth. You can't boil frog alive, it will jump out. As opposed to humans
- eloisant 9mo agoThat's because the frog has low switching costs from the pot to the outside world.
- p0w3n3d 9mo agofrog is not pot-locked-in
- xethos 9mo agoThe frog had to be pretty well lobotomized to keep it from jumping out. One can recreate the ”experiment” with a lobotomized frog and mostly get the result described though
- tjpnz 9mo agoPart of me thinks they wouldn't be doing this if their own ad team wasn't knowingly accepting money from fraudsters.
- otikik 9mo agoAdd high friction to scammy ads on your platform, Google
- PunchTornado 9mo agoI agree with high friction sideloading. it is the best of both worlds. no friction sideloading is too easily exploited by scammers. having a member of my family exposed to this kind of thing in the past taught me some things.
- reddalo 9mo agoI don't agree with the word "sideloading" though. It's just _installing_.
- B1FIDO 9mo ago"Installing" has the connotation of doing it directly from the Play Store. This is also known as "Downloading" (because the data is on a server, in the cloud, and you're fetching it "downstream" to a local device.) "Sideloading" doesn't refer to the installation process, but to the file transfer process. You're sideloading when you transfer, e.g. APKs from your notebook to your Android. Or, from a USB stick into your phone or something. In general, though, "sideloading" also refers to any "non-app-store" installation. It's a kind of colloquial shorthand. It's not really a technical term. But it's adequate for getting the point across. If you just called it "installing" without qualifying it, how would anyone know that it's a different process, or that it's accomplished not by navigating to the app store? It seems that you would invite ambiguity here!
- clhodapp 9mo agoThe point is that before walled-garden app stores, that was how pretty much every normal person installed software on their PC's. Using the term "sideloading" for that is a clever invention to try and retroactively rebrand what is actually super-normal as something scary.
- B1FIDO 9mo agoIt is not really though. "Sideloading" refers to data transfer between two local, peer devices. Really, that is it. It is not "something scary" or something forbidden. It is not even really installing. It's data transfer. So "before walled-gardens" people would install software in many many ways. I originally typed it in from scratch, or from a magazine. I loaded it from tape. Or diskette. That's not really "sideloading" if you think about it, because it's just "loading" from peripheral storage. Later, when people dialed up on a PC, they could "download" software and then install it or do whatever with other data or media. They could also upload it. They could transfer it among devices locally. This was not, at the time, called "sideloading" but just transfer, or "null modem", or "sneakernet", or "a station wagon full of backup tapes". If we're going to use "sideloading" in the strictest sense, then we cannot actually refer to the process of downloading APK files separately and then installing them, because that's literally downloading. But that is the colloquial meaning now. Hey, if you want to coin a new term or neologism for it, by all means do so. But it seems absurd to downplay "sideloading" as having "scary" or "negative" connotations, when it really doesn't. You've got to look past the hype and F.U.D. Remember, there was a time when people considered FTP and torrenting to be dangerous or subversive. Perhaps they still do.
- BatteryMountain 9mo agoIf the make sideloading high-friction, either via account-bound or apk upload or permissions from MNO/ISP, I will leave android. I have a bunch of my own apps that only I use, not released to the public, if I cannot use them, I have zero reason to stay on android. I think one of the reasons they want to lockdown the system is to prevent guys like me from locking THEM out of my home/ecosystems, as and example, I build my own launchers, specifically for TCL TV's, which runs Android TV and has Developer Mode + adb. Which means I remove all the bloat & ad garbage, which they want to prevent. We will get to the point where google will remove your ability to set custom dns servers and only use theirs.. just wait & see friends. Anywhoo, when this side loading fence materializes, I will jump ship to apple.
- shreddit 9mo agoYeah, as an iOS dev, the grass is not greener on this side of the fence…
- stavros 9mo agoIt's not, but at least it will be equally ungreen.
- jeroenhd 9mo agoFrom that I can see from the early leaks, it may actually be if you live inside of the EU where alternative app stores are now a requirement. iOS doesn't have the F-Droid ecosystem equivalent, but she F-Droid dies because of Google, there's a chance AltStore will be able to take its place.
- saurik 9mo agoThe point isn't that things are better on this axis on iOS, but that things are better on numerous other axes, to the point where many people are only using Android at all because it feels slightly more open and free than iOS... if Google wants to play Apple's game, then the only reasons to bother with the mess that is Android are gone, and so you'll see people switch to iOS.
- Sophira 9mo agoThe image at the top of the article is actually what already happens in Android and has done for years. At first, I thought that this meant that the article was very outdated, but no, this is from January 2026. I imagine the text of the article is fine, but I'm a little bit disappointed that Android Authority chose to lead with that image and caption and make it seem that this is what the future flow would look like. You'd think they'd know better.
- throwa356262 9mo agoI think i have an idea that would better protect normal users while not getting in the way for power users and developers: 1. All applications must be signed with a valid store key. 2. Anyone can import a store key after rebooting into the bootloader (similar flow as custom roms) 3. Google can maintain a list of malicious keys and reject them Why is this better? Because it makes it much harder to trick grandma into installing an APK some site just dropped.
- faust201 9mo ago1. google can arbitrarily revoke key. Countries can revoke key. 3. Like the amazing malicious crapware from PlayStore that they allow. They don't reject that. 4. Grandma installs crap mainly from PlayStore
- jhanschoo 9mo agoAs TFA does not mention it, and I don't see any top-level comments discussing it, this is a continued rollout of a "feature" first piloted in Brazil, Indonesia, Singapore, and Thailand. See: https://android-developers.googleblog.com/2025/08/elevating-android-security.html https://android-developers.googleblog.com/2025/08/elevating-... https://android-developers.googleblog.com/2025/11/android-developer-verification-early.html https://android-developers.googleblog.com/2025/11/android-de... https://www.channelnewsasia.com/singapore/google-android-devices-malware-scam-unverified-apps-sideloading-4102991 https://www.channelnewsasia.com/singapore/google-android-dev... Of course, HN reaction has always been skeptical about this including in earlier news. But the reporting on it, and the countries in which it is piloted in, seems to me to involve government/banking industry cooperation with or pressure on Google to combat cyber fraud. These polities are prime targets for Android cyber fraud of this sort due to Android penetration, and seemingly (to me) also cultural proximity to scam operators, and tech-illiteracy among the vulnerable demographic. (And anticipating a reply I got from a previous article on my comment on this feature---no, it's just not feasible to comprehensively educate retirees against evolving tactics by scam operators and expect that to be a sufficient sole countermeasure.)
- raverbashing 9mo agoYeah for every HN user complaining about it there are hundreds of people sideloading apps (not realizing what they're doing - under promise of loans or other advantages) and then getting their phone ransomed
- direwolf20 9mo agoFor every person getting ransomed by a sideloaded app there are ten people getting ransomed by apps they installed from the Play Store.
- raverbashing 9mo agoAnd two wrongs don't make a right
- spwa4 9mo agoThe real question is if you can still sideload: 1) a .apk that was not developer-verified 2) without informing Google of this
- GuestFAUniverse 9mo agoThe highest risk is the play store itself. Gambling and addiction. So, when does Google add "high friction" there, instead of encouraging it? Ah, well, it's the money! Than stop bending the truth.
- ycombinatrix 9mo agoThe current system is already high friction. Enabling "advanced protection" in your google account additionally requires installing apps through adb.
- or_am_i 9mo agoSteam phone incoming in 3... 2... 1...
- oceansky 9mo ago"3? What's that?" - Valve
- huflungdung 9mo ago[dead]
- ReptileMan 9mo agoThe year of linux desktop unironically may be close. What is the situation with mobile?
- danelski 9mo agoThere are community projects, but no Valve in sight.
- xandrius 9mo agoI take the opportunity to let people know that there are alternatives to Google/Apple duopoly on mobile. Link: https://www.ubuntu-touch.io/ https://www.ubuntu-touch.io/ Sure, GrapheneOS is often suggested but Ubuntu Touch is a really interesting alternative, their own store and ecosystem. The community is amazing and welcoming. If there are Android apps which you can't do without, they can be emulated and used anyway. Imagine switching to Linux and then using Wine for the apps you really still need. Yes, it's not perfect but Linux isn't either. If you think you're sufficiently tech savvy and want to make a change, give Ubuntu Touch a try. Find a cheap second hand supported device and play around, make some fun apps. (devices currently supported: https://devices.ubuntu-touch.io/ https://devices.ubuntu-touch.io/ ) To me it's like being back when there was only Windows and Macs as viable home computer OS, and people were getting their feet wet with Linux and all its flavours. Now, it's the same but for mobile.
- Al-Khwarizmi 9mo agoCorrect me if I'm wrong, but I suppose emulating Android apps on a non-Android system will have the same problem as trying to run them in an Android without Google Services or in a rooted phone, i.e., banking (and similar) apps detecting it and refusing to run? Were it not for that, I would never have stopped using Huawei, IMO the best phone brand by a mile. But I'm too busy a person to depend on hacks and having to regularly find new workarounds to access my banks.
- gspr 9mo agoI think you're right about certain apps refusing to run in an emulated environment. I'm beginning to think we need to consider such apps, and the hardware they run on, as the outsiders. Keep a cheap "normal" Android phone for those apps, and those apps alone. Then keep a "real" second device for everything else. Up to you which one gets the SIM card and provides connectivity for the other (and ordinary phone services). I'd rather go back to old-fashioned hardware dongles from banks – but hey, lacking that, maybe I'll just think of the first of those two devices as a clunky, overly expensive one of those.
- 9mo ago
- WhereIsTheTruth 9mo agoIn the technofeudal new world order, your smartphone is not just a device, it is your gov issued digital ID/wallet The Apple/Google OS duopoly exists by design, they view bootloader unlocking and sideloading as threats because they break that control They want to be able to define and/or revoke your existence in the system No escape, because no alternative
- danelski 9mo agoExactly. For most people not having a bank app, probably no digital payments due to that, and no government-issued digital ID is too much friction to even consider any alternative.
- hans_castorp 9mo agoCan we please stop calling it "sideloading"? It's simply "installing" software on hardware that I own, and that I should have full control over.
- deleted 9mo ago[deleted]
- shakna 9mo agoIf that's your bar - you should ban the whole of Android's ecosystem from your networks. https://www.bleepingcomputer.com/news/security/malicious-android-apps-with-19m-installs-removed-from-google-play/ https://www.bleepingcomputer.com/news/security/malicious-and...
- spondyl 9mo agoI'm sure I'm missing something but wasn't this already the case where the first time you try to install an APK, you had to go into Settings and mark the relevant application as a trusted source for installing APKs from?
- tentacleuno 9mo agoSome friction is probably wise. I remember them introducing the requirement to individually allow each app you're installing things from. The question is, how much more friction will they add? I suspect they will add prompts per install, too.
- 1023bytes 9mo agoSome manufacturers like Xiaomi already have a very annoying flow for enabling developer options and using ADB. You need to have a SIM card inserted, need to create a Xiaomi account and there's several popups with timers you have to wait through.
- isodev 9mo agoSo, which 3rd mobile vendor and/or OS are you moving to?
- barnabee 9mo agoNot OP but my GrapheneOS phone is fine with me installing things on it. It just seems like a better Android at this point.
- mrsssnake 9mo agoWould switch to PostmarketOS tomorrow if there was any fully supported hardware (camera, 4G calling, etc.). All programs/apps I use are FOSS and standardized anyway.
- LePetitPrince 9mo ago[dead]
- einpoklum 9mo agoThose of us who use Android phones now - and install FOSS apps form F-Droid or just any apps from elsewhere other than the church of Google - might be thinking: "Oh, I need to work out how I'll have decent app access after this happens." But what we should really be thinking is: "Oh, I need to _donate_ to projects which aim to patch Android-based phones to remove these restrictions; or to projects which aim to replace (most/all of) Android completely". We need to speak with our wallets in addition to just ranting about Google.
- qiine 9mo agoSometimes I wonder I we should instead fund massive marketing campaigns instead, because the vast majority of people have no idea it's even an option.
- goldenarm 9mo agoSideloading is a neologism to scare users and lawmakers, it just means "Installing software" and should be a basic right. Also software installation in Android has been high friction for a while. Installing an APK on my phone is at least 10 clicks.
- B1FIDO 9mo ago[flagged]
- goldenarm 9mo agoThat is my own opinion as an Android developer and ex custom ROM maintainer, I've not read that blog post. Instead of ad-hominem, can you explain what do you really disagree on?
- B1FIDO 9mo ago[flagged]
- goldenarm 9mo agoYou're infantilising the users. It's untrusted by Google, but it's trusted by myself. I actually trust the Termux and Kodi devs way more than Google, yet they Google has been blocking their updates. Note that the term sideloading is exclusively used by mobile OSes. On Windows MacOS and Linux you can install anything.
- B1FIDO 9mo agoWhat I'm talking about is actual trust. Like, there are cryptographic measures taken, certificates involved, code signing, that kind of thing. You claim that you "can install anything" on Windows, but that is simply false. The system's Driver Signature Enforcement will prohibit the install of unsigned or invalid signatures on device drivers. Windows SmartScreen will also give you trouble by blocking unsigned apps. So yeah, you can bypass these protective measures and "install whatever you want" ultimately, but it is basically the same process as sideloading on Android, isn't it? Disabling a bunch of protections that are there for your safety? Your trust, honestly, doesn't mean jack shit. There is cryptographic signing, and certificate authorities, and processes to approve the certificates that authorized developers use. You don't got jack shit with your "trust" of Termux and Kodi. It means nothing to the end-user. We do not work in "trust me bro" territory when it comes to signing software, anymore. I am sorry/not-sorry to say. It is very important to have a chain of trust that goes up somewhere above "goldenarm @ HN".
- middayc 9mo agoI was never an iOS user, or developer - exactly because Android was more "open", exerted less control over a user of the device. The same reason I use Linux for 25 years (not ideological, but it just makes most sense by far). In time where this view (win11 vs. Linux) is starting to make sense to more and more people, few rare config nuances are getting easier to solve due to LLM-s, going into the opposite direction with a mobile OS calls for users to also start seriously considering more open alternatives and making a path for users of our app to do the same.
- zelphirkalt 9mo agoAh yes, such enormous friction, to install F-Droid and install an app via it, instead of Playstore. Argh, sooo much friction, really unbearable. /s Google is getting more ridiculous by the day.
- sylware 9mo agoFunny way to say 'dark patterns'
- Macha 9mo agoSo I was actually planning on upgrading from a Pixel 7 Pro to a Pixel 10 around the time this announcement came out last year, but have put it on hold as I wait to see what form these changes take. Like if it was "you need to do the developer 7-tap of the version label in settings", it'd be like "whatever". But given how long this process has taken, I suspect that is not what they've planned - it wouldn't take this long to develop, it certainly wouldn't take this long to explain. So I suspect that we're actually in the "Maybe Later" phase of "Google wants to control which apps you install: [ ] Yes [ ] Maybe Later". And I mean, if their proposed solution turns out to be "Me and 25 of my closest friends can install apps I make by phoning home to Google servers", then like, I can do that on iOS too. And if I'm not going to have meaningfully more control of my Android device, I may as well just go to iOS where Apple at least have a better privacy record and don't seem to have have an all-encompassing goal of "where can we put AI features to drive AI usage metrics up the most?"
- Sytten 9mo agoHonestly just install grapheneos on your Pixel, that is what I did and bought a Pixel for that reason alone. I use all Google play services and it works great, only payment with phone doesn't work.
- palata 9mo agoYes I agree: if you already have a Pixel, try GrapheneOS on it. Then if it can wait (Pixel 7 is still supported for a while, isn't it?), GrapheneOS may support a non-Google phone in 2026, so it may be worth waiting.
- ece 9mo agoIf auto-updating apps stops working on fdroid, I'll be installing Graphene, Lineage or taking a shot at something like postmarket/ubuntu touch/plasma mobile. I've used Lineage as a daily driver before for a while, so I'll probably just go back to that and tell developers to support the platform I'm using. It doesn't rent seek on developers or users.
- 1970-01-01 9mo agoI'm with Google on this one. Idiots and old people (the public) use these devices daily. These are the very same people that send money to Nigerian royalty and expect to hear back about a great reward. This is mostly a CYA move with hard data behind it. If they completely removed side load, that would be a different story.
- deleted 9mo ago[deleted]
- pawelduda 9mo agoThis bit of article is what I'm hopeful will happen: > That explanation broadly matches what we’re seeing in recent versions of Google Play, where new warning messages emphasize developer verification, internet requirements, and potential risks, while still allowing users to proceed.
- kwhat4 9mo agoIf google really cared about security, they would place ad's for shady apps right above the 2fa or banking app I searched for to install.
- hypercube33 9mo agoThe old saying goes a fool and their money is soon departed. Why should the rest of us be punished?
- gruez 9mo ago>Why should the rest of us be punished? Exactly. I'm sick and tired of all the apps/websites that mandate 2fa. All of that adds friction when I'm a big boy who knows how to choose secure passwords. For that matter, why even invest resources into fraud detection or law enforcement? All of that money is coming out of somewhere, and why should my tax dollars go toward catching fake nigerian princes when it's just helping idiots anyways? /s
- 9mo ago
- WarmWash 9mo agoThe Apple app store was ruled to not be monopoly. When Google inquired in court how that could be if Apple doesn't even allow any form of side-loading, including other app stores (which Google does allow) The judge said, I shit you not, Apple doesn't have any competitors on their platform, therefore they can't be anti-competitive. Probably one of the worst most off the rails rulings ever. Google took notes and is now following Apple. You can thank the courts
- w4rh4wk5 9mo agoSemi-related question: how invasive is the Temu App on Google Play Store nowadays. Last time I read about it, it posed a bigger threat to users than the average side-loaded app.
- largbae 9mo agoArticles like this where we lament being trapped in an ecosystem duopoly are contemporary with articles saying that software engineering is over and LLMs can just vibe code anything you imagine. What's keeping the duopoly in charge?. Code signing?
- koolala 9mo agoYou think a local model will get to that point? Some AGI revolution like your describing is impossible for humanity as a whole even if LLMs get that smart. The same companies control the supercomputers and your access to them.
- phendrenad2 9mo agoApparently this "high friction" is a term entirely invented by Android Authority based on finding a few new generic warning messages about sideloading in the Android source?? I guess if there's no news, you have to play word games to make some.
- charles_f 9mo agoWait so did this rollback? Initially they were about to forbid any install from non verified accounts, then allow them but just a limited number, this article seems to suggest there will just be extra steps?
- TurboSkyline 9mo agoYes, after that they said that there will be an on-device flow to load apps from outside the Play Store after all. They didn’t describe how that will work and I didn’t see it discussed as commonly as the original announcement; I only saw it mentioned by the way in a Reddit thread.
- Noaidi 9mo agoBOYCOTT.
- kazinator 9mo ago> Google says the added friction is meant to educate users about the risks of sideloading. Or maybe the risks of monopolies and monocultures in computing.
- kazinator 9mo agoSide loading into a streaming box is an essential feature for me. I depend on a side-loaded app for Japanese TV. But of course, I have that in a separate Android box, so I'm not forced to update to a new OS when replacing a TV (as I just did this week).
- macinjosh 9mo agoCall me what you want but it is my belief that the reason google is locking down and Apple refuses to budge is that in the near term future our mobile devices will become our identity online and in public. Apple already offers digital ID in some states. They can do this partly because they can guarantee to the gov’t the ID is genuine because the user cannot modify the system. Google needs to be able to do the same thing. Age verification laws for online services will actually require something like a digital ID and Apple and Google want to be the providers.
- sgt 9mo agoIs the solution for sideloading to also have the same APK in the Play Store? That way, Google would have received the AAB and generated a signed APK that is used from the Play Store and also offered via sideloading.
- pier25 9mo agoThe vast majority of Android users don't sideload apps. I used Android for years and only did it during dev. I don't know anyone who does it.
- aembleton 9mo agoNo need to restrict it then
- pier25 9mo agoPlenty of users will benefit from restricting it or even disabling sideloading entirely. I know my mother in her 70s can't be trusted with downloading random crap from the internet.
- Ylpertnodi 9mo ago> I know my mother in her 70s can't be trusted with downloading random crap from the internet. There's a very simple fix for that, that doesn't involve her being a benchmark for others.
- ars 9mo agoI had to sideload telegram, the version on Google Play has restrictions (censorship I believe) that the sideloaded version doesn't.
- pier25 9mo agothe vast majority != 100%
- cmxch 9mo agoWhy not just go full Apple right now and just rebrand iOS? That seems to be the ultimate outcome.
- nunez 9mo agoAt least they aren't removing it like originally planned. A warning from `adb sideload` or `adb install` that can be bypassed with an environment variable is reasonable IMO.
- yjftsjthsd-h 9mo agoI'd really like to see details before drawing conclusions. If it really is just an extra up-front warning screen or something then yes that's reasonable. If it's something that unfairly disadvantages F-Droid compared to the much less safe Google Play store, then it's unreasonable.
- NoImmatureAdHom 9mo agoI think we should stop calling it "sideloading". I don't think the history of the term matters. By using that term, you imply that running the code you want on the hardware you own is somehow a secondary or second-class activity. Call it "installing" or "jumping the garden wall".
- j45 9mo agoDoes high friction involve parties needing to identify themselves?
- asadm 9mo agoiOS has fallen behind, I am struggling to use apps and even type on new liquid glass. My 2TB photo library is useless with the current photos app. I am trying out Pixel 10 on the side and I HIGHLY recommend it! Android does not suck anymore. I am in process of migrating stuff over slowly.
- EngineerUSA 9mo agoI wish the EU would step up and bring sideloading on iOS. iPhone hardware is great but the software is severely lackluster. I know a few developers there and they are not exceptional by any means. Chiefly because Apple pays much less than their competition so they do not attract the best talent
- amelius 9mo agoEU said that App Stores must have alternatives. So F-Droid can just continue with their alternative app store. If Google makes it harder than it needs to be, then I'm sure they will be fined/sued.
- Ylpertnodi 9mo ago> if Google makes it harder than it needs to be, then I'm sure they will be fined/sued. Aaaaand, Action! Cue EU hate messages.
- linuxhansl 9mo agoCan we stop calling this "side loading" please. There is nothing sleazy happening "on the side", I am simply installing an application of my choosing on some hardware that I purchased. As long as it remains possible (without extra developer verification, etc, etc), a bit of extra friction is probably OK, as is assigning accountability to the person who chose to install an app outside of the "official" store. But it has to remain possible. Otherwise can someone name any advantage that Android has over iOS?
- ptrl600 9mo agoFriction hopefully means "you have to plug in a USB cable" and not "you have to associate your phone with a particular Google account, then go through a process with Google's customer service to approve your phone for sideloading" etc.
- cess11 9mo agoEventually my so called smartphone will be a device for authenticating against a few services that require a special application, that I can also tunnel a serious device through for doing the things that I actually want to do. It would be interesting to know why they're doing this, but it's unlikely it'll ever become public knowledge. I also don't think it is important, the people responsible should be in jail for a lot of other reasons anyway.
- xnx 9mo agoCan we also get total app isolation sandboxing and location, network, etc. spoofing while we're at it?
- snapplebobapple 9mo agoGuys, a discussion of which big tech company is better is equivalent to talking about which cancer is the best to have.... Can we all agree that each operating system has good features but they share a terrible feature of being strapped to a giant vampire squid exfiltrating your data and selling your secrets to the highest bidder? Instead of wasting bandwidth on these two companies can we go and figure out how to force cell phones (and consoles and numerous other things) open like the PC was/ mostly still is?
- kurtoid 9mo agoMy guess is the 'high-friction' part is some kind of mandatory waiting period of 1 to 3 days
- FrozenSynapse 9mo agoSideloading is already painful. I tried installing Sora (which is not available in my region's Play Store). The phone didn't allow me to start the app (complaining about integrity) unless I disabled the Play Store Integrity Checks. It wasn't straightforward in saying what the problem is and how can I bypass the check.
- estimator7292 9mo agoIf anyone wants to debate whether sideloading is a neologism, take it up with Sandisk circa 2007 https://xdaforums.com/t/sandisk-announcement.316860/ https://xdaforums.com/t/sandisk-announcement.316860/ You're free to search XDA Forum. 2007 was the earliest mention I saw, but conversation seems to start in earnest around 2009 and never stops. Consistent hits in search from the last TWENTY YEARS. This is not new. It may be new to you but any scary and evil connotations are your own ignorance. The term has been in common use for decades.
- 5350-uiop-1130 9mo ago"high friction" is a good euphemism for modern tech in general, how it feels to use. reminds me of when theresa may said UK would become a "hostile environment", because it really feels like that in more ways than she meant. a high-friction hostile environment is a good description for life.