20 ms·
Google details new 24-hour process to sideload unverified Android apps
https://android-developers.googleblog.com/2026/03/android-developer-verification.html https://android-developers.googleblog.com/2026/03/android-de...
- gib444 7mo agoCalling for regulators, especially the EU, is futile. They want this. All you'll get is something that feels and sounds like pushback, at most.
- darkwater 7mo agoThey have now successfully turned the temperature knob from 2 to 5. I wonder what 7 will be.
- marak830 7mo agoNon-playstore applications will have restricted access(sms/telephony), and bit by bit the screws will be tightened. "Only 0.0004% of the userbase installs after the initial 24 period, greater than x% take 48 hours or more so the 24hr window is now 72hr", and repeat until its all nice and locked down for them. "Your google play account will now need ID to prevent children accessing adult software" will come along not long after. For the children. -.-
- ptrl600 7mo agoHey, the user doesn't need a Google account, that's good. Still a danger of frog boiling but not as bad as I was expecting.
- mzajc 7mo agotl;dr: - You need to enable developer mode - You need to click through a few scare dialogs - You need to wait 24h once I wonder how long this will last before they lock it down further. There was a lot of pushback this time around and they still ended up increasing the temperature of the metaphorical boiling frog. It still seems like they're pushing towards the Apple model where those who don't want to self-dox and/or pay get a very limited key (what Google currently calls "limited distribution accounts").
- throwuxiytayq 7mo agoWill these measures eliminate fraud? Of course not. What a shame; I guess we'll need to lock down the platform even further. This is so overt.
- kykat 7mo agoI propose we ban all computing devices to prevent fraud and harm to children.
- notrealyme123 7mo agoits so obvious what the real goal is. No sideloading. Period. But nice of them to show their intentions while still giving time to leave.
- kogasa240p 7mo ago>I wonder how long this will last before they lock it down further. As soon as the dust settles probably.
- tadfisher 7mo agoHonestly, if coerced sideloading is a real attack vector, then this seems to be a pretty fair compromise. I just remain skeptical that this tactic is successful on modern Android, with all the settings and scare screens you need to go through in order to sideload an app and grant dangerous permissions. I expect scammers will move to pre-packaged software with a bundled ADB client for Windows/Mac, then the flow is "enable developer options" -> "enable usb debugging" -> "install malware and grant permissions with one click over ADB". People with laptops are more lucrative targets anyway.
- dfabulich 7mo agoI predict that they're going to introduce further restrictions, but I think the restrictions will only apply to certain powerful Android permissions. The use case they're trying to protect against is malware authors "coaching" users to install their app. In November, they specifically called out anonymous malware apps with the permission to intercept text messages and phone calls (circumventing two-factor authentication). https://android-developers.googleblog.com/2025/11/android-developer-verification-early.html https://android-developers.googleblog.com/2025/11/android-de... After today's announced policy goes into effect, it will be easier to coach users to install a Progressive Web App ("Installable Web Apps") than it will be to coach users to sideload a native Android app, even if the Android app has no permissions to do anything more than what an Installable Web App can do: make basic HTTPS requests and store some app-local data. (99% of apps need no more permissions than that!) I think Google believes it should be easy to install a web app. It should be just as easy to sideload a native app with limited permissions. But it should be very hard/expensive for a malware author to anonymously distribute an app with the permission to intercept texts and calls.
- yjftsjthsd-h 7mo ago> But it should be very hard/expensive for a malware author to anonymously distribute an app with the permission to intercept texts and calls. And how hard/expensive should it be for the developer of a legitimate F/OSS app to intercept calls/texts?
- focusedone 7mo agoI'm generally OK with this, but the 24 hour hang time does seem a bit onerous. Most of the apps on my phone are installed from F-Droid. I guess the next time I get a new phone I'll have to wait at least 24 hours for it to become useful. I'm seriously considering Graphene for a next personal device and whatever the cheapest iOS device is for work.
- janice1999 7mo agoThe apps might not be available though. Many developers are simply stopping in the face of Google's invasive policies. I don't blame them. Say goodbye to useful apps like Newpipe.
- limagnolia 7mo agoI don't see anything on NewPipe's website about not continuing development?
- TurboSkyline 7mo agoA few apps have been showing pop-ups warning users in advance that they are not going to do the verification. Obtanium is definitely on of them. I think I saw something similar on NewPipe.
- plorg 7mo agoIf you install it or update it you will get a banner to this effect at first use.
- limagnolia 7mo agoIt says they are giving up, throwing in the towel? It is my understanding it provided information about Googles plans and how it will impact users?
- 7mo ago
- janice1999 7mo agoThe forced ID for developers outside the Play store is already killing open source projects you could get on F-Droid. The EU really needs to identify this platform gatekeeping as a threat. As an EU citizen I should not be forced to give government ID to a US company, which can blacklist me without recourse, in order to share apps with other EU citizens on devices we own.
- hactually 7mo ago[flagged]
- janice1999 7mo agoThe DSA covers App stores with a large numbers of users - this is about allowing users side load unsigned apps. Afaik there is no requirement to identify the developers of applications that can be installed on a vendors platform (outside the app store). Otherwise Microsoft would require Government ID to compile and email someone an EXE.
- anhner 7mo agostop spreading misinformation
- hactually 6mo agoDARVO
- fleroviumna 7mo ago[dead]
- 2OEH8eoCRo0 7mo agoSeems like a very reasonable compromise. What's the catch?
- hermanzegerman 7mo agoThat I have to wait 24 Hours on my own device to install software?
- fsh 7mo agoI don't find it reasonable that Google wants to make me wait 24h to install software on a device I own.
- ygjb 7mo agoMeh. I get the annoyance, but it's a one time cost for a small subset of their users. I would prefer if there was a flow during device setup that allowed you to opt into developer mode (with all the attendant big scary warnings), but it's a pretty reasonable balance for the vast majority of their users. (I suspect the number of scammers that are able to get a victim to buy a whole new device and onboard it is probably very low).
- izacus 7mo agoNote that adb won't have the 24 hour cooldown if you're in such a hurry.
- jcul 7mo agoGood point, having a once off advanced option to completely bypass this at device setup would be good. Also, other commenters have mentioned that adb is unaffected by this which makes it seem like less of a problem, to me at least. Still inconvenient that even if you adb install fdroid you can't install apps directly from it.
- barnacs 7mo agoGet with the newspeak, it's called "sideloading" now and your corporate overlords get to dictate the terms.
- 9cb14c1ec0 7mo agoIt's getting harder and harder to be an Android enthusiast. Especially given the hypocrisy of Google Play containing an awful lot of malware.
- mosura 7mo agoFrom a detached perspective Play Services itself is practically sanctioned malware and this is to protect that monopoly.
- omnifischer 7mo agoThose working in Google (AOSP) that write these code should be ashamed of themselves. Eventually they are doing a bad thing for the society.
- deleted 7mo ago[deleted]
- Aachen 7mo agoIs this in AOSP? I was assuming the changes are to GMS. I should hope that no distributor of AOSP(-based) images include this code anyway so it's just on the google devices
- astra1701 7mo agoThis is going to hurt legitimate sideloading way more than actually necessary to reduce scams: - Must enable developer mode -- some apps (e.g., banking apps) will refuse to operate and such when developer mode is on, and so if you depend on such apps, I guess you just can't sideload? - One-day (day!!!) waiting period to activate (one-time) -- the vast majority of people who need to sideload something will probably not be willing to wait a day, and will thus just not sideload unless they really have no choice for what they need. This kills the pathway for new users to sideload apps that have similar functionality to those on the Play Store. The rest -- restarting, confirming you aren't being coached, and per-install warnings -- would be just as effective alone to "protect users," but with those prior two points, it's clear that this is just simply intended to make sideloading so inconvenient that many won't bother or can't (dev mode req.).
- pmontra 7mo agoYou have to wait one day only once, when enabling the feature. I agree that enabling developer mode could be a problem but mostly because it's buried below screens and multiple touches. As a data point, I enabled developer mode on all my devices since 2011 and no banking app complained about it. But it could depend by the different banking systems of our countries.
- frays 7mo agoYou don't use the HSBC or Citibank app then I assume?
- pmontra 7mo agoThey don't operate in my county AFAIK. However that reinforces my idea that the endgame will be a pristine Android phone in a drawer at home with the banking apps required for accessing their sites with 2FA and another phone in my pocket for daily use.
- brewdad 7mo agoI’m not sure that Google/Android selling everyone two phones instead of one is the deterrent to this behavior that you envision.
- teroshan 7mo agoThat's a lot of words to explain how to install things on the device I supposedly own. Wondering how long the blogpost would be if it explained what the flow for corpoloading applications approved by Google's shareholders would be?
- _cenw 7mo agoThose don't usually have problems with providing ID for attestation??! Like, this is not a gotcha, at all? The casual cynicism on this website really is something.
- cobbal 7mo agoCan you set your clock forward or does this also require phoning home to a central server to install an app on your computer?
- 2postsperday 7mo agoIt requires an internet connection to adjust the toggle.
- zzo38computer 7mo agoI think it would be a bad idea to require an internet connection (for one thing, you might want to write your own app that does not require a internet connection); but, even if it doesn't, would not mean you can set the clock to avoid the delay, because it could be made to reset the delay if the clock is set.
- nickorlow 7mo agoIt'll be interesting to see how the timing is enforced. Can you just set up your own NTP server to fool your phone into thinking it's really the future (and not just you adjusting your phone's clock manually). Will Google run a clock that you have to get a timestamp from (would it be easy to setup your own MITM proxy to get around this?). If the time somehow jumped backwards, would you lose the ability to install apps? Can google remotely disable this after it's already enabled (I think yes)?
- hypeatei 7mo agoI'll say it again: this isn't a problem for Android to solve. Scammers will naturally adapt their "processes" to account for this 24-hour requirement and IMO it might make it seem more legitimate to the victim because there's less urgency. The onus of protecting people's wealth should fall on the bank / institution who manages that persons wealth. Nevertheless, this solution is better than ID verification for devs.
- limagnolia 7mo agoWhy should the bank/institution be responsible for protecting individuals from themselves? They don't have police power- protecting people from bad actors is like, the reason to have a state. If the state wishes to farm it out to third parties, then we don't need the state anymore!
- hypeatei 7mo agoThe bank/institution is where the money is leaving from therefore they should implement policies that protect vulnerable customers like seniors, for example. I don't know how that looks but it seems reasonable that they could put limits on an account flagged "vulnerable person" I'm not sure what you're getting at with the rant about police power and a state? Google isn't the government either. What would legislation provide that banks can't already do today?
- limagnolia 7mo agoSure, there are things banks can do, and those are features they can market. But ultimately, if the state isn't pursuing criminals who prey on the vulnerable, then society as we know it has failed and we would need a new society, or a new state, or both...The bank can't arrest anyone! I never said anything about it being Googles responsability, I agree it is not. And the only legislation that might be necessary over what we have is a budget directly to go after criminal fraudsters.
- hypeatei 7mo ago
- silver_sun 7mo agoIt's a little inconvenient for someone setting up a new phone to have to wait a full day to install unregistered apps. But while I can't speak for others, it's a price I'm personally willing to pay to make the types of scams they mention much less effective. The perfect is the enemy of the good.
- nullc 7mo agoOn what basis do you believe that it will meaningfully reduce the dollars lost or persons harmed by fraud, as opposed to simple shuffling around the exact means used?
- silver_sun 7mo agoWell maybe nothing ultimately changes. Maybe we end up in a world where Android users have to wait 24 hours to change a setting so that their devices will install any apps they want, from then on with no further delays. But this seems to me like a relatively low cost for a potentially huge benefit for victims.
- Evidlo 7mo agoHow would you feel about needing to wait 24 hours to visit an "unapproved" website on your phone? You would pay Google/Apple $25 to get whitelisted so people can browse to your personal website without getting a scary security message. This is the same thing since it applies to all apps, not just apps that need special permissions.
- silver_sun 7mo agoI don't think it's fair to extend the analogy to what amounts to censorship of websites since that's not the system they're proposing. Also isn't the owner of a website already identifying themselves when they register their domain name and/or rent a server? I think this is not the same as downloading an app by an unknown developer. From the article I understood this to be a one-time delay, as opposed to having to go through the same waiting process for every single "unlicensed" app I want to install (which I would not accept). I'm just waiting 24 hours once to permanently change my device into a mode where I can install any app I like without any restrictions/delays whatsoever.
- branon 7mo agoThis 24-hour wait time nonsense is a humiliation ritual designed to invalidate any expectation of Android being an open platform. The messaging is very clear and the writing's on the wall now, there's nowhere to go from here but down.
- module1973 7mo agoAm I going to have to wait 24hrs to have Google's malware and spyware forceloaded onto my phone, or is this a different category of malware?
- sebtron 7mo agoThat comes preinstalled :)
- xnx 7mo agoThis is eminently reasonable. Now if only Android would allow for stronger sandboxing of apps (i.e. lie to them about any and all system settings).
- fluidcruft 7mo agoI think it's only reasonable if you can install updates without having to do the whole dance (assuming you do the 7-day rather than permanent unlock).
- occz 7mo agoThe 24 hour wait period is the largest of the annoyances in this list, but given that adb installs still work, I think this is a list of things I can ultimately live with.
- summermusic 7mo ago24 hour mandatory wait time to side load!? All apps I want to use on my phone are not in the Play Store. So I buy a new phone (or wipe a used phone) and then I can’t even use it for 24 hours?
- 0x457 7mo agoYou can if you have a way to use ADB.
- MishaalRahman 7mo ago1) The one-time, one-day waiting period only applies if you go through the advanced flow to allow installing unregistered apps. You can still install registered apps (ie. apps made by developers who have verified their identity) even if they're distributed outside the Play Store. 2) You can use ADB to immediately install unregistered apps. ADB installs are not subject to the waiting period.
- NooneAtAll3 7mo agoasian development bank?
- bithaze 7mo agoAndroid Debug Bridge, a CLI for connecting to Android devices: https://developer.android.com/tools/adb https://developer.android.com/tools/adb
- nxtbl 7mo ago3) And how can we keep on using F-Droid and other app stores? 4) How can we install apps made by devs who won't do the verification dance with Google?
- MishaalRahman 7mo agoDevelopers who distribute Android apps on other app stores are not strictly required to undergo verification and thus can remain anonymous, but if they choose not to, then later this year (when the enforcement of verification goes active) their apps can only be installed on certified Android devices via ADB and/or the new advanced flow. Thus, you can still install unregistered apps if they're distributed via F-Droid or other sources, but to do so, you will need to use ADB and/or go through the new advanced flow. And remember, the new advanced flow is a one-time process - once you go through with it, you can allow your device to install unregistered apps indefinitely!
- aboringusername 7mo agoIt's not like the Google Play store hasn't been known to host malicious apps, yet you are not required to wait 24 hours before you install apps from their store. I suspect they are hoping users just give up and go to the play store instead. Google touts about "Play Protect" which scans all apps on the device, even those from unknown sources so these measures can barely be justified. Imagine if Microsoft said you need to wait 24 hours before installing a program not from their store, which is against the entire premise of windows. Computing, I once believed was based on an open idea that people made software and you could install it freely, yes there are bad actors, but that's why we had antivirus and other protection methods, now we're inch by inch losing those freedoms. iOS wants you to enter your date of birth now. The future feels very uncertain, but we need to protect the little freedoms we have left, once they're gone, they're gone for good.
- dang 7mo agoIs there an accurate, neutral third party link about this that we can make the primary link instead? https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sort=byDate&type=comment&query=corporate%20press%20release%20by:dang https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...? Edit: I've put one up there now - if there's a better article, let us know and we can change it again. I put the submitted URL in the toptext.
- aftergibson 7mo agoNothing screams being infantilised by your platform more than having to wait 24 hours to be allowed to install software on your own purchased computing devices.
- wolvoleo 7mo agoDo you need a Google account to opt out of the restriction? It says something about authenticating. I don't have a Google account on my Androids. But I can't remove play services on them, sadly. As an intermediate protection I just don't sign in to Google play, that gives them at least a bit less identifying information to play with. I hope this can be done without a Google account.
- aboringusername 7mo agoThe reauthenticate means using device pin/biometrics if you have them enabled. You will not need a Google account.
- wolvoleo 7mo agoOof that's what I was hoping for, thanks!
- devsda 7mo agoDeath, taxes and escalating safety are the only certainities in this tech dominated world. So, be ready for more safety in the next round few months/years down the line. Eventually Android will become as secure as ios. We need a third alternative before that day comes. It's not a win by any means. I hope that we don't stop making noise.
- wolvoleo 7mo agoIt's not secure when one of the main adversaries (Google) controls all the keys.
- Mogzol 7mo agoI believe that is why "escalating safety" and "secure" were written in italics in the comment. Those are the terms Google would use, not necessarily the truth.
- wolvoleo 7mo agoAhh in the glider app I use the italics didn't appear. I use very old version because I didn't like their last redesign.
- varispeed 7mo agoGoogle serves ads with known scams and nothing seems done about it. Yet, they are concerned about this. It has nothing to do with safety, but everything to do with control. I remember when Google disabled call recording in Android, so you no longer could record scammers. Thanks to recording I was able to get money back from insurance company that claimed they absolutely didn't sell me this and that over the phone (paid for premium insurance and got basic).
- flyinghamster 7mo ago> I remember when Google disabled call recording in Android, so you no longer could record scammers. Citation needed. My Pixel 7a with the latest updates has settings for call recording in the phone app. Since I never screwed around with it, I'd assume these are the defaults: Call recording is turned on, with "asks to record calls" set Automatically delete recordings is "never" Automatically record calls with non-contacts is off No specific numbers to automatically record calls are set There is also a note that you have to agree to their ToS to use it, and I'd also suggest being careful if you live in a jurisdiction that requires two-party consent for recording. In any case, I'm of the opinion that if F-Droid goes, I'm basically going to treat this as a feature phone and stay away from third-party apps in general aside from "musts" like banking.
- lucasay 7mo agoThe goal seems to be breaking the real-time guidance scammers rely on. 24h probably works, but it feels like a heavy tradeoff for legit users.
- EvanAnderson 7mo agoCapitulating now means next time the terms of the deal will be worse.
- hananova 7mo agoScammers will just start the process and call back the next day. There is an entire genre of scam relying on slowly building rapport and only cashing in once all the way at the end.
- deleted 7mo ago[deleted]
- neop1x 7mo agoExactly, it will have 0 effect on scammers. It is primarily made to piss off people and make it more difficult to install independent free software.
- budududuroiu 7mo agoiOS was supposed to prevent phone theft by making phones brickable through iCloud. Now, phone thieves just ask you at knifepoint or gunpoint to log out of iCloud
- fc417fc802 7mo agoUnfortunately that's your own misunderstanding. iOS (as well as modern android) quite effectively prevent phone theft while the electronics are in transit along the last mile of the supply chain. Anything beyond that is a happy accident. (I'm being a bit overly cynical there but IMO only the tiniest bit.)
- imhoguy 7mo ago
- grishka 7mo agoAt this point I'm convinced that there's something deeply wrong with how our society treats technology. Ruining Android for everyone to try to maybe help some rather technologically-hopeless groups of people is the wrong solution. It's unsustainable in the long run. Also, the last thing this world needs right now is even more centralization of power. Especially around yet another US company. People who are unwilling to figure out the risks just should not use smartphones and the internet. They should not use internet banking. They should probably not have a bank account at all and just stick to cash. And the society should be able to accommodate such people — which is not that hard, really. Just roll back some of the so-called innovations that happened over the last 15 years. Whether someone uses technology, and how much they do, should be a choice, not a burden.
- frogperson 7mo agoIts not society, this is simply more fascism. Corperate and government cooperation to surviel and controll the masses. So long as the 5g chips and the 2 mobile app stores remain under control, then 5 eyes has nearly full coverage.
- pixl97 7mo agoA fascist society is a society. Members of that society will gladly vote in more fascism.
- guelo 7mo ago> just should not use smartphones and the internet That's ridiculous. Phones are being made more and more of a requirement to participate in society, including by governments.
- grishka 7mo agoWhich is exactly my point! This is exactly the thing that desperately needs to be undone.
- coldtea 7mo ago>That's ridiculous. Phones are being made more and more of a requirement to participate in society, including by governments. The latter is what's ridiculous, not what the parent suggests.
- politelemon 7mo agoI'm not in agreement with most of you, hn. They've found a decent compromise that works for power users and the general population. Your status as a power user does not invalidate the need to help the more vulnerable. Having to wait a day for a one off isn't a big deal, if they kept it looser then you'd be shouting about the amount of scams that propagate on the platform.
- varispeed 7mo agoBut this is very rich from them given they serve scam ads with impunity. I'd say this has nothing to do with preventing scams, but to make independent software more difficult to distribute.
- keanebean86 7mo agoMy personal hard line is having to ask Google for permission to sideload. Even if it's free and no personal info is exchanged. This new process is annoying but I can see it helping prevent scams.
- deleted 7mo ago[deleted]
- t_mahmood 7mo agoSame with bootloader unlocking isn't it? Ah, its not much, just an email away ... oh, not much it's email and a phone call away ... Just wait 7 days ... no, it's just a month, and only one device par account? What's wrong with it? You are overreacting Wait! Why you want to unlock your boot loader, only 0.000001% does it. You are abnormal, not the mass user Fool me once it's on you Fool me twice ... it's on me. We are already over twice, but none the wiser.
- nolist_policy 7mo agoYou can buy a Pixel instead of a Xiaomi.
- t_mahmood 7mo ago
- andyjohnson0 7mo agoI'd rather not have to go through this ritual, but I appreciate that there is a genuine security problem that google are trying to address. I also suspect that they have other motivations bound-up in this - principally discouraging use of alternative app stores. But basically I could live with this process. Yeah, I know... Stockholm syndrome... Although I may not have to live with it, as none of my present devices are recent enough to still receive ota updates. Context: I don't use alternative app stores. I occasionally side-load updates to apps that I've written myself, and very occasionally third party apps from trusted sources.
- fluidcruft 7mo agoI don't think developers targeting alternative app stores would care much about having to perform verified developer registration. Particularly apps that are available in both Play Store and alternative app stores.
- anonym29 7mo ago>And what is malware? For [Android Ecosystem President], malware in the context of developer verification is an application package that “causes harm to the user’s device or personal data that the user did not intend.” Like when Google, Facebook, Apple, Microsoft, et al. cooperated with¹ the unconstitutional and illegal² PRISM program to hand over bulk user data to the NSA without a warrant? That kind of harm to my personal data that I did not intend? If so, I'd love to hear an explanation of why every Google/Alphabet, Facebook/Meta, and Microsoft application haven't been removed for being malware already. ¹ https://www.theguardian.com/world/2013/jun/06/us-tech-giants-nsa-data https://www.theguardian.com/world/2013/jun/06/us-tech-giants... ² https://www.reuters.com/business/media-telecom/us-court-mass-surveillance-program-exposed-by-snowden-was-illegal-2020-09-03/ https://www.reuters.com/business/media-telecom/us-court-mass...
- nullc 7mo agoI'd urge everyone here to seriously consider switching to GrapheneOS. It's a far simpler transition than e.g. switching from Windows or OSX to Linux, and many people find that it has basically no friction vs android. More people moving to GrapheneOS is the best tool we have against Google's continued and escalating hostility to user freedom and privacy and general anti-competitive conduct. (Of course, you could ditch having a smartphone entirely..., but if you're willing to consider that you don't need me plugging an alternative).
- kogasa240p 7mo agoWould but unfortunately I got screwed with a locked bootloader, either going to go the dumbphone or the (much less practical) cyberdeck + SIM card route.
- marak830 7mo agoThis has really moved up my timeline of switching to Graphene. Admittadly I was being lazy and not checking if Line works on it yet, but I'll be finding that out this weekend it seems.
- microtonal 7mo agoI'd like to add that you can start in a really affordable way. E.g. the Pixel 9a is typically 350 Euro here and a perfectly fine way to start out with GrapheneOS - it still has years of support in it.
- beepbooptheory 7mo agoI get that its pretty clear with the straight sideloading case, but can anyone say for sure what this will look like for an f-droid user? Its hard to keep track but I thought something new here because of EU is that alternative app stores != sideloading? Something where app stores could choose themselves to get "verified," whatever that means, to become a trusted vendor? Or is this completely wrong?
- RIMR 7mo agoI am not happy about this, but as long as advanced Android users can still turn this off and keep it off, we're still in a better place than iOS. Even though I understand the design decisions here, I think we're going about this the wrong way. Sure, users can be pressured into allowing unverified apps and installing malware, and adding a 24-hour delay will probably reduce the number of victims, but ultimately, the real solution here is user education, not technological guardrails. If I want to completely nuke my phone with malware, Google shouldn't stand in my way. Why not just force me to read some sort of "If someone is rushing you to do this, it is probably an attack" message before letting me adjust this setting? Anyone who ignores that warning is probably going to still fall for the scam. If anything, scammers will just communicate the new process, and it risks sounding even more legitimate if they have to go through more Google-centric steps.
- egorelik 7mo agoAs an idea, what about allowing the 24 hours to be bypassed using adb (edit: bypass to allow indefinitely, not just install a single app)? I understand there is some problem trying to be solved here, but honestly this is still quite frustrating for legitimate uses. If this is the direction that computing is moving, I'd really rather there were separate products available for power users/devs that reflected our different usage.
- pie_flavor 7mo agoThis is already how it works.
- deleted 7mo ago[deleted]
- gumby271 7mo agoRight, if this is being built into AOSP I dont see how they wouldn't add an adb command to immediately skip the "Advanced Flow" wait. if it's safe to let uses run "adb install", then "adb skip-advanced-flow" should be just as safe to do too.
- basilikum 7mo agoAs an idea, what about letting me install on my own device whatever I want? This is ridiculous. Google is trying to dismantle the concept of ownership and personal autonomy. Do not give them any ground.
- cindyllm 7mo ago[dead]
- Aachen 7mo agoI'm surprised but happy to see you and so many others here saying this. In recent years it seemed like this 'hacker' community was all about Apple devices, but now that Google is going partway in the same direction, people aren't all just taking it. Do you think there's two groups, and the people that cared simply went with Android and so there was never this outcry about installing free software on iOS, or that this will last only as long as the change still feels recent and like a new restriction?
- w4rh4wk5 7mo agoI'll repeat my question from a while ago. Is the official Temu app, available on the Play Store, still full of questionable malware / spyware code? If so, it's clear that none of these changes are actually to protect users.
- NooneAtAll3 7mo agois it 24 hour per app or to enable sideloading at all?
- Groxx 7mo agoFrom my read, it's explicitly a one-time thing. Presumably that means that even if you pick the "allow for 7 days" option, you can re-enable it after that without a delay (maybe with a reboot?).
- widowlark 7mo agoI switched to iOS in anticipation of this change. The reality is, if they are thinking about doing this, it's only a matter of time before they do it. If I have to choose between two walled gardens, apple will win every time.
- gumby271 7mo ago> In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee. I don't quite understand how those installs would be tracked. If I create a "hobbyist" account and share the apk, are the devices that install that app all reporting it to Google? To my knowledge, Google only does this through the optional Play Protect system, is that now no longer optional? I'd like to know if my computer is reporting every app I install up to Google.
- kykat 7mo agoYou thought it wasn't reporting every app you install?
- gumby271 7mo agoI mean, I'm happy to be conspiratorial about it too, I give Google no benefit of the doubt, but outside of Play Protect I don't think they explicitly say "your phone is telling us every app you install." This new feature is them making that explicit.
- Lammy 7mo agoHow can you say “outside of Play Protect” when it comes enabled by default and hassles me to turn it back on every time I install an APK?
- gumby271 7mo agoReally? I turned Play Protect off and have never been prompted to turn it back on, what phone do you have that does that?
- Lammy 7mo agoIt's this screen: https://support.google.com/googleplay/thread/230937718/annoying-play-protect-warning?hl=en https://support.google.com/googleplay/thread/230937718/annoy... (not several times per hour like this post says, but same UI) Pretty sure this is a Play Services thing, so I don't know that the phone model really matters. But regardless this is on a few different devices: my primary REDMAGIC 9S Pro (Android 15), Surface Duo 2 (Android 12), and my YONGNUO YN455 (Android 10).
- benatkin 7mo agoFunny how that post doesn't mention that a huge amount of malware is downloaded from Google (from the Chrome Web Store as well as from Google Play).
- surgical_fire 7mo ago> Wait 24 hours Man, fuck Google. I hope this bullshit is struck down by government regulation as malicious compliance to 3rd party app stores. I wonder if GrapheneOS will have the same level of user-hostile bullshit. That may be my salvation board right now. Sailfish OS would be great, but unfortunately my banks don't seem to play along with it.
- Retr0id 7mo agoThey should let you skip the wait if you're setting up a device for the first time.
- fluidcruft 7mo agoI think that's a good point. When you're playing around flashing ROMs it's going to get really old, really fast.
- NotPractical 7mo agoOr at least include this flag in the system backups and restore it upon switching to a new device... If you get most/all of your apps from F-Droid, they're essentially establishing a policy of "any time you get a new phone, you can't use it for 24 hours", which is... insane?
- grishkno 7mo agoThat's similar to the process of enabling developer options on Xiaomi phones, for the last 5 years
- fdghrtbrt 7mo agoReminder that when you use terminology like "sideloading" you're accepting the premise that there's something inherently dodgy about installing your software onto your operating system. Just call it "installing".
- kykat 7mo agoDon't use the enemy language
- jwlake 7mo agoIf android security is so fucked that the 24 hours helps, why do they maintain it has security?
- sevaustinov74 7mo ago[dead]
- pmdr 7mo ago> Balancing openness and choice with safety No, I'm afraid this is tipping the scale of control in Google's favor.
- modeless 7mo agoHmm, as long as the waiting period is not per-app then maybe this is OK. Especially now that there is a well supported way to distribute alternative app stores without going through the sideloading process.
- macinjosh 7mo agoThe secret reason they are doing this is because governments want to be able to identify everyone online everywhere it matters at all time. They want to strip anonymity from computing. Apple and Google can now credibly claim to governments to have nearly ubiquitous computing platforms that they can guarantee do not run any software that is not approved or antithetical to the goals of authorities. This makes the device safe for storing things like government IDs. OSs and Browsers will be required to present these IDs or at first just attest to them. Before posting online, renting a server, using an app you will have to idenitfy yourself using your phone or similarly locked down PC (i.e. mac). The introduction is under the guise as always of protecting the children. In reality they are removing your rights to privacy and free speech.
- jacquesm 7mo agoMalicious compliance.
- prmoustache 7mo agoThis is ridiculous, most malware is shipped by google itself through the playstore.
- spwa4 7mo agoWhat? No requirement to personally bring in a form in triplicate to the Google office in Siberia, of course notarized by the Pope and Zendaya, and simply prove it was signed on the moon.
- shadowgovt 7mo agoSo can it be breached by turning off networking and setting the date forward a couple days?
- quyleanh 7mo agoTbh, I love this flow. They truely think for users, all users not just advanced users. Unlike Apple, Apple just think for its ecosystem, its money. How the advanced flow works for users Enable developer mode in system settings: Activating this is simple. This prevents accidental triggers or "one-tap" bypasses often used in high-pressure scams. Confirm you aren't being coached: There is a quick check to make sure that no one is talking you into turning off your security. While power users know how to vet apps, scammers often pressure victims into disabling protections. Restart your phone and reauthenticate: This cuts off any remote access or active phone calls a scammer might be using to watch what you’re doing. Come back after the protective waiting period and verify: There is a one-time, one-day wait and then you can confirm that this is really you who’s making this change with our biometric authentication (fingerprint or face unlock) or device PIN. Scammers rely on manufactured urgency, so this breaks their spell and gives you time to think. Install apps: Once you confirm you understand the risks, you’re all set to install apps from unverified developers, with the option of enabling for 7 days or indefinitely. For safety, you’ll still see a warning that the app is from an unverified developer, but you can just tap “Install Anyway.”
- hermanzegerman 7mo agoDo you also like Dictators that decide and think for you?
- viktorcode 7mo agoJudging by the comments sideloading plays a major part in everyone's life. What apps do you sideload guys? Why those apps are not in a store?
- rcMgD2BwE72F 7mo agoWould Obtainium continue to work? I like the freedom of entrusting developers I know and installing APKs from repositories instead of restricting myself to app stores whose publishers have to be identified and approved by an advertising company. Can I keep this freedom?
- wasting_time 7mo agoI install from F-Droid when possible. It has less noise, and all apps are free as in software. There are some true gems such as:
- Aachen 7mo ago- NewPipe (I'm not sure if you wanted to edit in entries or if this was our cue :D)
- justagiirl 7mo ago> What apps do you sideload guys? I sideload no apps. I install most apps from either F-Droid main, or an other repo. > Why those apps are not in a store? All of them are in a repository. Just only the state sponsored ID-app is only available via the ad-infected Google RAT delivery service, also known as Google Play.
- Macha 7mo agoF-Droid. And also by Google's definition, everything I install from F-Droid. So Antennapod (Podcasts), ConnectBot, DAVx (sync my Fastmail calendar to my phone), Etar (Calendar app), Jellyfin (media player), Jiten (JP dictionary), KOReader (ebook reader), OsmAnd~ (Maps), VLC. Meanwhile from the Play Store I have Bitwarden, Firefox, 2 banking apps, a few airline apps, Wireguard and Whatsapp. So I actually have more from F-Droid than the Play Store from what I regularly use.
- notrealyme123 7mo agothey even say that you can allow sideloading temporary or indefinitely. Guess which option wont be available anymore in two years.
- PieUser 7mo agoSo convoluted... that's all I gotta say.
- bityard 7mo agoWelp, I guess my current Android phone will be my last one. At least half of the apps I use on a daily basis come from f-droid. This enforced 24-hour wait is simply not acceptable. Android has always been a far inferior overall user experience compared to iPhone. Android's _only_ saving grace was that I could put my own third-party open-source apps on it. There is nothing left keeping me on Android now. I'll probably get an iPhone next, but I do sincerely hope this hastens progress on a real "Linux phone" for the rest of us. Plasma Mobile (https://plasma-mobile.org https://plasma-mobile.org) looks very nice indeed. I'll be more than happy to contribute to development and funding.
- mikescandy 7mo agoIf I understand correctly, the 24 hour wait is a one off. After the sideloading feature is enabled, it should stay on.
- kykat 7mo ago24-hour wait is a one time setup, I'd imagine that fdroid will keep working as usual after this super hidden don't enable me option is enabled.
- MishaalRahman 7mo agoIf it helps, the 24-hour wait is a one-time process. You do it once, click the toggle to allow installing unregistered apps indefinitely, and then install whatever you want. You can even turn off developer options afterwards, per my understanding, and it won't impact your ability to install unregistered apps.
- Acrobatic_Road 7mo agoFor now.
- applfanboysbgon 7mo agoThat does not help. That is a fundamentally fucking insane limitation that will completely destroy any developer's ability to develop without getting approval from Google. Regardless of my feelings of the annoyance of going through this process myself, 90% of users simply will not go through this process to install apps, killing any potential userbase. Google has no goddamn right to be the sole dictator of who is allowed to develop software for the largest platform in the world, to decide who is allowed to have a career in mobile software development and who is not, and you should be utterly ashamed of yourself for accepting a paycheck to defend this. I hope your shitty company and Apple both get their comeuppance in court for these monopolistic practices, and may we some day get a future where anyone is free to develop software without approval of a central police corp.
- tavavex 7mo agoThe part in the flow where you select between allowing app installs for 7 days or forever is a glimpse into the future. That toggle shows the thought process that's going on at Google. I can bet that a few versions down the line, the "Not recommended" option of allowing installs indefinitely will become so not recommended that they'll remove it outright. Then shrink the 7 day window to 3 days or less. Or only give users one allowed attempt at installing an app, after which it's another 24 hour waiting period for you. Then ask the user to verify themselves as a developer if they want to install whatever they want. Whatever helps them turn people away from alternatives and shrink the odds of someone dislodging their monopoly, they will do. Anything to drive people to Google Play only.
- wlesieutre 7mo agoPay verification fee to continue
- observationist 7mo ago>"PLEASE DRINK VERIFICATION CAN TO CONTINUE"
- andai 7mo agoContext: https://files.catbox.moe/eqg0b2.png https://files.catbox.moe/eqg0b2.png I think they later made a Black Mirror episode along these lines. "Resume viewing... Resume viewing..."
- userbinator 7mo agoThat meme was 13 years ago.
- matheusmoreira 7mo agoFiften Million Merits. The one where advertisers literally torture a man with loud high pitched noises because he refused to view ads and didn't have enough money to skip them.
- ForHackernews 7mo ago> Install apps: Once you confirm you understand the risks, you’re all set to install apps from unverified developers, with the option of enabling for 7 days or indefinitely. For safety, you’ll still see a warning that the app is from an unverified developer, but you can just tap “Install Anyway.” If you can enable this once, forever, after a 24 hour cooldown period I don't hate this as much as I hated some of the other proposals from Google. It'll just be something you do as part of the setup for a new phone.
- IamDaedalus 7mo agothe best marketing apple has received in a long; death by self sabotage
- lenerdenator 7mo agoAnd now we see why Android never really was Linux. Does it have a Linux kernel? Of course. But this isn't a free operating system.
- Aachen 7mo agoRHEL isn't Linux either then?
- lenerdenator 7mo agoIt's more complex than that. RHEL has Fedora upstream. There's a group of people who regularly contribute to those projects on their own time and the userland for Fedora is made up primarily of FOSS where people routinely try to consolidate popular features into main code branches. There's a truly free software project that is the main project that someone provides paid support for. Fedora drives the evolution of the system; RHEL just gives a way to make that evolution palatable to the suits. Android has the AOSP but it's not the driver of Android as a platform. For the most part, the evolution is driven by a bunch of closed-source applications that Google and OEMs happen to run on Android. Those parties derive competitive advantage and brand identity from the proprietary code that runs on top of the Android OS, and don't make a habit of merging much of that into the project. There are the system-wide improvements that get updated, sure, but the ethos is not to keep the code moving up the chain into the project so that anyone can take it and do what they want with it for free. It's a hard difference to describe but it's there.
- megous 7mo agoMost of the problems are with the ease of modifications. Regular Linux based distro, with it's shared library model, masses of packages, and a proper packaging system, etc., will allow you fairly easily to just take any package, patch it however you like and just re-compile and install just the updated package. It's usually not a very hard process (well, Debian...) but there are distros where this is very simple, like Arch Linux, or Slackware. I mean how do I just take some random Android phone and patch out something I don't like in one of the apps, or improve some behavior I don't like in one of the core libraries (like allow the fucking phone to be fucking woken up predictably by a background app, without some stupid mean-well logic trying to prevent predictable behavior, because waking up for 500ms every 5 minutes is "draing the battery too much" or some such nonsense) There's usually not even a SW distribution, let alone a sane system for updating just one thing, without downloading 3 HDDs full of dev dependencies and re-building everything. Then HW is locked down, SW is locked down on purpose and just by sheer hostility to incremental individual small changes. Whole ecosystem has to be designed around the FOSS ethos of giving the user access to code for purpose of them being reasonably able to actually do something with it to incrementally improve their experience, and not just to look at it pretty.
- fhn 7mo agoAll these vibe coders and we're still stuck with Google and Apple. This is what you get with a duopoly
- sunaookami 7mo agoWhoever worked on this: Thank you for your killing open computing. I hope you are proud and don't spend all the money at once.
- 2001zhaozhao 7mo agoI think the new solution is a good compromise. The 7 days vs forever choice is still crappy and gives me a bit of bad vibes considering they are the ones that pulled the youtube promotions (shorts, games) you can never turn off forever, so there's the concern they will remove the forever option from Android in the future. But as long as they don't end up doing that, it's fine for me. Also, I do think it would be a good idea to make an exception to the 24-hour wait time if the phone is new enough (e.g. onboarding steps were completed less than one day ago), and/or through some specific bypass method using ADB. Power users who get a new phone want to set it up with all their cool apps and trinkets right away, and it's not good user experience to have to use ADB to install every single sideloaded app. Meanwhile a a regular user getting scammed right after getting a new phone is statistically unlikely.
- guilhas 7mo agoSome years ago had a scam call about my "router connection error logs" and "I needed" to install TeamViewer from the PlayStore... So can't imagine what is this going stop
- arendtio 7mo ago24H forced wait time?!? WTF When I side-load open-source apps for other people, I want to do it right in the moment, not activate the feature, and the next time I see them (like half a year later), install the app. When Google announced there would be an alternative installation method, I did not expect such a mess...
- marak830 7mo agoSo it seems it will work as they intended. "I did not expect such a mess", I certainly did. Another arm of the push to remove anonymity online.
- redwall_hp 7mo agoDon't forget offline. We now have an epidemic of license plate and face reading cameras rolling out all over the place. Orwell couldn't even dream of the invasive monitoring that exists right now.
- basilikum 7mo agoA lot of people here are looking for compromises. Any compromise on this means giving ground to Google's monopoly and the war on open computing and ultimately freedom. This is exactly what Google intended. This is why they started off by announcing completely removing device owner chosen installs (this is not side loading! It's simply installing.) and announced only apps allowed by Google would be available for install. They knew it would cause backlash. They anticipated that and planned ahead faking a compromise. They are trying to boil us like frogs by so slowly raising the temperature so we do not notice. Whenever the water gets so warm that people do notice they cool it down a little. But they will turn up the the heat again! This 24h window is designed to make device owner controlled installs as unattractive as possible. They try to reduce it as much as they can while having plausible deniability ("You can still install apps not whitelisted by us"). They want to get the concept of people installing software of their own choice onto their own device as far away from the mainstream as possible. They want to marginalize it. They want to slowly and quietly kill off the open Android app ecosystem by reducing the user base. The next step will be them claiming that barely anyone is installing apps not signed by them anyway. First they make people jump through ridiculous hoops to install non whitelisted apps, then they use the fact that few people jump through these hoops to justify removing the ability altogether. Google does not care about preventing scams. If they did they would do something against the massive amount of scam ads that they host. Scams are just their "think of the children". Do not play by their playbook! Do not give them ground! We must not accept any restrictions on the software we run on our own devices. The concept of ownership, personal autonomy and choice are being dismantled. Our freedom is the target of a slow, long waging war. This is yet another attack. We must not compromise with the attacker. We must not give them any centimeter of ground.
- user34283 7mo agoIt's 2026 and regulators are finally getting around to do something about the mobile app distribution chokehold. And Google thinks they can pull this? I hope regulators make it very clear that this is the wrong direction, and with record fines.
- thin_carapace 7mo agoim just as much of a hater of this as the next guy, because i depend on custom apks for work sometimes. pushing custom apks over adb is apparently going to be fine, so if that holds true, i dont care about this. at the end of the day, buying an android phone is buying a google device. i dont get the righteousness here. wouldnt this energy be better spent on discussing how we could make a new open source os to rival that of google? why would anyone at google (company at the forefront of anti privacy measures) care about what some nerds on the internet think about privacy? its like an ant screaming in front of an approaching bulldozer.
- jeduardo 7mo agoThe "protective waiting period" of 24h is what kills it. For people like me, who rely more and more every day on OSS apps not necessarily in the Play Store, installing a new phone will mean waiting a full day for almighty Google to allow me to do so. It reminds me of the same annoyance of carrier phone unlocks. I wonder how this will play out in the phones coming out of the Motorola+GrapheneOS partnership.
- lwkl 7mo agoA minuscule amount of nerds being slightly annoyed is definitely worth when it hinders scammers from ruining a persons live.
- branon 7mo agoThere's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. Would welcome evidence to the contrary. Is this truly a threat model that's seen in the wild? My gut says no because social engineering is about hijacking legitimate, first-party processes. Scammers attack login credentials, MFA flows, and use first-party apps to maintain access (think remote control software like TeamViewer). These apps come from the Play Store, not from meticulously curated collections like F-Droid, and not from somebody pressuring you to sideload an APK. And if scammers decide to use sideloading as an attack vector -- then like all the other security gates that can be defeated via social engineering, I expect they will find an end-run around this one as well. Either on a technical basis, or by social-engineering users into bumbling past it and on to the next stage of the scam. Build an idiot-proof system and society will build a better idiot. And yeah, the rest of us only wind up slightly annoyed, _for now_, until Google tightens their grip further on some other flimsy pretext.
- gruez 7mo ago>There's no way this is really about scammers. I have never heard of scammers pushing sideloaded apps upon their victims in order to carry out their scams. I also never got targeted by pig butchering scams[1], and neither did my immediate friends/family, so I guess those must not exist either? [1] https://en.wikipedia.org/wiki/Pig_butchering_scam https://en.wikipedia.org/wiki/Pig_butchering_scam
- inquirerGeneral 7mo ago[dead]
- medhir 7mo agotaps the sign: https://medhir.com/blog/right-to-root-access https://medhir.com/blog/right-to-root-access
- goodusername 7mo agoAlthough I'm slightly relieved there is a way out of Googles verification system, it's still pretty wild if you compare this to installing software on a Windows pc. I'm sure Microsoft is heading in the same direction with Windows, but today its still "only" a few confirmations to install anything. This will sadly still put a major damper on adoption of open source apps, while giving a false sense of security that apps from the Play store are safe. Years down the road, the low usage of apps installed from outside the Play store will be used as an argument for removing the functionality completely.
- freefaler 7mo agoApple has been doing it for years not allowing "unsigned" software to be installed using the same "for the safety of the user" even against the user's wishes.
- headsman771 7mo agoAnd they should remain the outlier.
- AlbinoDrought 7mo agoThere's an interesting subset of Windows machines out there running in "S" mode [1]. This mode restricts the customer to only using applications from the Windows Store. We get occasional support tickets about the popups that come when trying to run a regular installer while in this mode. Luckily, people can disable "S" mode, but there's no way to re-enable "S" mode without a fresh install. 1: https://support.microsoft.com/en-us/windows/switching-out-of-s-mode-in-windows-4f56d9be-99ec-6983-119f-031bfb28a307 https://support.microsoft.com/en-us/windows/switching-out-of...
- pjmlp 7mo agoYes, that is what happens with UWP applications, or sandboxing apps installed via the store with MSIX package identity.
- 13415 7mo agoThe alleged inability of a company like Google to create an operating system that makes banking apps secure while allowing users to install whatever they like is very implausible. Android apps are already sandboxed and have fine-grained access control, and the operating system controls everything that is painted on the screen. The security justification for this measure is not credible.
- Gud 7mo ago“sideload”, is installing software without some asshole preventing me. Let’s be clear here.
- chr15m 7mo agoIn addition to a enabling it in this onerous way, this should be a thing you can set when you first set up the phone after factory default: "I am technologically literate and I accept the risks of side loading indefinitely." If it's set once during set up then none of the vulnerable people will have it set for the lifetime of their phone. A scammer would have to factory reset their phone which would defeat the purpose of gaining access.
- yonatan8070 7mo agoI feel like even the "indefinite" option would be about as indefinite as setting your default browser on Windows
- chr15m 7mo agoProbably true. Asking a tech company to stay good is like asking a lion to stay vegetarian.
- foxes 7mo agoStop propagating the term sideloading like its some kinda dirty thing. Its just installing an app.
- monksy 7mo agoFind the email address of the CEO/board members. When you get this on your device. Let your thoughts be known to them with a screenshot. Feel free to use language that will make them feel dumb and sad. Don't expect them to understand logical arguments or pleas. Companies get away from this because they distance themselves from their customers and they have systems to hide feedback.
- hnburnsy 7mo agoWhat versions of Android will this apply to?
- garciansmith 7mo agoIt'd be nice if they put a little sticker on the box or a flashing warning when you go to buy the phone noting that you'll be unable to use it as you desire for 24 hours if you are not willing to bend over to your corporate overlord. Alternatives like GrapheneOS and Lineage are the way to go for right now, but I worry as things get more and more locked down that those options won't work with a lot of apps.
- idle_zealot 7mo ago> I worry as things get more and more locked down that those options won't work with a lot of apps I am increasingly interested in a dual-prong approach of building a parallel world of OSS apps, platforms, etc, plus an adversarial inter-op project for duping and wrapping apps/services from the commercial/normie world. We have some solid bases with Android/Graphene, Linux more broadly, wine, and Android VMs like Waydroid. Even if things don't get a lot of users, if the users it has are highly technical on average things can probably chug along.
- garciansmith 7mo agoYeah, I do hope that an "inter-op" idea can be possible, otherwise anyone who doesn't want to join the duopoly fully will slowly be unable to interact with more and more aspects of commerce, government, etc. I guess the GrapheneOS method of integrating Play Services but keeping the user in control (e.g., being able to block Play apps' internet connections) is something like that, but ultimately it's controlled by Google and there are problems with Play Integrity, meaning some things just don't work.
- idle_zealot 7mo agoI don't think Graphene quite embodies the "adversarial" aspect I'm talking about. They explicitly don't do Play Integrity spoofing, even though they can, because they're committed to the more political avenue of convincing banks and such to use an alternate non-Google attestation framework. It's admirable, but I expect they'll lose considering the vast disparity in resources and power between them and their ideological enemies. I like the idea of committing more energy to the cat and mouse game of cracking apps and spoofing checks at this point.
- hkt 7mo agoSailfishOS / Jolla are unlikely to do this. Time to switch. Google's monopoly power over android is showing, badly.
- cxr 7mo agoMaybe if the Jolla folks were serious about making inroads in the market for personal mobile devices that they're ostensibly trying to compete in. But they're just as deluded and as doomed as their Meego/Maemo/Moblin predecessors about the value proposition that the SDKs and system software they ship has with the market segment they're targeting.
- deleted 7mo ago[deleted]
- dzogchen 7mo agoCalling "installing something without Google's or Apple's consent" "sideloading" is stupid. I will die on this hill.
- zt64 7mo agoI agree fully. Sideloading has a negative connotation when it's literally just installing apps.
- RobotToaster 7mo ago'Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.' - Benjamin Franklin
- ceejayoz 7mo agoSure, but what's "essential"?
- semolino 7mo agoBeing able to decide yourself the software that is allowed to run on the hardware you own.
- ceejayoz 7mo agoBut you have that ability. There's a one-off 24 hour wait. You have a similar wait if you get it shipped to you from Amazon. Is the instant gratification essential?
- semolino 7mo agoWhether it's essential or not is up to the user, who should be able to load whatever operating system they want (enabling them to bypass the restriction) on their bootloader-unlockable device.
- danpalmer 7mo agoWhy should the bootloader come locked? That's restricting freedom isn't it by preventing those without a few minutes to unlock it from having true freedom. I'm not sure how an unlockable bootloader that comes locked and a signed and verified software only that can be unlocked is actually fundamentally different.
- kelseyfrog 7mo ago
- zb3 7mo agoSince after doing this Google knows the user knows what they're doing (and officially they say they don't want to get in the way), why does this only enable installing unverified apps (still unprivileged), why is the system still insanely locked down? I thought the 24-hour delay solved the "security" problem?
- kogasa240p 7mo agoAt this point the meta for tech inclined people is to go full dumbphone, get a UMPC with SIM card support, cobble together a cyberdeck with a SIM module, or building an ESP32 powered cellphone (https://www.xda-developers.com/someone-made-a-4g-esp32-smartphone-and-its-as-impressive-as-it-sounds/ https://www.xda-developers.com/someone-made-a-4g-esp32-smart...). RIP F-Droid.
- copirate 7mo agoSo if I have to reinstall my phone it won't be usable for 24h because I won't be allowed to install my F-Droid apps?
- nout 7mo agoThere are multiple apps that I know and want to use that are no longer available on Play Store, but only via Zapstore, Obtanium or similar. I'm just hoping that these changes don't affect solutions like GrapheneOS or that we will soon get linux based phone that's good...
- GeekyBear 7mo agoPeople already have the choice between an ecosystem that offers the safety of a walled garden and one that allows the freedom to do anything you like, including shooting yourself in the foot. Google's decision to walk back the supposed freedom to run anything you like removes user choice from the marketplace and harms consumers.
- mrmckizzle 7mo agoI'm not sure if I've heard this discussion from somewhere else and took it as my owm thought. Anyways, I consider this era the beginning of tech feudalism. I honestly don't think we'll be able to escape it. Please note I use Linux and GapheneOS as my two main daily drivers. Most normal people do not care and they think it's crazy I'd make my life so inconvenient. It's my perspective, but I believe users in general don't care, understand, and prefer convenience over choice. Which gives a lot of power to this push for max control. Wether we like it or not I think we won't be able to stop it. I'm not being negative about it or trying to demoralize anyone. We already have at least four basic tech-feudal states, Microsoft, Android, Apple, and Freedom-Software. Each one somewhat has a used base that reflects it's ideology.
- realxrobau 7mo agoI hate to say it, but I'm somewhat in agreement. I don't know why there's a allow 3 days/allow forever option. That's the only thing that's suspicious. Assuming the requirements are actually justified, this seems like a tolerable compromise.
- aniviacat 7mo ago> In addition to the advanced flow we’re building free, limited distribution accounts for students and hobbyists. This allows you to share apps with a small group (up to 20 devices) without needing to provide a government-issued ID or pay a registration fee. What stops scammers from simply creating a new hobbyist account for every 20 people they scam?
- storus 7mo agoThe constant sociopathic nudging from Google to do this or that to use something that was absolutely normal before or to enable something I didn't want and slowly removing reasonable options in favor of their dark pattern preferences was what made me to degoogle ~10 years ago, and they just seem to continue on the march to their dark side unconcerned.
- xp84 7mo ago> “In that 24-hour period, we think it becomes much harder for attackers to persist their attack,” said Samat. “In that time, you can probably find out that your loved one isn’t really being held in jail or that your bank account isn’t really under attack.” I wanted to be negative about the whole idea, as due to my age I'm resentful of not being allowed to use my own computer as I see fit. On the other hand, in principle I see what they're going for here. The only decent argument for these user-hostile lockdowns is the malware issue.
- linuxhansl 7mo agoThat's not entirely unreasonable. As long as there is a way to enable this in perpetuity for my device(s) and it works for all Android devices it's a compromise I could live with. Again, can we, please, stop call it side-loading. I'm not sliding in anything "from the side" on the sly, I am simply installing an app of my choice on my damn phone.
- palata 7mo agoI hate it of course, but I think for once there is a solution: just go for an alternative AOSP-based OS. Preferably GrapheneOS (soon available on Motorola phones). The truth is that 99.9% of the people don't care. The remaining 0.1% is perfectly capable to use GrapheneOS.
- TGower 7mo agoThis seems like a good solution that will put a sizeable dent in scam success rates while not actually removing options for developers and power users. The added friction will make some people bounce off F-Droid and the likes which is unfortunate, but the wins here in scam prevention are much bigger than the losses in onboarding power users.
- userbinator 7mo agoYet more reasons to keep using an old rooted Android for as long as possible and contribute to any efforts that make it easier to do so. I suspect the reason Android become dominant was the ease of modding and the community that created, and now they're trying to turn it into another authoritarian walled-garden like Apple. To paraphrase the famous Torvalds: "Google, fuck you!" "Those who give up freedom for security deserve neither."
- _cenw 7mo agoThis comment makes no sense to me. As an individual user, opting out takes 24 hours and is much easier than rooting. Either your criticism is that this is prohibitive for too many users who aren't likely to care enough to ever root their phone (which might be fair, but your response doesn't fit) or it is that Google is locking down the ecosystem for some nefarious purpose (they're evidently not).
- userbinator 7mo agoor it is that Google is locking down the ecosystem for some nefarious purpose (they're evidently not). Most of the comments here seem to agree that they are. Some people have clearly been so brainwashed that they can't figure it out.
- b8 7mo agoIf you login, log out they don't prompt you with the security warning on Android TV.
- ddxv 7mo agoI've been slowly degoogling because of how Google is treating Android. It's slow, but I've been setting up emails on other providers, stopped using Google search, stopped uploading photos etc.
- deleted 7mo ago[deleted]
- AdmiralAsshat 7mo agoHow exactly is this going to stop scammers from simply modifying their scam runbook to say "Turn this thing on, and get back to me in 24 hours.", and then continue on from the next step? We know from Nigerian email scams that these things can stretch out days, weeks, months, all to get the victim to do the thing.
- andrekandre 7mo ago> We know from Nigerian email scams that these things can stretch out days, weeks, months, all to get the victim to do the thing. the real issue i think is using technology to stop a non-technology problem (scams) as that is a society problem but it seems govts arent interested or incapable of solving the causes (education, opportunity, destitution, etc etc) and probably also influx of scams from sanctioned countries (again a society/world level problem) that cant participate in the world trade etc... so they lean on the technology companies to lockdown things more because what else can they do?
- azernik 7mo agoThe Nigerian type scams typically prey on greed; time pressure isn't part of the draw. There's another class of scams where the draw is fear - "your son is in jail", "your bank account is under investigation and will be closed in 24 hours if you don't act now", &c. They rely on time pressure to prevent the victim from reaching out directly to the parties they're lying about and disproving the scam. This is aimed at that particular type of scam and that particular type of victim.
- pentagrama 7mo agoI read several articles about this today, and surprisingly, found this video more clear and easy to understand what is the situation https://youtu.be/-WF34Sgq76c https://youtu.be/-WF34Sgq76c
- tjpnz 7mo agoThe only reason I stuck with Android was to have the freedom to basically install anything I like. This is not a solution, much less to any problem which existed before. I don't think my next phone will be Android.
- deleted 7mo ago[deleted]
- mkw2000 7mo agosuch a bummer man, might as well go back to apple i guess..
- zmmmmm 7mo agoIt probably sounds like a nitty gritty detail here but who is enforcing the 24 hours and how are they enforcing it? Because if that "enforcement" is Google then they are still engineering a situation where they hold the keys to the kingdom. They may benevolently let you install what you want, but the sword of damacles will hang over everyone forever, with the darth vader contract in full force ("pray we don't change the deal any further"). If nothing else, it will have a chilling effect. But more than likely, it will attract regulators like moths to a flame to coerce Google into banning their favorite open source apps that they don't like. In other words: it won't solve anything at all, really.
- robpx3 7mo agoThat's just friggin great, except for those who use newer phones from Cricket - who disables developer mode for until the phone's been active on their network for 6 months...
- t1234s 7mo agoAny chance there is push from the carriers to implement something like this to cut down on hijacked devices sending spam?
- kelvinjps10 7mo agoI feel like loading sideloaded applications it's locked enough, google created google protect (which I have disable) but it if you have it enabled you are unable to instal sideloaded apps, also you have to accept the prompt to accept the app you're installing from and the prompt from your android to let you install sideloaded apps, like how many prompts is enough? now also a fee and verification. Most of the apps I enjoy the most are in alternatives stores. Ankidroid,keeepassxc,revanced, newpipe,tubular.
- Andrex 7mo agoSupported Android since the beta m3 SDK in 2008 (ok, I was in high school, but I still downloaded it!) Never considered abandoning it before now. It's time to leave Android. Call me naive, but despite the feeling in my gut I was holding out for Google's answer. Reading what it is, this is still going way too far. You essentially need to be a developer in order to sideload, which brings Android down to parity with iOS. No, being able to sideload (on my phones, AND friends and family as-needed) is a fundamental computing right. This is my personal belief. And this move by Google is a step too far. The search begins...
- p0w3n3d 7mo agoHuzzah! Our most gracious sovereign shall bestow his mercy upon us and allow us to install apps on our phones
- hilbert42 7mo agoThis news confirms my thoughts to abandon Google's line of Android upgrades at the first opportunity. Even before Google's edict I disabled enforced Android updates in case that at Google's demand manufacturers slipstreamed some restrictive code that cannot be later removed. One only has to look at the disastrous precedent with Windows 11 to see how insidious and ever-increasing lock-in works. Fact is Big Tech cannot be trusted and there's a long lineage to prove it—MS Windows, Sun/OpenOffice and many others—and now Android. To avoid future calamities like this and to ensure survival of F-Droid, et al we urgently need to break Big Tech's nexus with open source independent of Big Tech's control. I can only hope more manufacturers are prepared to fork Android to cater for the upcoming demand.
- eviks 7mo agoBut you're not balancing anything, just saying that you are
- kaufmann 7mo agoAnytime I open the Play store it feels like I am getting hustled to install Scam Software I don't want. With Scam I mean either it is overblown with Ads or wants a subscription. I really extremely rarely open the Play Store. F-Droid is my place to. Even if the tools are simple, they are reliable. Maybe Google is also scared, that with coding agents some OSS Tools improve that much that commercial alternatives don't matter.
- wiradikusuma 7mo agoI can see that majority of response is negative, being mobile developer myself I can understand. What's the solution for 3rd world countries where 80% phones are android (and usually old/low spec) that balances freedom for knowledgeable users vs security/safety for the majority of users? you can roughly understand education level and tech literacy for the majority of people in 3rd world countries.
- Razengan 7mo agoI had a taxi driver ask me for help with their Android phone after their kid did something and now their phone kept getting ads every 5 minutes in every app no matter what they were doing
- creshal 7mo agoTo be blunt: I don't care. Don't make their incompetence my problem.
- megous 7mo agoEnable this per country then?
- leke 7mo agoThis is great news for my wife and my parents, but it would really be nice to have the choice when it comes to my phone's OS. Just like I had with Linux. I boggles my mind how the components in a phone are somehow different to the components in a PC in that they are unaccessible to people who write drivers for them.
- joelthelion 7mo agoI think I would be fine with that if they also provided the option to check the box immediately when you first setup your account on a new phone. I don't want to wait for 24 hours every time I change phones.
- Myzel394 7mo agoI think most people here live too much in their tech bubble and don't realize how dumb the vast majority of people are when it comes to tech. I know that feeling myself that you lose the grip to "reality" when you are too much into tech, but after dealing a bit with "ordinary" people, I do understand why Google wants to do that. Most people have absolutely no idea about tech at all. So many people don't even know what exactly a browser is, what a "tab" means or can't even get to install an iPad. Google mainly has to take care of these people, not people who install apps using F-Droid. Go to the streets and ask strangers if they know what F-Droid is, and if they don't, try to explain it to them. The 24 hour wait period looks like a good trade off to me. Still allowing experienced users to install apps, but the majority of people will be protected, and it won't even affect most people. And no, I'm not a bot or some pro Google activist, check my github account, I even use GrapheneOS myself.
- creshal 7mo agoScammers have no problem waiting 24 hours, so this doesn't protect incompetent people at all.
- gasull 7mo agoAs someone who has been forced at the Australian border to unlock my phone, and seen it taken away, maybe this isn't a bad idea.
- pcthrowaway 7mo agoThis instruction set should be linked in the Urbandictionary definition for Kafkaesque
- smashah 7mo agoWe need to get Epsteinist Interests out of our tech.
- hamdouni 7mo agoCorry's enshitification is in charge
- iamcalledrob 7mo ago> Restart your phone and reauthenticate: This cuts off any remote access or active phone calls a scammer might be using to watch what you’re doing. This is smart. But putting my design hat on here: couldn't this be the whole approach? When enabling the "unverified apps" setting, the phone could terminate all running apps and calls before walking the user through the process. Why do you even need the rest of the complexity -- if the fear is that non-savvy users are being coached into installing malware,then preventing comms while fiddling with the settings seems pretty OK? You could even combine this with randomised UI, labels etc. so it's not possible to coach someone in advance about what to press.
- creshal 7mo ago> But putting my design hat on here: couldn't this be the whole approach? No, because protecting users is just an excuse. The overreach is the goal.
- iamcalledrob 7mo agoHaving worked in big tech, my money would be on Hanlon's Razor here -- "Never attribute to malice that which is adequately explained by incompetence"
- basilikum 7mo agoIt isn't adequately explained by incompetence. This is out of the playbook of boiling the frog. Nothing about this is new or unexpected. We have plenty of history about how these things go down. First they make installing device owner chosen software ridiculously laberous. Then they will remove the option altogether.
- KomoD 7mo agoI don't understand how it makes any difference. A scammer is going to be familiar with the flow and can also just... call again? "Just follow x, y, z and I will call back to help you"
- TheChaplain 7mo agoThe criticism against this decision seem to often miss the point of it IMHO. Let's be realistic, there IS a problem with sideloaded apps being downloaded by ignorant people, and they do get scammed/hacked or whatever. This leads to unhappy people complaining to their banks, politicians and media, these in turn starts lighting a fire under Googles bottom. So, my point being, how do we solve the ACTUAL problem with rogue apps then?
- zx8080 7mo agoThere will no any benefit from using Android instead of iPhone if there's no sideloading. As for the IDs, I think what happens is that Google sees no need to have hobbyists anymore in the ecosystem. Companies are easier to deal with, easier to change ecosystem to what's needed for Google. While for app development companies, there will be a single enterprise account with some ID used for many developers. And companies just shut up and follow almost any non-financial requirements Google wants to add. In contrast, opensource developers frequently go public advocating for user privacy and data prorection, while companies tend to be on the same side as Google squeezing any bit of personal user data to sell it for any margin possible. Is any open mobile device and OS ecosystem possible at this point of time, other than the hobbyist one? With closed gates of LTE/5G ecosystem it seems there's no such possible at all.
- shevy-java 7mo ago> As for the IDs, I think what happens is that Google sees no need to have hobbyists anymore in the ecosystem. Google has become an extremely selfish company.
- odo1242 7mo agoPersonally, I think they should at least drop the $25 fee if you publish outside of Play Store.
- evolighting 7mo agoI think this topic is not about safety, but about profit and responsibilities. The reality is that users should take responsibility but are not allowed to, so Google takes over and makes a profit. You don't need a CS degree to use a phone, but you can be a power user by time....but not anymore, the company needs you to stay fool and pay for "help" (not directly sometime). This is a marketing tactic, similar to a side-load.
- shevy-java 7mo agoAndroid should be freed from Google. I know, I know, not realistic, not easy to do, but still. With that I mean there should be only open source software at all times, at the least for any base system to use (so, not only Google but ALL of them; this is a different focus than open source alternatives).
- seu 7mo ago> Flip the toggle and tap to confirm you are not being coerced This is just spreading fear. If you're being coerced to do this, then you're in a much bigger danger than what a rogue application sideloaded to your phone represents.
- Hackbraten 7mo ago“Being coerced” typically means “you’re on the phone with a person who claims to be a bank representative and who is trying to push you into flipping the toggle.”
- crvdgc 7mo agoEven alternatives like GrapheneOS relies on AOSP. I wonder if it's possible for regulators in certain countries to pressure Google to kill it in the future. Even if that's not the case, I'd imagine attestation apps like banking apps would require some kind of identity verification in exchange for trusting Graphene's keys. In principle it doesn't make sense to leave any escape hatch, but I guess as always, it boils down to economy.
- Hackbraten 7mo ago> Even alternatives like GrapheneOS relies on AOSP There are alternatives that don’t: Mobian, Ubuntu Touch, PureOS, postmarketOS, Sailfish OS.
- the_wolo 7mo agoIt fun to see how they know exactly that really no one is trusting them.
- contingencies 7mo agoThis is destroying and devaluing the app ecosystem on all platforms, discouraging companies from treating it as a stable target, right when Apple is gaining dominant market share. Is it really worth executing payments, maps, geospatial APIs, etc. on one platform if >30% of your customer base can't use it and it changes every 6 months (because that's what they've engineered)? No. Who wants to maintain that? Then what is the interface people are pushed to? The browser, where Google historically dominates.
- bonoboTP 7mo agoA big problem that causes gullible people to follow scammers guidance is that real software with legit and important functionality is often utter crap and requires regularly dismissing various big red warning screens like expired or misconfogured ssl certs on the web, etc. People are taught to not take warning screens seriously because they often have to be bypassed for legit reasons.
- jasonvorhe 7mo agoI hate this. GrapheneOS all the way. I'll never purchase devices that force this on users without a simple way to opt out. I'm done with Google. Glad I cut all ties with that entity over the last few years. Just despicable.
- deleted 7mo ago[deleted]
- smeggysmeg 7mo ago* enable developer options * confirm that you are not tricked * restart phone and re-authenticate * wait one day * confirm with biometrics that you know what you are doing * decide if you only want unrestricted installs for 1 week or forever * confirm that you accept the risks * enjoy the few apps that still have developers motivated to develop for a user-base willing to put up with this
- chanux 7mo agoGood guy Google must have published the numbers of scamming incident due to current software installation setup. I appreciate if some good samaritan can link to it.
- croemer 7mo agoSo this means one can't just copy over unsigned apps from previous phone when transferring. As others have suggested, there should be an option skip the 24hr wait when activating at setup time. Or, alternatively, when the previous phone one is transferring from has it enabled it should be without wait time on the new one.
- zelphirkalt 7mo ago"Sideload", "unverified"!!! Woaa, careful now, we can't guarantee for anything!! Danger, danger! How much can you twist words and language to engage in fear mongering? The headline could just as well have been "install", and "free choice" and "Google gatekeeps".
- alexovch 7mo agoFeels like one of those changes that makes sense from a security perspective, but will mostly hurt smaller devs who rely on sideloading. Curious how this will play out for niche apps that aren’t on the Play Store.
- doe88 7mo agoOne gotta give it to them, advanced flow, what a great new double-speak-ism, would have made the ministry of truth very very proud.
- xorcist 7mo agoNewspeak is the trademark of oppressive regimes. Can we please not overexert ourselves in trying to please the global tech companies by pre-emptively changing our language? Google details new process to install unverified Android apps. The sentence is much more clear using established language. Not "side-load", whatever that means.
- cubefox 7mo agoImagine if Microsoft did that with Windows. Absurd. The difference between Microsoft and Google seems to be that Microsoft accepts a small fraction of not-so-bright users getting scammed, because this is obviously much less bad than locking down the OS for everyone. (I say this as someone who is usually much more positive about Google than about Microsoft.)
- jleask 7mo agoI've stuck with Android despite privacy concerns because of the control I have over the device. If they're going to do this I might as well go Apple.
- BatteryMountain 7mo agoSame here! I've traded some privacy for freedom, but if they take away freedom, I'm still paying the privacy price. In this scenario, there is nothing left for me here. So Apple beckons.
- yaro330 7mo agoA lot of you have never seen your loved ones get some shitty app on their phones and it shows.
- swiftcoder 7mo agoI’m often annoyed at the 10 second timeout when installing Firefox extensions - 24 hours is beyond egregious. Telling me to come back tomorrow to install software on a device I own is a giant “fuck you”. Pretty sure I’d rather they banned side loading outright than this
- DeathArrow 7mo agoThey do it for your own good, to defend you from dangerous software. Dangerous software is software that is not making Google money and that does not give Google control.
- acqbu 7mo agoThere is a way out! https://grapheneos.org https://grapheneos.org
- zombot 7mo agoSo Google tightens its iron grip for "alternative" app stores.
- gamin8ing 7mo agoThis is the first thing I will be doing in my new Android Smartphone, in the very first hour. Also, was this really necessary Google?
- vbezhenar 7mo agoHow does it track time? Is it possible that user will just change current time to the future to instantly process the request? Is it possible to track time "safely"?
- Retr0id 7mo agoidk if they'll use it for this, but Pixel phones have "secure" clocks used for image attestation, among other things. https://security.googleblog.com/2025/09/pixel-android-trusted-images-c2pa-content-credentials.html https://security.googleblog.com/2025/09/pixel-android-truste...
- fredgrott 7mo agoIf this was truthful about security... Google could make a mobile website to take an app apk and verify it if its secure and offer to install it back to android users ... My bias, former Android app developer. This is using the increase in attacks to do a business monopoly goal instead...
- Grimblewald 7mo ago"Don't be evil" how far we've fallen. dear google: fuck off and die. May something worth the resources it consumes grow from your fetid corpse.
- dankobgd 7mo agostopped reading at "combating malware"
- nubinetwork 7mo agoRandom thought, but doesn't disabling developer mode turn off all of the changes in there?
- jwr 7mo ago"Android is one of the most open systems I've ever seen. What makes Android great is it's literally designed from the ground up to be customised in a very powerful way." -- Sundar Pichai Oh, how times have changed. And so many believed this and repeated it.
- whatsupdog 7mo agoTime to put pressure on manufacturers to move to something more open like graphene, or another community based project
- whatsupdog 7mo agoA king wanted to test the complacency of his subjects. He put a toll on a bridge. There were some noises but eventually everyone got used to it. He slowly kept increasing the toll, which came with increasing noises which would all eventually subside. He decided to take it a step further. He proclaimed that anyone crossing the bridge will be slapped by one of his guards. This time the protests were stronger and getting bigger. He thought "thank God my populace has woken up". He went outside to meet the leaders of the protesters and asked why are they protesting. The leaders said: "you started taking toll, we said nothing, you kept increasing it, we said nothing. But with this new policy, there's only 2 guards delivering the slaps, leading to huge line ups. So we demand that you employ more guards at the bridge to ensure faster slaps and smooth flow of traffic."
- LauraMedia 7mo agoSo this effectively means, if you buy a new phone and want to set it up, you'll have to do it tomorrow, because of an arbitrary flow Google created to save their play store percentages...
- whatsupdog 7mo agoSo what's the solution? Graphene OS? Let's convince everyone we know to buy the upcoming Motorola phone. If it's sales hit 10s or 100s of million devices, only then Google will listen.
- ninjagoo 7mo agoIt is way past time to build a 'people's phone', funding it through a platform like LiberaPay [1][2] or Open Collective [3][4], with a requirement for the device to be completely open-source. [1] https://liberapay.com/ https://liberapay.com/ [2] https://en.wikipedia.org/wiki/Liberapay https://en.wikipedia.org/wiki/Liberapay [3] https://opencollective.com/ https://opencollective.com/ [4] https://en.wikipedia.org/wiki/Open_Collective https://en.wikipedia.org/wiki/Open_Collective If we start today, we could have a new phone in 2-3 years. Future generations will thank us. It's not just phones. There is a concerted movement by massively-moneyed folks to destroy the fabric of open society, so there are a number of different areas that need attention. A coordinated effort across the breadth of society to restore, maintain or improve the foundations of open society.
- Anonyneko 7mo agoOpen phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services).
- ninjagoo 7mo ago> Open phones are all fine and well, but good luck convincing banking and government applications to work on those (especially in countries where bank login is used to access government services). First phones, then lobbying. As citizens of an open society, government exists to serve us, not the other way around. With enough users, they will have to respond. As I said, there are a number of areas that need attention and a coordinated effort across the breadth of society to restore, maintain and improve the foundations of an open society.
- Psype 7mo agoit also makes it urgent to have a platform with leverage under 3-5 years, with a whole lot of countries pushing for digital ID globally.
- 7mo ago
- noisy_boy 7mo agoThe timing is interesting. With the measurable shift in quality of models and the agentic workflow becoming more popular (exacerbated by SaaS companies trying to democratise app building), there will probably an explosion of even more apps (as if there aren't enough already). The programmer in me likes that because I can easily build an app that is specific to my needs. But so can a person who doesn't have the technical background which combined with poor security track record of LLM generated code, is a risky combination security-wise. Not sure if that was actually the motivation or whether it was preserving the revenue from the developer ecosystem by creating another walled garden.
- ChoGGi 7mo agoHow is a 24 delay for manually installing apps going to combat malware on Google's play store?
- dugite-code 7mo agoSelfhosted apps are going to start using PWA's in an even bigger way if this goes ahead.
- sokoloff 7mo agoThis is getting a ton of hate here, but I think it feels like a pretty reasonably balanced response to competing concerns: protecting literally billions of non-tech-savvy users from potentially malicious social-engineering attacks while allowing devs and tech-savvy a path to bypass that protection if they’re sure they want to. What concrete change to the policy would be a strict Pareto improvement keeping just those two concerns in mind?
- eykanal 7mo agoI'm pretty surprised at the amount of hate here. All the "just build it ourselves!" and "Google wants your data", and almost no top-level comments even discussing the difficulty of dealing with malware and social engineering. There are at least three moral arguments that can be made: - Google, as a capitalist company, is ignoring the privacy and FOSS implications, and is guilty of screwing the customer due to greed - Regular, non-tech folks are constantly being robbed of their privacy, money, and/or identity through malware and social engineering attacks, and Google is guilty of not doing enough to protect them - Enabling malware delivery and use props up criminals and known bad actors (e.g., north korean), and by not stopping this Google is guilty of supporting these bad actors I'm not seeing either of those last two points being made strongly. Maybe it's just not the target audience — people here aren't as likely to be scammed, and few of us are regularly thinking about north korea — but I'd expect to see more consideration for the costs of inaction here.
- wat10000 7mo agoIt’s pretty common for techies to overestimate how widely their opinions and desires are shared. If you think a good chunk of the population wants to sideload apps, then this feels like an attack. But it’s really just a decision not to cater to a tiny fraction of the market. It’s the same thing in discussions about headphone jacks or small phones. People act like it’s nefarious, when really it’s just that their desire for those things is pretty uncommon. Personally I think there should be a lot more work done on how to secure arbitrary apps from arbitrary sources so that they are unable to hurt people, rather than focusing so much on on preventing random apps from being installed in the first place. This would help the average person as well, since these walled gardens still make mistakes. But it’s not realistic to put a box in everyone’s pockets that’s three taps away from sending all their money to some dude in Laos.
- davsti4 7mo ago50 times more likely? Don't they need to supply the data for that when making an "advertisement"?
- porknbeans00 7mo agoThey made a huge mistake with Dalvik and they seem to be doubling down on that mistake.
- hansvm 7mo agoTo their credit, the 24hr hold would actually serve an important, legitimate purpose if the same malware weren't going to be on the PlayStore anyway. I was expecting to disagree with their public statements more than I actually did on this topic. This still isn't a good idea. It's not going to materially improve security for anyone, so all the negatives (beaten to death here and elsewhere) are still top-of-mind.
- 1970-01-01 7mo agoIf this becomes widely successful and side-loaded crapware apps and Android phone scammers drop off a cliff, we will still be upset because we want a perfect world where everyone is above average in their digital security. Time boxing is a great compromise and you've lost none of your previous freedoms. Guaranteed convenience of side-loaded software was never in the Android terms of use.
- timedude 7mo agoSwitch to GrapheneOS
- gib444 7mo agoComing soon: - New toaster requires permission from manufacturer to toast bread from a local bakery. - Car manufacturer to vet all passengers. Any unidentified and unvetted passengers will disable the vehicle. - TV manufacturer requires 7 days advance notice of what you want to watch.
- glenstein 7mo agoI feel like there's a big thing being missed in all of this, which is that F-Droid lives. I scrolled through hundreds of comments so far and not seen anyone make this observation. Do I love it? Absolutely not. But F-Droid was facing an existential threat from the early early versions of the proposal and now will continue to live. Again, I don't love it but this is a huge change to the fate of F-Droid.
- rpdillon 7mo agoWell, Google is keeping the fees and the ID requirements for devs, while also vastly shrinking the population that will be willing to get permission to sideload from Google, decimating much of F-Droid's reach. They are basically attacking freedom on both sides, clamping down and extracting on the supply side, and creating friction and confusion on the demand side. I'm extremely worried for the future of open source on mobile operating systems. We traded freedom for convenience.
- Andrex 7mo agoTBH it is a little surprising, because one option available to Google was staying the course and hiding behind their Epic court loss. "Everyone can still access F-Droid, it just has to live in the Play Store. We're bound by law to support alternative app stores now anyways. Everyone wins!"
- ptx 7mo agoCould this be worked around by installing a single shell app which then loads other apps internally? I think it's possible to dynamically load Dalvik byte code in ART these days, right? Obviously permissions would be a problem, as you can't update the app manifest, so there would either have to be one shell app per publisher (which would at least solve the problem of installing updates for their apps) or the shell would need its own internal system for managing permissions (like a browser does). Maybe it could also sandbox different apps from each other in different subprocesses, unless that needs root privileges, but maybe it's possible with Landlock? Or we can always fall back to the "sweet solution" Steve Jobs offered us with the original iPhone, and just let the web browser be the shell. Or implement everything as WeChat mini programs.
- NotPractical 7mo agoThat would be very similar to LiveContainer for iOS [1]. I think that unsandboxed JIT is still possible as of Android 16, but Google has been cracking down on it. [1] https://github.com/LiveContainer/LiveContainer https://github.com/LiveContainer/LiveContainer
- capital_guy 7mo agoThis is the main thing that Android users have been saying is the differentiator for them using Android, and they're butchering it in multiple ways. Wild.
- marssaxman 7mo agoWell, this sucks. The fact that I can sideload whatever I need and stay out of Google's ecosystem is the whole reason I use Android. Given the miserable choice between two fully locked-down platforms, why would I pick theirs?
- Kim_Bruning 7mo agoThere are numerous alternative operating systems and variants out there that should get more of our attention now. There's a mobile ubuntu, e/os , and more.
- nickorlow 7mo agoThey're treating users like toddlers. Having to wait 24 hours to use my phone how I want to?
- tsoukase 7mo agoThe measures seem a lot less restrictive than I expected. 24h wait time is nothing if you suppress your ego, developer options is already the first thing I enable, an open adb channel is and will be a constant choice and the one-time-forever option a neat convenience. They could kill user experience for all but it's more a friction and not a restriction.
- pugchat2 7mo ago[dead]
- wisenet 7mo agoDevelopers could protest by changing our app icons to grayscale: https://news.ycombinator.com/item?id=47354917 https://news.ycombinator.com/item?id=47354917
- alpineidyll3 7mo agoI actually was kinda looking for a reason to give up phones. Thanks google.
- mvdwoord 7mo agoUnfortunately for making and spending my money, I am forced to have a phone. Either Android or Apple. I need my authenticators for work, banking apps etc. Will consider graphene os, not sure if it supports all the things I need. Otherwise I will get the cheapest iphone, only install required stuff and get a nice small laptop to carry around. Unfortunately I need to be reachable by phone (elder care) and dumb phones I think do not support authenticators/banking apps?
- aerzen 7mo agoCould the title say "process to install non-curated Android apps"? "Sideload" and "unverified" imply that the collection of centrally approved apps is the default way to install software. Or maybe it is and android's promises about openness are dead.
- BrandoElFollito 7mo agoThis is what I have with my bank. I need to wait 24h after adding a new recipient for wire transfers. Being treated as a toddler by an organization that is itself completely disfunctional is mzking me angry.
- xinayder 7mo agoSo much hassle to enable sideloading that I just... don't want to use Android? Having to go through 5 different menus, 3 different warnings AND wait 24 hours to install F-Droid? fuck no.
- seovisible 6mo agoHmm, interesting. Haven't seen this.