Google has just made the decision that sideloading must be made harder:
Guess what all you dumb Android users, we are going to “protect” you by making all sideloaded app developers register with us. This will totally stop all Android malware being sideloaded, just like there is never ever any malware at all on Google Play. After all, things like this:
totally do not happen on a weekly basis. Guys, stop reading that last link. It totally never ever happens ever. We are Google, we are secure, and above all we know better than you, so just shut up and register. We would never ever create an automated verification system that was unreliable and prone to bans.
Just saw this. Doesn’t change the fact that it’s wrong, and that it will eventually happen but at least we got some time to figure something out:
The requirement will go into effect in September 2026 for users in Brazil, Indonesia, Singapore, and Thailand. Google notes how these countries have been “specifically impacted by these forms of fraudulent app scams.” Verification will then apply globally from 2027 onwards.
I wonder if it will be a simple disable on a rooted device, or a simple edit of a file…
This will only apply on new Android versions? Or it will be backported?
Custom roms will become more popular (if newer phones bootloader will be ALLOWED to be unlocked lol)
Phones without Google services will be unaffected, so if I have to eventually, I will ditch them. Been thinking about going vanilla for a while anyway.
ars18 posted something along the lines of:
“if someone downloads malware for virusscam.com, its his own problem”
to which my response is:
I cannot accept this as a good faith argument, and I will lay out why:
It contributes to a notion that people who get malware on their device are doing it on purpose.
It implies that most malware advertises the fact it’s malware, which is patently false.
It doesn’t recognize legal and corporate responsibilities to protect users from malware.
It ignores the consequences of having an unsafe os, such as entities halting the development of apps for such platforms.
It fails to accept that the company behind the most used mobile OS in the world will lose a lot of market share if devices are only suitable for tech savvy users.
It shifts the blame to users, instead of focusing on fixing legitimate vulnerabilities harming users.
It lacks empathy to those who are easily social engineered and often living in fear of what’s to come.
It underrates the skill of hackers, sometimes being backed by foreign governments/actors.
I want Android to continue to be successful and sustainable in the long term, and short sightedness is not the solution to that.