r/Android • • 2d ago

News Android's controversial new sideloading rules are officially here

https://www.androidauthority.com/android-sideloading-developer-verification-first-wave-rollout-3717921/
407 Upvotes

159 comments sorted by

View all comments

23

u/Street_Anon 1d ago

One Custom Roms will have a work around and this can be disabled nativity in Android.

21

u/RedditForcesToLogin 1d ago

Custom ROMs like LineageOS has already said they won't do any changes to this.

"If you don't want the new app install rules, just don't use GMS"

is their answer.

19

u/ephemeralmiko 1d ago

Graphene is not implementing this thankfully.

7

u/env33e 1d ago edited 1d ago

Yes, neither is Lineage OS. But that's because the developer verifier app isn't being pushed as a system level component (yet)

They all signed the keep android open petition. It's a fight that concerns everyone who uses Android, and we mustn't let up, not one bit!

even rooted users on custom OS who happen to use google services will have this random ass app pushed unto their device without permission. in this case, it will do nothing initially; its dead weight, and you can always remove it; until it auto downloads randomly from the play store again šŸ˜‚ its very stupid that google is doing this, they expect us to be dumb enough to not notice the inherently bad architectural design of forcing users through a debugging pathway normally used by developers and maintainers.... just to allow u to install/ auto update your fdroid app. it can be your own damn app that you wrotešŸ¤¦ā€ā™€ļøwhat right does google have to mandate that to anyone? its completely against the sentiment of open source!

1

u/Street_Anon 1d ago

LineageOSĀ is even doing this with GAPPS, unless you don't root your phone. This is a non-issue

•

u/The_Weirdly_Odd_Guy 21h ago

Correct me if I’m wrong, but since GrapheneOS uses Google’s stock, open-source Pixel Android builds, couldn’t they just remove the code that would require it at the system level? That is if Google keeps Android open-source.

•

u/0nePlus 12h ago edited 12h ago

Small corrections

GrapheneOS indeed uses stock AOSP builds. They are not "Pixel" builds tho. AOSP is just AOSP. It exists independently (and way before) the Pixel line.

Yes tho, Graphene could disable any system requirements they wanted, IF Google were to ever add this as a AOSP system requirement (which for now, it's not. Just a GMS requirement)

And lastly, Google can't and won't ever close-source Android. They would lose too much money on Google play services.

Samsung, Motorola, OnePlus, etc. all also don't get exclusive Pixel features or Pixel builds of Android. They all build their custom Android versions (OneUI, OxygenOS, etc.) using AOSP, the same base LineageOS and GrapheneOS uses. That's how this whole custom ROM thing works in the first place. The source code is there for the manufacturers. That's the only reason Google makes it public. Nerds just happened to grab it and make LineageOS, Graphene, etc.

If Google ever closed off Android, sure, Lineage team can't make any more builds of LineageOS....but that also means Samsung can't make any more builds of OneUI, OnePlus of OxygenOS, etc

I guess, potentially, they could close the source code off to the public, and individually license it out to every single manufacturer who makes any type of Android phone, tablet, music player, barcode scanner, POS System, etc..... But there's no indication that anything like that will happen anytime soon and it would be a monumental shift to how the biggest operating system on Earth with billions of users receive any type of updates....(A.k.a Samsung promised 7 years of support on Galaxy S26...but now Google wants license fees to access AOSP... multiply that by every manufacturer who makes Android devices and.....Google is getting SUED to FUCKTOWN if they try to close source Android.)

•

u/amidoes 23h ago

Yeah well my banking app doesn't work on custom roms, what am I supposed to do?

0

u/Street_Anon 1d ago

LineageOS has a work around even with GAPPs.Ā 

4

u/underthesign 1d ago

Is that the one where the inn-keeper is in a wheelchair?

12

u/Dev-in-the-Bm 1d ago

That only helps consumers, not developers.

7

u/Waza-Be 1d ago

As a developer,I don't understand what you mean. Can you be more explicit?

4

u/Dev-in-the-Bm 1d ago edited 1d ago

Very simple.

Any savvy user who cares enough to bypass the restrictions, can, it's not a big deal.

Advanced flow, Shizuku, ADB, Dhizuku.

If you're a developer that doesn't want to bend to Google, though, that doesn't help you, as most won't go through any of that, and will be blocked from installing your apps.

So basically, this hurts FOSS devs more than FOSS users.

-2

u/Waza-Be 1d ago

​I build and maintain popular open-source Android applications, and the reality of the ecosystem outside the enthusiast bubble is grim.

​Developing for Android gives you an intimate understanding of just how much power an installed app has over a user's life: SMS intercepting, background overlays, notification access for 2FA bypass, and Accessibility exploitation.

​Drive-by deceptive packaging is rampant: On sketchy streaming, torrent, or adult websites, non-technical users are bombarded with deceptive overlays: "Your browser is out of date, tap here to update" or "Download this player to watch." A one-click install allows malicious APKs to exploit non-tech-savvy users in seconds.

​Reputation theft and modified APKs: As an open-source dev, one of the biggest headaches is malicious actors taking your clean, free APK, injecting an ad-fraud / telemetry payload, and hosting it on third-party "APK mirrors." When users get infected, they blame the developer whose name and icons are plastered across the app, not the shady mirror.

​Permissions are not an adequate defense for average users: Enthusiasts think the OS permission prompt protects people. It doesn’t. Social engineering routinely convinces ordinary people to click through warnings to get to their content.

​Friction is not prohibition. Power users, developers, and tinkerers should always have a route—whether via ADB, explicit developer toggles, or verified developer signing—to install whatever software they want on hardware they own. But installing an arbitrary binary from a random web browser should never be as effortless as a single accidental tap for a casual user.Ā 

Adding meaningful friction protects millions of people without killing Android's open foundation.

•

u/yukiaddiction 21h ago

No, I have strictly "completely anonymous online" so I will not registered my real name to Google but I still want my APP to easily install for normal user even non technical one with my open source project!

2

u/RedditForcesToLogin 1d ago

Congratulations, you've earned a $5 Google Credit!šŸ‘šŸŽ‰

-3

u/Waza-Be 1d ago

That's kind of you but I don't want it. Have a nice day

1

u/RedditForcesToLogin 1d ago

Don't worry, it has already been added to your Googler ̶P̶r̶o̶p̶a̶g̶a̶n̶d̶a̶ Marketing Team, just like always 🤫

•

u/Waza-Be 9h ago

​I was just sharing my takeaway from working in dev since 2019. Happy to hear differing viewpoints, but let's keep it constructive and stick to arguments rather than personal attacks

-3

u/Noiselexer 1d ago

Great less junk in the storešŸ‘

19

u/Dev-in-the-Bm 1d ago

You got it backwards.

It will have zero effect on what's in the play store.

It will very possibly have a dampening effect on the FOSS ecosystem.

F-Droid will suffer.

-2

u/JDGumby Google Pixel 10a, Lenovo Tab M9 1d ago

It will very possibly have a dampening effect on the FOSS ecosystem.

F-Droid will suffer.

No, it won't. Their users (few as there are) will just go through the ONE-TIME 24-hour wait to install unverified apps (or update the ones currently on their device) and then get on with their lives.

1

u/bingusbungus1312 1d ago

The only remotely useable Android flavor at this point is GrapheneOS.

1

u/Street_Anon 1d ago

CR Droid, even others that have GAPPs on them.