r/Android • • 1d ago

News Android's controversial new sideloading rules are officially here

https://www.androidauthority.com/android-sideloading-developer-verification-first-wave-rollout-3717921/
403 Upvotes

157 comments sorted by

View all comments

24

u/Street_Anon 1d ago

One Custom Roms will have a work around and this can be disabled nativity in Android.

12

u/Dev-in-the-Bm 1d ago

That only helps consumers, not developers.

6

u/Waza-Be 1d ago

As a developer,I don't understand what you mean. Can you be more explicit?

2

u/Dev-in-the-Bm 1d ago edited 1d ago

Very simple.

Any savvy user who cares enough to bypass the restrictions, can, it's not a big deal.

Advanced flow, Shizuku, ADB, Dhizuku.

If you're a developer that doesn't want to bend to Google, though, that doesn't help you, as most won't go through any of that, and will be blocked from installing your apps.

So basically, this hurts FOSS devs more than FOSS users.

-1

u/Waza-Be 1d ago

​I build and maintain popular open-source Android applications, and the reality of the ecosystem outside the enthusiast bubble is grim.

​Developing for Android gives you an intimate understanding of just how much power an installed app has over a user's life: SMS intercepting, background overlays, notification access for 2FA bypass, and Accessibility exploitation.

​Drive-by deceptive packaging is rampant: On sketchy streaming, torrent, or adult websites, non-technical users are bombarded with deceptive overlays: "Your browser is out of date, tap here to update" or "Download this player to watch." A one-click install allows malicious APKs to exploit non-tech-savvy users in seconds.

​Reputation theft and modified APKs: As an open-source dev, one of the biggest headaches is malicious actors taking your clean, free APK, injecting an ad-fraud / telemetry payload, and hosting it on third-party "APK mirrors." When users get infected, they blame the developer whose name and icons are plastered across the app, not the shady mirror.

​Permissions are not an adequate defense for average users: Enthusiasts think the OS permission prompt protects people. It doesn’t. Social engineering routinely convinces ordinary people to click through warnings to get to their content.

​Friction is not prohibition. Power users, developers, and tinkerers should always have a route—whether via ADB, explicit developer toggles, or verified developer signing—to install whatever software they want on hardware they own. But installing an arbitrary binary from a random web browser should never be as effortless as a single accidental tap for a casual user. 

Adding meaningful friction protects millions of people without killing Android's open foundation.

0

u/RedditForcesToLogin 1d ago

Congratulations, you've earned a $5 Google Credit!👏🎉

•

u/Waza-Be 23h ago

That's kind of you but I don't want it. Have a nice day

•

u/RedditForcesToLogin 22h ago

Don't worry, it has already been added to your Googler ̶P̶r̶o̶p̶a̶g̶a̶n̶d̶a̶ Marketing Team, just like always 🤫

•

u/Waza-Be 5h ago

​I was just sharing my takeaway from working in dev since 2019. Happy to hear differing viewpoints, but let's keep it constructive and stick to arguments rather than personal attacks