• Ulrich@feddit.org
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    14 hours ago

    As I said earlier, only a vague mention of an “advanced flow” that’s still in the works. Nothing saying they are no longer going to require distributors to register with Google, but it does say that they will require it on Google’s own website:

    Starting in September 2026, Android will require all apps to be registered by verified developers in order to be installed on certified Android devices

    • Pika@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      12 hours ago

      Just adding in, The Android developer page does clarify this problem. It will be a default on and will require the user going out of their way to turn it off.

      They have a direct question there labeled as the following.

      If I want to modify an app and install it on my own device, or if I’m a power user, is there a way to turn this verification requirement off

      And then the response is as follows.

      We understand this is an important use case for many developers and power users. While the verification requirement itself is a core OS feature to help protect the broader ecosystem from malware and can’t be turned off, we plan to offer two paths for experienced users to install unverified apps:

      • Advanced flow: We are building a flow that allows experienced users to proceed with installing an unverified app after going through a series of clear warnings. This new mode is designed to resist social engineering, helping users fully understand the risks, but ultimately gives experienced users the choice to accept the heightened security risk and install the software. We are gathering early feedback on the design of this feature now and will share more details in the coming months.
      • Android Debug Bridge (ADB): Developers and power users can still use Android Debug Bridge (ADB) to build, test, and install modified or unverified apps on their own devices, which remains the standard method for development work.

      Honestly, it doesn’t seem all that different than how fdroid is currently configured on Google. I expect that you’ll have to enable an option on top of the unofficial sources toggle that also states unverified apps.

      Being as they also specify what the Android debugging bridge is as a second bullet point, I expect that it’s not going to be through ADB like a lot of people were worried about as well.