The Register Home Page

back to article Google gives Android users a way to install unverified apps if they prove they really, really want to

It turns out you won't be limited to Google-verified apps and developers on Android after all. In the face of sustained community dissatisfaction with its developer verification requirement, Google has given Android users an out. On Thursday, Google said it will offer Android users a way to continue installing software from …

  1. iron

    > And then they need to wait one day.

    What a load of bullshit. No-one wants to wait a day to be able to install an app, this still kills independent developers and FDroid.

    Try again Google.

    1. Long John Silver Silver badge
      Pirate

      I rely on F-Droid for useful and trustworthy Android software. Also, the official Google store offers a garish nightmare experience.

      1. tunacoffee

        Play is a shithole appstore polluted with adware software and pay 2 win live-service gacha slop. Also what happens if the user turns off developer mode after enabling "un-verified" software installation? Will I have to keep dev mode turned on at all times? Some third party android software throws a hissy fit if you so much as have dev mode turned on.

    2. Kevin McMurtrie Silver badge

      I bet you can enable Airplane mode, roll the date back a day, turn on side loading, then turn off airplane mode.

      Criminals will find much easier workarounds in no time. Google's security is all theatrics to distract from their true sinister goals.

    3. Anonymous Coward
      Anonymous Coward

      No-one wants to wait a day to be able to install an app

      Hmm. As I read it this is wait a day to allow installation of any google-unverified apps; i.e. you only have to wait a day once, at the start of the permissions change. This would indeed be annoying, but at least it is less bad than waiting a day for each different app...

      1. that one in the corner Silver badge

        Re: No-one wants to wait a day to be able to install an app

        The blog (link in TFA) explicitly says "This flow is a one-time process for power users" - and it is *intended* to be annoying: a little bit annoying for you, a power user who isn't vulnerable to cons, to do ahead of time, in readiness for finding an ap to install, but VERY annoying for a scammer trying to run the con on innocent Joe and Mrs Bloggs.

        1. Paul Hovnanian Silver badge

          Re: No-one wants to wait a day to be able to install an app

          I'd venture a guess that power users have probably enabled developer mode shortly after taking their device out of the box. I know I did, so this would be a non issue for me.

          "but VERY annoying for a scammer trying to run the con on innocent Joe and Mrs Bloggs."

          Maybe not. How long did that guy have the "Do not redeem!" scammer on the line? (Check the clock in the upper right corner)

          1. FeRDNYC Bronze badge

            Re: No-one wants to wait a day to be able to install an app

            I'd venture a guess that power users have probably enabled developer mode shortly after taking their device out of the box. I know I did, so this would be a non issue for me.

            I'm not so sure. I didn't read it as "wait one day after enabling developer mode", but as "wait one day after enabling non-registered app installation". (Which, granted, power users are likely to also likely to do as soon as they take the device out of the box, once that option is available in developer mode.)

    4. Sorry that handle is already taken. Silver badge

      Now read the next line...

    5. osxtra

      I read this to be a one-time setting, for any and all apps installed in the future.

      If that's not the case, you're 100% correct; it's not a 'fix' at all.

  2. This post has been deleted by its author

  3. steviebuk Silver badge

    Fucking idiots

    This is an attempt to stop the likes of grayjay. They had to remove features to get it in the play store so we all just download it off their site to install it.

    But on another note. At work, we used a 3rd party company that refused to pay for a certified play store app so we always had to install it manually with their APK. So their stupid new rule would stop this. Cockends have never worked for normal companies or really, its just google wanting more control and money.

    Cunts.

    1. that one in the corner Silver badge

      Re: Fucking idiots

      > their stupid new rule would stop this

      Their "stupid new rule" being - the one that the article is telling us about, which is the one that *allows* you to install your APK? Or do you mean the *previous* new rule, the one that the new new rule is modifying, which was indeed going to prevent you, but which is no longer going ahead in its original form, so in practice won't prevent you from installing your APK?

      Or, more properly, won't stop your normal company's IT people from installing the APK.

      1. Dan 55 Silver badge

        Re: Fucking idiots

        By waiting a day? I bet the corporate BOFH will love that.

        1. that one in the corner Silver badge

          Re: Fucking idiots

          By waiting a day *once*, done as the first thing after the device arrives oin the IT dept. and goes on soak before it is handed to you.

          Assuming your BOFH takes care to check things are working properly before handing it over to you.

          1. collinsl Silver badge

            Re: Fucking idiots

            Last time I had a work phone it was handed to me brand new in box, and the company had put all of the locks on it in place via the IMEI through the carrier & Microsoft InTune, so the minute I switched it on and did the initial setup it had all the company profiles on it, all of the blocks required, and all of the apps the company required auto-downloaded.

            If there had been a fault with the handset it would have been sent back to the carrier.

    2. FeRDNYC Bronze badge

      Re: Fucking idiots

      I don't even know what grayjay is, so I doubt they're targeting your favorite class of persecuted app (whatever that may be).

      They're targeting scammers and data thieves who trick people into installing malware, I have no problem believing them on that front. Their motivation isn't in question, their approach very much is.

  4. Catkin Silver badge

    What's old is new

    I don't know how many Symbian users can still remember a similar situation where you had to acquire a device specific key of your own to install unsigned software but it was a vicious hassle. It might have been a contributing factor to why we don't use Symbian anymore.

    1. Dan 55 Silver badge

      Re: What's old is new

      There was certainly less malware on Symbian because if the app did what at least half the Play Store apps do it had to be reviewed by a real human. Anyone who really wanted unsigned installation without the hassle used a custom ROM.

  5. mark l 2 Silver badge

    WTF! Imagine this was how Microsoft decided that Windows should work, and if you want to download and exe from the internet, you had wait 24 hours before you can install it.

    1. Andy Mac
      Go

      This, this, this, this and this.

      Commentards like to put the boot into MS, and with good reason, but Google et al are doing things 90’s MS only did in their (wet) dreams.

      1. Anonymous Coward
        Anonymous Coward

        90's MS was a saint compared to modern MS. Just clumsier and with a less efficient lobbying group.

    2. Anonymous Coward
      Anonymous Coward

      No, on a new device, you have to wait 24 hours to be granted the ability to install unverified apps. It's a one-time operation, not for every app.

      1. that one in the corner Silver badge

        Don't go around being accurate and quoting what Google's blog says, you're asking to get downvoted here today.

        Anyway, it isn't (just) a one-off 24-hour wait; you'll be able to opt to have the unverified install ability revoked after 7 days, which means that you'll then have to wait *another* 24 hours! Or you could take the option to retain the ability indefinitely, but then you'd also have to give up the option to *complain* about waiting for 24 hours, which would just take all the fun out of it.

        1. Solviva

          As a 'power' user then you'd enable this in advance (permanently) for the day you think you might need it, and download at your own risk tomorrow onwards.

          As a regular user who uses nothing more than the Play store, when Peter Smith with a funny non-matching accent calls and asks you to go to this 'ere website and install this app to make your banking secure again, then they'll be frustrated that they can't get their instant kill anymore. However sadly they often prey on these people as if they've got them to the website already and trying to download then they've passed the 'easily manipulated' test and they just keep them on the hook for the next day when they *can* now install random app having been told how to 'fix' the issue with your phone.

          1. Roland6 Silver badge

            But then you now have to remember the new application permission:

            “ Users will have the option to enable such apps for seven days or indefinitely.”

            Not clear whether this option is per app or preset for all unsigned app’s…

    3. Ex-PFY

      MS can f*@! right off

      Try running llmfit in Windows Sandbox and you'll realise true pain and stupidity [undisableable device guard] from Microsoft. A power user can't even run it / bypass device guard.

      Some clever registry and power shell / policy stuff can get you through if you're truly sadistic enough to pursue it.

    4. Roland6 Silver badge

      It’s Windows, you would simply rename the file to something like xyz.jpg and double click on it, because it’s not a .exe Windows “downloaded .exe” protections won’t kick in. However, in attempting to open it as a .jpg, Windows (or the default MS app) will discover the file’s binary format is .exe and so execute it…

  6. Fruit and Nutcase Silver badge
    Alert

    Hurrah!

    I can now trust my apps and myself! Or can I? Or should I?

  7. Blackjack Silver badge

    I have been never as motivated to install an Android alternative as I am right now, thanks Google, you turned Android from FOSS into a closed System.

    1. Sorry that handle is already taken. Silver badge

      This is more motivating than the blanket ban they'd originally proposed?

      1. that one in the corner Silver badge

        blackjack>> I have been never as motivated to install an Android alternative as I am right now

        Sorry...> This is more motivating than the blanket ban they'd originally proposed?

        Of course it is! Now they are just toying with us Android users: when the time comes (*IF* it comes, if th3 deadline passes and they stick with it) now there is a horrid decision to make: do I enable this ability? If I do, should I enable it just for one week (and regain the bit of protection against scammers) or do I enable indefinitely? Aaargh, questions, questions, I can't cope, will have to take the easy route out and install an Android alternative!!!! Now, which alternative has a supported build for my phone model? None? Never mind, just rebuild from source, that is still easier than this "wait for 24 hours" insanity!

        /s, btw

        1. ThatOne Silver badge

          > If I do, should I enable it just for one week (and regain the bit of protection against scammers) or do I enable indefinitely?

          Come on, the only two cases where this applies are either you're senile and don't trust in the continuity of your judgment, or you install something on some elderly relative's phone.

          In other words, people who will use this feature usually should be savvy enough to not fall for "very urgent" support scams. Meaning they can leave it on forever.

    2. Eric 9001
      Boffin

      Android was never free software - it was always proprietary software.

      The only partially free version of Android that exists is Replicant.

      1. Anonymous Coward
        Anonymous Coward

        And AOSP.

        see android-x86 and bliss-os

        1. Eric 9001
          Boffin

          "AOSP" is useless, as it does not include the software required to get a *single* Android device working (distributions like LineageOS add the missing software, extracted from fully proprietary distributions, which of course is proprietary).

          I figure you can't get AMD64 Android to work without a proprietary ARM translation library.

          All versions of BlissOS are proprietary software (I don't understand why you would write "might" when right below the massive amount of proprietary software is listed); https://blissos.org/licensing.html

          "Q: Does Bliss OS include proprietary software?

          A: Yes. Our GMS/Gapps releases include proprietary software, and are intended for individuals only, while our FOSS and Vanilla builds might include some proprietary parts as well.

          Proprietary redistributables in all Bliss OS public builds:

          - linux-firmware blobs

          - Proprietary linux drivers (broadcom-wl for example)

          - some media codecs (for decoding H.264/HEVC)

          - ARM Translation Library (Houdini or libndk-translation)

          - Widevine L3

          Extra proprietary redistributables in BlissOS Gapps builds include Google Play Services & Google Play Store."

          broadcom-wl doesn't even try to cover up that it's a proprietary Linux driver - don't forget that if you *ever* distribute a proprietary Linux driver, your license under the GPLv2 is automatically terminated, permanently - therefore BlissOS is illegal, as it's distributing Linux without a license.

  8. jfm

    Do it once…

    It's a one-off process. I for one don't intend to wait 24 hours the first time I want to install something. This workaround is going to be released weeks before the restrictions are enforced, so I shall plan ahead,, set the option, wait 24 hours, and confirm it knowing that when I do install software it'll Just Work.

    Not sure why the comments are such a muppet show

    1. MrReynolds2U

      Re: Do it once…

      Imagine you bought a new phone and wanted to install something not on Play store.

      That'd be a little annoying, right?

      1. that one in the corner Silver badge

        Re: Do it once…

        A *little* annoying. Not *terribly* annoying, really. And after that day's wait, you're gannin' along at full whack agin.

      2. Anonymous Coward
        Anonymous Coward

        Re: Do it once…

        What? Are you saying you're not spending 24-48 hours after buying a new phone setting it up just the way you like it? You know, deleting/hiding all the junk, rooting (if possible and your banking software doesn't cry out), transfering via USB all the old aplications you've kept because updates fucked them up....

        1. Roland6 Silver badge

          Re: Do it once…

          I suspect for a new/replacement phone a user will have to go through the 24 hour wait aggro, just so they can reinstall all the app’s installed on the previous phone…

          Given phones have a habit of dying just when you don’t need it; this will be very annoying…

    2. phuzz Silver badge
      Unhappy

      Re: Do it once…

      It'll still be a paint in the arse, assuming this setting is per-device, every time you get a new phone (or whatever Android device), you'll have to wait a day before you can install all of your apps.

      1. segfault188
        Devil

        Re: Do it once…

        It'll still be a paint in the arse

        If you have paint in your arse, you have bigger problems to deal with.

    3. Blackjack Silver badge

      Re: Do it once…

      Because this depends on Google Play Services meaning Google can disable it any time with a simple update.

  9. Jamie Jones Silver badge

    Look at it from Google's point of view

    Like most of you, I hate the fact android has gotten more closed over the years. You have to go through so many hoops just to have root on your own device.

    Without root, you can't easily debug/kill an out of control process, you can't rsync everything to your own backup server, you can't tweak certain settings, and so on. And system monitoring apps are less useful due to the extra restrictions.

    I HATE IT. I used to do far more tinkering with my 5.0 devices than with my current ones, and they were the better for it.

    Of course, it's not for everyone, and no-one should need to be a tech geek to operate one.

    HOWEVER, I do have to feel some sympathy for Google. Every time they restrict something, malware updates its instructions accordingly. I've even heard that when some options had to be enabled via ADB, certain malware promising free sports gave a step by step guide to the "consumer" on how to do it. Despite many of the warning along the way.

    Remember the old couple scammed out of money, featured on BBC scambusters or something. The scammer said they were from the bank. etc. and told them they needed to transfer the money. Then they told them that when they called the bank, the bank would need a reasonable reason to transfer the money, so they needed to make up it was for their son or something. The scammer coached them on how to lie to the bank, because he reasoned that's the only way to get your money out because of "government mandated rules". They lied to the bank, ended up losing their savings, and then moaned about the bank about it.

    Now, I know a certain person here will reply "You're just making that up", but unfortunately, unlike the last time he accused me of that, I can't in this case follow up with a link to the relevant video.

    Back to android - people will follow instructions for free videos, free sport, free porn etc. and for even more innocent goals, and they will switch off all reasoning skills because the person on the end of the phone sounded nice.

    And then the newspapers have articles about "Android is insecure, this is what happened to some people" - Now, if it's a legitimate issue, then Google deserves to be called out. But if you delve deeper, most of them are due to the user doing something stupid.

    Can you imagine a newspaper report "LOCAL BANK GIVES AWAY CUSTOMERS MONEY WITHOUT SIGNATURE", and reading on you find that the person left their card in a public place with a big sign saying "My PIN is abcd"?

    It boils down to the same sort of thing, but people are seemingly allowed to get away with it when it comes to their phone.

    I grew up in a non-techie household - all my friends and past girlfriends have been non-techie. I'm fully aware of how computerised things can get confusing, and am the first to moan about stupid UI's on devices - I constantly deride "designers" who are so absorbed in geekism, they can't seem to use any common sense in their design.

    But that's a different issue. In this case there is unfortunately a definite need for some people to be "protected from themselves" - and for as long as google/etc. are blamed when things go wrong, they are going to be compelled to drop functionality completely.

    This proposed method sounds ridiculous - but all other "jumping through hoops" methods have failed, and as we speak, no doubt some malware writer is thinking how to get people to jump through these hoops whilst convincing the punter that they are legitimate.

    1. Jamie Jones Silver badge

      Re: Look at it from Google's point of view

      Ok, I found the episode: https://www.bbc.co.uk/programmes/p0gd4m3z

      It's very similar to this case: https://www.bbc.co.uk/news/uk-england-leeds-67208755

      Now, if this was instead an android phone, newspaper headlines would be saying "INSECURE ANDROID PHONE STEALS COUPLES LIFE SAVINGS"

      1. Roland6 Silver badge

        Re: Look at it from Google's point of view

        > "INSECURE ANDROID PHONE STEALS COUPLES LIFE SAVINGS"

        With AI and agentic AI such as OpenClaw, I suspect it won’t be long before we see such a headline.

  10. bolangi

    "break the cycle of coercion"

    There is an unintended irony here.

  11. Anonymous Coward
    Anonymous Coward

    "Google gives Android users a way to install unverified apps..."

    "... if they prove they really, really want to."

    You: I'll tell you what I want, what I really, really want

    Google: So tell us what you want, what you really, really want

    You: I'll tell you what I want, what I really, really want

    Google: So tell us what you want, what you really, really want

    You: I wanna, (ha) I wanna, (ha) I wanna, (ha) I wanna, (ha), I wanna really, really, really wanna install this unverified app on my phone

    Google: We're still not convinced that you want it enough. Click here to try another way to tell us what you want, what you really really want.

    1. Anonymous Coward
      Anonymous Coward

      Re: "Google gives Android users a way to install unverified apps..."

      So glad the steps involved are easier than it was to avoid that song, back when it was relevant.

    2. Alumoi Silver badge

      Re: "Google gives Android users a way to install unverified apps..."

      Damn it, man! You've done a bad, bad thing, I was ready for Rick.

      1. Anonymous Coward
        Anonymous Coward

        Re: "Google gives Android users a way to install unverified apps..."

        You didn't like the Space Curls? Who doesn't like the Space Curls?

  12. IamAProton Bronze badge

    Certified android devices

    Certified android devices = every device sold with google services installed? or just a subset of those?

    I do not plan to use devices with google bloatware anymore, but for relatives cheap models from TCL for example are ok-ish, much cleaner than samsungs for example

    This stupid process reminds me the bootloader unlock process for xiaomi devices: device can't be too new, need a windows software to request the unlock and then the device to be unlocked need to connect wth its own data (4g, not over wifi)

  13. Dinanziame Silver badge
    Meh

    I was happy with the existing solution. You want to sideload apps, you need to go in settings and explicitly allow yourself to do it. Takes five minutes. But on one hand, people have been complaining that this is way too restrictive and makes it too hard for independent developers who do not want to pay the Google tax (was it really?). And on the other hand, I assume, Google is justifying the new rules by claiming it was not restrictive enough and that some people somewhere were still getting scammed.

    I'm not sure how many people's life savings are going to be rescued from scammers by this change, and I wonder if it is worth the millions of people who will now have to wait even one day.

  14. Anonymous Coward
    Anonymous Coward

    Insanity

    There's a lot of dumbasses in these comments that read like Reddit users having a shit fit. Rooting doesn't have a heyday anymore. The people considered "power users" are like old politicians who refuse to either retire or die. I could give fuck-all to those who think that spending over $1k on a phone means they have the right to perpetrate malware from their phone to others phones of friends and families who are NOT savvy at all, and stand to suffer multiple data and financial injuries. Why? Because Android is like Windows. Bad actors target the OS because it's so widely pervasive around the entire fucking world. Therefore those people in these comments comparing what Google is doing to M$ are a particularly idiotic breed of dumbassery.

    To all those, I think you can all fuck off royally.

  15. FrogsAndChips Silver badge

    Does it work the other way round?

    If I tell Google I really really want it and really really know what I'm doing, can I be allowed to uninstall all the crapware that came preloaded on my phone? Happy to wait 1 day or even 2 if they insist.

    1. Mike VandeVelde Bronze badge
      Pint

      Re: Does it work the other way round?

      I would do facial recognition plus me-doing-cartwheels recognition for proof of life every day for a week or more for that option! I would figure out how to do cartwheels! Regrettably I have just one upvote to give. Cheers!

  16. Baucent
    Facepalm

    "Users must first enable developer mode in system settings."

    That alone would stump most gormless users as most would have the attention span to press the particular setting the requisite number of times, even if they understood the instructions in the first place.

    Although I would agree that Alphabet in the first instance is just following the "do evil" part of its corporate mission statement.

  17. cd Silver badge

    The trick is to buy a way-outdated phone and never let it update. The worst malware is the updates. Which are never going to fix stupid-user moving targets.

    "Security" plus more aggravating Skinner-box interface changes riding along like bedbugs.

    Turn Play off completely. Note how after v10 they included location in Play so it's a Pyhhric victory.

  18. skalamanga

    The play store is the very last resort for apps I use. Its become nothing but an obnoxious slop delivery platform crammed full of complete trash.

    I dont understand how this is not an antitrust case yet,

  19. karlkarl

    No. This is just a form of DRM. For example, you can't do it offline, you must connect to Google's servers.

    Offline from inception is not possible. This is just landfill-ware.

  20. Missing Semicolon Silver badge
    FAIL

    A visible switch

    Wait for your banking app to stop working because you enabled sideloading.

  21. timrosu

    Xiaomi inspired them

    If you wanted to unlock bootloader of xiaomi phones from the last 5 years, you needed to wait 15 days! And if you took sim card out for a minute, the countdown would reset.

    For earlier phones you had to wait 7 days.

    TLDR: it's very annoying and almost makes you give up trying to give phone a second life with something like lineage or postmarket os.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon