- Joined
- Jun 9, 2003
- Messages
- 7,064
For those who may not be aware, Google has been taking an increasingly proprietary approach to Android bit by bit over the past several years. The divergence of Pixel devices and their proprietary applications from the AOSP variants is a good place to start, but other factors including an increasingly stringent "SafetyNet" checksums making it difficult to run custom ROMs or even just individual apps with a (knowingly) unlocked bootloader, among other issues over recent years. However, there is a big potential change on the horizon that would essentially reduce Android to a near-Apple level of lockdown and its detailed here - https://keepandroidopen.org/ .
Essentially, Google plans to mandate that anyone who wants to develop an application that works on a standard Android installation (as opposed to a specifically bypassed dev-mode option) would have to register with Google, including providing their real life ID. If this goes through, it will no longer be possible for some Android developers, notably the Free and Open Source community such as F-Droid, to simply develop their APKs independently and have them work on standard Android installs. Instead, as of September 2026 Android will claim these applications have unverified keys, and refuse to run unless the user goes through a process that is several times more involved than even sideloading/approving install from non-Play Store applications, instantly causing their OS to fail SafetyNet checks and thus apps - like those for Banking or other secure functions - to refuse to work. This will have the effect of normalizing removing what were previously normal security safeguards and thus open the attack surface to actual malware.
Though the aforementioned technical vulnerabilities are a concern they are dwarfed by the astounding privacy, usability, and ethical implications that will come from Android blocking any app that isn't tied to a "properly verified developer" using Google approved accounts and keys. Once again faux "security" justifications arebeing used as an excuse to quash the openness that made platform desirable for so many years, in favor of Google being practically the sole arbiter of who can develop and what apps are allowed on Android devices. If this comes to fruition its likely that state level actors like China capable of forking and running an independent 'hard fork' version of Android will be an option to sidestep the issue, but that's its own conversation with its own considerable downsides. Some have proposed that Android device manufacturers will intercede even out of their own self interest but this is not likely to benefit users or conceptual openness - we can see how just this month Samsung is apparently removing access to the bootloader features, sideloading updates, ADB and other features from its latest Galaxy devices - https://archive.is/2nvO0 .
There are still things that we can do to hopefully pressure Google to reverse course. The outcry at the start of the announcement is why Google bothered to suggest there may be an "advanced flow" to allow people to "accept the risks of unverified software", however there have not been further details and the description of the program still is unchanged. The KeepAndroidOpen page, as well as a few to which it links, detail things that developers and users can do to voice their objection to such a policy and all the hypothetical harms that could come from its implementation. Banners, reminiscent of those used for past successful campaigns by the EFF against SOPA/PIPA are available for site owners interested and are already present on F-Droid. However, the biggest thing is simply to spread awareness of Google's plans to those who develop on Android, FOSS independently developed Android apps, Fdroid / NeoStore , Obtanium and other manners to install apps from repositories outside Google Play, Custom ROM users, and more in the hopes they'll make their voices heard.
Essentially, Google plans to mandate that anyone who wants to develop an application that works on a standard Android installation (as opposed to a specifically bypassed dev-mode option) would have to register with Google, including providing their real life ID. If this goes through, it will no longer be possible for some Android developers, notably the Free and Open Source community such as F-Droid, to simply develop their APKs independently and have them work on standard Android installs. Instead, as of September 2026 Android will claim these applications have unverified keys, and refuse to run unless the user goes through a process that is several times more involved than even sideloading/approving install from non-Play Store applications, instantly causing their OS to fail SafetyNet checks and thus apps - like those for Banking or other secure functions - to refuse to work. This will have the effect of normalizing removing what were previously normal security safeguards and thus open the attack surface to actual malware.
Though the aforementioned technical vulnerabilities are a concern they are dwarfed by the astounding privacy, usability, and ethical implications that will come from Android blocking any app that isn't tied to a "properly verified developer" using Google approved accounts and keys. Once again faux "security" justifications arebeing used as an excuse to quash the openness that made platform desirable for so many years, in favor of Google being practically the sole arbiter of who can develop and what apps are allowed on Android devices. If this comes to fruition its likely that state level actors like China capable of forking and running an independent 'hard fork' version of Android will be an option to sidestep the issue, but that's its own conversation with its own considerable downsides. Some have proposed that Android device manufacturers will intercede even out of their own self interest but this is not likely to benefit users or conceptual openness - we can see how just this month Samsung is apparently removing access to the bootloader features, sideloading updates, ADB and other features from its latest Galaxy devices - https://archive.is/2nvO0 .
There are still things that we can do to hopefully pressure Google to reverse course. The outcry at the start of the announcement is why Google bothered to suggest there may be an "advanced flow" to allow people to "accept the risks of unverified software", however there have not been further details and the description of the program still is unchanged. The KeepAndroidOpen page, as well as a few to which it links, detail things that developers and users can do to voice their objection to such a policy and all the hypothetical harms that could come from its implementation. Banners, reminiscent of those used for past successful campaigns by the EFF against SOPA/PIPA are available for site owners interested and are already present on F-Droid. However, the biggest thing is simply to spread awareness of Google's plans to those who develop on Android, FOSS independently developed Android apps, Fdroid / NeoStore , Obtanium and other manners to install apps from repositories outside Google Play, Custom ROM users, and more in the hopes they'll make their voices heard.