Apps can now block sideloading easier and force downloads through Google Play
androidauthority.com
androidauthority.com
Things will get even worse because Google is working on the AVF framework which includes so called "protected VMs" - of course they're meant to be protected from you, the user. Their "security" (where you're the "attacker") is based on the TEE but also a so called "protected vm firmware". In their design document they explicitly say that these protected VMs can provide "security" only with locked bootloader.. you probably know what that means..
So, no, I will not stop it.
OP is highlighting an example of software being used to redefine what ownership means - from you pay, it is yours to do as you wish to you pay and it is, highly conditionally, yours to use within an ever changing envelope defined by an evolving terms of service agreement and ecosystem with progressively more anti-features that are not clearly communicated at any stage of the purchasing process and rarely seem to benefit the user aside from 'security'.
Feels like the type of changes outlined in the post are the very definition of "x isn't really yours".
As others have pointed out this is an extremely sneaky way to do this. It isn't Google doing it just enabling the ecosystem to do it, with the net effect being the same.
Unfortunate.
https://locusmag.com/2017/09/cory-doctorow-demon-haunted-wor...
However, Google is developing a new obfuscation method called pairip (officially automatic integrity protection) that makes it really hard to patch apps by moving some java code to an encrypted vm riddled with checksums and anti debugging checks.. Fortunately "really hard" (and yes, the vm is crazy..) doesn't mean impossible.
But for server side services, this will unfortunately serve its purpose.
More discussion: https://news.ycombinator.com/item?id=41515588
Privacy conscious folks will just... not use those apps. With any luck app devs will notice that apps with this flag get installed less and stop setting it.
For apps that don't, Google is currently developing a new obfuscation VM called pairip (that libpairipcore.so). This extracts some java code into a VM, so patching an app is not simply a matter of patching smali code - that VM employs many checksums on its memory.