Given that Google both owns Android/Google Play Store and YouTube: what do you think they would do with the developer information of someone who makes an app that skirts their ad-model for YouTube?
The "security" wording is the usual corpospeak - you can always trust "security" to mean "the security of our business model, of course, why are you asking?"
Things like Newpipe seems much more of a target, especially if you want to take legal action. More so than stopping users, this gives Google fat more leverage about what Apps can exist. If they ever want to stop Newpipe a serious lawsuit against whoever signed the APK seems like an effective way to shut down the whole project. Certainly more effective then a constant battle between constraining them and them finding ways to circumvent the constraints.
The fact that there was a temporary workaround didn't change the endgame.
It's just there to boil the frog more slowly and keep you from hopping out of the pot.
It's the same game plan Microsoft used to force users to use an online Microsoft account to log onto their local computer.
Temporary workarounds are not the same thing as publicly abandoning the policy.
“In 2024, the App Store made $103.4 billion to Google Play’s $46.7 billion.”
Android used to be weak against iPhone and needed to cooperate, so they allowed more apps in to grow the userbase. Now that they're big and strong, they don't need allies, so they start kicking out everyone who isn't making them money.
Every "enshittified" service does it - Imgur, Reddit, whatever. Everyone selling $10 bills for $9 does it. Microsoft did it. They took a step backwards by buying GitHub, when they realized they were totally blowing it on cloud. But now that they have users stuck on GitHub and VS Code, they're defecting again.
It means that Android is no longer suitable for my own private dev projects.
There's only so much you can do as a maintainer of a custom OS like Graphene before its too hard to maintain. I don't think there's enough coming in by way of donations to play catch-up.
Need legislation quick. But I suspect the EU doesn't want side loading either in the grand scheme of surveillance.
Thats the Banks fault then. I complained to mine and they removed the safetynet check / let you skip it.
Also, with this move, Google has made it very clear that they don't want people to have any real control over their machines -- so I'm not inclined to think that using adb to work around the problem will always be possible.
It's fine, though. My hobby projects will continue into the future, just probably without using Android.
https://www.androidpolice.com/use-wireless-adb-android-phone...
Do that + identity check = bans for virus makers are not easily evaded, regardless of where they live.
Googles/Apples argument would have been much stronger if their stores managed to not allow scams/malware/bad apps to their store but this is not the case. They want to have the full control without having the full responsibility. It's just powergrab.
Scam apps are rife in the iOS App Store. But what they can’t do easily install viruses that affect anything out of its sandbox, keyloggers, etc
I agree let's have sandboxed app instalations on platforms. Flatpak is already going this way. But it looks like big players Microsoft,Apple and Google are gatekeeping app sandboxing behind their stores instead of allowing people/devs to use sandboxing directly.
ChromeOS/ChromiumOS uses heavy sandboxing. Android currently uses sandboxing transparently, despite plans to iOS-ify the platform. Hell, Windows uses app isolation sandboxing these days.
All four consumer platforms let you run the software you want to and they provide sandboxing at the same time. They also let you configure sandboxes, too.
As for open source, consumer products like the Steam Deck use sandboxes, popular game launchers like Lutris use sandboxes, Firefox transparently uses sandboxing by default, as does Chromium/Chrome, anything installed automatically with Flatpak or Snap are sandboxed by default and AppArmor/SELinux works in the background automatically on most distros and are activated by default.
Saying open source projects like the Steam Deck, Firefox, Chromium, ChromiumOS and Android suck for consumers is a weird opinion, but you're free to have it.
And Android’s sandboxing is so bad, you always hear about the malware of the week especially outside of the Play Store.
ChromeOS also isn’t open source. And expecting end users to “configure sandboxes” you might as well not have one.
Firefox is s browser, and didn’t they tighten what third party extensions can run?
Android - or at least the version that most people use - is not “open source” by any stretch of the imagination.
Apps can and do ship with sandboxing rules that will be applied at runtime.
> ChromeOS also isn’t open source. And expecting end users to “configure sandboxes” you might as well not have one.
I listed ChromeOS as one of four consumer operating systems used by billions of people that uses sandboxing, not as an open source OS.
Notice how I did use ChromiumOS when referring to open source software, along with Chromium.
> And expecting end users to “configure sandboxes” you might as well not have one.
Who said anything about expecting users to do that? I just mentioned that you could configure them if you wanted to, like I said in my GP.
Again, my point is that these are consumer products that billions of people use everyday that use sandboxing by default, yet somehow not even having to think about sandboxing is too onerous for end users?
> Firefox is s browser, and didn’t they tighten what third party extensions can run?
Yes, it is open source consumer software that does sandboxing by default without the user having to think about it.
> Android - or at least the version that most people use - is not “open source” by any stretch of the imagination.
AOSP is very much open source
Hardly any apps outside of the Mac App Store voluntarily opt in for sandboxing
> I listed ChromeOS as one of four consumer operating systems used by billions of people that uses sandboxing, not as an open source OS.
And also locked down…
> AOSP is very much open source
Calling AOSP open source when it’s almost useless to most consumers without the proprietary bits from Google is just as disingenuous as calling iOS open source because Darwin is open source.
If users without that level of technical skill are pressured into making those decisions, that's because they're being mistreated.
Is that really your answer? To make the phone ecosystem as fraught as Windows PCs for the average user? How is they worked out for PC users since the 80s?
Just to be clear, are you claiming that we would be better off if PC hardware and OS vendors had the level of control that smartphone vendors do today?
You really can’t trust developers to do the right thing - even major developers like Zoom (the secret web server) , Facebook (the VPN that trashed usage actoss apps on iOS) and Google (convincing consumers to install corporate certificates to track usages on iOS).
Even more to the point, you read about some app installed outside of the Google Play store that’s malware - including the official side loaded version of FortNite…
https://blog.checkpoint.com/research/fortnite-vulnerability-...
You really can’t trust developers to do the right thing
Indeed not, and that includes OS developers. Imagine if Microsoft had been able to block web browsers other than IE in the name of "security".
In the modern day, I actually think this mostly works? Are you aware of instances where normies installed Windows malware because they purposefully disabled Windows Defender?
Everyone always talks about the "Dancing Bunnies Problem" but I'm not convinced it's actually a thing.
On the Mac, people installed Zoom and it installed a backdoor web server.
0 - https://discuss.grapheneos.org/d/16046-google-keyboard-w-net... 1 - https://discuss.privacyguides.net/t/sandboxed-google-play-pr...
I think they’re just going to track down a random person in a random country who put their name down in exchange for a modest sum of money. That’s if there’s even a real person at the other end. Do you really think that malware creators will stumble on this?
This has to be about controlling apps that are inconvenient to Google. Those that are used to bypass Google’s control and hits their ad revenue or data collection efforts.
Developers, and power users often pre-date these kinds of smartphones.