Google is right to make sideloading harder on Android
by Rajesh Pandey · Android PoliceStarting this September, Google will begin rolling out one of the biggest changes to Android's sideloading process since its inception.
At first glance, the new rules may seem too restrictive, preventing power users from easily sideloading their favorite apps.
However, the changes are a step in the right direction because they will make Android safer for everyone.
Related
I ditched Google Photos for Immich, but Google made the exit surprisingly painful
Getting the photos out of Google was harder than leaving it
Posts By Oluwaniyi Raji
Scammers have exploited Android's openness for years
Open Android comes with risks
Sideloading has long been one of Android's biggest strengths. If an app is not available on the Google Play Store, you can sideload it on your phone in just a few taps.
However, scammers have increasingly exploited this freedom, using urgent calls and fake banking alerts to trap unsuspecting users.
Over the years, Google has added several security features to make the sideloading process safer. It has also introduced additional friction to deter regular users from installing potentially harmful apps.
These warnings are no match for a determined scammer, though. The scammer can remain on the phone, creating a false sense of urgency and telling the victim exactly which buttons to press.
If someone believes that their bank account is being emptied or that the police are about to arrest them, another warning dialog will not necessarily stop them.
My father uses an Android phone, and somehow, he occasionally ends up sideloading shady news apps. He is not technically savvy enough to enable installations through Chrome or another app on his own.
It remains a mystery to me how he can get past Android's existing safeguards without understanding what he is doing.
And if my father can, so can other unsuspecting users, especially if they are guided step by step by a scammer.
It's not only my father. Several of my friends' parents have fallen victim to sophisticated banking scams after scammers persuaded them to sideload malicious apps.
Android displayed its warnings, but the scammers convinced them to ignore those warnings.
With AI making app development easier than ever, such sophisticated scams will only become more common. And that's a real concern, as it stands to affect millions of users worldwide.
To address this, Google will soon roll out a new sideloading process for Android. It will require developers to verify their identity and register their apps.
Power users — like you and me — can still sideload apps from unverified developers, but it will require completing an "advanced flow."
This will involve enabling an option from the hidden Developer Options menu and then waiting 24 hours.
Google will make the advanced flow available in August, and enforcement will begin on September 30. Initially, the changes will be limited to Brazil, Indonesia, Singapore, and Thailand before expanding to more markets in 2027.
During the initial phase, the requirements will apply only to selected app stores, so direct sideloading from other sources will not immediately change.
The friction is the most important security feature
A delay can stop a scam
Google's new sideloading process adds several steps and friction. And that's a good thing.
It will make it harder for scammers to trap unsuspecting users by creating a false sense of urgency. They want their victims to act before they realize what they are doing.
A warning that can be dismissed immediately or a toggle that can be easily enabled is not enough to prevent a determined scammer.
However, a mandatory advanced flow that includes restarting the phone and waiting 24 hours will disrupt the scammer's plan.
It gives the user enough time to talk to someone they trust, all without the scammer being on the phone and creating a fake sense of urgency.
Google's strategy of requiring developers to verify their identity and register their apps is equally important.
Today, a scammer can create an app and distribute it under any identity. When the app is flagged as malicious, they can return with a new package name.
And thanks to AI, they can do this at scale with ease.
Developer verification will make it harder for malicious actors to create and distribute malicious apps anonymously.
It won't make every registered app safe or trustworthy, but it will make this cycle more difficult and expensive.
Ultimately, each registered app will be tied to a verified person or organization to hold accountable for any malicious app, instead of an anonymous developer account.
Android will remain open
There are a lot of concerns about Google's new sideloading process for Android.
As a power user, I know this change will annoy me and make sideloading more complicated. But this is also a change that the Android ecosystem needs.
Google is still giving power users the freedom to sideload apps from outside the Play Store. There's just an advanced flow and a 24-hour waiting period.
When enabled, the advanced flow can remain active indefinitely, while ADB installations remain unchanged, so experienced users will still have practical ways to install unverified apps.
If that change benefits the entire Android ecosystem and helps prevent unsuspecting users from falling victim to scams, it's worth it.