Opening my weather app this morning I was greeted by this warning:

Google has announced that, starting in 2026/2027, all apps on certified Android devices will require the developer to submit personal identity details directly to Google. Since the developers of this app do not agree to this requirement, this app will no longer work on certified Android devices after that time.

It’s the first time I hear about this, seems to be about:

Tech crunch article from august, “google will require developer verification for android apps outside the play store”

Cirrus app: Github

Was this a big thing I somehow missed? I hope more devs will follow suit.

  • FriendOfDeSoto@startrek.website
    link
    fedilink
    English
    arrow-up
    153
    ·
    1 month ago

    Yes, you must have missed it. And so it begins.

    Google is moving to make Android less open source. I’m not sure more devs following suit is going be good for them or their users. The G doesn’t give an F.

    What we need is an OS fork that gets maintained. If not that, some other workaround that fools the Google servers. Because you can bet money that nobody made from flesh and blood is going to look at this inside Google.

    Maybe devs can band together and form Middle Finger Corp. and designate one willing person as their contact to serve as registered dev for a gazillion apps. Follow the letter of the law, not the misguided spirit of it, in a manner of speaking.

    If you are sitting on a mobile OS and you were afraid to fail like Windows, maybe now is the time to give it a go?

  • Ulrich@feddit.org
    link
    fedilink
    English
    arrow-up
    120
    arrow-down
    2
    ·
    1 month ago

    They’re not “pulling” the app from anywhere, it’s just simply not going to work on “certified devices”. This is the end of Android as we know. It’s been a good run.

        • Akip@discuss.tchncs.deOP
          link
          fedilink
          arrow-up
          27
          ·
          1 month ago

          Done! for the curious, original title, “Cirrus App dev pulling app from certified android devices in '26/'27” new, “Cirrus app dev informing the app will stop working on certified android devices in '26/'27”

        • freedickpics@lemmy.ml
          link
          fedilink
          arrow-up
          2
          ·
          1 month ago

          It’s also absurdly lacking in features compared to Android/iOS (never mind app support) and the dev team is so small they can barely maintain existing device support. VoLTE is still unsupported in the majority of devices. The OS doesn’t even have basic security features like drive encryption

          I like UBPorts a lot but I think the alternative/FOSS smartphone market is too fragmented between it and SailfishOS/PostMarketOS that none of them will emerge with enough adoption to be real competitors to the iOS/Android duopoly. Didn’t mean to be overly negative. Just my two cents

    • Rustan@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      9
      arrow-down
      1
      ·
      1 month ago

      Only works for those of us who own a pixel or bought one for the reason but this won’t effect Graphene users

      • tiramichu@sh.itjust.works
        link
        fedilink
        arrow-up
        23
        ·
        1 month ago

        Except it will, because developers aren’t going to bother maintaining an app where the install base is just pixel users with Graphene

        • pogmommy@lemmy.ml
          link
          fedilink
          English
          arrow-up
          12
          ·
          1 month ago

          Yep. We’ll be fine for a while but Google’s seriously axing the platform for foss projects and security-minded users. In no more than half a decade I anticipate Android’s open-source development scene will begin looking very similar to Apple’s.

        • Auli@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          1 month ago

          Why if it isn’t on the app store the install base is already insanely small. People who sideload are not the majority.

      • Ulrich@feddit.org
        link
        fedilink
        English
        arrow-up
        11
        arrow-down
        1
        ·
        1 month ago

        It’s going to affect 100% of Android users because no one is going to develop apps just for the 10 people using uncertified devices.

      • vodka@feddit.org
        link
        fedilink
        arrow-up
        15
        arrow-down
        2
        ·
        1 month ago

        Nope, from how Google puts it, play services will block any and all apps without a valid signature from working at all on play certified devices.

        You’ll be able to install them via adb probably, but when you run them play services will stop you.

        Play services already prevents certain apps from starting until you say a yes/no on a popup, so the framework for this is already in place.

        • Mubelotix@jlai.lu
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          1 month ago

          This is completely wrong. I asked this exact question to google in their poll and I got an answer from them saying it would always work with adb. It’s for devs so you can run those apps of course. This means F-Droid can implement a Shizuku backend to install apps and the UX will be even better since it will bypass popups. However, initial setup will be far more complicated

      • Ulrich@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        1 month ago

        You can but that’s REALLY not a solution. How many times/day to plan on plugging in your phone and running a couple dozen commands to update your apps?

    • Akip@discuss.tchncs.deOP
      link
      fedilink
      arrow-up
      16
      ·
      1 month ago

      Thank you for these links they are fantastic! I was aware of the procedural lock in via play integrity services and also the lockdown on side loading so that didn’t get past me, but I wasn’t aware google also wants to alienate developers now by requiring ID. It seems to me google want to now fully commercialize the platform, transforming it into the ad infested network that web2+3.0 already became. I think their plan, by alienating non commercial devs, is that all apps will run on their ad models and non without them will be left.

  • Babalugats@feddit.uk
    link
    fedilink
    arrow-up
    58
    ·
    1 month ago

    And so it continues… Google trying to shoehorn themselves into a position of authority of the internet. Imagine they get as much sway as the banks now have? Private entities controlling the masses for massive profits. Fuck off Google.

    • Akip@discuss.tchncs.deOP
      link
      fedilink
      arrow-up
      32
      ·
      1 month ago

      First of all thank you for providing a foss app!

      I think it’s a big difference if the platform tolerates you or actively wants to stop you from doing it. You got my fullest sympathy.

      • mat@linux.community
        link
        fedilink
        English
        arrow-up
        16
        ·
        1 month ago

        Thank you so much for the kind words! It’s indeed a bad time to be an app delevoper. At least the framework I use is portable-ish, so the work won’t be fully lost.

  • Ugurcan@lemmy.world
    link
    fedilink
    arrow-up
    46
    ·
    1 month ago

    Wording of the message implies it’s possible to have uncertified version of Android… Such a thing possible?

  • fodor@lemmy.zip
    link
    fedilink
    arrow-up
    40
    arrow-down
    1
    ·
    1 month ago

    Yet another possible antitrust lawsuit series. Some day maybe a judge will do something to help the consumers.

    • Ulrich@feddit.org
      link
      fedilink
      English
      arrow-up
      42
      arrow-down
      2
      ·
      1 month ago

      Google just came out of the biggest antitrust suit since 1998 completely unscathed so you can expect this sort of anticompetitive measures to continue.

      • birdwing@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        15
        ·
        edit-2
        1 month ago

        Aaand the reason’s called ✨c o r r u p t i o n ✨

        Whenever a politician comes from a big company or goes to one after retiring from politics, that’s when you know they’ve been bribed.

        • Ulrich@feddit.org
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          1 month ago

          I mean when the entire tech industry has front row seats at your inauguration, that’s a pretty good indicator as well.

    • arthur@lemmy.zip
      link
      fedilink
      English
      arrow-up
      42
      ·
      1 month ago

      Even apps installed outside the Play Store will need to have a “verified developer”, and this change will affect any devices that use Google Play Services, so it will be a problem even to old devices.

      • Da Oeuf@slrpnk.net
        link
        fedilink
        arrow-up
        3
        ·
        1 month ago

        I don’t personally have Google Play Services installed but I can see how devastating this could be to open source on Android.

    • muhyb@programming.dev
      link
      fedilink
      arrow-up
      28
      ·
      1 month ago

      If you don’t have Google Play Services installed, then you’re not affected. Of course, how many custom ROMs will live to that day is unknown.

      • mnemonicmonkeys@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        8
        ·
        edit-2
        1 month ago

        The Mihon dev team has already announced that they’re going to get authorized and continue their work.

        It’s… an interesting choice given what they’re working on, but they also took steps to stay legal

      • KSP Atlas@sopuli.xyz
        link
        fedilink
        arrow-up
        10
        ·
        1 month ago

        I’ve heard that it will still be possible to install unverified apps via ADB, so theoretically it wouldn’t be hard to make an app installer that uses Shizuku (tool that allows you to ADB into your own device) and have a website that automatically installs that using WebUSB or something

        • vodka@feddit.org
          link
          fedilink
          arrow-up
          12
          arrow-down
          2
          ·
          1 month ago

          You’ll be able to install them, but play services will very probably stop them from starting.

          They already have the framework for this in place, “unrecognised” apps get blocked by Play services already asking you if Google can scan the app before you start it, the app will not start at all unless you click yes or no.

          • daniskarma@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            3
            arrow-down
            1
            ·
            1 month ago

            Maybe yes. Maybe not. I think from now they won’t push that far, among other things because even developing for android platform would become a burden. Not being able to even test some app concept without a verified signature…

            Maybe eventually they’ll go that far. But as of now I do think is unlikely they’ll completely block the adb way.

            Anyway many current users won’t go adb. And third party stores will take a massive hit. That’s google’s goal.

        • ReversalHatchery@beehaw.org
          link
          fedilink
          arrow-up
          2
          ·
          1 month ago

          app manager can already work as an app installer, but it needs wireless debugging enabled which can be a security risk. and you have to install app manager too somehow.

  • plyth@feddit.org
    link
    fedilink
    English
    arrow-up
    21
    ·
    1 month ago

    Was this a big thing I somehow missed?

    It’s one of the many small things that hide the big thing. In 2027 android will be fully locked down, unnecessarily.

    The big thing is whatever the lockdown is for.

  • Sir_Kevin@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    21
    ·
    1 month ago

    Would people be able to circumvent this by downgrading their version of Google Play Services? …or not updating it in the first place?

    • daniskarma@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      29
      ·
      1 month ago

      I think you could still adb install unverified apps into your phone.

      That untill they’ll block that path too.

      Also I suppose that you’ll need to adb every update. So apps that would want to go this way should self check updates instead of relying on an external store.

    • EddoWagt@feddit.nl
      link
      fedilink
      arrow-up
      5
      ·
      1 month ago

      They’re baking this right in the package installer of android, it goes beyond play services. I have my doubts that this will pass in the EU

      • Sir_Kevin@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        But that begs the same question. If you never update your existing phone with google’s malware, you should be ok.

        Obviously if you buy a new phone that’s already infected you’re screwed unless you can flash a new ROM on there.

        My point is. People’s current phones do not have this malware on it yet. If you disable updates and/or degoogle, your device should continue to work as is. Perhaps without being able to use Google Play Store, but honestly that’s not huge loss for anyone that cares about this stuff in the first place.

          • Sir_Kevin@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 month ago

            That’s a bet I would rather take given the alternative.

            I don’t want any big tech shit on any of my devices. Microsoft, Google, Meta, X, etc can all eat a dick. I have zero trust in any of em.

  • Alfredolin@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 month ago

    This news makes me actually sad. I have had high hopes in the last years in the FOSS world, having myself and three other persons move to use Linux as daily driver on Desktop/Laptop.

    My phone has FOSS apps only except for banking, health, transport tickets and 2/3 work rekated stuff. My messaging, files and pictures are handled by FOSS apps installed from third parties (F-Droid, Obtainium) on selfhosted servers… I was finally seeing the light at the end of the tunnel.

    This news sound to me like the tunnel ahaead is collapsing.

    • Telorand@reddthat.com
      link
      fedilink
      arrow-up
      4
      ·
      1 month ago

      From what I’ve seen elsewhere, yes. adb sideloading will still be possible, but that adds a level of inconvenience many people will not enjoy, especially since FDroid and similar have been so easy.

    • Dumhuvud@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      Install, maybe. What about updates though? Do you plan to pull out adb for each and every one of them? Or would you rather keep using old, potentially insecure, versions?

  • HiddenLayer555@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    1 month ago

    How easy is it to convert an Android app to a Linux mobile app of you’re the developer? If it’s written in JVM languages it shouldn’t be that hard right?

    • nomadjoanne@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      1 month ago

      Just use a custom ROM. This sadly will affect app developers. But if you are on a custom ROM without GMS it will continue to work just fine.

      • HiddenLayer555@lemmy.ml
        link
        fedilink
        English
        arrow-up
        14
        ·
        edit-2
        1 month ago

        Google is trying to kill custom ROMs too. Also I thought the majority of modern phones aren’t bootloader unlockable.

        • MML@sh.itjust.works
          link
          fedilink
          arrow-up
          3
          ·
          1 month ago

          You can unlock the bootloader on just about every phone, just depends on how much effort you want to spend.

        • nomadjoanne@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          1 month ago

          Ehhhh… sorta maybe. Ultimately they can’t, but they can make development more difficult.

          Also Google has nothing to do with whether or not you’re bootloader is unlockable. Get a phone that is.

          If you rally want to go down the whole FOSS path it does ultimately become a bit of a lifestyle.

    • Ephera@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 month ago

      End-users can use e.g. waydro.id to run Android apps on Linux.

      I’m not deep into Android development, but I doubt it’s possible to just port an app without basically a complete rewrite. Android has an own layer on top of the JVM, called Zygote, and there’s presumably lots of system libraries which the Android apps implicitly depend on, for handling graphics and whatnot, which make tons of assumptions about running on an Android device.

  • Imad@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    1 month ago

    I got the same alert on Gmaps WV (google map wrapper found f drood) Google is giving us more reasons to switch to a custom ROM