Google’s Secret Update Will Lock Out Every Unregistered App Worldwide

Now you’re changing what I’m saying.

Before you claimed that I said that people should have to wait to install things on their own device and now you’re saying that I don’t consider it an unreasonable requirement.

If you are running a device with privileged play services, you can simply wait 24 hours to install an app.

All I’m saying is that the sky isn’t falling.

1 Like

This is, transparently, very bad. If we had to do the exact same authentication flow to install apps that don’t come from the Microsoft Store (every Steam game, for example), then folks would be up in arms about it. The conditioning of the Play Store being “how you install apps on Android” has been an enormous detriment to the expectations of freedom people have with their devices. I didn’t even know you COULD install apps any other way until about a year ago, and I thought of myself as a power user.

I wish I could do more, but I just spread the word to people I know. It’s hard to get them to care about this, though, since it will not actually affect their experience yet. I wish we were (as a species) better able to look down the long barrel of consequences to see the chambered round at the end, and take action before our liberties have been blown away.

3 Likes

Knowing Google, they’ll use AI/Machine learning to automate the verification process, with probably no human eyes looking at it. What’s stopping people from using fake identification?

1 Like

The same thing stopping people from using fake identification for banks.

1 Like

Why should something be a certain way is simply a way of speaking. I am not responsible for your misunderstanding, my phraseology is sound.

All I’m saying is that the sky isn’t falling.

Expressing concern is not the same as saying the sky is falling. That argument is usually used by those who want to quell dissent or questioning (“Tsk tsk, you’re so overreactive.”) Things are done for a reason; one should always question why (especially nowadays) as the reasons aren’t always altruistic. The existence of this forum proves that.

So my question still stands: how is it reasonable to require someone to wait 24 hours to install something on a phone they own? Are they “protecting us from ourselves”?

4 Likes

Yea I don’t know about that…people have been using second identities for years even opening bank accounts in other names, everything from abuse survivors to people just wanting to get away from their past…

5 Likes

It’s a good question, and the answer is unknown.

1 Like

Google decided that the supposed benefits of preventing people installing malware are greater than the drawbacks of waiting 24 hours once in order to sideload.

I’m not saying that it will actually have those benefits.

In a way, but it also is designed to protect against scammers by slowing down the process to install apps. The human might be the biggest weakness in the Android security landscape.

1 Like

The human is always the weakest link in any well-made chain of security. It would be one thing if they introduced an “I’m giving this phone to my tech-illiterate Grandma”-mode that did the above. They didn’t do that, and are instead taking steps to close off the Android app ecosystem.

There are other solutions to the problem of malicious apps. This is the 3rd largest company in the world, with enough free cashflow ($76bn in 2025) to do literally whatever it wants. They do not need you going to bat for them, trying to post-hoc justify their hurtful decisions. They chose a route to solving this problem that involves a private, uncontrolled third party dictating what I can and cannot do on my device, that I’ve potentially spent over $1,000 on. That’s just unacceptable behavior, and will not be justified however you try to spin it for them.

6 Likes

I’m not trying to spin it any way, I’m just explaining that it’s an overreaction and will have minimal real world impacts. People are talking about this as if it’s ChatControl 2.0 and the end of Android. It’s a 24 hour wait, once, when you’re using Google Play Services, which is a proprietary privileged system component.

It’s literally a wait for 24 hours, once, for developers that aren’t identity verified. You’re running their privileged services on your phone, you don’t have to.

They already control what you do on your device if you use Google Play Services. This is really a minimal change.

1 Like

Are you pretty experienced in the privacy space? This isn’t a gotcha, I’m trying to understand your perspective.

1 Like

I think you may be missing the underlying issue here.

If a third party can decide what you can do with your own hardware, they can decide what you can and can’t watch on your television, what you can and can’t listen to on their audio device, etc. You say it’s just 24 hours, but again, do you have to wait 24 hours to wash your clothes in the washing machine you bought? Do you have to wait 24 hours to drive the car you purchased (I mean, you could kill somebody with that thing!)

The pretense of “protecting you” doesn’t fly, especially when Google can’t or won’t provide any numbers as to how many people were affected by malicious apps in a given period. “We’re protecting you.” ‘From what?’ “Don’t worry about it, just be glad you’re safer.”

6 Likes

@yes

Or for someone to mock Google, or abandon the Android system. The one who motivated you will possibly do it.

@Expert4870
Google has had enough time to defend the system against “malwares,” and in recent versions they’ve integrated “advanced protection.” Real nice, but knowing the company as it is, it’s just another business.

2 Likes

Update:

Why did the lockdown date change from September 2026 to January 2027?

The lockdown was initially stated to start in September 2026 in four initial countries. It has since been updated to limit the initial rollout to a specific list of Android app stores, which does not include F-Droid. This means that the activation in September will NOT affect F-Droid itself or any apps installed through F-Droid. The date at which the lockdown will start impacting F-Droid users is not yet published. We will keep this page updated with any new timeline details that we are given. For more details, see Google’s developer verification FAQ.

Frequently Asked Questions

A lot of applications work just as well on a browser. You don’t always have to install an app.

Fortunately keepandroidopen.org was kind enough to tell us how to defeat Google in 9 easy steps halfway down their page.

Copied directly:

Google’s “escape hatch” is a trap door

Google says “power users” can “still install” unverified apps. Here’s what that actually looks like:

  1. Delve into System Settings, find About Phone
  2. Tap the build number seven times to enable Developer Mode
  3. Dismiss scare screens about coercion
  4. Enter your PIN
  5. Restart the device
  6. Wait 24 hours
  7. Come back, dismiss more scare screens
  8. Pick “allow temporarily” (7 days) or “allow indefinitely”
  9. Confirm, again, that you understand “the risks”

Nine steps. A mandatory 24-hour cooling-off period. For installing software on a device you own.

So… as long as you can count to 7, remember your pin, and wait 24 hours one time then you will be able to download any app anywhere anytime. Developers don’t even have to register with Google.

This entire story is a good litmus test for who knows how to read past a headline and who just sees a headline and clicks the angry emoji and shares.

2 Likes

It’s about the basic principle. These instructions might still work now, but what about in 2028? Will the time limit be set to 24 days then? In 2029, to 24 months? And in 2030, will Google decide to disable this feature entirely? You’re yet another one of those negative examples who downplay everything and blindly put up with it until it’s too late and then wonder afterward how things could have gotten this far.

That comes right after the people who claim they have nothing to hide and want to get rid of encryption.

2 Likes

It’s funny how people rant about the 24h limit here, while in web development it’s the opposite. Devs complain that old package managers like npm don’t have such a policy, and every new package manager advertises a cooldown that blocks installs of freshly published versions (typically 1–3 days).

Same in banking/crypto: 24–48h lock on withdrawals to a newly whitelisted address. Oh no, it’s my hardware money, how could you.

I’m not saying the cases are identical. But a cooldown on security-sensitive actions is a reasonable policy that’s being adopted in many areas. A lot of supply-chain attacks and data leaks wouldn’t have happened if it had become standard years ago.

but what about in 2028? Will the time limit be set to 24 days then? In 2029, to 24 months?

Google didn’t pick a random number, and it doesn’t have a three-year plan to lock out @zoqqa specifically. A one-day cooldown is common practice in modern environments

You forgot to include one tiny bit from the source you generously quoted. No biggie. I’ll help you out:

“Worse: this flow runs entirely through Google Play Services, not the Android OS. Google can change it, tighten it, or kill it at any time, with no OS update required and no consent needed. And as of today, it hasn’t shipped in any beta, preview, or canary build. It exists only as a blog post and some mockups.”

It’s fine. Everything is fine. We’re good. We can finally move on.

Here’s an app waiting for… the day to come?

Take a look (the description is in Spanish):

1 Like