TL;DR
Fraud and malware risks exist due to unverified app developers on Android devices. Google is implementing Developer Verification, requiring apps to be linked to identity-verified developers.
✦ Why It Matters
Engineers should prepare for increased app verification requirements and potential impacts on user experience.
Key Takeaways
Full Summary
Fraud and malware are significant concerns in the Android ecosystem, particularly from sideloaded apps, which are apps installed from sources other than the official Play Store. To address this, Google is rolling out Developer Verification, a requirement that apps must be registered to an identity-verified developer before installation on certified Android devices.
This verification process will check the developer's registered signing identity, impacting all installation sources, including third-party stores and direct APK sideloading. For power users, Google offers an 'advanced flow' option to install unverified apps after acknowledging the associated risks and waiting a full day.
Google cites that over 50 times more malware originates from sideloaded sources compared to the Play Store, and regulatory pressures are also influencing this move. The rollout will begin in regions with high fraud rates, such as Brazil and Indonesia, indicating a targeted approach to enhance security.
This change will primarily affect users on stock ROMs, while LineageOS users remain unaffected.
Related