If You Won’t Put Your Name Behind Your Code, Why Should I Trust My Data With It?
The Android Verified App Debacle

If You Won’t Put Your Name Behind Your Code, Why Should I Trust My Data With It?
The Android Verified App Debacle
Back in September of last year people were freaking out over Google ‘killing sideloading’. And I posted saying no, Google is not killing sideloading. What they are doing is verifying developer identities. This means if they find a scam app out there they can look up the developer and ban them. And this would improve the safety of the entire Android ecosystem.
But people complained very loudly and Google was like, “Fine, we will allow you a way to install apps without the developer having to verify.” I was extremely interested in what this looked like.
Well, Google finally put out their method for allowing installation of unverified apps. And it’s quite a process:
- Enable normal developer options
- Enable “Allow Unverified Packages” in the developer options
- Confirm that you are not being coerced
- Enter your password
- Restart the device and wait 24 hours
- Return to the developer options and select either “Allow temporarily” (seven days) or “Allow indefinitely.”
- Confirm that you understand the risks
Two things. First Google says this process will not be told to the user, they have to look it up online. I believe Android does not allow sideloading unless the user allows it. I know this because there was a message telling me this. This unverified system will likely not have that message. And second it takes 24 hours which makes the process even more complicated.
Now I get what Google wants to do with this new process. They want to prevent scammers from coercing people to install malicious applications. And at the same time they want to make Android maximally open.
Although in trying to solve both problems they’ve created a solution that, unfortunately, solves neither problem. In my previous post I discussed two ways malicious software can end up on people’s devices.
The first is classic fraud. Someone calls you up and says, “This is your bank. We’ve noticed some suspicious activity on your account. You have to download this app to keep you safe.” Before they could do this fairly easily. Now… they can still do this fairly easily, nothing has changed.
In the previous post I noted that the scammers could get the victim to lie to bank officials. You think this 24 hour wait will change anything? Scammers will just add “I’ll call you back at this same time tomorrow to finish the security update” to their script.
The second example I gave in the original post is pirated apps. Someone can just slip in some malware and redistribute it. Now people who pirate apps are pretty sophisticated. They’re going to just flip that unverified app switch, wait 24 hours, and then pirate all the apps they want.
And then they could get infected with malware. Or at least make Android a less attractive platform to develop for.
And since this solution has come out people have not stopped complaining. From reading the comments it seems like nothing has changed. This 24 hour change is functionally the same as not allowing verified apps at all.
It seems to me we have a classic cursed problem.
[embed]
A cursed problem is a problem with two contradicting goals. Solving one means not solving the other. Here Google wants to lock down Android to malware and keep these random Redditors happy. Google thinks they can be clever but what they’ve really done is create a way to annoy both sides without really fixing the problem.
You know what I think Google should do? Just ignore the people asking to install unverified apps in the first place. I mean, like, why do they even care so much? Third-party app stores have never taken off.
In fact in a previous post I noted how Google was giving a custom install process to third-party app stores. This would be like if Microsoft or Apple allowed a custom install flow for alternative browsers. The court would have to order them to do it. So why is Google doing it? Because third-party app stores make up such a trivial amount of installs that it doesn’t matter. Well, except for in China because Google doesn’t operate there.
The cost to set up payments, list your app, and keep it updated (for each app store) is just too much for most developers. So all the apps gravitate to Google Play and because of that everyone uses Google Play.
I have no idea why people are complaining so much. Are there really that many people installing unverified apps? I highly suspect that the majority of complaints are coming from people who want to pirate apps. And to that I say, “Who cares what they think?”
This is because anyone who wants to make money from their app is on Google Play because it’s the biggest. If it’s not on Google Play it’s probably open source. And, you know, if it’s open source you can just build it yourself and install it on your device. No one is stopping you. So why don’t you?
Because if no one put their name behind the code why should anyone trust their data with it? My thoughts exactly.
메타데이터
- post_id
- 2fade8bf1aea
- slug
- if-you-wont-put-your-name-behind-your-code-why-should-i-trust-my-data-with-it-2fade8bf1aea
- url
- https://medium.com/@impure/if-you-wont-put-your-name-behind-your-code-why-should-i-trust-my-data-with-it-2fade8bf1aea
- canonical_url
- https://medium.com/@impure/if-you-wont-put-your-name-behind-your-code-why-should-i-trust-my-data-with-it-2fade8bf1aea
- author_url
- https://medium.com/@impure
- status
- ok
- fetched_at
- 2026-06-09 15:37:30