The app ID is com.google.android.verifier, which I assume will be used for the upcoming developer verification program for installing 3rd party apps.

Starting September 30, developers (signing authors) need to be verified from Google to distribute apps in the following app stores:

  • Google Play Store
  • Honor App Market
  • OPPO App Market
  • Samsung Galaxy Store
  • Transsion Palm Store
  • vivo V-Appstore and
  • Xiaomi GetApps

only in the countries of Brazil, Indonesia, Singapore and Thailand.

F-Droid is not included for this time.

It is planned to be rolled out globally across all markets/app stores by January of 2027.

Relevant sources:
https://developer.android.com/developer-verification/guides
https://keepandroidopen.org/

I used App Manager (io.github.muntashirakon.AppManager) for the screenshot; you can use your regular ‘Installed Apps’/‘Apps’ menu to see if it’s been rolled out automatically for you as well.

edit: First link was originally a typo, my bad. Fixed it.

  • ReluctantZen@feddit.nl
    link
    fedilink
    English
    arrow-up
    4
    ·
    12 hours ago

    Thanks for sharing. It was installed for me as well on the 14th apparently, even though my phone’s not getting updates anymore. I was hoping I wouldn’t get it because of that, but I guess it’s purely a play services thing.

  • Ripley_Tripley@lemmus.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    14 hours ago

    What I feel no one is asking is, and what I’m still confused about, would MicroG still be working wthin all of this? Its a sandbox, I get it, but that dosent mean it could have the ability to stop working since it can’t access apps. Like if that gets closed off, then what? There are still some app that are not fully stock android that a lot of people need to use unless you have them on computer or tablet ( For banking for example, I use my apps for all my finances on my iPad)

    Maybe I don’t get how the sandboxing works for MicroG but, if its using google, I would avoid it as much as I can.

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    23
    ·
    1 day ago

    My kids’ phones (Pinwheel-managed Moto G Play models) attempted to install this in the background as well. I only found out about it because I got an app request from the devices; the kids had zero knowledge of it.

    I blocked the installation.

    • bampop@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      13 hours ago

      Hold up, what magic is this? You can gatekeep installations of any app on their phones? I’ve looked into doing this with Google Play but as far as I can tell they only enable it for mature content. Which doesn’t help to stop my old father in law from installing trash “security” apps on his phone.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        4 hours ago

        Yes. It’s a company called Pinwheel, they provide phones pre-setup with what is essentially MDM, but geared towards child usage.

        I can do the following remotely from the “caregiver portal”:

        • Install/uninstall apps from Pinwheel’s “curated” app list
        • Enable/disable Google Play store (apps still require approval)
        • See their texts and calls (including actual content - they know we can see this, we don’t hide it)
        • Approve/block contacts; or, allow them to manage their own contact list, but blocked contacts cannot be bypassed
        • See their live location and location history
        • Set schedules and modes to enable/disable apps/features at certain times, and after any specific duration if desired
        • Remove the lockscreen passcode

        …all remotely.

        If your FIL can’t handle smartphone stuff, I would absolutely recommend something like this for him.

        The catch is that Pinwheel costs about $15/mo per device. Worth it IMO. They also have their own optional MVNO plan, with everything rolled into one price. I forget how much it is - I just put my kids on Mint Mobile.

  • Anti_Iridium@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    ·
    1 day ago

    When it rolled out, it removed my root as well. I guess I may be jumping ship to lineageos soon. I like root features too much.

      • redjard@reddthat.com
        link
        fedilink
        English
        arrow-up
        7
        ·
        14 hours ago

        Not op, but I use it to make automated proper backups of all important apps. Androids own backup system does not catch a lot of stuff, some apps don’t support or allow it at all, and it’s limited. I just get a full package of all the apps data, every morning, then synced to my nas via syncthing.

        I also remove a long list of annoyances:
        󠀀- Apps setting brightness (youtube when going fullscreen increases it a bit, some apps do it when showing qr codes (making them hard to scan) ) 󠀀- Make all notifications editeable (The wifi portal ones are anoying in countries that have login websites for all public wifi)
        󠀀- Let me screenshot everything
        󠀀- Let me downgrade apps and change certificates (e.g. going from a github to fdroid release without reinstall)
        󠀀- Apply my vector app-icon pack to systemui, i.e. the app switcher (and app details)
        󠀀- Force apps to allow reverse portrait orientations when they inexplicably forbid it (I use reverse portrait while charging sometimes when the charger is behind/above me)
        󠀀- Make my notification drawer transparent
        󠀀- Mod the home button out of firefox (fennec), and severely mod discord
        󠀀- Record calls (my memory is bad, I protocol details afterwards sometimes. Recordings auto-delete after a bit)
        󠀀- Remove all drm support from my phone, just in case
        󠀀- Let Adaway work in hosts mode, to improve performance and so it doesn’t influence an active vpn
        󠀀- Morphe modded youtube without its own microg app (while I still have gsm)
        󠀀- Lets me select all paths in those app share storage dialogues, so I can make an app save directly to downloads and don’t have to make a subfolder for example
        󠀀- Make fdroid install just like playstore can, without any forced popups or dialogues, having full system permissions and the ability to downgrade apps.
        󠀀- I may have used root to disable the thin gesture bar hint thing at the bottom of the screen in gesture navigation. I don’t have it in any case.
        󠀀- I also use root to change adb settings on my phone conveniently, like thinner back gesture triggers, using the full 4k resolution of my screen, changing screen locking procedures, hide some icons in my status bar, hide the popup whwn rotating the phone on locked rotation, hide thepopup for screenshots, hide the popup for copy, disable googles play protect scanning and background app killer, change connectivity checker and time server to urls not tracked by google, … 󠀀- I use root to easily set up and manage a second profile, have my file manager access the entire filesystem inclusing system files, enable the olde GameGuardian (similar to CheatEngine, arguably even more powerful, and for android), and to view and share my wifi passwords regardless of what my specific rom happens to think of that at the moment.
        󠀀- I also use it for shizuku, which could work rootless via adb but would be some effort to maintain like that, while for me it’s been chugging away for years by itself.

  • Appoxo@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    70
    arrow-down
    1
    ·
    2 days ago

    F-Droid is not included for this time.

    How-To:

    • Open Developer Options and select Apps from unverified developers.
    • Turn on Allow apps from unverified developers.
    • Authenticate using your screen lock.
    • Confirm that nobody is pressuring you to change the setting.
    • Restart your phone and wait 24 hours.
    • Return to the setting and choose whether to allow apps from unverified developers for seven days or indefinitely.

    Source:
    https://www.androidauthority.com/google-android-advanced-flow-sideloading-rollout-begins-3700073/
    https://www.pocket-lint.com/android-new-sideloading-option/

    • d-RLY?@lemmy.ml
      link
      fedilink
      English
      arrow-up
      9
      ·
      22 hours ago

      After going through both my Galaxy 24U and Pixel Tablet initially, I wasn’t seeing the option (was looking for the old “Install from unknown sources” which is in a different location (and per app toggles). I went back and manually disabled and enabled the “Android Developer Verifier” app and then saw the option for “Apps from unverified developers” show up. Then was able to follow the steps (very glad you provided that second source which is what led me to what I did).

      So I guess if you don’t see it. First search in your apps that the verifier app is present. If it is, then go into the app info for it and toggle disable and then enable. Willing to accept that maybe I was just blind to it due to the old way of sideloading that made me miss it in Developer Options. But for sure saw it after the toggles. Now I just need to remember to go back tomorrow to set the “indefinitely” option. Curious if this will allow Play Protect to not try to yeet apps if PP is turned back on. I had to turn it off a couple months ago because it kept flagging SyncThing-Fork installed from F-Droid trying to trick me into uninstalling it (which was weird that was the only app it freaked out about out of all the third-party store and Obtainium apps).

    • zout@fedia.io
      link
      fedilink
      arrow-up
      65
      ·
      1 day ago

      That’s some pretty big hurdles to be honest, just a reminder of how sketchy Google is these days.

      • Appoxo@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        18
        arrow-down
        2
        ·
        1 day ago

        Less issue for me than Apple lol.

        You can always (for now) go to LineageOS or GrapheneOS ¯\_(ツ)_/¯

        • Zedstrian@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          38
          arrow-down
          1
          ·
          edit-2
          24 hours ago

          Every shift away from open Android that users accept emboldens Google to lock it down further.

          • Appoxo@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            11
            arrow-down
            3
            ·
            1 day ago

            Switching from Android to Apple is really smart lol.
            Why would you even switch from a pretty much open system to a fully closed one (even with the things the EU forces Apple to do)?
            (This questions excludes Linux OSs on smartphones)

            • Zedstrian@sopuli.xyz
              link
              fedilink
              English
              arrow-up
              13
              ·
              1 day ago

              Apple is of course still far worse, but users shouldn’t be accepting Google’s changes to Android without complaint.

        • zout@fedia.io
          link
          fedilink
          arrow-up
          8
          arrow-down
          1
          ·
          1 day ago

          Not if you want your banking app to work, or some other apps that require you to have the “certified” os on your phone. If I have to stop using these apps, I might as well go back to a dumbphone.

          • UnityDevice@lemmy.zip
            link
            fedilink
            English
            arrow-up
            3
            ·
            15 hours ago

            Yep, and my bank just announced that they’re getting rid of the web portal at the end of the year. It’s app only from then on. And their app already didn’t work on my rooted phone. This will just be a more constraining restriction.

            I can change banks, but it’s a sign of things to come.

          • Lka1988@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            3
            ·
            1 day ago

            Not if you want your banking app to work, or some other apps that require you to have the “certified” os on your phone. If I have to stop using these apps, I might as well go back to a dumbphone.

            I would rather stop using apps that require this bullshit than give up the literal pocket computer that’s powerful enough to do damn near whatever I want with it. I make my phone my bitch and I intend to keep it that way.

            Banking apps that require this aren’t worthy of being installed. Just use their website. Banks still have websites.

            • zout@fedia.io
              link
              fedilink
              arrow-up
              1
              ·
              17 hours ago

              I would rather stop using apps that require this bullshit

              Yeah, one of these apps is needed to log on into government websites to do my taxes and communicate with different agencies. It is possible to do without, but not practical.

              • Lka1988@lemmy.dbzer0.com
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                4 hours ago

                The only govt website that requires extra security in the US is the IRS, but it’s through ID.me. I have my token for that on the Aegis authenticator app (FOSS, F-Droid, can be used on rooted/“insecure” devices).

            • Diurnambule@jlai.lu
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 day ago

              They ask to enter a pin on the application to unlock the web site. I may have to leave my bank…

                • Diurnambule@jlai.lu
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  15 hours ago

                  Have to go in the phsysocal agency to do some operation like sending monney and you can’t set reccuring transactions…

          • Jakeroxs@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            7
            ·
            1 day ago

            Web browsers exist still, though some particularly shitty sites don’t even have a mobile web view these days.

          • Turret3857@infosec.pub
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            My bank currently works but in the past it hasnt and the website worked just fine for the period of time the app didnt work.

            • Lka1988@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              2
              ·
              1 day ago

              You don’t “use Magisk” to do that. Magisk only provides a path to do so.

              What modules are you using to achieve this?

          • vogi@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 day ago

            My Bank works even without microG or some other Google supplement. It does show a warning on the initial boot that it might not, but it does. They also do not require to have the app, but its still nice to have.

  • onionsinmypores@sh.itjust.worksOP
    link
    fedilink
    English
    arrow-up
    82
    arrow-down
    1
    ·
    2 days ago

    Update: Interestingly, since it is still classed as a User app, I can uninstall it myself without any special perms. The installation source is shown as Google Play Store, and you can manually find the app on the store.

    Here’s a screenshot of that - though it has no ratings, reviews, options to review etc. that you would expect from ordinary or even other Google produced apps.

    • zout@fedia.io
      link
      fedilink
      arrow-up
      26
      ·
      1 day ago

      I can find it there, but only uninstall updates. Guess it’s ADB time.

      • BeatTakeshi@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        Same for me, I can only uninstall the updates, and I can’t tell the play store to not update it automatically, so it will obviously do this. I’m eyeing at fairphone, or graphene, or /e/os, or Jolla, or iodé, or calyx, or lineage, or pinephone a bit more everyday

    • Turret3857@infosec.pub
      link
      fedilink
      English
      arrow-up
      20
      ·
      edit-2
      1 day ago

      At this time it is currently better to go with a custom Android ROM. Linux phones are currently have almost 0 security. I say almost 0 because postmarketos does support LUKS encryption, but only on some devices, and pmos uses an “upstream kernel” update model for devices, so a lot of the drivers for supported phones are not fully complete.

      None of them have sandboxing, or measured boot, and excluding postmarketos, none of them get driver level security updates either.

    • untorquer@quokk.au
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      1 day ago

      Goto “app details” at the bottom of the settings page for the app. Then select “uninstall updates” should no longer appear in app list.

      • PointlessLifePersonified@slrpnk.net
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        1 day ago

        “App details” is greyed out for me. Pixel 7 Pro.

        Edit: never mind - it was because I had the Play Store disabled. Not that it’ll mean much, but I flagged the app as inappropriate while I was there.

        Edit 2: Wow, they’re paying for fake reviews that are blatantly a bad joke.

  • REDACTED@infosec.pub
    link
    fedilink
    English
    arrow-up
    14
    ·
    edit-2
    1 day ago

    Weird, I could uninstall it (and the key verifier one too), and so I did. Yeah, this is definitely not going to come back to bite me in the ass

    EDIT: OnePlus Open, I haven’t unlocked bootloader or rooted it.

    • lost_faith@lemmy.ca
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 day ago

      Been using my pixel 6, according to the app list it has been “used since Aug 13” I cannot archive(greyed out), disable says (get this) “It came preinstalled on my device” funny since I’ve been using this device for years and by its own account was just installed aug 13

      • Turret3857@infosec.pub
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 day ago

        You can probably get rid of it by installing GrapheneOS, CalyxOS, iodéOS, or LineageOS, unless youre in the US and bought the phone from Verizon

            • Lka1988@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              4
              ·
              1 day ago

              Bummer 🫤

              Wasn’t the entire point of custom ROMs to avoid this whole situation to begin with? Doesn’t make sense for a custom ROM to drop support once official support has ended, it kinda defeats the purpose of keeping an older device…

              • Turret3857@infosec.pub
                link
                fedilink
                English
                arrow-up
                4
                ·
                1 day ago

                The security model of GrapheneOS and CalyxOS are similar on this specific issue. They drop support after OEM support has ended because the proprietary drivers that are borrowed from the official ROM stop being updated. It introduces an unpatchable security hole unless someone can reverse engineer all the proprietary drivers and keep updating them with security fixes, and even then, hardware security flaws may eventually surface.

                LineageOS and iodéOS are good for keeping older devices working as long as you are okay with a looser threat model (not having those hardware level security updates, and not having the extra features provided by Graphene or Calyx)

                postmarketos is a Linux distro aimed at reverse engineering those drivers to allow supported phones to live even longer. However, the team doesnt recommend ANY devices for daily driving. The OnePlus 6T and Pixel 3 are recommended for people who want a tolerable experience but they are not perfect. The Pixel 6 series was recently supported, but Im not even sure if they have graphics drivers working yet. (not to mention, pmos has no security features outside of LUKS encryption. No measured boot, no sandboxing, no fine grain permission control etc)

                • Lka1988@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  4 hours ago

                  Ahhh. That makes more sense.

                  It’s been very interesting watching the evolution of custom ROMs over the years… From CM to Lineage, AOSPA to Paranoid Android (miss those guys, that was my favorite one), and so many others… Glad Lineage stuck around.

  • atro_city@fedia.io
    link
    fedilink
    arrow-up
    20
    arrow-down
    1
    ·
    2 days ago

    No idea where you are nor which phone you have, but maybe it’s time to install an Android alternative OS (not sure what to call it) like GrapheneOS, LineageOS, or eOS. From what I understand they don’t allow this kind of shit.

    • I Cast Fist@programming.dev
      link
      fedilink
      English
      arrow-up
      34
      arrow-down
      1
      ·
      2 days ago

      Easier said than done, especially as there are more models that don’t have any sort of support for those OSs than models that do. Not to mention the hassle to even enable the option to flash it and risk of bricking. Worse, banking apps may refuse to work.

      Google and the OEMs never wanted you to own your phone and they are mostly winning on that front.

      • FunnySalt@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 day ago

        Easier said than done, especially as there are more models that don’t have any sort of support for those OSs than models that do.

        This is a big hurdle. I had to buy a different phone to install a custom ROM. I bought it used, but even so still fairly expensive. And an extra cost can be a limiting factor too.

        Not to mention the hassle to even enable the option to flash it and risk of bricking

        GrapheneOS has a webUSB installer that is very easy to use. I would argue it eliminates the hassle. Bricking is still a risk.

        Worse, banking apps may refuse to work.

        I don’t use banking apps on my phone. I don’t like having anything installed that has access to money. I just access my financial institutions via their website. But I acknowledge they may fill some need others have that I do not. And that not everyone has access to a computer to access websites , and I can see banks trying to force app use when accessing from a mobile browser.

      • HerbGrower@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        Could go back to a flip phone tbh. Only got a FF4 a few months ago and put calyx on it, used a flip phone before that for a few years.

          • HerbGrower@slrpnk.net
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            Its only to receive calls from people and employers who still use phone/SMS as a contact method.

            Anything important can be done on a Linux PC. So then the question is how portable of a Linux PC can I comfortably get.

      • benjirenji@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        1 day ago

        Just buy a phone that comes preinstalled without Google.

        My banking apps all work. Some of the shittier apps that force you to watch ads break though.

  • vogi@piefed.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 day ago

    What happens if you try to install an unverified apk now? Like is there a message or something? Does it go away after just uninstalling the developer verifier?

    • Psythik@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      This app also got silently installed on my device, but I just updated YouTube Morphe and there was no issue. So for now the app doesn’t appear to do anything. I disabled it and will be uninstalling with ADB soon.

      • vogi@piefed.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 day ago

        Ah okey, thanks for the info :)
        Better hope they do not merge it into Google Play Services then and that I didn’t just jinx that to happen…