Cirrus app dev informing the app will stop working on certified android devices in '26/'27

cross-posted from: https://discuss.tchncs.de/post/45277582

Opening my weather app this morning I was greeted by this warning:

Google has announced that, starting in 2026/2027, all apps on certified Android devices will require the developer to submit personal identity details directly to Google. Since the developers of this app do not agree to this requirement, this app will no longer work on certified Android devices after that time.

It's the first time I hear about this, seems to be about:

Tech crunch article from august, "google will require developer verification for android apps outside the play store"

Cirrus app: Github

Was this a big thing I somehow missed? I hope more devs will follow suit.

354 points · 65 comments · view on lemmy.world

65 Comments

Wizard_Pope@lemmy.world · 106 pts · 342d (20 replies)

Can't have shit in a closed system. Fuck google.

Linux on phones needs to become a thing. If they start locking down like apple does I will literally go back to a dumb phone.

unexposedhazard@discuss.tchncs.de · 18 pts · 342d (17 replies)

Degoogled android ROMs will not have this restriction, as they will just have googles verification system removed. So until linux for mobile is a bit more ready you can still use graphene/lineage/etc.

sorghum@sh.itjust.works · 12 pts · 342d (10 replies)

So long as you can still have GrapheneOS and others. Google's handling of pushing updates and device tree shows how fragile that actually is. Linux phone is going to be the best solution so long as Google runs Android

possiblylinux127@lemmy.zip · 3 pts · 342d (1 reply)

Linux wouldn't fix that

If you don't have the source code you can't do anything.

UltraMagnus0001@lemmy.world · 2 pts · 342d (7 replies)

Aparrently they are trying to close the Sharing off android.

possiblylinux127@lemmy.zip · 1 pts · 342d (5 replies)

They can't actually do that as vendors build off of the sources.

Luckily we have other vendors like Motorola who are very supportive of custom roms

Turret3857@infosec.pub · 4 pts · 342d (2 replies)

Idk if I'd call it "very supportive", Motorola voids your warranty to install custom ROMs.

possiblylinux127@lemmy.zip · 1 pts · 342d (1 reply)

Are there any companies that don't?

Anyway I've never had to use the warranty plus my most current phone is a eBay refurbished device

Turret3857@infosec.pub · 2 pts · 342d

Google and Fairphone don't. I can't imagine Shift does either being a German company.

DeathByBigSad@sh.itjust.works · 2 pts · 342d (1 reply)

"Very supportative" like making you wait 7 days before the option in dev settings become un-greyed lol (serious wtf, I was just about to install Lineage and learned about this bullshit, welp, guess I have to wait till next week)

possiblylinux127@lemmy.zip · 3 pts · 342d

It really sucks but at least the unlock process is simple and reliable.

Much better than Samsung and other companies

01189998819991197253@infosec.pub · 1 pts · 342d

Yes they are. And it's bleak.

Wizard_Pope@lemmy.world · 6 pts · 342d

The issue with that is that fewer and fewer phones have unlockable bootloaders.

possiblylinux127@lemmy.zip · -1 pts · 342d (4 replies)

I'd stay way from Graphene but Lineage OS is solid

blackris@discuss.tchncs.de · 9 pts · 342d (2 replies)

Does your opinion come with a reason?

possiblylinux127@lemmy.zip · 2 pts · 342d (1 reply)

Louis Rossman: https://www.youtube.com/watch?v=4To-F6W1NT0

Techlore: https://www.youtube.com/watch?v=Dx7CZ-2Bajg

TL;DR: The Graphene devs are crazy. I wouldn't trust them personally. If they were making something lower risk like a text editor I wouldn't be a concerned but I take my phone seriously.

blackris@discuss.tchncs.de · 2 pts · 342d

Thx for the context.

unexposedhazard@discuss.tchncs.de · 2 pts · 342d

Why stay away from Graphene?

possiblylinux127@lemmy.zip · 9 pts · 342d

Linux on phones no where near as private or usable

Android (AOSP) is really solid as a platform. Even with Google trying to turn it into a proprietary hellscape projects like Lineage OS still work to build a open platform

hobwell@sh.itjust.works · 4 pts · 342d

Not an endorsement, but I just found out about the existence of this phone today: FLX1 which purports to be based on Debian.

rumba@lemmy.zip · 28 pts · 342d (6 replies)

Seems to me like there's about to be one hell of a market for phones that you can run alternative operating systems.

HobbitFoot@thelemmy.club · 11 pts · 342d (3 replies)

Except the economics for it are trash. Google uses Android as a loss leader to make money on Google's services.

spicehoarder@lemmy.zip · 3 pts · 342d (1 reply)

Damn the economics. The only people who care about "cheaper phone" are those who don't care about other things

ulterno@programming.dev · 4 pts · 342d

I am going to refute you over here.
I can't seem afford a Linux phone (or any mobile device really), simply because they tend to be made by labour in high-pay countries, while I am in a low pay country (which means I am not paid as much either).

And then I can't afford to try any possibly existing Linux ROMs on my phone, because I can't afford to brick it at all.

rumba@lemmy.zip · 2 pts · 342d

I think fairphone is doing ok. Kind of expensive

skuzz@discuss.tchncs.de · 2 pts · 342d
[ removed ]
KeenFlame@feddit.nu · 1 pts · 341d

Ah yes cause that's the only part of any platform that requires a full name and address and will absolutely make a dent when the walled garden servants now have to use their slave names people sure will Exodus in droves

lath@piefed.social · 28 pts · 342d (3 replies)

Technically, this would allow the identification of malware providers in Google's app store.

Practically, every us citizen's personal identification details were taken by doge idiots and are likely by now up for sale at a cheap price, so false identification by malware providers is pretty much guaranteed.

It's a "we covered our ass" policy same as any "save the children" that does anything but the implied thing.

wizardbeard@lemmy.dbzer0.com · 13 pts · 342d

This is about all app makers, not just ones in the Google Play Store. This also applies to third party app devs and hobbiests making open source apps to put up on alternative app stores like the all open source F-Droid.

ReversalHatchery@beehaw.org · 6 pts · 342d (1 reply)

Technically, this would allow the identification of malware providers in Google's app store.

play store publishers are already needed to submit (and publish) their name and address. they made it a requirement ~5 years ago.

lath@piefed.social · 1 pts · 342d

Obviously fictional. An ID and a picture of yourself holding today's paper are also needed to confirm authenticity.

Korhaka@sopuli.xyz · 20 pts · 342d (10 replies)

How do I uncertify an Android device then?

01189998819991197253@infosec.pub · 14 pts · 342d (8 replies)

Install a custom ROM. Or buy a Chinese made phone, such as Xiaomi (which I do not recommend***).

Edit: some custom ROM links in no particular order:

*** Edit 2: I don't recommend the route of a Chinese brand, because I've had only bad experiences.

possiblylinux127@lemmy.zip · 8 pts · 342d (1 reply)

Don't buy a Chinese phone

Resonosity@lemmy.dbzer0.com · 2 pts · 341d

Why?

Turret3857@infosec.pub · 5 pts · 342d

iodeOS is good too.

Zangoose@lemmy.world · 4 pts · 342d (2 replies)

Note that if you're in the US, Samsung doesn't unlock the bootloaders at all and afaik Motorola is also hit or miss. Importing a phone is also risky as international versions might not have the cell bands required for US carriers.

If you want a custom ROM in the US you basically have to buy a pixel, and at that point you might as well go with GrapheneOS since it's the most secure

captain_aggravated@sh.itjust.works · 2 pts · 342d (1 reply)

And aren't they stopping that with Pixels?

Somebody needs to actually make a Linux phone.

Zangoose@lemmy.world · 1 pts · 342d

They haven't stopped it yet for the pixel 10s but who knows how long it'll last

Railcar8095@lemmy.world · 3 pts · 342d (1 reply)

Why the Chinese phone would work? In Europe they have Google play services and thus are also affected. Maybe it's the Chinese version of those? Not sure if they have Google play services there

01189998819991197253@infosec.pub · 2 pts · 342d

That's a fair point. It depends on the manufacturer. Some brands don't have google play preinstalled. I probably should have mentioned that before, sorry mate. The Xiaomi I had didn't have playstore installed, so I had installed fdroid and aurora store. I'm actually not sure about the future of aurora store with this play store integrity bs.

Natanael@infosec.pub · 1 pts · 342d

Root it

stray@pawb.social · 6 pts · 342d (4 replies)

I'm really confused by this. First, does any phone running a legit copy of Android count as a "certified Android device"?

How can they enforce this for apps not on the play store? Like if I write my own APK will my phone just refuse to run it if I don't go through some paperwork with Google? How does that work?

Like if they're capable of this then why aren't they doing it already to prevent piracy?

BennyTheExplorer@lemmy.world · 11 pts · 342d (2 replies)

To your first question: Google released a list of all "certified" android devices and it's basically every phone from every halfway known brand. So yeah, you will be effected. The only devices unaffected by this would probably be no name Chinese phones (probably also Huawei, but I am not shure) and IOT devices like smart fridges. The best way to avoid this would probably be installing a custom ROM, like Graphene OS.

To your second question, the Android System already controlls the package Installation process, do you know the "Do you want to install this APK" popup, you geht every time you want to install an app outside of the playstore? That's controlled by the android operating systen and by extension Google. In the future, every android apk would have to have a unique "developer key" attached to it and if it isn't verified by google, the android system can just refuse to install the apk. For that, you don't have to go through the playstore, but you still would have to go through a verification process with Google for every app, you make. How that will be implemented in detail is not yet quite known.

Google could have done this much earlier, it isn't hard to implement, but you can't make it in a way that only negatively impacts ransomware or pirated apps. And most sideloading on Android is perfectly legitimate, so the reason, why Google hasn't done it, because there is (deservately) a big pushback from developers.

Ilandar@lemmy.today · 4 pts · 342d

(probably also Huawei, but I am not shure)

Huawei's HarmonyOS NEXT is no longer based on Android code and requires some workarounds to install applications outside of AppGallery (Huawei's app store).

stray@pawb.social · 1 pts · 342d

Thank you.

ReversalHatchery@beehaw.org · 1 pts · 342d

certified android devices are those you can get in most stores. the play store is important for many people, ajd many apps don't work correctly without the google mobile services components, and device makers can only legally install these on their phones if they certify their device. the certification process requires an array of quality controls and restrictions.

How can they enforce this for apps not on the play store?

certified devices will need to integrate an app verifier that will check if an app has been approved by google. the public AOSP project is said to also get this, but anyone basing on it can rip it out or modify it to their advantage. but certified device makers don't have a choice thn to include this restriction.

Like if I write my own APK will my phone just refuse to run it if I don't go through some paperwork with Google?

what we know so far, apps you made can be installed through a development tool. but app store aps like fdroid don't have access to this tool, it's difficult to enable, and somewhat risky too

cupcakezealot@piefed.blahaj.zone · 0 pts · 342d (6 replies)

it will most likely be patched to be able to bypass this; if not just don't update your phone.

possiblylinux127@lemmy.zip · 7 pts · 342d (5 replies)

Those are both really bad options

Use Lineage OS

cupcakezealot@piefed.blahaj.zone · 1 pts · 342d (4 replies)

maybe a dumb question but i've been looking at both lineage and graphene. i currently have a s24+ so obvs i'm going to need a new one anyway to do anything. is one better than the other? i do have google fi (i don't like google services but it's a cheap phone plan compared to verizon). it seems like google fi works fine on graphene with the sandboxed google fi app would it work as good on lineage? and if so what do you think about pixel 9 vs 8? i was leaning for the 8/9a vs the pro since i wanted to keep my s24 just in case but if the a series is that much worse then i'll just bite the bullet.

JustARegularNerd@lemmy.dbzer0.com · 3 pts · 342d (1 reply)

You're probably best making this a post, and also mention what you want out of your phone and why you're currently unhappy with your S24+

cupcakezealot@piefed.blahaj.zone · 2 pts · 341d

thanks will do (i'm not unhappy with the s24; i just read custom roms don't work on them because of oneui changes to the bootloader)

0xD@infosec.pub · 2 pts · 341d

Graphene is by far the most technically secure option and it allows you to choose for yourself how much google you want on your phone. But you need a google phone. Lineage, as far as I know, is "just" a custom ROM with more device flexibility.

My experience with Lineage is very old and I've been running Graphene for more than a year now. So take it with that in mind.

possiblylinux127@lemmy.zip · 1 pts · 342d

I just recently replaced my Moto G7 power which lasted me about 6 years.

Lineage OS for me provides a really nice experience where I'm in control of the device. I do wish Lineage OS had bootloader locking support since many devices do support it. However, I get where the devs are coming from.

rkk@lemmy.world · -15 pts · 343d (2 replies)

I guess if you are using any of these, (which I do and like them a lot) then the chance is high to get this message. I think this is about the russian hunt that came in effect after a US presidental order. No russian devs allowed even in the linux kernel developement. Big cleansing went down to secure IT from sabotage. Google has to oblige.

takeda@lemmy.dbzer0.com · 19 pts · 342d

The same president that paused cybersecurity defense program, the same that first blocked funding for Radio Free Europe and when judge reinstated it he just blocked the satellites over Russia, the same president that suggested to have joint cybersecurity program with Russia?

If anything, this move is there to restrict further access to information for us.

primrosepathspeedrun@anarchist.nexus · 4 pts · 342d

Of course american sabotage is encouraged.

node815@lemmy.world · -25 pts · 343d (7 replies)

I have a bird identifier which listens to the mic when you run it and it easily identifies the birds and it gave me that tonight when I opened it. I'm thinking that F-Droid (where it came from ) may be injecting that in the installs for those devs which have yet agreed to Google's changes or otherwise flat out said they wouldn't. I'm not sure if that would be the case with this app, but since you got the same one I did, it makes me wonder if that is the case.

pulsewidth@lemmy.world · 48 pts · 342d (1 reply)

Let's go ahead and not accuse alternative app stores of injecting code into apps they distribute with absolutely no evidence, hey?

primrosepathspeedrun@anarchist.nexus · 12 pts · 342d

Yes but if we don't accuse them, how will we lock down and own all software so nobody can avoid our malicious code!?

takeda@lemmy.dbzer0.com · 31 pts · 342d (3 replies)

If it is whoBIRD it's the same author.

horseloaf@sh.itjust.works · 2 pts · 342d

Yes, it's whoBIRD

ChaoticNeutralCzech@feddit.org · 1 pts · 342d (1 reply)

And Audio Spectrum Analyzer

takeda@lemmy.dbzer0.com · 2 pts · 342d

Actually it looks like author developed a lot of apps, they are listed on GitHub https://github.com/woheller69/omweather

Tetsuo@jlai.lu · 15 pts · 342d

As far as I know F-Droid are adament about builds being easily to reproduce.

They are the only alternative market that worked for hours for free to come up with a build system that let's you get the same APK with every builds.

So basically you are accusing an alt market that makes it a point that you can recreate any APK on their market. They are the only actually making sure you can check there is nothing "injected" in an APK.