Google Play Protect now asks for PIN in order to sideload some Android apps

19 pointsposted 10 hours ago
by thunderbong

19 Comments

hnburnsy

an hour ago

Does it do this if Play Protect is off. Just waiting for my banking app to not work because PlayProtect is off...

Play Protect verdict API

NO_ISSUES Play Protect is turned on and did not find any app issues on the device.

NO_DATA Play Protect is turned on but no scan has been performed yet. The device or the Play Store app may have been recently reset.

POSSIBLE_RISK Play Protect is turned off.

ksp-atlas

40 minutes ago

I've experienced this, I really wish sandboxed play services were a thing outside grapheneOS (which is very device limited)

kelnos

8 hours ago

That seems... fine? I think there's plenty to complain about on Android (or on iOS), but this doesn't feel like a big deal to me.

greatgib

5 hours ago

No, this is not fine. The is again another barrier to ensure that things are more difficult and scary when you don't use the official play store. It's an anticompetitive behavior again.

You are already logged on your phone interface when you try to install so this additional check is excessive. I could have understood to have it just in the case that you don't protect your phone access with a pin.

Also, to not be anticompetitive, the behavior should be the same when using the play store or not. Like asking your pin to use the playstore like what is done in iOS. Even if it sucks if you want my opinion.

iszomer

4 hours ago

Every time I want to install a package off AUR I have to use sudo preceding the command. And people want to whine about that.. /shrug

greatgib

17 minutes ago

In addition with other comments, you are also free to disable this behavior, you are also free to install an alternative "package manager" that will not require a sudo for each package installation ...

And out of the box, you can also install apps in our own user account without needing a sudo.

yjftsjthsd-h

3 hours ago

You also have to use sudo to install from official Arch repos. It would be fine if the Play store required a PIN too.

dmm

5 hours ago

It depends on the implementation. Prompting for a pin for a one-time install of a downloaded apk is not a big deal.

If it requires a pin every time you install or upgrade from fdroid that would be really excessive and actively discouraging alternative app stores.

hulitu

5 hours ago

> but this doesn't feel like a big deal to me.

Just normal enshitification. Nothing to see here. /s

(maybe Google shall try to run Play Protect on the Play Store, i've heard that there is a lot of malware there)

appendix-rock

7 hours ago

[flagged]

theshrike79

7 hours ago

It's a sign of the modern times. Something being different than what Main Characters are used to are always bad and should be changed.

Have they considered changing the way they do things? No.

The world must change to the way they think is best.

Vuska

5 hours ago

This is such a myopic view. The average smartphone user may not immediately understand why increasingly locked down and user hostile devices are bad, but it does not negate the fact they are.

warmfusion

6 hours ago

Seems like a good idea to me. Means if anyone gains access to your device while its unlocked, its less easy to side-load nefarious things while the device is out of your control.

cute_boi

5 hours ago

yes, and it should ask pin while installing from google play too.

xnzakg

9 hours ago

I mean, in a way this really wouldn't be that different from having to authenticate when installing software on a desktop OS if this was required for all apps.

And AFAIK Apple already requires you to confirm with your unlock method when installing apps from the App Store.

Honestly I wouldn't mind enabling requiring my pin for all app installs.

horsawlarway

2 hours ago

This seems reasonable to me. Plenty of malicious apps on the play store too

Even things that aren't directly malware can be malicious if installed unknowingly on someone else's phone, ex - child-lock/tracking/recording apps. It also would allow parents to pass a phone to kids and not have them add junk.

Would love to just have all app installs require auth.

joemazerino

an hour ago

To even enable sideloading you have to input your bio/PIN (via developer options).

Mindwipe

6 hours ago

Seems fine as long as the same is done for apps from Google Play too.

Which of course it isn't.

nhinck2

9 hours ago

Doesn't seem egregious.