{"id":18131,"date":"2026-07-23T11:02:28","date_gmt":"2026-07-23T18:02:28","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18131"},"modified":"2026-07-23T11:02:28","modified_gmt":"2026-07-23T18:02:28","slug":"developer-verification-google-android","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/07\/23\/developer-verification-google-android\/","title":{"rendered":"Developer Verification &#8211; Google Android"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A good post on Google&#8217;s Android developer verification, and how this will affect installing apps (sideloading). It&#8217;s interesting that it&#8217;s a separate package from the Play Store. It doesn&#8217;t affect LOS, but if it is one day rolled into the Play Store, it might possibly get implemented in a GApps package, though unlikely. And LOS would disable it along with other annoying Play Store OTA update implementations. Consequently, this isn&#8217;t a random initiative, as Windows, macOS and iOS are moving in similar ways to limit what software you can install on your computer via a similar mechanism, and I believe it ties into the age verification and digital ID laws to protect the children, leading to agentic AI spyware being required on computers to access the internet. But like Flock cameras, people are resisting. And it is definitely time to drop all the closed source software implementations and go opensource, especially your operating system. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/lineageos.org\/Developer-Verification\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/lineageos.org\/Developer-Verification\/<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_69ecb340-8096-448f-a53b-112541137133\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"913\" height=\"311\" src=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-45.png\" alt=\"\" class=\"wp-image-18129\" srcset=\"https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-45.png 913w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-45-300x102.png 300w, https:\/\/jasonsblog.ddns.net\/wp-content\/uploads\/2026\/07\/image-45-768x262.png 768w\" sizes=\"auto, (max-width: 913px) 100vw, 913px\" \/><\/figure>\n\n\n\n<h6 class=\"wp-block-heading\">Written on July 4, 2026 by Nolen Johnson (npjohnson)<\/h6>\n\n\n\n<h2 class=\"wp-block-heading\">Developer Verification: What it is, and how it affects you<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What is Developer Verification?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/developer.android.com\/developer-verification\" target=\"_blank\" rel=\"noreferrer noopener\">Android Developer Verification<\/a> is Google\u2019s requirement, rolling out regionally starting September 2026 (global by 2027), that apps be registered to an identity-verified developer before they can be installed on a \u201ccertified\u201d Android device, meaning any device shipping Google Play, Play Services, and the rest of the Google Mobile Services (GMS) suite. This applies regardless of the installation source; whether it is the Play Store, third-party stores, or direct APK sideload.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How does this affect LineageOS and its users?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">TL;DR: This will not affect LineageOS directly. But it <em>may<\/em> affect users running the stock ROM on their device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the <a href=\"https:\/\/wiki.lineageos.org\/glossary\/#stock-rom\" target=\"_blank\" rel=\"noreferrer noopener\">stock ROM<\/a> is installed on a certified device, package installation will be gated by the package \u201cAndroidDeveloperVerification\u201d, which will check against the developer\u2019s registered\/verified signing identity. Google is providing an <a href=\"https:\/\/android-developers.googleblog.com\/2026\/03\/android-developer-verification.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u201cadvanced flow\u201d<\/a> opt in for power users to install unverified-developer apps after acknowledging risk and waiting a full day. This is a one-time toggle to disable verification, not something you have to redo every time you wish to install a package.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why is Google doing this?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We don\u2019t actually know. What we have is Google\u2019s stated reasoning, and even if you\u2019re skeptical of the outcome, it\u2019s worth taking at face value.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google\u2019s public justification is fraud and malware prevention: they claim <a href=\"https:\/\/www.androidauthority.com\/android-developer-verification-requirements-3590911\/\" target=\"_blank\" rel=\"noreferrer noopener\">over 50x more malware<\/a> comes from sideloaded\/internet sources than from the Play Store, and that anonymous, disposable developer identities let bad actors get caught, rebrand, and redistribute the same malware in hours. They\u2019ve also pointed to regulatory pressure (the EU\u2019s DSA, India\u2019s IT Rules, etc.) pushing platforms toward developer traceability generally and framed the rollout order (fraud-heavy markets first: Brazil, Indonesia, Singapore, Thailand) as evidence the fraud rationale is the actual driver rather than a pretext.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s the claim. Whether or not it\u2019s the whole story is a separate question.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Critics such as F-Droid, EFF, and <a href=\"https:\/\/keepandroidopen.org\" target=\"_blank\" rel=\"noreferrer noopener\">\u201cKeep Android Open\u201d<\/a> point out that this also happens to route every install path through Google-controlled infrastructure, hands Google a kill switch over any app or developer worldwide, and arrives shortly after Google\u2019s antitrust lawsuits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both things can be true at once: real fraud is a problem and the restriction of developers is a convenient side effect of solving it this way &#8211; and we\u2019re not in a position to pretend we know Google\u2019s internal reasoning. We\u2019re just telling you what they\u2019ve said and what it changes; you can weigh the \u201cwhy\u201d yourself.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What are we going to do about it?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This changes <em>nothing<\/em> for LineageOS, so we don\u2019t need to take any direct actions. This isn\u2019t a switch Google flips on our behalf, it is enforced by a dedicated application called \u201cAndroidDeveloperVerification\u201d (<code>com.google.android.verifier<\/code>), which the OS is then told is <em>the<\/em> designated verification gatekeeper. For curious developers or other ROM maintainers, it is wired up through two framework overlays, <code>config_developerVerificationServiceProviderPackageName<\/code> and <code>config_developerVerificationPolicyDelegatePackageName<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is a different situation from <a href=\"https:\/\/wiki.lineageos.org\/quirks\/snet\/\" target=\"_blank\" rel=\"noreferrer noopener\">Play Integrity<\/a>: Play Integrity\u2019s attestation logic lives inside Play Services itself, and apps call into it directly for attestation. Developer Verification, by contrast, is its own standalone app that the frameworks are pointed at as a provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have not ever, nor do we intend to ever, ship GMS. That means we\u2019re not subject to the Google Test Suite (GTS) certification Google apps are required to pass. Therefore we have no obligation to install \u201cAndroidDeveloperVerification\u201d or point the aforementioned configurations (overlays) at it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What can you do about it?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you sideload <a href=\"https:\/\/wiki.lineageos.org\/glossary\/#gapps\" target=\"_blank\" rel=\"noreferrer noopener\">GApps packages<\/a>, be aware that a GApps package could choose to bundle \u201cAndroidDeveloperVerification\u201d and enable it. We\u2019re not aware of any reason an aftermarket GApps package would opt into that, since doing so would restrict what its own users can sideload. If your GApps provider ever does, you can simply switch to a different package.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">So it\u2019s a separate app\u2026 for now. Could Google move the functionality into Play Services?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">They absolutely could. If that happens, we\u2019ll do what we already do for a number of annoying Play Services-provided <a href=\"https:\/\/github.com\/LineageOS\/android_vendor_lineage\/blob\/lineage-23.2\/prebuilt\/common\/etc\/lineage-component-overrides.xml\" target=\"_blank\" rel=\"noreferrer noopener\">over-the-air update implementations<\/a>: disable it globally.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What have we (LineageOS) done about all of this?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We have signed the <a href=\"https:\/\/keepandroidopen.org\" target=\"_blank\" rel=\"noreferrer noopener\">\u201cKeep Android Open\u201d<\/a> petition alongside a number of other FOSS foundations and organizations with the hope of supporting independent developers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The LineageOS Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A good post on Google&#8217;s Android developer verification, and how this will affect installing apps (sideloading). It&#8217;s interesting that it&#8217;s a separate package from the Play Store. It doesn&#8217;t affect LOS, but if it is one day rolled into the Play Store, it might possibly get implemented in a GApps package, though unlikely. And LOS [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-18131","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18131"}],"version-history":[{"count":2,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18131\/revisions"}],"predecessor-version":[{"id":18151,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18131\/revisions\/18151"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}