Android Apps Now have Secure ID; Avoid Malicious Installs
Google is to mark Android apps to show they originated in the Google Play store. It's described as a security measure that could be particularly helpful in places with unreliable data connections.
The change is to APK files, which stands for "Android PacKage"; these are files used to install an Android application on an Android device. Whenever you download an app from the Google Play store, it's always an APK file which is installed. However, the format is also the same if the app were to be downloaded from a third party website.
Google is adding security metadata to all APKs distributed on the Google Play store. This small piece of code confirms where the APK originated from, similar to how secure servers use certificates to validate they sites are in fact secure. The idea is that if the file winds up getting to a user via another route (other than the Play store), the device will be able to confirm the app is indeed legitimate.
Apps Can't Be Altered Without Detection
The way the security metadata is built in to the APK file means it won't be possible to take a file from Google Play, alter it (to add malicious elements, for example) and distribute it without devices being able to spot the tampering.
While it might seem an odd move for people who habitually get their Android apps directly from the official Play Store, it does have some uses. In countries with limited or unreliable data plans, many users - with Google's support - share Android apps through peer-to-peer file sharing software. This can mean getting a file in multiple tiny pieces from multiple sources and reassembling it when complete.
Google says the change will mean people getting apps in this way will be able to confirm that the file they wind up with is indeed the same one that was added to the Play Store. (Source: googleblog.com)
Automatic Updates Enabled
Another benefit is that apps that carry the metadata will be eligible to get automatic updates from the Google Play Store.
Not everyone has welcomed the move without reservations, however. Some have raised concerns that the metadata could be used to force users to update to an unwanted new edition of an app, or even that Google or phone manufacturers might one day use the metadata as a way to block devices from running any app that didn't originally come from Google Play. (Source: slashgear.com)
What's Your Opinion?
Do you have an Android device? If so, have you ever obtained an app from a source other than the Google Play store? Is this new move a good balance between security and choice?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Allow APK installs from third parties
As far as I know there is an option in Settings -> Lock Screen and Security -> Unknown sources which allows you to install apps from third parties (that are not from Google Play). With the new APK security metadata, there should also an option from Google to not automatically upgrade apps from unknown sources during the program install. This could be done by keeping track of where the APK originated from (I.E.: not from Google Play's website). This would keep some users happy, though I agree with Google's approach that validated apps are eligible for the automatic upgrades because they almost always fix security issues.