Android devs prepare to hand over app-signing keys to Google from August
- Reference: 1625144405
- News link: https://www.theregister.co.uk/2021/07/01/android_app_bundle/
- Source link:
Dom Elliott, Google Play product manager [1]said that from next month: "This will replace the APK as the standard publishing format."
The APK (Android Package) format will still be used on the device, but the idea of the App Bundle is that when a device requests the installer from Google Play, it will receive an APK optimised for the device rather than a universal APK prepared by the developer.
[2]
App Bundles also enable additional features, described [3]here . On-demand delivery lets developers offer feature modules which are downloaded as required, reducing the size of the application for those who do not use those features.
[4]
[5]
Conditional delivery is a variation on the same theme, where certain modules may be installed only in certain countries, or if a device has certain hardware features.
Instant delivery lets developers configure a small base module and feature module (below 10MB) that can be tried by users without a full install.
[6]
Applications requiring large assets (generally games) formerly used OBB (Opaque Binary Blob) expansion files, but can now use Play Asset Delivery, with assets hosted by Google, offering several delivery modes. Play Asset Delivery is more secure, since OBBs are not signed.
[7]Samsung commits to 5 years of Android updates... for its enterprise smartphone users at least
[8]Good news: Google no longer requires publishers to use the AMP format. Bad news: What replaces it might be worse
[9]Google creates 'optimized' Android for one smartphone — that will only be sold in India
[10]What you need to know about Microsoft Windows 11: It will run Android apps
Elliott called this "Modern Android Distribution" and said the "majority of the top 1,000 apps and games on Google Play" already use App Bundles.
There is one aspect giving developers pause for thought, though, which is that using App Bundles requires enrolling in a scheme called [11]Play App Signing .
"With Play App Signing, Google manages and protects your app's signing key for you and uses it to sign your APKs for distribution," the docs explained. This is a departure from the old APK submission, where developers can sign with their own key.
Google's [12]documentation for signing with a developer-managed key is full of warnings. "If you lose or misplace your key, you will not be able to publish updates to your existing app. You cannot regenerate a previously generated key. Your reputation as a developer entity depends on you securing your app signing key properly, at all times, until the key is expired," it says.
[13]
On the other hand, using Play App Signing means [14]agreeing to give existing app-signing keys to Google and that Google can generate APKs, modify them, and sign them on the developer's behalf.
Google has said: "Your keys are stored on the same infrastructure that Google uses to store its own keys. Keys are protected by Google's Key Management Service."
Keep a copy
There is an option to keep a copy of the signing key locally, provided that it is also given to Google.
The Android App Bundle is a unique feature of Google's Play Store. Developers who wish to distribute through other channels, such as other app stores or direct downloads for users who allow installation from "unknown sources," can still do so.
It is possible to download distribution APKs from the Play Store, or to build APKs for distribution elsewhere, and to sign them with either the same key used by Google (if a copy is retained) or with a different key.
Google also has an optional feature intended to reassure developers, called [15]Code transparency for app bundles. This uses a second signing key, held only by the developer, and can be used to verify that the APK delivered by the Play Store matches what the developer built, subject to some limitations.
This verification is "used solely for the purpose of inspection by developers and end users" – it is not enforced by Android or by Google in any other way.
Another aspect of "Modern Android Distribution" is that it underlines the advantages Google has in controlling app delivery on what is, after all, its own platform.
Efforts such as those by Microsoft/Amazon to enable Android apps to run on Windows 11 cannot use Android App Bundles or any Google Play Services, so they have to first persuade developers to support their Store as well as the Play Store, and second, to provide alternatives to any Play Services APIs that the app requires. ®
Get our [16]Tech Resources
[1] https://android-developers.googleblog.com/2021/06/the-future-of-android-app-bundles-is.html
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YN3gsNX1lI35ERHHODNtdgAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://developer.android.com/guide/playcore/feature-delivery
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YN3gsNX1lI35ERHHODNtdgAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YN3gsNX1lI35ERHHODNtdgAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YN3gsNX1lI35ERHHODNtdgAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/06/29/samsung_five_year_android/
[8] https://www.theregister.com/2021/06/28/google_amp_core_web_vitals/
[9] https://www.theregister.com/2021/06/25/google_jiophone_next/
[10] https://www.theregister.com/2021/06/24/microsoft_windows_11/
[11] https://support.google.com/googleplay/android-developer/answer/9842756?hl=en&ref_topic=7072031
[12] https://developer.android.com/studio/publish/app-signing#opt-out
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YN3gsNX1lI35ERHHODNtdgAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://play.google.com/about/play-app-signing-terms/
[15] https://developer.android.com/guide/app-bundle/code-transparency
[16] https://whitepapers.theregister.com/
Re: End of privacy
One key for the Application.
One key for the Encryption.
It's only the application key that they are asking for.....;-).
Re: End of privacy
Sure, and the application key gives them the power to compile whatever the hell they want and call it your app.
If they want to pull a Sourceforge style stunt and add advertising, they can do that. If they want to weaken any encryption, they can do that. If they want to install something that pops up a flag when certain people use the app, they can do that.
Re: End of privacy
"...they can will...they can will...they can will"
FTFY
Hey friends!! Welcome to the new USA government surveillance program!! Courtesy of Google!! Please hand over your keys, we got you from here.
In all seriousness, the USA gov. was probably already hijacking the keys, but that pesky word "illegal" was problematic... not anymore.
Limitations...
To be fair to Google (!), it does seem that they are technical limitations, such as being unable to guarantee shared library code.
But you can't trust an organization that is prepared to let Google sign on their behalf. Non-repudiation is a central tenet of digital signatures.
I want to see app devs boast about 'code transparency". Indeed it would be good to see devs implementing their own internal authentication mechanisms...
On to F-Droid
Well, I've been putting off moving to F-Droid long enough... guess I better get off my butt.
Re: On to F-Droid
Why not just host packages on your own sales page (or, if open-source, github) like... well, proper modern software?
I never quite understood why app developers flocked to Google Play so easily. I even fell for it for a while until I started to realize that it was providing a worse experience for my users.
Re: On to F-Droid
Because Google Play is "the place" to distribute your apps. It's the only place where the phone doesn't throw a shit-fit and make you jump through half a dozen hoops when you try to install something.
At least it's not as bad as Apple, where you have to jailbreak the phone to install from anywhere other than the Apple App Store.
Because phone apps aren't really proper modern software. For Android, I'm stuck using their IDE (which isn't bad, but that's beside the point) and I have a choice of 2 languages (Java or Kotlin) or the pain of writing a C library.
F-Droid is basically a github for Android. They package your app and set things up so the phone can easily download and install it.
None of this sounds like a good idea
Literally handing the keys to the kingdom over. For what? The ability to make dynamic apk's, making app archiving even harder than it currently is, and non-install trial versions, in a world where data and bandwidth are just going up.
Looks more like (Yet Another) Google power grab from here.
Re: None of this sounds like a good idea
Fortunately all of what you said is wrong.
AABs mean smaller download sizes for ALL users so data and bandwidth are saved for everyone. All my apps had download sizes reduced by over 50% when I moved to AAB distribution last year and none of them use optional features or trial versions.
With the old APK you are downloading language files for languages you don't understand, files for resolutions your device doesn't support and potentially ABIs for an entirely different chip architecture. With AAB the dev uploads all these things in a single AAB, Google then splits it apart into individual APKs for each language, resolution, ABI, etc and only serves the user exactly what they need. So you don't get x86 code on your ARM phone or resources for 50 languages when you only speak one. It really is a good thing.
Dear Valued Android Developer...
Dear Valued Android Developer,
We've analysed your app $app-name to see how well it shows adverts to your users. We feel that your current advert display rate of 0 is a little below what our extensive market research has shown to be optimal, which is 15,000 per second per user. We've taken the opportunity to amend your code and have re-signed and re-released $app-name for you.
To give your users a chance to fully appreciate the benefits of the new version, we've also locked the app against further changes for 28 days. If you wish to make any changes you'll need to wait for the lock period to expire.
Google Developer Support Program
Customer Unification and Networking Team at it again
Looks like Google's CUNT (Customer Unification and Networking Team) is hard at work again thinking of fresh ways to shaft their users.
I migrate my APKs between phones
But if the binaries I get are "optimized for my device" from here on, then I guess that's the end of that. Thank you so much, Google.
Losses accumulate
" it will receive an APK optimised for the device rather than a universal APK prepared by the developer. "
Not only loss of control over signing - now we've lost control over the code as well.
Why doesn't Goooooooooooooooooooooooogle just create all the apps itself? Lack of talent? Shhhhhhhhhhhhhhhhhhhhh!!
End of privacy
So it appears that this is the way governments are going to tackle the end to end encryption problem.
Now the target of surveillance will have a Play Store update waiting for them to install a special version of Telegram or Signal and it will be signed with the developer key.
Well played, well played.
> Google also has an optional feature intended to reassure developers, called Code transparency for app bundles. This uses a second signing key, held only by the developer, and can be used to verify that the APK delivered by the Play Store matches what the developer built, _subject to some limitations_.
Of course :-)