Conversation

Probably meant to be a privacy related change? No more ad networks or apps snooping on package adds? Though, no bueno that this isn't documented or shared anywhere I can find :\
1
Replying to and
For apps targeting API 30+, they're only supposed to be able to see apps in their whitelist unless they request QUERY_ALL_PACKAGES. A lot of changes were made to support this. For now, anyone can use QUERY_ALL_PACKAGES and it's not user-facing yet. It will likely get locked down.
1
Replying to and
It just doesn't make much sense for them to start heavily locking it down when apps can simply drag their heels and avoid adopting API 30+ until it becomes mandatory on the Play Store at the end of next year. This way, at least app manifests will have a list of apps or that perm.
1
Replying to
Makes sense. I was assuming there will be a big wave of breakages when they start forcing people to provide bundles vs apks, leading to all these have a hard depricated date as well
1
Replying to and
Not all app developers want to have Google-managed signing keys. There's substantial pushback against this because of them tying it to app signing, and they didn't really need to do that. They could have the SDK run bundletool to generate the same set of apks that Play does.
1
Replying to
Completely agree. It's definitely getting ties to many things, had many discussions with devs who /want/ those features and don't care about the key risk. Most don't guard the keys much anyway, is what I've seen... Will be interesting to see how it plays out
1
Show replies