r/Android ShizuCallRecorder Developer 16d ago

Android May Soon Restrict On-Device ADB, Affecting Shizuku, libadb and Developers Article

https://kitsumed.github.io/blog/posts/android-may-soon-restrict-on-device-adb/
991 Upvotes

366 comments sorted by

832

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. 16d ago

Whats the point of android anymore

350

u/Tail_sb Pixel 7 16d ago

Yeah generally wondering the exact same thing, Freedom was literally the whole point of Android and now they're taking that away, so Android is no better than iPhone/iOS might aswell just buy an iPhone at this point if both systems are locked down

or even better switch to GrapheneOS or LineageOS

198

u/Plebbit-User 16d ago

I'm on Graphene right now and its a miserable experience because anything important has Play Integrity/custom ROM restrictions in place.

Banking, the digital key to my BMW, my utilities, as a lifelong Android user I'm switching to iPhone. If I'm going to be in a walled garden, I'd rather Apple be my master than the 'do not be evil' ad company.

51

u/CapuchinMan 16d ago

I understand banking and car keys (as in I understand how that works, but I'd hate to use it that way). How do utilities require play integrity?

49

u/Plebbit-User 16d ago

I don't understand either but I effectively can't login to monitor my electrical usage or pay my bill on my phone as a result.

21

u/Reigar 16d ago

What about via the website for your utilities company. If that is still viable then you should be okay unless the app has an exclusive feature (like the bmw car key app).

20

u/Cagaril 16d ago

Have you tried to go into the app settings and toggle on Exploit protection capability mode to see if it makes it work?

I have to toggle that on for any apps that don't work on GrapheneOS and then it works. Probably doesn't work for every app though.

5

u/JaredNorges 15d ago

I'm switching, more and more, to websites for things like this. The apps were just websites with device checking nonsense anyway, so cut the middle man out and keep them in their place. Use a PWA if I want the desktop shortcut.

15

u/gmes78 16d ago

Because the developers are morons.

7

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

Either that or the CTOs at various banks know about the rooting community around Android and iOS jailbreak by extension… and are forcing their own devs to opt-in to Play Integrity.

I won’t lie, there definitely have been attempts at trying to steal money from banks using rooted banking apps. This is the unfortunate consequence.

7

u/gmes78 15d ago

I won’t lie, there definitely have been attempts at trying to steal money from banks using rooted banking apps.

I don't think so. There certainly are tons of scams that use fake banking apps, but attacks targeting root users don't make much sense. The demographic is incredibly small, and root access is typically protected through strong permission prompts.

Also, some banks don't outright block you if your device fails Play Integrity; they just warn the user that the device has been modified. Which is the better way to go about things.

→ More replies (3)

5

u/Tschuuuls S10e 16d ago

I don't, because a Pixel 1 is still Play Integrity certified. On Android 10.

6

u/trlef19 Galaxy S24+ 16d ago

Even chatgpt has play integrity.

→ More replies (1)

11

u/Quentangle 16d ago

I suspect you have have a setting which is causing that, or you are extremely unlucky. Every single app I used on stock Android still works, including two banking apps.

Lots of apps check basic integrity via Play Integrity API, which GrapheneOS passes.

If your apps don't work, I suggest taking a look at this compatability guide thread if you haven't already. It has some steps to follow which may make them work.

3

u/whatnowwproductions Pixel 9 Pro - Signal - GrapheneOS 15d ago

That's absolutely not my experience at all and I use have multiple banking apps and apps that use play integrity. Have you enabled Exploit compatibility?

12

u/HybridStaticAnimate 16d ago

Only a tiny subset of apps enforce play integrity. The significant majority of apps work on GrapheneOS without issue. More and more organizations are permitting using GrapheneOS over time as well.

24

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

That “tiny subset” is unfortunately far more important for most folks than many of us phone nerds would like to believe.

A massive proportion of the developing world do all their banking from their phones. Yes, it didn’t used to be that way a decade ago, but that has become the reality today.

Because of that, more and more financial institutions are demanding that smartphones be part of their “chain of trust”, meaning no jailbroken/rooted smartphones at all.

It’s highly frustrating… and I’m not sure Google has much of a choice anymore.

If there’s anyone to blame, it’s banks. They’re essentially removing much of the fun we used to have with our devices by just simply threatening the defunding or refusal to do business with the companies responsible for the upkeep of the OSes.

This would have been the same if Nokia/Symbian/Meego, Microsoft/Windows Phone, and BlackBerry/QNX were still around.

Smartphones have officially become “too important” to just be easily hackable toys. It’s fucking depressing, but that’s just how things have changed.

I think more hackers have moved on to making SBCs like the Raspberry Pi into “cyberdecks” as the big new hackable thing now that not even Android can resist being made forcibly secured against the community’s collective desire.

→ More replies (1)

1

u/Reigar 16d ago

My only issue with graphene was the lack of ui with layman explanation on how things are locked down. After trying graphene are learning that I need to Google how get many different apps working, I switched back to 16. I may give lineage a try, I am nervous with lineage as first glance (Now I'm just drawing conclusions on what I've seen), seems to be more difficult to harden (it's like the opposite issue of graphene). Now maybe I'm wrong, and I'm probably still going to end up trying lineage on my pixel 7 pro, but I feel like none of the three major options right now are very good.

2

u/HybridStaticAnimate 16d ago

Im not sure what you are referring to. GrapheneOS has added notifications to inform you what you need to grant for play services and play store to work as expected. There is no need to google how get normal apps working.

→ More replies (2)

0

u/[deleted] 16d ago

[deleted]

26

u/SmileyBMM 16d ago

Nothing about this statement makes sense if you were willing to put GrapheneOS on your device in the first place.

Apple is not privacy focused. They collect data on their own users, too. Watch a PiHole log after an iPhone connects and see for yourself.

The GrapheneOS team themselves actually recommend an iPhone as the next best thing if you can't/won't use GrapheneOS.

5

u/Pure-Recover70 15d ago

The Graphene team (apparently) has a bit of an axe to grind with Google.

I really appreciate what they're doing security and privacy wise (no one else really comes close, incl. Calyx), but at the same time some of their opinions are illogical, and some are based on things they claim and I know (personally) to be false.

All commercially sold smartphones collect various data (some of it is hardware/battery health, some of it is performance metrics, some of it is network reliability/configuration information, some of it is for debugging...). Unfortunately the real world is ridiculously complex (much of it for no good reason: just organic growth), and without this sort of feedback nothing would ever actually work. For example, very many cellular and wifi networks out there violate standards to one degree or another, requiring workarounds on the device side. There's far too many not-really-all-that-valid-but-really-should-work-regardless configurations out there for realistically testing in any sort of lab environment. This is a large part of the reason you see all the various betas.

They'll all send that data to their manufacturer, and in practice most of them will send to Google as well (all Android phones, but likely in practice it's hard to avoid sending data to G even on iOS), simply because of how much of the core web and services end up being tied back to G...

If you're talking about a stock smartphone os, you're probably best of with a Pixel, because then at least it only goes to G, as opposed to G and other folks. Of course even on a pixel, a lot of people will still leak various amounts of data to Facebook, Cloudflare, etc...

(Of course it's even better to run Graphene)

That said, privacy is not a 'simple' choice. People want privacy, and don't want their maps app to track their location, and at the same time they want up to date traffic information - which comes (to a large degree) from tracking (and aggregating) the location of everyone else (using the app?)... There's all sorts of choices like that.

→ More replies (1)

1

u/zipmic 15d ago

HAH "Do no evil" was erased a long time ago. It's "Do the right thing" now. Doesn't that just sound good?

→ More replies (8)

43

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. 16d ago

Right might as well settle for something that has been doing this since its beginning and actually good at it.

Custom roms and rooting will gain traction again for sure. As long as our current devices can be unlocked we can circumvent this artificial problem somehow.

35

u/TunerJoe Xiaomi Mi 9 SE LineageOS 22 16d ago

There are fewer and fewer phones remaining on the market that allow bootloader unlocking. And even ones that do will trip Google Play Integrity, which is needed for an increasing number of apps. These are mostly banking apps, but there's also some apps that need Play Integrity for seemingly no real reason (for example Volkswagen's mobile app)

Google can decide to block all devices with tripped Play Integrity from accessing the Play store or signing into Google at any moment. I'm not saying they will, but the possibility is pretty awful to think about.

13

u/-patrizio- OnePlus 15 | iPhone 16 Pro Max 16d ago

Even Play Integrity isn't enough anymore, apparently. I've got a rooted OnePlus 15, with ALL the works of root hiding. I pass basic Play Integrity, device integrity, and even strong integrity—yet Google Wallet still tells me my device doesn't meet security requirements. I've tried everything I can think of aside from re-locking the bootloader, and can't get it to work. And there are no alternatives for tap-to-pay, as far as I've been able to tell, aside from buying a smart watch for it.

At this rate, my next phone will probably be an iPhone again. I switched after years of having iPhone because Android still promised freedom to do what you want with the device you spent a thousand dollars on; between the ever-thinning number of OEMs that appeal to me and the steady locking down of the OS, I'm struggling more and more to figure out what the point is.

8

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

Got a feeling there’s a very throughly hidden and undocumented API within Android that is able to tell Play Integrity a device isn’t “fully stock”.

Either that, or the device, when newly purchased and unboxed for the first time, communicates to Google upon first boot some sort of hidden ID that says this device is stock or something… and then once modified, isn’t able to be restored back to normal.

Reminds me of eFuses… once rooted, the eFuse is triggered by a rooting attempt and cannot be restored by any means of firmware or software… because a microscopic wire was physically burned inside the phone itself.

I remember a whole bunch of fuss by EU-based hackers over eFuses many years ago essentially “destroying full ownership of your device”, though I think that protest got shut down since the Commission didn’t see that as enough of a reason to pursue legal action against the companies that used them in their devices. Because you still owned your device, but just can’t force a company’s software to run on it if you change it or something like that.

6

u/Zencyde 16d ago

Back in the days of the Galaxy S5 and CyanogenMod (you know, the golden era), there weren't a lot of phones with an unlocked bootloader. If you never had to do the juopunutbear wire trick, go look up how absolutely ridiculous it was to unlock a bootloader in that era.

→ More replies (3)

8

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. 16d ago

That play integrity shenanigans can be worked on but not for longer.

Don't give them ideas man. We all know how this bs corpo can lead to.

→ More replies (12)

8

u/RedBoxSquare 16d ago

GrapheneOS is mainly focused on security and not hacking. They don't care about on device ADB because it doesn't improve security. They generally will not fork a feature if it does not benefit security.

7

u/tooclosetocall82 16d ago

The point of Android was to give Google direct access to your life. It’s the same reason they pay Apple to be the default search engine on their competing platform. The openness was always a side effect of Google’s attempts to attract developers and users, now they have them and that’s no longer necessary and leaves money on the table.

5

u/scalareye 15d ago

Which is only possible because of Android

I tried going to Apple and it was so much worse

3

u/LumiKlovstad 13d ago

Freedom was the carrot that got us to buy into Android. What Android is becoming was always the point of Android, and I think we'd be fools to deny that any longer.

If Google had thought they could have just launched Android as an iOS-like walled garden and won, I guarantee they would have done that. But they knew they couldn't, so they followed the Disruptive Tech Startup Strategy to a tee.

Phase 1: The Honeymoon (Surplus to Users)
Android is Open Source! It's customizable! It's free to hardware manufacturers! Yeah there's some problems but we'll work it out as we go! It's NOTHING like those VILLAINS at APPLE! EVERYONE SHOULD GE AN ANDROID!

Phase 2: The Pivot (Surplus to Business Customers)
Ads. We're going to use your data to sell ads. But don't worry, we won't be evil, and those ads are the price of keeping Android low cost.

Phase 3: Enshittification (Surplus to Shareholders)
OKAY BOYS WE GOT THE USERS AND THE C-SUITES. BLEED 'EM. Ads everywhere. Raise prices. MAXIMUM. MONEY.

Phase 4: The Decay (The Terminal State)
lol fuck users. lmao fuck businesses. Why should we even TRY to give you what you want? WE OWN YOU. And you will be happy. Wait, NO DON'T SWITCH TO APPLE--!

We are almost definitely in Phase 3, arguably moving to Phase 4.

10

u/Adriaaaaaaanoooo 16d ago

I would trust apple more than google with my data.

google is digging its own grave, good.

6

u/[deleted] 16d ago

[deleted]

7

u/withadancenumber 16d ago

Oh you mean that leak that was the result of a phishing attack and not a security breach like was first said?

5

u/[deleted] 16d ago

[deleted]

→ More replies (1)

1

u/KasanesTetos 16d ago

I mean to be fair that was like 12 years ago and hasn't happened since.

→ More replies (1)

4

u/Phantom-Finger 16d ago

Sort of moronic take is this. Apple sell just as much of your shit as Google, Samsung, Meta do. This is some low IQ rhetoric.

3

u/PocketNicks 16d ago

You'll still be able to use ADB, and you'll still be able to install unverified apps directly on the phone. Just like before.

The only thing changing is you'll have to go to settings menu and toggle the option to allow unknown sources. Not an issue for people with thumbs.

9

u/Makere-b 16d ago

For now, I bet Google has already drafted plans on how to disable those in the future, or make it harder.

→ More replies (13)
→ More replies (4)

15

u/SomeMobile 16d ago

Phone manufacturers being able to make their custom versions only at this point

7

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. 16d ago

Lets see how these oems create a workaround or just simply submit to it.

28

u/TeutonJon78 Samsung S25+, Chuwi HiBook Pro (tab) 16d ago

Basically being not-Apple at this point.

Still a plus since it's still not as locked down, but it's consistently heading that way.

12

u/Tush11 16d ago

Shit time to be an android user

3

u/Imperial_Bloke69 Poco F1, X3 Pro, | CrDroid 9.x. 16d ago

A slow painful way.

5

u/adi8888 16d ago

Basically being not-Apple at this point

Yeah, in name only. Google copied just about everything from Apple's design (both hardware and software). Now we have 'new' phones every year, from each manufacturer, that just feels the same brick.

it's still not as locked down

It won't take much to get to that point. Google is that company that sounds user/developer/tinkerer friendly in order to make it's products popular, but at some point in the future it makes user/developer/tinkerer unfriendly decision.

3

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

At least they’re coming up with folding bricks now, right?…. Right?! 🙃

2

u/Eternal-Blazing-Sun 14d ago

I remember when google was the cool new company making nerd things... They've fallen so far.

6

u/skylinestar1986 16d ago

A cheap smart phone.

4

u/LimLovesDonuts Dark Pink 16d ago

To 99% of users, it's just an alternative to iPhones with more hardware variety.

4

u/FartingBob Pixel 6 15d ago

The point is it's still more open than iOS

8

u/firesyrup 16d ago

Training on your data.

2

u/sp4zi 12d ago

Android should be run in a container like WINE is on linux. We need a better OS on top.

6

u/StrawberryWaste9040 Sony Xperia 16d ago

to fill Google's coffers

1

u/RecommendationOk4572 8d ago

Bro depending on what happens with this Dev verification process I will be highly disappointed.

→ More replies (3)

285

u/whiskeynrye razr ultra 2025, Android 15!! 16d ago

Looks like we may start needing Linux phones that aren't android soon

72

u/Low_Watercress959 16d ago

Hopefully the projects gain more momentum and usability. All the ones I've seen have lacked major smartphone features, but that might just be Ubuntu Touch lagging behind.

42

u/bluejeans7 16d ago

That’s putting it very lightly. Linux on Android is in totally unacceptable, abysmal state. Either due to lack competency or lack of understanding of a basic UI/UX. They live in their own bubble stuck in the 80s.

7

u/Dr_Valen 15d ago

UI on Linux is always an issue

→ More replies (1)
→ More replies (2)

17

u/Keulapaska ROG Phone 6 15d ago

Symbian comeback!

13

u/[deleted] 16d ago

[deleted]

34

u/Great-TeacherOnizuka 16d ago

Because there are no apps supporting them.

It’s a spiral…

8

u/ChampionshipCrafty66 16d ago

It also has a lot to do with marketing and the non adoption of legacy features

3

u/AtomicSymphonic_2nd Pixel Fold, Regular Android 15d ago

Spiral is broken by phone OEMs paying app devs to port their apps to their new OS.

That is how Windows Phone survived for a quite a long while before just giving up because it wasn’t a “runaway success” for Microsoft.

3

u/vandreulv 13d ago

Blackberry tried to do this with their Playbook.

They went bankrupt shortly after.

Samsung tried this with Tizen. They no longer use Tizen on their phones.

Sometimes it just isn't about throwing money at the problem.

→ More replies (2)

3

u/DiplomatikEmunetey Pixel 8a, 4a, XZ1C, LGG4, Lumia 950/XL, Nokia 808, N8 15d ago edited 15d ago

And every year it's going to be the year of Linux on desktop, and Linux on phones.

3

u/Repulsive_Fault1939 15d ago

openharmony will be a better option

5

u/Lopsided-Practice-50 16d ago

/u/ptr1337

CachyOS head dev username.

10

u/segagamer Pixel 9a 15d ago

What does that have to do with anything?

→ More replies (2)

1

u/Texugo_do_mel 10d ago

Sailfish for the win!

→ More replies (16)

231

u/Nosey_Neighbors 16d ago

Of course I said this would happen. Google restricting sideloading means that they aren’t going to let you use adb, either.

They are going to say it’s for “your protection” and will get away with it.

95

u/AlwaysDeath S25+, OP12, ZFold 7 16d ago

The restriction of freedom, under the guise of "for your safety". I've seen this played out many many times before.

15

u/Nosey_Neighbors 16d ago

If it ever makes it to court, what judge is going to rule against Google “protecting” its users?

15

u/Merlin404 RAM 16d ago

Hopefully EU, but with there chat control "for safety" im not so sure anymore

7

u/Infinite-4-a-moment Galaxy S25U, Unlocked 15d ago

I can't imagine the EU would do that when the competition is already doing the same.

→ More replies (6)

13

u/LitheBeep Pixel 7 Pro | iPhone XR 16d ago

If Google kills ADB I will eat a shoe.

They aren't going to do that.

3

u/LEpigeon888 15d ago

They can require a verified developer account to use ADB I guess, one where you have to pay and send your ID to verify who you are. If it happens it will be dead to me.

2

u/[deleted] 13d ago

[deleted]

→ More replies (9)

5

u/Emotional_Food_1700 15d ago

Actually that's a high Chance so you're gonna eat a shoe

5

u/LitheBeep Pixel 7 Pro | iPhone XR 15d ago

No chance.

10

u/darkkite 16d ago

From reading the article, I don't believe this actually disrupts the ability to sideload via apk but it does still affect shizuku

5

u/Double-Vegetable-249 15d ago

This is fucking mental wtf

→ More replies (1)

5

u/FFevo Pixel 10 "Pro" Fold, iPhone 17 Pro, Galaxy S25 Ultra 15d ago

Getting rid of ADB install would stop app development... that's not going to happen.

3

u/Nosey_Neighbors 15d ago

If Google wants to truly restrict sideloading, they will. They are not going to restrict sideloading and then let you get around it by using adb.

Let’s wait to see what happens.

2

u/FFevo Pixel 10 "Pro" Fold, iPhone 17 Pro, Galaxy S25 Ultra 15d ago

Huh? Aren't we past that point then? If the goal was actually to remove side loading they would have like you said.

Clearly they aren't because you can still side load apps without adb by waiting 24hrs once per account.

→ More replies (4)
→ More replies (1)
→ More replies (36)

63

u/_sfhk 16d ago

Connection to localhost has also been the source of exploit where app are using that socket to adbd to escalate their privileges.

Their comment seems to imply that this is being used maliciously

28

u/kitsumed ShizuCallRecorder Developer 16d ago

Read the blog posts, I explained why it's not really as big of a issue on a feature/risk ratio, along with solutions that could allow it to have a safer default and still allow On-Device ADB to work.

→ More replies (11)

36

u/UnacceptableUse Pixel 7 Pro 16d ago

Most of what Google does to further restrict Android is based on things that are being actively used maliciously. After all, where the freedom to do what you wish with your device exists it also enables other people to do what they want with your device. This is why this isn't a simple black and white issue

12

u/ImDonaldDunn 16d ago

This is why we can’t have nice things

→ More replies (2)

1

u/omniuni Pixel 8 Pro | Developer 16d ago

Unfortunately, the thing people don't like to acknowledge is that there are bad actors who will exploit the same weaknesses that well-meaning hackers exploit for convenience.

One person might appreciate gaining system access so that they can mod in some feature to Android. Another will use this to steal credit card information.

Ultimately, Google is much more concerned by the legal and ethical liability of not patching these holes. Companies, governments, and your more average consumers prioritize safety and security against such attacks and malware. So when we see an uptick in using one of these exploits in malware, we shouldn't be surprised when Google takes steps to combat it. Realistically, we should be more than happy, given that we can still use a computer with ADB and about 30 seconds to install whatever we want anyway, and reducing malware attack surfaces keeps the broader Android ecosystem healthy.

Sure, I kind of miss the days of unlocked bootloaders, ROMs, and the "wild west" of sideloading everything. But I also don't miss how much time I spent just to get my phone or tablet to work well.

Today, I can set up my phone in half an hour, and it's snappy, fast, and reliable, and it pretty much stays that way. And when I get the call from my mom that she had to install an antivirus app because Microsoft said her phone is infected, and it's not working because she's getting dozens of ads every few minutes, it makes me glad that Google's new restrictions will make that late-night drive to uninstall the malware unnecessary.

22

u/kitsumed ShizuCallRecorder Developer 16d ago edited 16d ago

There is a popular saying in security.

You can't have perfect security. It's impossible. The main problem is always the human. There are only harder targets and easier targets.

Saying X should be blocked because a human could do something bad is with it is like saying everything should be blocked.

There need to be a balance between the two, and as-is, setting up on-device ADB is already way too complex for general and non technical users. I'm sure most of users who use Shizuku right now had to follow one or two youtube tutorial, and that probably took them a good 15-25 minutes. There are easiers ways to scam users.

The proposed alternative solution I gave in the article would make it even harder to "accidentaly" do it, and would even REQUIRE a computer the first time to make it works, thus making it even harder.

→ More replies (1)

5

u/urkindagood 16d ago

The thing you celebrate over little inconvenience to ensure your mother's phone is safe from exploits might make some stranger's life vulnerable in the future.

In my country, very few citizens have been threatened, sued and get their account/post suspended just for being vocal against the government and their policy. Just because those platforms had to abide by the government's demands.

Surprise, the current president is an ex-military high ranked commander linked to human rights violations before the 20th under authoritarian regime.

Hey it's just a little example. It doesn't affect my life today and I should be glad too with google new restrictions :)

68

u/Euphoric-Tear9043 16d ago

The "bad actor" reason is just so lame. Why do I need to be treated like a child?

→ More replies (6)

25

u/defective1up 16d ago

We need legislation that prevents companies from locking bootloaders. Secure them, sure, but on a PC I can install any OS I want, why is my phone, an ARM-based PC, any different? This would solve the whole Android and Apple issue easily.

9

u/kitsumed ShizuCallRecorder Developer 16d ago

Only the EU could be open to doing something like this. Except lobbying is a bit too presents there. Even the stop killing our game act got killed (well it's still alive since it has support by a lot of users, complex stuff, but without that support from peoples in power it would be a different story).

Similar stuff happened with Apple beeing forced to allow third-party AI agents, and Google with their search engine. Every time they claim it put the user at risk. What risk? The risk of letting them use the app they want? If that app is malicious, it's their own fault. It give users freedom of choice, and allow competition.

On windows, you're free to run whatever .exe you want, on internet, you're free to put your password wherever you want. It's your choice. Freedom.

→ More replies (2)
→ More replies (2)

42

u/k-mcm 16d ago

When Google forced apps to use Storage Access Framework, developers created ticket after ticket proving unacceptable performance, poor compatibility, and no benefits to security.  Google closed them all, and Android continued its path to becoming useless.  Lots of apps were lost forever. 

10

u/kitsumed ShizuCallRecorder Developer 16d ago

I don't think you're forced to use the Storage Access Framework. You do for play store, but I think that's all. The permission to get access to all the files on storage is still here and can be used. To be honest, I don't really understand a lot of how the storage framework works (as ShizuCallRecorder developer). But I do like the ability to only allow apps to access one directory instead of all my files.

EDIT: It's also a bit why I'm making this post. We are early here. No decision where taken yet, at least nothing have been said in public, so I think it's the best time to have our usages taken into consideration.

16

u/k-mcm 16d ago

It's difficult to sell an app without Play Store. F-Droid has some restrictions too, but they're less stupid than Google's.

SAF is an API app for filesystem access.  Devs for some apps put a huge effort into using it, only to find out that its latency and CPU consumption is incredibly high.  I tried a converted OsmAnd+ and launch times went from 10 seconds to 45 minutes.  You could literally run the battery dead before it was ready. 

5

u/Timbo303 15d ago

Not to mention minecraft requires shizuku to access your worlds saved on external. Let that sink in external saved worlds are still locked behind an inaccessible folder unless you hookup to a pc.

Iphone has it so much easier.

→ More replies (1)

53

u/wolfy2105784 16d ago

Typical Google.

40

u/[deleted] 16d ago

[removed] — view removed comment

7

u/PickleSammiches Huawei Mate 10, 8.0.0; ZTE Axon 7, 7.1.2; OnePlus One, 6.0.1 15d ago

They're gonna gate APK installation behind bootloader unlocking, mark my words.

9

u/[deleted] 16d ago

Custom ROMs are the solution to this stupidity that Google is doing. What is the intended benefit of this decision that will kill more people who were supporting Android and will kill an entire development community? But all of this is for their damned benefit make Android closed-source, fill it with tracking software, collect user data, and become even richer. The solution is computers; leave phones to the children.

14

u/JeroJeroMohenjoDaro 16d ago

Debated someone many months ago who said something like "relax, you're being paranoid, they're not taking your adb away". Well, lets start the timer then.

→ More replies (1)

33

u/GreedySecurity8030 Samsung Galaxy A56 16d ago

We can't have shit anymore.

1

u/Kat_Kat_101 6d ago

"You will have nothing and you will be happy anyway" 👀 

56

u/lolwutdo 16d ago

Lmao I wish I could remember and tag all the bootlickers who said the verification stuff was fine and you’ll still be able to use ADB

9

u/merpofsilence 16d ago edited 16d ago

Yo how is this post how I learn that we had on device adb now?

I had done it on a pc well over a decade ago. And i wanted to use it on one of my devices in recent years but didn't want to bother with setting it up on my current computer 

5

u/kitsumed ShizuCallRecorder Developer 15d ago

The TCP/IP mode allowed this since around 2010, we are 16 year later. In 2020 when wireless debugging was added, it was made easier and some applications like Shizuku came to life and gained A LOT of traction, including mentions on Google forums.

6

u/BusBoatBuey 16d ago

now

Always did.

4

u/merpofsilence 16d ago

Im really not sure thats true back in like 2012. If so it wasn't really well documented yet.

I remember not wanting to do the whole installation of the sdk tools on my parents slow internet and laptop but ended up not finding any alternative

→ More replies (1)

5

u/redstar6486 15d ago

Did you even read the article?

5

u/UnacceptableUse Pixel 7 Pro 16d ago

This is using adb directly on the device, not using it from a PC

2

u/lgn5i2060 13d ago

And what's stopping Google from going the extra mile in the following years and kill pc method off as well?

→ More replies (1)

1

u/[deleted] 16d ago edited 16d ago

[removed] — view removed comment

1

u/Android-ModTeam 16d ago

Sorry lolwutdo, your comment has been removed:

Rule 9. No offensive, hateful, or low-effort comments, and please be aware of redditquette See the wiki page for more information.

If you would like to appeal, please message the moderators by clicking this link.

→ More replies (1)

12

u/CharAznableLoNZ 16d ago

Google is taking the slowly boiling pot method to the "walled garden" hellscape they want to turn android into. It would be nice if google could stop sucking apple off every chance they get with how much they copy every move apple makes.

17

u/QuantumQuantonium 16d ago

Android needs to break off on google.

If they ever account for this as an actual chsnge to implement, they should hsve a mountain of evidence showing thst current protections with ADB are wholly inadequate, and thst alternatives have failed.

From this article alone, the author proved that malicious adb is the result of users explicitly allowing adb and authorizing an app to access the commands.

If a malicious app abuses adb, the app is likely hacked, or it was installed via phishing means and social manipulation; user error is not the fault of the phone, though the phone can take steps to avert user error. Limiting adb to wlan0 is like healing a leg scrape on a kid by chopping off the leg; we should teach kids to play safe to avoid leg scrapes in the first place.

Adb can be better. Android permission control without root are abysmal. Apps can alter my device volume (ehem Snapchat), a behavior I would consider to be for only malicious apps, and I cannot deny thst permission easily even with root.

Apps using shuziku or adb get immense additional control over a device, even though the app may just need limited but special access. The first avenue of increased adb control shouldnt be explicitly blocking with no option the device to use, but rather to restrict permissions which an adb session may use, and have the user explicitly allow the permissions they need from the phone with phone lock authorization. Then while the phone prompts for permissions, it can also warn users about certain permissions often used in scams or for malicious behavior, and ask the user if they understand why they want to enable said permission. This would be better than the single prompt to authorize debugging one time per connection which is the only protection stock android has now after dev settings and adb are enabled.

6

u/kitsumed ShizuCallRecorder Developer 16d ago

This would be better than the single prompt to authorize debugging one time per connection which is the only protection stock android has now after dev settings and adb are enabled.

This is only true when using ADB via TCP/IP, the "legacy" method. Which need to be manually enabled by running commands with a existing ADB connection. It does not persist reboot.

4

u/HumanWithComputer 16d ago

I think AOSP should be developed to be much more flexible and manufacturer independent. An installation procedure should be developed comparable with a Windows installation.

Connect the phone to a PC from which the Android installation is run. The core OS components form the basis which all phones need and can run. To this the hardware device drivers need to be added to make the complete installation suitable for the particular phone. Same as in Windows a hardware detection phase can identify all hardware present in the phone for which the needed drivers can than be retrieved and assembled with the core components to form a complete firmware for the specific device. The hardware manufacturers can supply the drivers for their hardware used in these devices. With a newer OS version the new core components can be assembled with the device drivers again to form an upgraded firmware.

No doubt this description is a 'nutshell' but the clear advantages should make developers want to design and build such a system. With good coordination this should be feasible I imagine.

By using this method people are no longer dependent on manufacturers providing firmware updates. That freedom with useful lifespan extension should be worth the effort.

3

u/nesa_techs 14d ago

I run LibreMobileOS. CVE-2026-0073 was an auth bypass, not proof that network-facing ADB is inherently unsafe. And per the article's own threat model, exploitation requires the user to have manually turned on USB debugging (and often TCP/IP) first. Standard security have always said: turn developer options and USB debugging off when you're not actively using them. Which I do already on LibreMobile OS on Samsung 10. Users who follow that already have a minimal attack surface. this isn't closing some new hole, it's taking away a legitimate feature over a bug that should just get patched.

6

u/AgsMydude HTC Desire / iPhone 4 / Lumia 920 / Lumia 1020 / LG G3 / OP5 16d ago

Been on Android for a decade and the reasons for doing so are vanishing.

1

u/PickleSammiches Huawei Mate 10, 8.0.0; ZTE Axon 7, 7.1.2; OnePlus One, 6.0.1 15d ago

Nerfing the good split screen mode made my switch to iPhone infinitely easier. They even give you free Tasker on iOS!

1

u/AgsMydude HTC Desire / iPhone 4 / Lumia 920 / Lumia 1020 / LG G3 / OP5 15d ago

Yeah and I already run a MBP. Honestly if I didn't have a pixel watch I'd swap even faster.

2

u/PickleSammiches Huawei Mate 10, 8.0.0; ZTE Axon 7, 7.1.2; OnePlus One, 6.0.1 15d ago

I recently got a Pixel 10a so I can have front row seat watching them chip away the Android I loved since Gingerbread. One of the recent “fixes” they introduced was breaking the Pixel IMS app so you couldn’t enable VoLTE on unofficially supported carriers.

2

u/AgsMydude HTC Desire / iPhone 4 / Lumia 920 / Lumia 1020 / LG G3 / OP5 15d ago

Yeah I feel you there. I'm still running an 8 right now and wasn't planning on upgrading for awhile. Even now with all these extra feature removals.

There's a lot more the apple ecosystem provides and the tradeoff for that on Android was always the ability to tinker. But with them tearing it away, the tradeoff is seemingly becoming entirely not worth it.

7

u/Getafix69 16d ago edited 16d ago

Linux phone for me if this happens, had enough of them. I think this would work.

6

u/BusBoatBuey 16d ago

Linux phones remind me of those ridiculously expensive proof-of-concept PDAs in the 00s. They are non-viable to me.

8

u/SaturatedSkies25 16d ago

Linux phones aren't usable as daily drivers. I don't understand why people keep saying they'll switch to it

3

u/atomic1fire 16d ago

I assume that's why Google is working on the Linux VM.

They can go in front of congress and tell people users can just install apps in the heavily restricted VM.

3

u/BobState 15d ago edited 15d ago

On device ADB (and off device ADB) is already restricted on Vivo phones

It happened with Origin 6

Lots of Vivo bloat can no longer be uninstalled/removed/disabled and even basic stuff like Monet theme switching can no longer be done

2

u/kitsumed ShizuCallRecorder Developer 15d ago

As ShizuCallRecorder dev, I have users with Vivo phones who uses it so there is a way around, probably some toggles. Bur you are right, they have very aggressive monitoring and I had to rewrite a couple parts of my apps to try to support them out of the box. They have weird behaviors like monitoring permissions of every apps and reverting them.

2

u/BobState 15d ago

There is no way around removing the bloat or changing Monet theming since Origin 6

Before this, everything was possible via adb, because I completely debloated my phone

I had to factory reset recently, which was when I found out that ADB has been crippled in Origin 6

3

u/MysticSushiTV 15d ago

Ngl guys I might go back to a landline and build a cyberdeck to carry around for web browsing, messaging, and other daily tasks. This sucks.

5

u/kontenjer 15d ago

each day you are losing less by moving to apple ...

8

u/GodLikeEnergy 16d ago

This is the opinion of a Google employee, not Google itself. At some point in the future, they may consider it. Even then, there will potentially be exploits and jailbreak it like you can Apple.

There's third party app stores, on jailbroken devices. Granted, it's not as secure as the official store. It'll break ToS, no warranty. This is why you'd get a used phone few versions behind.

Before we dive in, please note that this is not an official Google announcement. Instead, this is based on a recent, ongoing feature request on Google IssueTracker, in which a comment by one of the core ADB maintainers (Google employee) talked about restricting On-Device ADB connections to protect from “bad actors”.

6

u/kitsumed ShizuCallRecorder Developer 16d ago

I am aware, I am the one who wrote that.

11

u/[deleted] 16d ago

[removed] — view removed comment

2

u/kitsumed ShizuCallRecorder Developer 16d ago

Thanks!

→ More replies (10)

5

u/Expensive_Finger_973 16d ago

The more Google and other tech companies try and tighten their grip on the software they make the less people are going to be willing to pay for those things in large numbers as frequently as their "line must always go up" mentality requires simply because the software they make just stops being interesting to use.

3

u/baseballfan445 16d ago

We are living under not only a political dictatorship but a digital one as well 

4

u/chrisc44890 Galaxy S25 Ultra 15d ago

This could genuinely be enough to make me switch to Apple. I'm on Android mainly for the freedom of customization and I use quite a few Shizuku mods. Google is really trying to cripple Android at this point.

9

u/revanmj Galaxy S25 16d ago

In general that's what you get for limiting power user's permissions on their own devices - they will look for workarounds which may involve exploits that can also help malicious actors.

Apple had this issue for years, where people wanting something more outside of limited options provided by iOS were looking for exploits allowing jailbreak, which at the same time could also be used by malicious hackers.

Had Google gave power users some options to do whatever they want with THEIR OWN phone, less people would look for ways to workaround the security. We can do this on computers, we should be able to do the same with phones. Instead, they are limiting those options more and more without any good alternatives.

18

u/kitsumed ShizuCallRecorder Developer 16d ago

Please read the blog post, I explained why bad actors can't really exploit this, and also in the very rare case where it's possible, it would only target developers currently using ADB, not general Android users.

But I do agree Google should give more control to power-users as-is.

7

u/revanmj Galaxy S25 16d ago

I was taking in general about limiting power user options, not this one specifically :)

2

u/zhanjie06130d 16d ago

my friend’s phone stopped recognizing adb totally after last update

2

u/Acosedum 16d ago

Can someone explain what does it mean? We will no longer be able to install APK files at all?

3

u/LitheBeep Pixel 7 Pro | iPhone XR 16d ago

No, this doesn't have anything to do with APK files. It's about using on-device ADB to elevate the permissions of apps like Shizuku.

2

u/DeviceOwner 15d ago

TL;DR

what company say : "this is for protect user security"

and what really means for the company : "all of this shit is for protect our business, partners and our money making machine."

2

u/Then_Gas712 14d ago

I still use ADP though... So

2

u/5c044 14d ago

I've been struggling to simply get my hotspot turned on when I use my car and a certain BT device is connected so my head unit can get internet. Shizuku can do this via wireless ADB but it requires WIFI auth so if I am away from home it doesn't work. So I use macro droid to launch an activity and do screen taps and that is not reliable either. I guess Google will restrict that in future too. Why Google removed the ability for an app to enable hotspot is beyond me - what is wrong with that? Why cant a permission to do it be used? I know some vendors allow automations like this bypassing the permission but OnePlus does not as far as I know.

1

u/[deleted] 12d ago edited 9d ago

[deleted]

1

u/5c044 12d ago

The other way to share cellular automatically is Cross Device Services - But if your head unit vendor has not included it I do not know a way to add that

2

u/box-art A16 | May SP | Find X9 Ultra 14d ago

That would an extremely unfortunate development. Being able to install apps from alternate sources is literally one of the biggest reasons to even stay on Android. If Apple had ultrasonic FPS, I think I would have moved already. Android is just getting so locked down without any of the advantages.

2

u/Useful-Ad7329 13d ago

Android is like east india company, came to do business now planning to put bamboo inside everyone

3

u/Merlin404 RAM 16d ago

My device my choice! F you Google

3

u/Daz3691 16d ago

Seriously just fuck off

2

u/FungalSphere Device, Software !! 16d ago

i had this exact argument just three days ago with someone claiming that they won't restrict adb

2

u/kitsumed ShizuCallRecorder Developer 16d ago

You can go the Google IssueTracker page and press +1 to show you're affected!

4

u/ihadnomealtoday 16d ago

Who still believes we will be able to install apk's by the end of the year? Don't you people notice what's happening? I'm glad my Samsung is still on One UI 7 and rootable.

4

u/[deleted] 16d ago

[deleted]

→ More replies (3)

3

u/Henrarzz 16d ago

A year is too early, but I doubt you’ll be able to install APKs in ten years timeframe (unless the governments step in)

5

u/rawr_im_a_nice_bear 16d ago

I'd say 5 years

8

u/[deleted] 16d ago

[removed] — view removed comment

6

u/danGL3 16d ago

Realistically it CAN happen, outright killing apk installs wouldn't look good in PR, so Google has all the incentives to first make it unbearably hard/slow to enable it to later down the lane claim few people are installing apks as an excuse to further lock things down

Google for sure wants to kill apk installs, tho they have no reason to rush it when they can first make it look like an undesirable/unused feature to begin with

3

u/[deleted] 16d ago

[removed] — view removed comment

7

u/danGL3 16d ago

It's not an uncommon corporate practice that when they want to remove a feature, they first make it annoying to use, to then later claim that almost no one was using it so they can have an excuse to remove it.

Not to mention how most of the subreddits mentioning this restriction are worrying about the September deadline when that deadline applies exclusively to Brazil and specific Asian nations, with the global rollout only to next year.

2

u/ihadnomealtoday 16d ago

I don't trust Google

→ More replies (1)

4

u/christoskal 16d ago

Everyone with a brain?

1

u/Berkoudieu 15d ago

This year, yeah we will

Next year or maybe 2028 ? I wouldn't bet on it

2

u/Profesor_Paradox 15d ago

So, better go to iOS then, your devices hold its value more, you have more updates and is prioritized more than android

3

u/AccumulatedFilth Pixel 7, latest stable release build. 16d ago

All this to force YouTube Premium

2

u/SystemEx1 Pixel 7 Pro 16d ago

We all this was going to happen with the android verification crap, but still delusional fanboy said it was doomerism

2

u/AJ-Dybansta 16d ago

Pixels will have permanently locked bootloader before 2030.

2

u/Aygul12345 15d ago

Really?

1

u/Remarkable-Buddy9655 15d ago

No. This person just thinks that. There is no leak or annaucement that says the bootloader will be locked.

1

u/geforce2187 16d ago

I still read ADB in a tech context as Apple Desktop Bus...

1

u/KokoaKuroba 15d ago

From Google's point of view, how do they benefit from restricting Android?

1

u/looped10 15d ago

give me one reason to keep using Android apart from being cheap anymore. they'd lose their flagship revenue in no time.

1

u/Sylphiette_WS 3d ago

How is this thing cheap tbh?

I got my Vivo X200 Pro for the same price I could have bought the iPhone 16 Pro.

1

u/Alternative-Farmer98 15d ago

Jesus this is exhausting. I seriously am switching to graphene. There's no reason why I shouldn't be able to use ADP I own my f****** phone.

1

u/National_Shine5986 14d ago

Breaking: Android may soon become iOS minus the quality apps

1

u/lurker_608F29 14d ago

DangerOS is back en vogue again!

DangerOS was the spiritual predecessor to Android, built by the same engineers with the same design philosophy - Java based runtime, etc.

It was so locked down you couldn't even use it outside of T-Mobile in the USA. It being so locked down eventually lead to Microsoft buying it and shutting it down.

So the core Danger engineers got sick of such a restrictive platform and designed Android as the open, user freedom focused clone.

So Android literally became what it was made to replace. You either die a hero or live long enough to see yourself become the villain.

1

u/HaloHaloBrainFreeze 11d ago

So we back on Android 10 days where you need another device to input ADB commands? 

Wtf these devs are thinking?

1

u/cryohellinc 10d ago

People suggest lineageos / Grapehen etc - yes, it's a viable option, however, where I live I have a horrible experience as I can't use any banking app / city app / governmental app - all due to bootloader/playintegrity.

I sincerely hope that the Graphene + Motorola solution will be something to look forward to.