• pirat@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    Unfortunately, I think this plays into the EU Cyber Resilience Act, and the developer verification is how Google is trying to comply with it…

    Distributors and importers must verify that products comply with CRA standards before selling them. They must review technical documentation, ensure that software does not have known vulnerabilities and comply with update obligations. They must work with vendors to report vulnerabilities and request patches. Finally, they must conduct audits to ensure continued security over time.

    […] Finally, the resilience of mobile apps must be verified through regular testing.

    Source: https://www.mobisec.com/en/regulatory-compliance/cyber-resilience-act-dispositivi-applicazioni-mobile/

    • Auli@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      2 days ago

      But why would they matter to Google they where not selling those apps. Are computer manufactures going to be blamed for stuff installed on a computer.

      • lolcatnip@reddthat.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        2 days ago

        It says distributors and importers. That’s what Google is via the Play Store. Still no reason I can see the disallow side loading, but Google’s lawyers, or the EU’s, may see it differently.