Linux kernel maintainers are evaluating a new approach to authenticate developers and verify code provenance, aiming to reduce reliance on the current PGP-based web-of-trust process that requires in-person identity checks and manual key signing. The push is framed as a supply-chain hardening measure informed by past ecosystem compromises, including the 2011 kernel.org breach and the more recent xz backdoor attempt, and is positioned as a model that could be adopted by other open-source projects.
Separately, Google’s plan to expand developer identity verification to Android app sideloading distribution channels is facing organized opposition from dozens of technology and civil society groups. The policy would require identity checks and a one-time $25 registration fee for developers distributing apps for installation on certified Android devices outside Google Play, prompting concerns about increased gatekeeping, privacy/surveillance risk, barriers to entry for smaller developers, and potential antitrust implications; an unrelated ZDNET piece on PCLinuxOS focuses on distro popularity and usability rather than security controls or a specific security event.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Google plans to begin requiring developers to register apps for sideload installation on certified Android devices, including identity checks and a one-time $25 fee. The change would extend Google Play-style registration controls to alternative app distribution channels.
Linux kernel and Linux Foundation Decentralized Trust participants began exploring a new identity and code-authentication approach based on decentralized identifiers and verifiable credentials. The effort remained in prototype stage, with further discussion planned for Linux Plumbers and the Kernel Summit.
A coalition of 37 technology companies, nonprofits, and civil society groups published an open letter calling on Google to withdraw its planned Android developer registration requirement for sideloaded apps on certified devices. The group argued the policy would centralize control, create barriers for smaller developers, and raise privacy, competition, and antitrust concerns.
Google applied developer registration requirements, including identity checks and a one-time fee, to Google Play developers. The later sideloading policy was described as an extension of this requirement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.