Google Tests Third-Party App Store Support in Play Store Following Epic Games Antitrust Ruling
Google is currently testing several new features in the Play Store, including an experimental section called Play Labs, support for third-party app stores, and an expanded search bar. These changes have been identified in a recent version of the service, although most of the new capabilities remain inaccessible to regular users at this time.
The most significant development is the planned ability to install alternative app marketplaces directly from Google Play. The company had previously confirmed work on this functionality, which stems from the ongoing antitrust proceedings involving Google and Epic Games. After the settlement between the two companies was withdrawn, the 2024 court ruling once again became active, requiring greater openness to competing stores.
The new menu option for third-party stores was discovered only after direct intervention in the application code. It appears in an additional menu but currently returns an error when users attempt to open an alternative marketplace. In the same area, researchers also found Play Labs, an experimental section where users will likely be able to test upcoming store features before they reach general availability. Google already uses similar experimental sections in other products, including its main search engine.
While Play Labs and the third-party store option are not yet functional, the updated search interface is already working. Google is preparing a two-line search panel designed to accommodate longer natural-language queries, accompanied by an Ask Store prompt. Instead of entering a short app name, users will be encouraged to describe their needs in detail, after which the store will attempt to suggest suitable applications.
These experiments follow recent Play Store improvements such as enhanced search capabilities and the option to test widgets during app installation. Broader rollout of the new search panel is expected in the coming weeks. However, APK analysis only reveals features currently under development, and Google retains the option to modify, postpone, or abandon any of them before release.
The direction of these changes is notable: the main Android app store is preparing to distribute competing marketplaces to users, effectively turning competition itself into a feature that can be installed through Google Play.
Related articles
Passkeys in Production: How One Developer Replaced Passwords with Face ID in Three Days Using FastAPI and Next.js
Yaroslav Morozov details a complete production implementation of Passkeys based on the WebAuthn standard and FIDO2 protocols. The article explains why Passkeys eliminate phishing and database breach risks compared to traditional passwords while providing biometric login via Face ID or Touch ID. It covers database schema design with PostgreSQL tables for credentials and challenges, SQLAlchemy models, and minimal dependencies including py-webauthn on the backend and SimpleWebAuthn on the frontend. Full working code for registration and authentication flows is provided, showing how Passkeys integrate with existing JWT token systems without major refactoring. The guide includes environment configuration, error handling, challenge management with five-minute TTL, and security considerations such as sign count verification to detect cloned keys.
Yandex Disk Files Become Partially Inaccessible After Sasovo Data Center Incident
A detailed user report reveals that approximately one percent of files stored on Yandex Disk are currently unavailable for download following reported incidents at the Sasovo data center. The problems manifest in three distinct states: missing thumbnails with downloadable originals, visible thumbnails with inaccessible originals returning 504 Gateway Time-out errors, and cases where both thumbnails and originals fail to load. Technical analysis using curl requests traced the failures to specific storage nodes such as s418klg.storage.yandex.net, indicating that some data shards may reside in affected infrastructure while others remain operational. Yandex support requested original files for diagnosis but closed the ticket without providing an official explanation or confirming data integrity. The author emphasizes that the issue affects files across both the Photos and Files sections and recommends maintaining offline backups due to the lack of guaranteed availability during data center failures.
Keurig K-Supreme Smart Coffee Maker Generates Nearly 1 TB of Outbound Traffic in Ten Days
A Keurig K-Supreme Smart coffee maker unexpectedly produced around 1008 GB of outgoing traffic over ten days, overwhelming a home UniFi access point while generating only 9.94 GB of inbound data. The device had been placed on a separate network segment, yet the traffic remained largely internal to the home LAN rather than traversing the internet connection. The anomaly was discovered by user Nomad while assisting family members with network maintenance through the UniFi dashboard. After the coffee maker was powered off, the issue could not be reproduced in subsequent testing, and no packet captures were available to determine the content or root cause of the traffic. The model requires internet connectivity for remote control, scheduling, capsule recognition, and automatic reordering of coffee supplies. No similar incidents have been reported by other users, and the manufacturer has not issued any statement regarding the event.
Hash Functions Part 1: Core Properties, Security Requirements and Practical Applications
The article provides a detailed introduction to hash functions, explaining how they map arbitrary-length input to fixed-length output while satisfying three fundamental security properties. It covers preimage resistance, second preimage resistance, and collision resistance, along with the avalanche effect that makes even minor input changes produce unrecognizable output. The text explains why a 256-bit digest is required to achieve 128-bit collision resistance, referencing the birthday paradox and its implications for MD5 and SHA-1. Practical guidance includes using OpenSSL for hashing, applying hashes in commitment schemes, enforcing subresource integrity on web pages, and securely storing passwords with Argon2 and bcrypt. The post emphasizes that hash functions alone do not guarantee integrity without proper transmission of the digest and announces a follow-up on SHA-2 and SHA-3 internals.