App sideloading: installing outside the official store
What sideloading means on Android and iPhone, EU marketplace rules, malware risk, and the real fight over fees and device ownership.
For more than a decade, getting software onto an iPhone meant one door: Apple's App Store. Android was looser — sideloading APKs was always possible, with scary permission prompts and malware for anyone who ignored them. Then regulators in the EU forced Apple toward alternative marketplaces, and the word "sideloading" left the geek forums and entered ordinary news.
The fight is about money, safety, and who controls the software that runs on a device you think you own.
What is sideloading?
Installing an app from outside the platform's official store — a website, another marketplace, or a file. On Android it is a toggle and a habit. On iPhones historically it meant developer tricks or jailbreaks for most people. EU rules pushed Apple to allow alternative distribution under conditions: developer terms, notarization-like checks, and fees that critics called compliance theater.
Security people split. One camp says locked stores reduce malware. The other says monopoly stores tax developers 15–30 percent and still ship scams, fake crypto wallets, and rip-off subscriptions. Both camps have evidence.
Why do stores get blamed either way?
Because they are gatekeepers. When a malicious app slips through, the store failed review. When an indie developer cannot ship without a cut, the store is a landlord. When a government wants a backdoor or a local champion marketplace, the store becomes foreign policy.
Users mostly want apps that work and do not steal from them. They get caught in speeches about "open ecosystems" that somehow always end in a fee schedule.
What should a normal person actually do?
On Android, avoid random APK sites. Prefer Play Store or well-known F-Droid-style sources if you know what they are. Read permissions. On iPhone, stick to the official store unless you have a clear EU marketplace you trust and a reason. Enterprise and hobbyist installs are different worlds — do not mix "I saw it on a forum" with banking.
Sideloading does not automatically destroy security. Blind sideloading does. The same hands that install a cracked game install spyware.
The ownership question underneath
If you cannot run code you trust on hardware you bought, the device is a rented portal. If every binary is allowed unchecked, the device is a petri dish. Healthy platforms live between those poles: user choice with sharp warnings, real malware defense, and competition so one company's policy is not law.
Watch the fees and the defaults, not just the slogans. Openness that still routes every payment through the same toll booth is just a longer hallway.