CYBER WELFARE

Protect your Digital Privacy

Downloading apps only from official stores: the front door that already does half the work

Helen has just received a message in the group chat of her yoga class. One of her friends has shared a file: “It’s the photo editing app, the paid one, but this version is free. I’ve put it on my phone and it works brilliantly.” Helen taps the file, and her phone shows a warning: for security reasons, installing apps from this source is not allowed. Underneath, there is a button: “Settings”. All she would have to do is tap it and flick a switch.

It is a common situation: the file comes from someone you trust, and the app promises exactly what you were looking for. The trouble is that nobody — not the friend, not Helen — really knows where that file came from, who has modified it, or what it does apart from editing photos.

This recommendation — R26 of the Cyber Welfare Framework — offers a simple rule: download apps only from official stores, meaning the channels built into your phone’s system, and keep the side door of installing from unknown sources firmly shut. You do not need technical skills. You need to decide once where your apps come in, and stick to that decision even when an offer seems too convenient to turn down.

What this recommendation says

Recommendation R26 states that apps should be installed only from the official store of your phone’s or tablet’s operating system, or from an authorised and verified alternative store where the law allows it. Never from links received in messages, files sent in chats or download websites.

An official app store is the distribution platform built into the device’s operating system: the catalogue from which the phone expects to receive its apps, after developers have put them through a series of checks. In some places, such as the European Union, recent rules also allow authorised alternative stores: catalogues other than the default one, but recognised and permitted by the operating system through specific procedures.

The rule rests on two habits:

  • choosing the source: looking for apps inside the store, or following the link on a service’s official website that takes you to its page in the store;
  • keeping the side door shut: leaving switched off the option that lets you install apps from unknown sources, meaning files and links that do not go through a store.

Installing an app by getting round the store also has a technical name, sideloading: you take an installation file — the package that contains the app — and open it directly on the phone.

What it is not. It is not the rule that helps you pick the right app inside the store: that is the job of the recommendation on checking an app is genuine, which comes straight after this one. R26 decides where apps come in; R25 helps you work out which one to choose. Nor is it an absolute guarantee: stores reduce the risk considerably, but no check is infallible.

Where it applies. To phones and tablets, to personal and work apps, and to the devices of family members who ask you for a hand. The same principle applies to computer programs: download them from the system’s store or from the official website of whoever makes them, not from sites that collect software from all sorts of places.

Why it matters

An official store is not just a catalogue. It is a filter that works before the app reaches your phone: publishers have to identify themselves, apps are analysed for harmful behaviour, and when an app turns out to be dangerous it can be removed from the catalogue and, in many cases, disabled on the devices where it was already installed. Apps installed from there then receive their updates through the same route.

A file that arrives in a chat skips all of these steps. Nobody has checked who built it, nobody knows whether it has been altered, and it will not receive updates except through more files of the same kind. That is why modded apps — copies of well-known apps altered to unlock paid features, remove advertising or add cheats to games — are one of the most common ways of getting malware onto a phone: software designed to cause damage, spy on you, or steal data and money. The mechanism is explained in the post on modded and pirated apps.

The concrete consequences of an app installed from the wrong source show up on four fronts:

  • personal data exposed — photos, contacts, messages and location can be read and sent elsewhere;
  • accounts and credentials at risk — some malicious apps display fake login screens or read the codes that arrive by text message;
  • unexpected costs — subscriptions activated behind your back, unauthorised payments, drained data and battery;
  • loss of control over the device — special permissions that let the app act on the screen in your place, or make it hard to remove.

One aspect deserves special attention: the unknown sources switch. When you open it to install a single file, it often stays open. From then on, the app you gave the permission to — the browser, the chat app, the file manager — can offer you further installations with a single tap.

Benefit of official storesWhy it counts
A check before installationThe app has been examined and the developer identified
Updates from the same sourceSecurity fixes arrive without hunting for other files
Apps can be withdrawnAn app found to be dangerous can be taken off the catalogue and off devices
No side door left openA link or file received by mistake does not install itself
A rule that is easy to rememberOne source, always the same, including for the people who ask you for help

A concrete example

Back to Helen. The phone’s warning makes her hesitate, but her friend insists: “Don’t worry, it hasn’t done anything to mine.”

Helen does not tap “Settings”. She closes the file, opens her phone’s store and searches for the photo editing app. She finds it: the basic version is free, and some features are paid for. She checks the developer, as R25 suggests, and installs that one.

Then she takes a closer look at the file she received. The name is similar to the original app’s, with “premium unlocked” added. Her friend admits she found it on a website that collects free apps.

Helen does not need to establish whether that file really contains anything harmful. It is enough for her to know that she cannot know, and that nobody has checked it for her. She sends her friend a kind message: it might be worth uninstalling it and checking the phone. She also sends her the guide on what to do if your phone has malware.

The only decision that really counted was the first one: keeping shut the door her phone had shown her.

When to apply it

The rule applies to every app, but there are moments when it makes an obvious difference.

  • When someone sends you an app in a chat. Even when it comes from people you care about, an installation file tells you nothing about where it came from. Ask for the app’s name and look it up in the store.
  • When a message asks you to install something. Texts, emails or chats about parcels waiting for collection, accounts to unblock or urgent updates, with a link that downloads a file: ignore the link.
  • When a paid app is offered for free. “Premium”, “pro” or “unlocked” versions outside the store are the most common disguise for modded apps.
  • When a website invites you to download directly. Pages for events, shops or services offering the app file “from here”: if the service is genuine, its app can be found in the store as well.
  • When you set up a new phone or help a relative. This is when lots of apps get installed one after the other and settings are changed more casually.

How to apply it

A few steps are enough, and most of them only need doing once.

  1. Check the unknown sources setting. In your phone’s security or privacy settings, look for the option that allows apps to be installed from unknown sources. On many phones the permission is granted app by app: make sure that none of them — browser, chat app, file manager — still has it. The steps are explained in the guide on how to block installs from unknown sources.
  2. Look for apps only in the store. Open the store from your phone, or start from the service’s official website and use its buttons that lead to the app’s page in the store.
  3. When you receive an installation file or link, do not open it. Ask for the name of the app and look it up yourself. If it is not in the store, that in itself is useful information.
  4. If you use an alternative store, check that it is authorised. Where the law provides for it, the operating system shows which alternative stores are recognised. Install them only by following that procedure, and find out beforehand who runs them.
  5. Keep the built-in protection switched on. On many phones the operating system scans installed apps and warns you if it finds harmful ones. Leave this feature on: the post on built-in protection against harmful apps explains how it works.
  6. Update your apps from the store. Never from pop-ups in the browser or from files promising a “new version”. It is the same principle as the recommendation on keeping your software up to date.
  7. If you have already installed something from outside, tidy up. Remove the apps you do not recognise or do not use, and shut the side door again. The recommendations on removing unknown apps from your phone and removing apps you no longer use will help.

A legitimate exception. Some organisations distribute work apps through a device management system controlled by their IT department. In that case, follow its official instructions, received through internal channels — not from a message that imitates their style.

Common mistakes to avoid

  • Opening unknown sources “just for a moment”. The switch often stays on afterwards, and the app that received the permission can offer further installations.
  • Trusting a file because it comes from a friend. Whoever sends it is usually acting in good faith, but does not know where the file really came from.
  • Looking for the free version of a paid app. The price you do not pay in money is often paid in data or security.
  • Ignoring the phone’s warning. When the system blocks an installation, it is not a fault to work around: it is the protection doing its job.
  • Downloading from sites that “collect” apps. Even when they look tidy and professional, they cannot guarantee that the files are identical to the originals.
  • Thinking the store does everything on its own. The store filters the source, but inside the catalogue you still need to choose the right app and grant only the permissions it needs.

How this connects to the Cyber Welfare Framework

R26 sets a simple boundary: apps come in through a single door, the one your phone knows how to check.

PillarHow this contributes
SkillsKnowing where to find the unknown sources setting and recognising an installation file
AwarenessUnderstanding that an app’s source matters as much as the app itself, even when it comes from someone you trust
Secure BehaviourInstalling only from the official store and keeping the side door shut, with no improvised exceptions

Digital maturity levels.

  • FL1 — Basic. You install apps from wherever they turn up: store, links, files you receive. It is a common starting point, not a fault.
  • FL2 — Beginner. You install only from the store and have checked that installing from unknown sources is switched off.
  • FL3 — Autonomous. You combine choosing the source with checking the app and its permissions, and you always update from the store.
  • FL4 — Skilled. You spot suspicious files and offers straight away, and you regularly review installation permissions and the apps on your phone.
  • FL5 — Expert-Guide. You help family members, colleagues or your organisation set up their phones and keep this habit going.

R26 is one of the first steps from FL1 to FL2, and it remains the foundation for the later recommendations on apps.

How to check you are applying it properly

Three questions, to be answered honestly.

  1. Did you install every app on your phone from the store?
  2. Could you say whether any app on your phone currently has permission to install other apps?
  3. If a friend sent you a “free premium” app in a chat tomorrow, what would you do?

Quick checklist

  • ☐ I install apps only from my phone’s official store
  • ☐ Installing from unknown sources is switched off for every app
  • ☐ I do not open installation files received by chat, text message or email
  • ☐ I do not look for free versions of paid apps outside the store
  • ☐ The operating system’s built-in protection is switched on
  • ☐ I update apps only from the store, not from browser pop-ups

If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.

In short

Official stores are the door through which your phone expects to receive apps: they check who publishes, analyse the apps and deliver the updates. Links, files in chats and download sites skip all of that.

Downloading apps only from official stores takes a few habits: keeping installation from unknown sources switched off, looking for apps in the store or via the service’s official website, ignoring installation files and links, using alternative stores only if they are authorised, keeping built-in protection on, and always updating from the same source.

Digital security does not ask you to give up the apps you need. It asks you to let them in through the front door.

Something to think about. Among the apps on your phone, is there one you cannot remember the origin of?

Explore this recommendation

This recommendation is the pivot of a content unit. Each post looks at a different aspect.

Related resources

Short reads from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.