Labor Day today, which around here just means I've got no meetings and a laptop on the porch instead of the couch. I've had about six tabs open all week about the Fortnite-on-Android mess and I keep meaning to actually write something instead of just complaining about it to whoever's in the room, so here we go.
Quick recap for anyone who missed it: Epic put Fortnite on Android back on August 9th, but they didn't put it on the Google Play Store. You had to go to Epic's own site, download an APK, and dig into your settings to allow installs from "unknown sources." For the first few days it was a Samsung Galaxy Note9 exclusive too, tied to that phone's launch, before Epic opened it up to more Samsung devices around August 12th and then everyone else a bit after that. The official reason was Epic didn't want to hand Google 30 cents on every dollar, which, fine, I get it, that cut is enormous and everybody in the industry knows it.
I actually tried sideloading it onto my nephew's old Pixel over a weekend visit just to see how bad the process was, and it's genuinely not built for normal humans. You get a scary warning screen, a setting buried two menus deep, and if you're not paying attention you leave "install from unknown sources" flipped on afterward, which is exactly the kind of thing that got people nervous. There was already a wave of fake Fortnite Android apps stuffed with malware floating around back in the spring, cashing in on people searching for the real thing before it even existed, so the caution wasn't paranoid. It was earned.
Which brings me to the actual news part of this post. Google's security team, Project Zero, found a real bug in Epic's installer, the kind where another app already sitting on your phone could quietly swap in a different file during the Fortnite install and get itself installed too, without you noticing. Epic fixed it fast, within days. But Google published the technical writeup about a week after telling Epic, way short of the 90-day disclosure window that's become the industry norm, and Tim Sweeney was not happy about it. He went on Twitter and called it irresponsible, and pretty directly accused Google of trying to make Epic look bad right as Epic is trying to route around the Play Store's cut.
Honestly? I land somewhere in the middle and I don't think that's a cop-out. The bug was already patched, the technical details were narrow enough that publishing them didn't hand anyone a working exploit against current installs, and security researchers pushing back against a giant platform holder is generally the system working the way it's supposed to. At the same time, Sweeney's not wrong that Google has an obvious interest in this story getting written up as "look what happens when you leave the Play Store," and the timing sure was convenient for that narrative. Two things can be true. It's a security disclosure and a business fight wearing the same coat.
What bugs me more, honestly, is that this whole saga is a preview of a fight that's going to keep happening as more companies try to build direct relationships with users instead of going through app store gatekeepers. Everyone involved has a story about principles, and everyone involved also has a very specific dollar amount they're protecting. I don't think Epic did anything wrong by skipping the Play Store. I also don't think Google did anything wrong by talking about a bug in software that fifteen million people had already downloaded within the first weeks. I just think it's funny that both sides are dressing up a fee dispute as a matter of user safety, and both of them are sort of right about the other one.
Anyway. Google turns 20 tomorrow, September 4th, if my memory of that founding date isn't off, which feels like a weirdly fitting thing to be typing the day before, given this blog is closing in on its own seventh year in November. Different scale obviously. Still counts as a milestone in the same week.
Back to the grill. Or at least back to pretending I'm going to read the rest of those tabs before the long weekend's over.