It's already live, I had to go through it last week. It's in developer options, then it asks if you're moving the selector to allow the installation of non-play store apps because you're being asked to by someone.

Then it starts a 24 hour timer. When that hits zero, you have 1 hour to go back in and select that you want to install apps on a device you own and paid money to own.

It's not scam-resistant at all. Any scammer will gladly work around this and send someone to one of many malicious apps in the play store, or a malicious URL, or even just set an appointment to call Grandma back the next day.

They're not necessarily wrong about it being scam resistant, based on some of the research into the psychology of scams. Adding time defuses the urgency of phone scams, leaving plenty of time to seek a second opinion from family members or the internet, and forcing the scammer to re-explain what the original goal was. It's too much time to breathe and defuses the fight or flight reaction needed for a high success rate. You mention URLs, but a web browser based scam page doesn't accomplish much, because the scammer's goal with fake apps is to acquire persistent remote access (akin to how the AnyDesk Android app uses accessibility permissions for Teamviewer-like remote access to an entire phone).

But yeah, it's hilarious that they're pushing this so hard when the Google Play Store still has so much malware.

What? It only stays enabled for exactly 1 hour after the 24 hour timer? I was under the impression that it would stay enabled permanently after waiting the 24 hours once.

IIRC, it's the button to permanently activate it that is only available for one hour. Once you do manage to press it, you've permanently enabled it. If you miss the window, you have to start the 24 hours again.