F-Droid shipped its biggest overhaul in 15 years on September 24. Six days later, Google starts enforcing rules that could make open Android distribution a thing of the past. That timing is worth paying attention to.
What Google’s Rule Actually Does
Starting September 30, every app installed on a certified Android device must come from a developer who has registered an identity with Google — regardless of where the app came from. That means sideloaded apps too. Google’s own language is unambiguous: “If your app runs on a certified device, these requirements apply to you, regardless of your app’s download source.”
The full verification path requires a government-issued ID, a one-time $25 fee, and registration of your app’s APK signing key. Google has a lighter option — “Limited Distribution” — with email-only verification, no ID, no fee. The catch: it caps you at 20 devices. For indie developers with real audiences, that’s not a distribution model, it’s a demo limit.
A third option, the “Advanced Flow,” is supposed to let power users install unverified apps through a friction-heavy process involving developer mode activation, a device reboot, a 24-hour waiting period, and multiple confirmation screens. Google promised this option before enforcement began. It wasn’t available.
Enforcement starts September 30 in Brazil, Indonesia, Singapore, and Thailand. The global rollout follows in 2027. By then, any developer distributing outside the Play Store will need to be on Google’s registry or count on their users knowing how to dig through settings to install unverified software.
F-Droid 2.0: The Rewrite That Arrived at the Wrong Moment
While this was coming, F-Droid was building. The 2.0 release is a complete ground-up rewrite in Kotlin and Jetpack Compose — the first major architectural overhaul in the project’s 15-year history. An independent security audit by the Open Technology Fund’s Security Lab cleared the new codebase. Automatic background updates now work on any recent Android version without needing the F-Droid Privileged Extension. A redesigned three-section layout replaces the old interface with Discover, Search, and My Apps. The new EU Digital Markets Act-enabled pre-approval installer API smooths out the installation flow.
In short: F-Droid 2.0 is the app it should have been for years. The irony is that it launched six days before everything shifted.
The Signing Key Problem Nobody Has Solved
Here’s the technical crux. F-Droid builds approximately 85% of its app catalog from source code and signs the resulting APKs with F-Droid’s own key — not the original developer’s. That’s intentional: it enables independent verification that the binary matches the source. But Google’s verification ties app identity to the developer’s signing key. If an original developer registers with Google using their own key, their F-Droid-distributed copy still won’t match. There’s no mechanism for a developer to say “F-Droid’s key is authorized to distribute my app.”
F-Droid board member Marc Prud’hommeaux isn’t mincing words: “The regulations will end the F-Droid project and other free/open source app distribution sources.” Developer Hans-Christoph Steiner frames it more pointedly: “Google is clearly shifting the management of Android from the technical people to the competition lawyers.” According to The Register, F-Droid’s core team sees no technical workaround on the current timeline.
The Opposition Is Organized
Moreover, this isn’t a handful of open-source advocates venting online. The Keep Android Open campaign has brought together 71 organizations across 23 countries. Formal complaints have landed with the European Commission’s Digital Markets Act enforcement team, the UK Competition and Markets Authority, the US Federal Trade Commission, and competition regulators in over 20 jurisdictions. Whether any of that moves fast enough to matter before 2027’s global enforcement is a different question.
What Developers Should Do Before September 30
If you distribute an Android app outside the Play Store and have users in Brazil, Indonesia, Singapore, or Thailand, you need to act now. The Android developer verification announcement lays out your options:
- Register through the full path. Government ID, $25, signing key registration at the Android developer verification portal. Not ideal, but it’s the only option that works without friction for your users.
- ADB installs remain untouched. Dev builds, CI pipelines, direct test installs over USB — none of this changes. The rule targets end users, not developers working on devices they control.
- If you use F-Droid for distribution, watch closely. The project is exploring reproducible builds — where F-Droid’s compiled output matches your signed binary — as a path forward. Only about 15% of the catalog supports this today. It may become the only viable model.
Google’s stated rationale is security: eliminating anonymous bad actors who hide behind unverified identities to distribute malware. That’s a real problem. However, the mechanism it chose — key registration tied to government identity — effectively taxes open distribution and hands Google a kill switch over any app that reaches certified hardware. Android’s openness has always been the argument against iOS’s walled garden. That argument just got harder to make.













