Skip to content

Google’s Sideloading Crackdown Is the Wrong Fix, and F-Droid 2.0 Shows Why

Google's developer verification starts Sept. 30 overseas and reaches the U.S. in 2027. F-Droid 2.0 shows why the plan goes too far.

Black Android smartphone lying on a wooden table, illustrating Google's developer verification rules for sideloaded apps
In this article
  1. What Google is actually asking for
  2. F-Droid 2.0 is a statement
  3. The security case is real. It’s still not enough.
  4. What Google should do instead

Next Tuesday, September 30, Android changes in a way most Americans won’t notice yet. In Brazil, Indonesia, Singapore and Thailand, Google’s developer verification rules switch on. From that day, apps from developers who haven’t registered with Google get pushed behind a wall of warnings and a 24-hour waiting period. The rest of the world, the U.S. included, follows in 2027.

Days before that deadline, F-Droid, the open-source app store that has quietly served Android power users for well over a decade, shipped the biggest update in its history. The timing reads like a dare. It’s also the clearest argument I’ve seen that Google’s plan, as designed, goes too far.

What Google is actually asking for

Under the new rules, any developer who wants their app to install without friction on certified Android phones has to register with Google. The Register lays out the options:

Developer path Cost Government ID Reach
Full distribution $25 one-time Required Any number of devices
Limited distribution Free Not required Up to 20 devices
Unverified Free Not required Only via the “advanced flow”

That advanced flow is where it gets ugly. As 9to5Google describes it, you open Developer options, turn on “Allow apps from unverified developers,” click through the warnings, then come back after a mandatory 24-hour wait before you can allow installs for seven days or indefinitely. ADB installs still work, which tells you exactly who this is and isn’t meant for.

F-Droid 2.0 is a statement

The new F-Droid is a genuine rebuild: core components rewritten in Kotlin with a Jetpack Compose interface, a Material Design overhaul, a simpler Discover, Search and My Apps layout, sharper search and filters, and automatic background updates switched on by default. It also taps Android’s install pre-approval APIs, which the EU’s Digital Markets Act pushed Google to open up, so installing feels much closer to the Play Store. The team says the Kotlin move “will help us deliver improvements more quickly in the years ahead.”

That’s a project planning for a future. Its own board isn’t sure it has one. “If it were to be put into effect, the developer registration decree will end the F-Droid project and other free/open source app distribution sources as we know them today,” board member Marc Prud’hommeaux said, per The Register.

The problem is structural. F-Droid builds apps from source code, and many of them come from hobbyists, pseudonymous privacy developers and tiny volunteer teams with zero interest in handing a passport scan to Google. Under verification, their apps land in the penalty box no matter how clean the code is.

The security case is real. It’s still not enough.

To be fair to Google, sideloaded malware is a real problem, especially in the four countries going first, where scam apps pushed through chat links routinely drain bank accounts. Tying apps to an accountable developer is not a crazy idea.

But a sensible idea can be badly scoped. Verification treats a transparent, source-built open-source app exactly like a random APK from a Telegram link. A 24-hour cooling-off period may slow down a scam victim, but it also punishes the power user who knows precisely what they’re installing. And running the whole check through Google’s own software hands one company a veto over apps it doesn’t even distribute.

F-Droid technical lead Hans-Christoph Steiner put it bluntly: “Google is clearly shifting the management of Android from the technical people to the competition lawyers.”

What Google should do instead

There’s a better version of this policy, and it isn’t hard to sketch:

  • Trust the stores, not just the developers. Let established open-source repositories like F-Droid vouch for the apps they build from source, instead of forcing every volunteer to submit ID.
  • Drop the 24-hour wait for anyone who has already enabled Developer options. That step alone filters out the people the warnings are meant to protect.
  • Show the numbers. Publish how much sideloaded malware verification actually stops in Brazil and the other early markets before rolling it out to everyone.

American Android owners have roughly a year before this reaches them. That’s enough time for Google to sand down the rough edges, and enough time for U.S. users who care about an open Android to say so loudly. Openness is why many of us chose Android over the iPhone in the first place. It shouldn’t come with a waiting period.

Sources: The Register, 9to5Google, Android Authority. Photo by Adrien on Unsplash.

Written by

Harish

Harish writes about Android phones, apps and the Google ecosystem for Android Captain.

Join the conversation

Your email address will not be published. Required fields are marked *