F-Droid Frames Google's Mandatory Android Developer Verification as 'Malware'
F-Droid, the open-source Android app repository, has published a polemic recasting Google’s upcoming Android Developer Verification (ADV) program as malware. The rhetorical framing—describing ADV as a rooted system service silently pre-installed on roughly 4 billion devices running Android 8+ and awaiting activation—is a deliberate inversion of Google’s own anti-malware messaging. The actual mechanism is a policy change: starting September 30, Google will require every Android developer to centrally register before their apps can be installed, with an initial rollout targeting Brazil, Indonesia, Singapore, and Thailand and a broader global expansion planned for 2027.
F-Droid’s core objection is that ADV does little to stop malware at its source—its only real effect is forcing an already-identified bad actor to create a new account—yet Google is using that narrow justification to make itself the sole gatekeeper for which apps may exist. The group points to less heavy-handed alternatives (enhanced on-device scanning, or a federated model letting users pick their own trusted verifiers) that were passed over. Verified developers must pay a fee, hand over government ID and personal details, and register signing keys, while agreeing to Console terms that permit termination for distributing ‘malware’—a word left undefined, which F-Droid argues lets Google brand any disfavored software (ad blockers are cited as precedent) as malicious on commercial or political grounds.
The piece also disputes Google’s claim that 99% of developers have opted in, attributing that figure to automatic enrollment under existing Play Store agreements rather than genuine support. It cites a petition with hundreds of thousands of signatures and opposition from over 70 organizations including the EFF, FSF, and ACLU under the ‘Keep Android Open’ banner. The significance for F-Droid is existential: its transparency-based trust model is fundamentally incompatible with a regime where Google alone defines ‘security’ and ‘trust,’ and it remains unclear what will happen to sideloaded apps and their data once enforcement begins.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.