Forgot your password?
typodupeerror
Open Source Android Google

F-Droid 2.0: FOSS Android Appstore Continues Updating Despite Google's Pending 'Developer Verification' Plan (theregister.com) 56

"F-Droid, a third-party app repository that only distributes free and open-source software packages for Google's Android mobile platform, on Thursday announced version 2.0 of its Android app," reports The Register.

Though they also note "a big banner across the top of the F-Droid site" pointing to a site describing pending changes from Google that threaten the future of F-Droid... [D]evelopers who want their apps broadly distributed outside the official Google Play Store will need to register with Google and verify their identities. Google's Full Distribution option includes paying a one-time $25 fee, handing over a copy of a government-issued ID to verify one's identity, and conforming to Google's terms of service. Google also offers a free Limited Distribution option that doesn't require government ID verification but restricts distribution to 20 authorized devices, while apps from unverified developers can still be installed by users who enable Android's advanced installation flow.

The potential death warrant hanging over its head hasn't stopped the F-Droid team from rolling out a bunch of new features for an app it says it intends to keep working on for years to come... The team also credited the EU's many Digital Markets Act decisions against Google for making the installation experience smoother for users. F-Droid can now use a unified installation service for its apps thanks to the availability of a pre-approval API that allows users to approve an installation when they request it, rather than waiting until the app has finished downloading. That, said the F-Droid team, "brings the F-Droid install experience on official Android devices much closer to what the built-in app store can provide." Additionally, F-Droid 2.0 can fetch and install app updates automatically, which it now does by default.

All of those changes, however, won't matter much if Google pushes ahead undeterred with its plans to force registration onto non-Play Store developers. F-Droid's announcement on Thursday makes it seem that the team isn't going to go quietly.

F-Droid has gone 10 years without a major update, notes Ars Technica — and spent over a year developing F-Droid 2.0: The new F-Droid client was redesigned from scratch in Kotlin Compose, which is the standard for modern Android apps. This makes the store much more responsive, and there's optional support for Android's Material theming. The interface has also been cleaned up considerably, making the most important functions easier to access and hiding some others in overflow menus... Unlike the Play Store, F-Droid doesn't track your taps and installs to push ads and suggestions — it helps you find things and gets out of the way.

F-Droid now includes a huge number of categories, drilling down to specialized niches like firewalls, password managers, and VPNs. You can see all these groups in the search tab. There are also higher-level categories listed on the main Discover page. When searching for apps, F-Droid will now be able to return results based on app descriptions rather than just names.

"One of the goals of the rewrite was to lower the barrier for new contributors," F-Droid said in their announcement. "We are excited to begin rolling out F-Droid 2.0 to users over the coming weeks after 14 test releases." (And if you want the 2.0 release right now, it's available on the versions page.)

F-Droid 2.0: FOSS Android Appstore Continues Updating Despite Google's Pending 'Developer Verification' Plan

Comments Filter:
  • by williamyf ( 227051 ) on Friday September 25, 2026 @04:37AM (#66350356)

    I used F-droid on my Blackberry Q10, and KeyOne, But I used so few apps from there, and all of them were on the official playstore, so, at the end, for my Razr+ 2024, I did not bother to install F-droid.

    Still, glad to see the team moving forward, I desire them good luck, and have nothing but gratitude towards them.

    • Re:Thank you F-DROID (Score:4, Interesting)

      by Errol backfiring ( 1280012 ) on Friday September 25, 2026 @05:24AM (#66350380) Journal
      F-droid is the only app store on my phone with LineageOS. Off course, the Google "services" are not installed either. I am never going back to stock Android again.
      • Couldn't have said it better myself. LineageOS, F-Droid, and sideloading FTW.

        I'm still using the version of SoundHound that I had on my HTC Evo 3D from more years ago than I want to think about. Yeah, security, I know. But newer versions are more intrusive and enshittified. The age has never caused any problems, maybe because I also don't use my phone for banking, payments, or any other shit that AFAIC is the province of my laptops.

        As an aside, have you tried PipePipe? It can be a bit flaky for me, but the

        • I use both newipe and pipepipe, and both work great. Newpipe officially supports peertube, and pipepipe has more adblocking options.
  • GrapheneOS (Score:3, Informative)

    by FPhlyer ( 14433 ) on Friday September 25, 2026 @05:33AM (#66350384) Homepage

    I've used Fdroid for years (mostly for Termux) but I started moving from Android to GrapheneOS little by little over this last summer, first on my Pixel Tablet and more recently on my Pixel phone. Fdroid is an excellent app store here.
    If you are lucky enough to own a Google Pixel device, switching to GrapheneOS is an option to escape from Google's "walled garden".
    Motorola has announced plans to start offering GrapheneOS as an option on some future models as well.

    • the irony of buying a phone from the same company that wants to screw you over. graphene is a joke, and I don't care what they say "only Pixel phones have secure elements" or whatever.
      • Yes, buying a Google phone to escape Google! Hence various folks are excited Lenovo are joining the effort. GrapheneOS has a laundry list of requirements only Tensor/Pixel could meet. The latest Snapdragon-powered Moto Signature announced this week does now.

        Later revisions of the ARM spec, such as MTE are supposed to segfault when performing an illegal op in C code, you'd hope security bug reports would flow upstream to fix coding errors - their Wikipedia page lists a Bluetooth fault that was patched.

        ( But

        • >"Yes, buying a Google phone to escape Google! Hence various folks are excited Lenovo are joining the effort."

          Yeah, I have always wanted to run an alternative Android. However, only one of my past phones could do so because the alternatives only supported very few phones. And, ironically, the best-supported ones are Google's phones.

          There are a few features I have wanted by having an alternative. The main would be the ability to force/control all permissions and with spoofing. Example- location servic

          • Re: GrapheneOS (Score:4, Interesting)

            by alexgieg ( 948359 ) <alexgieg@gmail.com> on Friday September 25, 2026 @09:36AM (#66350508)

            the alternatives only supported very few phones.

            I only purchase phones I know I can install alternative OSes on. When one of my current ones is getting too old and in need of replacement, I research what the current alternative Android OSes are, chose a bunch I find are nice enough, then find the list of devices supported, the chose one from among those that's within my budget range. Those tend to be Motorola, whether officially or via some hack.

            I don't buy a phone to play games, which means most any phone is performant enough for my needs, so I go with the cheapest option that does what I actually need. This also means that warranty is irrelevant: if the phone breaks for some weird reason, which is rate, getting it serviced by paying for the service, or buying a new one outright, aren't a big deal. Hence, the moment the new phone arrives I follow the procedure to get it unlocked, then the new ROM into. Sometimes with Google apps, sometimes without, depending on what I'm using it for.

            As for bank apps and the like, I keep an old, tiny, cheap phone with stock, years-old Android that banks, due to mysteries of the universe, consider "secure" despite having hundreds of unpatched holes all the way down to the kernel. When I need to do banking I pick it from the docs drawer, turn it on, do what I need, turn it off, and back into the drawer it goes. For everyday use I have a debit/credit card, no app necessary with them.

            Streaming is a loss, but eh, YouTube works well enough either with the official app, an alternative one, or a mobile browser, so good enough for watching something on the go. For me that suffices.

            But yes, for those for whose use case is way more mainstream that's certainly not a good fit.

        • One of the reasons I got on the OnePlus bandwagon years ago, was the ability to put CyanogenMod on it. Then the idiots there thought they could literally take on Google head on, and experienced on of the greatest blunders short of land wars in Asia and Sicilian with death on the line, without first immunizing against iocane.

          My only hope right now, is Starlink/Spacex/Testa/xAI creates a whole new ecosphere for communications. Crossing my fingers Starship becomes fully operational sooner than later. Its the

      • Android is on a very slow, but death spiral. Good that there are now alternatives. Not perfect, but good. I have lived with very minimal Android dependencies for almost a year now and only turn it on briefly in a virtual machine on my physical phone. I won't cry when it finally dies just because Google locked out nonapproved developers.
    • Motorola has announced plans to start offering GrapheneOS as an option on some future models as well.

      Excellent... I have been a Motorola customer for quite a while now, mainly because they put out phones that are decent and relatively inexpensive. My current one is 2 years old, and cost me a grand total of $250 after buying protective gear for it.

  • Weird how a service continues to provide that service, even if some other largely unrelated service does other things. Shocking.

  • by Zarhan ( 415465 ) on Friday September 25, 2026 @07:26AM (#66350430)

    Ok, sorry, but while I get the initial backlash for when Google was going full Apple-style walled garden, the new approach where you need to *one time* enable "yes, allow sideloading" after you get your device (and wait 24 hours) is just fine.

    The 24-hour waiting period is exactly for those scammer cases where they ask you to "download and install random APK from some https://scammers.are.us/0wned.... [scammers.are.us] real fast or your money is gone, emergency!" - it stops those.

    Of course Google can change those terms later, but at that point you might as well install Lineage or Graphene (or get Jolla phone and use Sailfish - they have launched new product just recently). For now that *one-time* 24-hour waiting period is just fine and I really don't get the complaints apart from some scaremongering about "they'll try to lock it up again in a few years". Ok, and then what? It's not like those heavier options for degooglefying are going away?

    • I don't know, what do you think the problem is with going into into your App Store of choice and clicking a download button that lets you download sometime tomorrow?

      People aren't complaining about installing a single app here. F-Droid is an app store. Expecting users to wait 24 hours to install each and every app is as good as a death knell, aside from an initial phone setup most apps are installed on a per need basis, not a per "I think maybe I'll need this tomorrow" basis.

      Person 1: "Hey can you tell me wh

      • by AmiMoJo ( 196126 ) on Friday September 25, 2026 @09:09AM (#66350480) Homepage Journal

        That's not what is happening. The first time you enable sideloading, there is a 24 hour cooling off period. After that, installs are instant. And there is probably no delay at all if you get F-Droid from Google Play, only if you download the APK and install it that way.

        The other issue is that Google is requiring all developers to register if they want their apps to install on certified devices. Certified means runs Google Play and passes the security checks that some apps (e.g. banks apps, Google Pay) require. This is already an issue for Graphene OS users, because such apps will refuse to run for them due to the lack of certification.

        It's hardly new though. Apple has required it since day one, and on Windows drivers need to be signed which means identifying yourself to a certificate authority. I imagine the solution will be the same as it is on Windows - someone will register and then sign F-Droid and all the apps offered on F-Droid. If you didn't know, F-Droid builds apps itself. The app source must compile on F-Droid's servers, with various limitations like not having any dependency on Google Play Services.

        • someone will register and then sign F-Droid and all the apps offered on F-Droid

          The problem with that is that Google says it will ban developers whose apps signed this way violate its ToS, which can have anything they want on it, so F-Droid will have to policy apps uploaded to make sure they comply with their own and Google's ToS, and if some gets through that review and does violate Google's, since it'd be signed by F-Droid, that might mean that one account responsible for all F-Droid apps being banned out of a sudden, and with it all F-Droid-installed apps on a single go.

          I imagine an

          • by AmiMoJo ( 196126 )

            Is that so? I can't find a source for Google saying that. Do you have one?

            In any case, I think we will have to wait and see, because I can't imagine the EU being okay with them banning open source developers who refuse to register in that way.

            • I found these ToS [android.com] by searching. I'm not quite sure this is the most up-to-date version, as I don't have a Google developer account and don't want to create a new one to check, but it says these things:

              5. (...) You may not use the ADC:
              * beyond the intended ADC functionality outlined in the Terms and other ADC documentation;
              * to engage in, promote or encourage illegal activity or abusive behavior; (...)
              * to access any other Google product or service in a manner that violates the terms of service of such other Google product or service.

              6.3 Google may make changes to the Terms at any time with notice and the opportunity to decline further use of the ADC. (...)

              6.4 If You do not agree with the modifications to the Terms, You may terminate Your use of the ADC, which will be Your sole and exclusive remedy. You agree that Your continued use of the ADC constitutes Your agreement to the modifications of the Terms.

              6.5 If You violate any of the Terms or if You distribute malware or other harmful applications, Google may terminate Your access to the ADC.

              7.2 You agree that if Google does not exercise or enforce any legal right or remedy contained in the Terms (or which Google has the benefit of under any applicable law), this will not be taken to be a formal waiver of Google's rights and that those rights or remedies will still be available to Google.

              Plenty of apps on F-Droid violate these. Several are illegal in different countries, while others directly violate the ToS of individual Google products. Since F-Droid would be the one signing on all of them, its own ADC use could be cut, and then trying to install apps signed with that terminated ADC key woul

              • by AmiMoJo ( 196126 )

                Not sure that's the case, and above the bit you quoted it does also mention that there will be a special version for hobbyists that has different terms.

                In short I think it's too early to say. It sounds like they haven't figured out what they are going to do yet.

                • That's the limited distribution [android.com] version of the ADC. It has these limits:

                  What can a limited distribution account do?

                  * Register apps

                  * Share apps with up to 20 devices that end-users have explicitly authorized.

                  How does app sharing work?

                  Sharing apps with a limited number of devices is achieved through a secure handshake process involving QR codes or links, user consent on the device, and registration using the Android Developer Console.

                  Check if this account type is right for you

                  The following are common use cases for a limited distribution account:

                  I am a(n): Hobbyist
                  I build apps to: Share with family and friends, or for personal use. My apps have no commercial intent.

                  So, not viable for the scale of F-Droid, or for any application that has more than 20 users, assuming each user would install it on a single device. And yes, they've figured quite well what they're going to do.

                  • by AmiMoJo ( 196126 )

                    Ah, yes. Well, we will have to wait and see I suppose. I would be surprised if they ended up killing F-Droid though, I really can't see the EU being happy about that.

                    • The EU wouldn't care. Google's model as described is still way less restrictive than Apple's, and they've approved Apple's. If Apple's model was found to be acceptable, so will Google's.

                      Their answer to F-Droid will be quite simple: change how it works so it's compatible with how the ADC works by either registering for a single ADC key and being liable for all apps on the store, or by allowing every developer providing apps through F-Droid to have its own ADC and liability. And if F-Droid doesn't want to do

                    • by AmiMoJo ( 196126 )

                      I think the EU would care, especially since Android is currently open and Google is taking something away. Apple gets away with it because they have been like that from day one.

                    • You're supposing the EU doesn't like the control this gives them. Consider how they're pushing privacy invasive age verification all around, and tying the process to people using verified iOS and Android devices. With ADC they'll be able to know exactly who made this or that app they dislike, and it will give them another means by which they can request specific apps providing features the EU doesn't approve of can be disabled.

                      Besides, if they prevent Google from limiting their system in a way similar to ho

                    • You're supposing the EU doesn't like the control this gives them. Consider how they're pushing privacy invasive age verification all around, and tying the process to people using verified iOS and Android devices. With ADC they'll be able to know exactly who made this or that app they dislike, and it will give them another means by which they can request specific apps providing features the EU doesn't approve of can be disabled.

                      EU law (articles 30 [eu-digital...es-act.com] & 31 [eu-digital...es-act.com] of the Digital Service Act) requires that the author/publisher of an app be identified.

                    • by allo ( 1728082 )

                      The EU *would* care, but it will take five years for any action of them to take effect. Google will pay a fine that's no problem for them and in these five years they already got all ex-F-Droid users to says "Fuck, using F-Droid is too complicated now, let's go back to play".

                    • by AmiMoJo ( 196126 )

                      Yes, look at how they are pushing age verification. It's actually a decent implementation, if you accept the basic premise that there is a reasonable interest in protecting children from adult services and material.

                      In fact it might be an improvement over what we have now, where people have to show ID to enter certain venues or buy certain products. The checkout is anonymous, unless you have to show the clerk your ID to prove you are old enough to buy alcohol.

                      They way they have implemented it, you verify onc

                    • I don't accept that premise. If there were, methods would have been open to discussion by the community and one of the actually privacy-preserving alternatives would have been chosen, such as having every website declare the age bracket in the HTTP header, legal determination it cannot be informed incorrectly, parenting tools within devices coming enabled by default and, if not opted-out, which only the adult buyer would be able to do after showing proof of purchase (no identity required), and browsers and

                    • Or F-droid users can just wait 24 hours to set up our new phones. So what?

                      It boggles the mind that F-droid and F-droid-distributed apps keep throwing up these scare banners months after Google altered the new policy to one that allows us to continue as before with only a minor one-time speed bump.

        • "Guys, guys, guys calm down. Stalin has assured us that it's only a one time temporary abrogation of our freedoms and he has no plans to ever do anything else. He wouldn't lie? Right?"

          The water is already bubbling around the frog.

        • by allo ( 1728082 )

          If you get F-Droid from Play, you cannot upgrade it using F-Droid later (different signature keys). So this means you rely on Google for upgrading your non-google store.

        • That's not what is happening. The first time you enable sideloading, there is a 24 hour cooling off period. After that, installs are instant.

          Can you provide evidence that this is actually the way it works? Android currently enables sideloading on a *PER APP BASIS*. Everything Google has announced so far doesn't seem to indicate that they will revert this to a system wide level.

          But the point remains the same. Even if it is system wide (which I am keen to see evidence that it is, since I can't find any on the Android developer website), the last point still stands. It'll now take longer to setup your phone than reinstall Windows and all the softwa

          • by AmiMoJo ( 196126 )

            Android has two toggles for sideloading. The first is the global toggle which enables or disables it for all apps, and then beyond that each individual app that wants to launch an install has to get the permission to do so. But they only have to get it once, and then they can install as many apps as many times as they like.

            So for example, once sideloading is enabled globally I needed to also enable it for F-Droid. But only once, then F-Droid could install apps and updates with only a "are you sure you want

      • Doesn't that cumbersome procedure have to be done a single time (for the first non-signed app), and then it's good for all following apps, and still months after that? Or does it expire?
        • If it's implemented the way Android currently does, then the actual check on the final app is on a per app basis. Thought the developer mode only needs to be enabled once.

      • by Zarhan ( 415465 )

        What on earth are you talking about?

        As others have already said, you need to give *one-time* permission to sideload. The only question asked is if you want to allow sideloading forever or for 7 days. Those are the timeframe choices. It's not for every single app.

        So, get a new phone, go through the menus, allow sideloading, allow forever, reboot phone, 24 hours later you can install whatever APKs you want.

        • As others have already said, you need to give *one-time* permission to sideload.

          As of right now Android manages sideloading on a per app-source basis, and manages certification on an individual per-app basis. I have found zero evidence anywhere that this is an enable once OS wide setting that Google is implementing.

          On my current phone I've had to individually allow "installation from unknown source" about 20 times. Unless they fundamentally change something the only OS wide setting which would stick here would be entering the developer mode.

          Please share a link to actual Google document

          • by Zarhan ( 415465 )

            Seriously, there's a ton of articles about this, but here's a link directly from Google:

            https://support.google.com/and... [google.com]

            Steps 1 & 2 are for the one-time 24-hour cooloff, step 3 is just like before. Oh and note 2e: "After the security delay is complete, you can choose whether to keep the advanced flow on for seven days or indefinitely."

  • F-droid is always the first app I install. The automatic app updates are highly appreciated. You rock!

  • I'm wondering how this is going to work. I have a Play Store account (I paid up the money, handed over all of my ancestory's IDs, work histories, qualifications and inside leg measurements, etc). Every 6 months, I get emails from Google saying "do SOMETHING with your account, or else we'll close it!!". All in the name of "security", apparently.

    It would seem to me then, that an F-droid developer would have to be publishing to f-droid AND to Play Store, or else Google will close their developer account, thus

  • by denisbergeron ( 197036 ) <DenisBergeron@DE ... om minus painter> on Friday September 25, 2026 @10:30AM (#66350570)

    My phones are either on Graphene or Lineage with microG.
    My phone, my choice :-)

    I own it.

    • Love your non-sig sig!

      LineageOS here, but no micro-G. Thankfully, I don't need that shit for my use case.

      • /e-OS/ here (about the same as LineageOS); I did setup micro-G just to get the Canon Camera Connect app to control my EOS-camera, which worked nicely for a couple of years but then an upgrade started to demand a login to a Canon ID. ;-( So ditching micro-G and sideloading an older version is what I do nowadays...
  • as usual there are lots of way to support the team, but particularly there is quite a backlog of app MRs waiting for test/review. If you want to support the F-Droid then it is a really practical way to help them out: https://gitlab.com/fdroid/wiki... [gitlab.com]
  • They sussed that a lot of us are using older OS's on our phones, And that some of us block all of android & google's shit (literally all of it), And that said people will never receive a 'devoloper verification' on their device. I will sideload whatever I want, Whenever I want and no fucking 'big tech' dickhead is gonna make me do otherwise. I would rather destroy my phone entirely than give these people an inch. And I'm not fucking joking.

A company is known by the men it keeps.

Working...