back
564 comments
> F-Droid is different. It distributes apps that have been validated to work for the user’s interests, rather than for the interests of the app’s distributors.

F-Droid's curation saved me at least once when I wanted to upgrade my Simple™ apps and couldn't find them in F-Droid anymore, which led me to learn that SimpleMobileTools was sold to a company that closed sourced the apps[1] and that there's a free fork called Fossify[2].

Had I installed these through Google Play, they wouldn't have cared about this particular change and I would've gotten whatever random upgrades the new owners pushed.

Each app store's policies have their pros and cons, but that's why it's so important to have a diversity of marketplaces.

[1] https://github.com/SimpleMobileTools/General-Discussion/issu...

[2] https://github.com/FossifyOrg

This weekend I needed to send a few PNGs by email. They were huge, so I figured I’d just grab an image compressor from the Play Store.

I checked out five different apps, each with millions of downloads. Every single one was riddled with data collection prompts and stuffed with ads.

Fine, I thought, I’ll pay to remove the ads. But the options were:

- “Free trial” that defaults into a $5/month subscription

- Or a $19 “lifetime” purchase

It’s so clearly designed to trick people into a recurring subscription for what’s essentially nothing. These apps are just wrappers around existing Android libraries. And if you check the reviews, they’re obviously bought.

This was literally the first time in a year I tried to download something from the Play Store, and the experience was so bad I just gave up and solved it faster in the browser instead.

The SimpleMobileTools fiasco and the way FDroid stayed resilient against it is the perfect example case of how their 'security' argument behind the side loading ban and developer registration mandate is hollow, misleading and harmful.
I used Simple apps in the past but lost track of them. Now i know why. Thanks for bringing it to my attention.

Indeed we need diversity of the ecosystems.

I had no idea fossify was fork. Until this moment I had apps from both of them, some orange, some green, but the calendar started bugging out by opening a different date to what I clicked on. I see my phone hasn't updated it since last year. Now finally I've deleted them all in favour of the fossify ones. Thanks.
Google has a track record of turning a blind eye to malware and fraud delivered through their own channels. I like how F-Droid tackles them both - they've been my default app store for years at this point.
Thank you for this info. I had no idea why a couple weeks ago the calendar app was suddenly needing to connect to the net on startup and then doing a splash ad. Will be installing the Fossify version shortly!
Is Simple Gallery known to do anything shady now, behind the scenes? I had no idea it was sold either, and it's been my go to gallery app on all my devices for a long time. Just curious.
HA! I use the "Simple" apps as the poster child for my rants about apps kneecapping themselves on purpose.

It's funny how the more one gets burned the more one becomes the kooky old fart the cliche requires us to be...

I did the exact same research and came to the same conclusion. I wouldn't have been prompted to do it without F-Droid
I contacted the European Commission DMA team on this gross abuse of power (Google just followed Apple in this regard, who reacted to the DMA by coming out with this notarization of developers), here is they flacky answer:

"Dear citizen,

Thank you for contacting us and sharing your concerns regarding the impact of Google’s plans to introduce a developer verification process on Android. We appreciate that you have chosen to contact us, as we welcome feedback from interested parties.

As you may be aware, the Digital Markets Act (‘DMA’) obliges gatekeepers like Google to effectively allow the distribution of apps on their operating system through third party app stores or the web. At the same time, the DMA also permits Google to introduce strictly necessary and proportionate measures to ensure that third-party software apps or app stores do not endanger the integrity of the hardware or operating system or to enable end users to effectively protect security.

We have taken note of your concerns and, while we cannot comment on ongoing dialogue with gatekeepers, these considerations will form part of our assessment going forward.

Kind regards, The DMA Team"

The DMA is in fact cementing their duopoly power, the opposite of the objective of the law.

F-droid has been stellar in steering the alternative app store environment over the past 15 years or so, and I'd heed their call on this.

A small call to any googler on the thread - put your support towards this internally. I understand the internal dynamics, and it may seem current option is best amongst imperfect choices, but in this case F-droid is right in that closing out anonymous (but good) software is a line crossed with peril for any open ecosystem. Today it's play store, tomorrow it will be the web, and that will have a significant negative impact on Google.

I've built a couple of tools for myself over the years, some of which includes android apps. They were never released to the public.

If we go down this path, I will stop all development on android (and at work too, as it is up to me how we deliver, coincidentally). I implore all other developers to resist this. This will completely lock down the platform forever, there will be no going back.The entire reason why android is so attractive is because we have linux in our palms and all the amazing benefits of that. If google wanted to do the right thing, they would go in the opposite direction and make it easier to gain root access on mainstream devices instead of locking it down further.

It seems the only last bastion left is Firefox, so I will be focusing on making all my tools work well on Firefox (mobile & desktop) instead of app ecosystems.

While Google are capable of being evil all on their own I wonder if the regulatory environment companies are facing around the world is contributing. It is going to lead to increasingly restricted systems with less choice for consumers.

I recently tried to install Thunderbird email on my 17 year old's phone so he could access our self-hosted email for education, jobs, government things that young adults require. After jumping through hoops with age verification it turned out not to be allowed for his age for some unfathomable reason. Increasingly content providers, app stores, os providers etc are coming under chilling industry codes here requiring age verification and age restriction. So I used f-droid so my young adult could start making applications.

What I see as freedom might look a lot like circumvention to regulators.

As all the big commercial services step into line with government codes and turn restrictions to their commercial advantage I am not sure where that leaves those of us who use FOSS software. My apps come from Flathub, arch, debian, f-droid not Apple, Google, or Microsoft stores. My devices come OS free when possible. The volunteers involved haven't participated in the development of industry codes and aren't in a position do all the compliance stuff that governments increasingly demand from tech companies. How much longer will free and open source be tolerated?

I still haven't seen anyone discuss the issues with distributing applications containing GPLv3 components under these new rules given the clause (from the GPLv3):

> “Installation Information” for a User Product means any methods, procedures, authorization keys, or other information required to install and execute modified versions of a covered work in that User Product from a modified version of its Corresponding Source. The information must suffice to ensure that the continued functioning of the modified object code is in no case prevented or interfered with solely because modification has been made.

At the moment, the workaround here is that keys can technically just be generated on the fly (with some caveats). With Google's new requirements, that's not possible.

We need to start treating phones differently. We're entering a world where we can't choose what we run on them. Their primary purpose is to gather data on us and serve us advertising, they're engineered for addiction, yet engaging in the world is immensely difficult without one.

Phones are as much a burden as benefit in 2025, and our behaviour towards them should reflect that. Mine is currently off and in the drawer of my desk. I'll turn it on again when I need 2FA, some service provider's app, or when I'm likely to be out of the house for an extended period. I'll turn it off again when I don't need it.

The "vote with your feet" argument was always specious in a duopoly. If consumer rights depend on the whims of giant corporations like Google and Apple, then consumers never had rights. "Just switch to Android if you don't like iOS lockdown" is now becoming a joke.

Consumers desperately need specific legal rights to do what we want with the electronic devices that we've purchased, rights that cannot be overridden by the decisions of any vendor.

Apologists have always said, "Apple has a right to do what it wants with its platform." Well guess what, by that principle, so does Google. Don't worry, though, because you have a "choice" between two collaborating duopolists.

What a disaster this will be. The end of any really open phones. By the time I cannot sideload apps or torrent onto my device, I might as well move to an iPhone and at least get less data tracking and better security.
I was waiting for fdroid's voice about this. Google's move is as bad as I initially thought. This makes me a bit sad honestly, android development is getting worse every year. I wonder if the same will happen to web as well.
Sadly, our current age of computing is getting locked in devices. Not only most computing today is SoC with closed drivers but it's actively locking the user.

Ironically it all started with Cydia and "hacking" the iPhone until executives understood they can make a cut.

The EU did help to some extent by requesting Apple to enable non-appstore apps. but sadly, instead of doing the right thing of simply having a user switch that allows me to decide if I want to put my device at risk, they went with provisioning that seems to be agreed.

So now, we're getting the same slap from Google/Android which I must say very strangely gets blessing from very specific governments:

> The requirement goes into effect in Brazil, Indonesia, Singapore, and Thailand. At this point, any app installed on a certified device in these regions must be registered by a verified developer.

Related thread from a month ago: We should have the ability to run any code we want on hardware we own, link: https://hugotunius.se/2025/08/31/what-every-argument-about-s...

(Discussion link: https://news.ycombinator.com/item?id=45087396)

I trust F-Droid more than the Google Play Store. I have F-Droid installed, but not the Google Play Store.
I turned on "Advanced Protection" a couple weeks ago, and promptly turned it off the other day when it blocked f-droid updates. What a scam android has become.
Better totally leave Android.

It will be a long tough uphill battle, but digital freedom is possible.

Purism is for example providing the Librem 5 phone with PureOS. Closing the app gap is big challenge, but I use the Librem 5 as my daily phone. Yes, I may have some inconvenience, but I have freedom, and the software is getting better and better.

For more info see also:

* https://puri.sm/posts/googles-new-sideloading-restrictions-w...

* https://puri.sm/posts/closing-the-app-gap-momentum-and-time/

This whole situation sucks. I enjoy F-Droid exactly. Because I can use stores like F-Droid or just download a package from github and be able to run it on my phone. That going away for corporation and governmental greed is just... Sigh.
Reminds me of Nokia/Symbian. To install a `.sis(x)` with any useful capabilities (permissions in Android) one needed to sign it with Nokia's keys; which they normally couldn't, at least with non-business email addresses. Until someone found a way to hack the roms and it became a Tom&Jerry struggle between hackers & Nokia who wanted to suffocate them by patching those loopholes.

Then came Android. The freedom to sideload any `.apk` on any device was magical. And now we've come full circle.

Except that Symbian wasn't source-available, so there was a bigger hope for a successful rebelion.

F-Droid is great. It's a stark and sad outlook that the only path forward suggested by F-droid is to contact your representative. Effectively, this means there's nothing we can do. Expecting our representatives to go to war with Google on this somehow doesn't seem too plausible. I think it's more likely there will always be a way to sideload apps, or if not, maybe the degoogled OS alternatives will find their moment to shine.
F-Droid apps have enabled me to more-or-less DeGoogle my tablet and populate the device with some truly exceptional software, much of which just isn't available on Google's Play Store. I've also made sure to pay/donate where possible: we can't afford to lose this resource!
If you aren't already aware of it, here is Google's official feedback form on this proposal:

https://docs.google.com/forms/d/e/1FAIpQLSfN3UQeNspQsZCO2ITk...

"You may also need to upload official government ID."

That would be illegal in Germany, and probably also in other EU countries. Only the gouvernment and banks are allowed to make copies of IDs. Alle others aren't. Can get you in serious legal trouble. Not that a data hog like Google would care.

The article has corrupted paragraphs towards the end? Only for me? Read it with niche browser, did not verify with any mainstream browser.
I think we have reached the point when AppStore / Google Play must be spun off from Apple / Google and made to work as a separate companies, and have access to Android / iOS platforms on equal terms with other vendors.

We have a great example of such approach on desktop: while some people decry Steam for being a monopoly, it is totally different. Users aren't forced to use it, but choose to use it, and nobody prevents them from installing epic store or whatever. This will stop monopolistic anti-user abuse in their tracks and greatly improve conditions for everybody (except Google and Apple, but after all these years, they kinda deserve it).

Anyone else thinking this looks like precursor to banning Signal and similar?

1) Put google in control of what you can install.

2) Get google to block it.

Noting that making it harder to install does most of the job as you need you contacts to use signal before you can.

My Pixel 6 just broke, and after 15 years of using Android (I still miss that Nexus One trackball!), I’ve finally been convinced to move to iOS.

If I have no options left and must live in a walled garden, I suppose I’ll choose the one with nicer flowers.

The time to fight is now!! We are careening toward a bleak future of mobile computing.
Syncthing-fork is only distributed by f-droid and direct download from github.

F-droid is essential for many apps.

I managed to get around with apps only from F-Droid. No ads, no popups, no notifications, work without Internet access, better than Google Play apps in every aspect. The only thing left is to make a ROM without preinstalled garbage apps from the vendor.
So for Australia, what can someone do?

I don't believe that regulation these days can stand against corporate interests. I have seen this happen many times already. So what can I as a consumer do? The two practical options seem to be either Apple or Google.

I see a lot of comments here talking about "end of free computing" and similar stuff. However, I'm trying to find ways to be somewhat optimistic. There are already companies that attempt to make smartphones that actually try to preserve our freedoms (Fairphone and PinePhone come to mind, I'm sure there are more). So even if mass-market smartphones become locked-down completely, we will still have alternatives. Sure, in some ways these alternatives might be less convenient, and they might be expensive - but if you can put a price tag on your freedom then you might not need it too much in the end.
F-Droid is the best. I have around 20 apps from them on my phone, more then half of them can not be found on the Google Play Store.
I'm glad fdroid is voicing its concerns and asking people to act.

This is not just another technical challenge. If your country is ever in the crosshairs of "American interests" and bears the brunt of its sanctions, it is possible that you cannot install apps from your fellow citizens i.e. your own local government, bank and store apps.

Countries that are likely to face sanctions are also likely to be predominantly Android users, so it affects them disproportionately. Good luck teaching your fellow citizens to root phones their phones(which is getting hard and outright impossible on certain phones) if that happens.

This is a real challenge that countries need to think and plan for.

If Google really goes through with this I might seriously consider GrapheneOS. At least Pixel hardware ought to still support unlocking the bootloader. But for how long...
This isn't just a competition between app stores; it's a struggle for choice and dignity Your phone shouldn't be a cage carefully constructed by others, but an extension of your own will. Allowing apps like F-Droid to exist preserves an enclave of freedom, transparency, and trust in the digital world. It protects not a particular platform, but our fundamental dignity as digital citizens: my device, my choice
I wonder what would happen if F droid signed all software under their keys even though they aren't the developer? Make Google ban them instead of just giving up?
- there is no escape from digital techno feudalism

- you will have to obey corporations

- sooner or later everything will work using digital ID, or some other IDs

- sooner or later phones, PCs, browsers, will be locked in

- majority of populations will have no problems about that, aka golden cage

- I do not such a future exists when it will not look like this

- I am uncertain what is the future of open source. I think it also will be regulated by accounts, digital IDs. You will not be able to participate in open source without verification

I still don't understand a lot of the specifics of the signing. So they're going to force through this change with a Google Play Services update? This will affect even old devices - like ones running some kiosk app?

How does this work with Chinese ROMs - that don't come with Google Play Services? How do it affect secondary app stores? A developer releases their app on Vivo's app store - and he has to register with Google's ID procedure?

If you're running some old Android version and you block Google Play Services from updating, will the Play Services stop working entirely and brick the kiosk phone/tablet?

If this was a change required in the next version of Android, then I could kind of understand. You buy a new phone and this is the Faustian bargain you choose to accept. Google's search ad cash cow is dieing. Time to milk all their assets. Google obviously doesn't want people making money off of their Android work - to me this was inevitable. But the fact they're forcing this down the throats of existing users.. this seems messed up and maybe illegal?

It irks me to no end that for proper GrapheneOS support one has to buy a Pixel.
Doesn't this issue get solved by reproducible builds?

Using reproducible builds allows developers to publish apps on F-Droid using their own signing keys [1]. Those signing keys can then be verified by Google.

In 2023 already, 2 out of 3 new apps used this approach [2].

With this in mind, F-Droid should be able to continue functioning after this change by mandating reproducible builds.

[1] https://f-droid.org/docs/Reproducible_Builds/

[2] https://f-droid.org/2023/09/03/reproducible-builds-signing-k...

Well, that's because of trusted computing: https://en.wikipedia.org/wiki/Trusted_Computing

And again, to quote Benjamin Franklin, "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety".

Sadly nobody cares nowadays.