Google Can't Kill Your Sideloaded Apps Yet. F-Droid 2.0 Is Why.

Bottom line: F-Droid shipped version 2.0 on September 24, 2026, its biggest rewrite in a decade, six days before Google's developer-verification rules take effect.

The first wave hits Brazil, Indonesia, Singapore and Thailand on September 30, with the rest of the world following in 2027. F-Droid 2.0 doesn't stop Google's rules.

What it does is make the one store built to survive them easy enough for ordinary people to use. If you sideload apps, this is the week to install it and learn how it works.

I've recommended F-Droid to friends for years, and I've watched every one of them quit within a week.

The old app looked like a spreadsheet from 2014, and it made installing a simple notes app feel like a favor you were asking of your phone. I told myself that was the price of freedom.

I was wrong about that, and F-Droid's team clearly agreed. On September 24 they shipped F-Droid 2.0, and it hit the top of Hacker News within hours.

By some counts it passed 1,000 points and 270 comments fast.

The timing is the story. This isn't only a redesign. It's a store getting ready for a fight.

What Google Is Actually Changing

Google's new rule is simple to state.

Every Android developer has to register with Google, pay a one-time $25 fee, and verify a government-issued ID before their app counts as "verified." That applies even if the app never touches the Play Store.

Unverified apps can still be installed, but with friction. Users have to enable developer options and sit through a 24-hour wait.

The first enforcement wave starts September 30 in Brazil, Indonesia, Singapore and Thailand. Everyone else follows in 2027.

Google's stated goal is stopping malware from anonymous publishers. That's a real problem, and I'm not going to pretend otherwise.

But the fix treats every independent developer as a suspect until they hand over an ID.

F-Droid has been blunt about what that means for it.

Its position is that the developer-registration decree, if put into effect, would end the project and other free and open-source distribution sources as we know them.

That's a strong claim, and it's the reason this update matters.

The Contrarian Take: The Fight Isn't About Security

Most coverage frames this as security versus freedom. I think that framing lets Google off too easy.

F-Droid doesn't work like a normal store. It builds apps from public source code itself and signs them with its own keys.

Thousands of the developers behind those apps are hobbyists, volunteers and anonymous maintainers who never asked for a relationship with Google.

Article illustration

They aren't a malware risk. They just aren't customers.

A rule that makes anonymity expensive doesn't remove bad actors. It removes the people who never wanted to be in the system. Malware authors will pay $25 and use a stolen ID.

A volunteer who maintains a bus-schedule app in their spare time probably won't bother.

So the real question isn't whether Android will stay secure. It's whether Android stays a platform anyone can publish to without permission.

That's a much bigger question, and it's why a rewrite of an app store trended above nearly everything else this week.

Why the Redesign Is Part of the Defense

Here's the angle I think most people are missing. Resistance to a platform rule doesn't run on principle alone. It runs on usable alternatives that normal people will actually pick.

F-Droid's old weakness was never ideology. It was UX. If the alternative is confusing, people take the default, and the default is whatever Google allows. F-Droid 2.0 attacks that weakness directly.

The new version was rebuilt in Kotlin with Jetpack Compose, which lowers the barrier for new contributors.

It has three-tab navigation (Discover, Search, My Apps), multi-level categories, and better search with CJK language support. You can also filter by category, device compatibility and anti-features.

It shipped after 14 beta releases and an independent security audit, according to byteiota's write-up.

An independent audit matters more than it sounds. Google's argument is that unverified distribution is unsafe.

A third-party audit of the store's own client is the most direct rebuttal an open project can offer.

The Framework: Three Layers of Platform Control

Here's how I think about it. Every platform controls what runs on it through three layers, and Google is tightening the third.

Layer 1: The Store

This is where apps live, and it's the layer everyone knows. Google Play decides what appears and what doesn't. F-Droid has always been the alternative here.

Layer 2: The Installer

This is the code that puts an app on your phone. Android historically let any app act as an installer once you granted permission.

F-Droid 2.0 leans on this layer with changes to background installations, Tor support and panic features.

Layer 3: The Identity

This is the new one. It asks who made the app and whether Google knows them. Once identity becomes the gate, the store and the installer don't matter much.

You can build the best alternative store in the world and still be blocked by a checkbox you don't control.

The quotable version: you can win the store layer and still lose the platform at the identity layer. F-Droid 2.0 is a strong move on layers one and two.

It can't fix layer three by itself, and it would be dishonest to say otherwise.

What This Means for You

If you're a regular Android user, nothing breaks on September 30 unless you're in one of the four launch countries.

But the rules are coming everywhere in 2027, and habits are easier to build now than in a panic later.

Install F-Droid 2.0, add two or three apps you actually use, and learn what the update flow feels like.

If you're a developer, the calculation is harder. I'd think through three things:

If you run a team that relies on internal sideloaded tools, check how enterprise distribution is treated under the new rules.

I don't know the full details of every exemption, and you shouldn't assume there are none.

Article illustration

What I Got Wrong

I used to think alternative app stores lost because people don't care about freedom. I don't think that anymore. People lost interest because the alternatives were unpleasant, and pleasant is a feature.

Watching F-Droid ship a real, modern app was humbling. Volunteers with a fraction of Google's budget did in about a year what I'd assumed was impossible for them.

I'd written the project off as a niche tool for people who enjoy suffering. It turns out it just needed a designer and some time.

I'm also cautious about the victory lap the internet is taking. F-Droid 2.0 is good news, and it isn't a win.

Google still controls the operating system, the verification program and the enforcement dates. A well-designed app doesn't change who holds the keys.

The Bigger Picture

The deeper issue is what "your phone" means. When you buy a laptop, nobody asks you to register with the manufacturer before you run a program you wrote.

Phones drifted away from that norm slowly, one reasonable-sounding safety feature at a time.

Each step made sense on its own. Together they built a device that runs what a company permits, even though you paid for it.

F-Droid is one of the last places where the older idea still lives: that software is something you can build, share and run on your own hardware without asking anyone.

That's why a store update landed like a protest. It wasn't a protest in the traditional sense. It was a well-built alternative that shipped on schedule, six days before the deadline.

I think the real test comes in 2027, when the rules reach everyone and people find out whether they care enough to use the alternatives that exist.

So here's my question for you: if installing an app from outside Google's system meant a 24-hour wait and a developer-mode toggle, would you still do it, or would you just give up on the app?

Sources: Android Authority, The Register, byteiota, Notebookcheck, F-Droid Forum.

Story Sources

Hacker Newsf-droid.org