Skip to content

Build1 publisher2 min readPublished

Android's developer verification rule extends past Google Play in four countries on September 30

Google's Android developer verification starts September 30 in Brazil, Indonesia, Singapore and Thailand, covering apps from any channel on certified devices. Developers shipping outside Play, F-Droid included, now need a plan for verified identity in those markets.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Android's developer verification rule extends past Google Play in four countries on September 30
Generated illustration

What happened

  • Limited Distribution lets individual developers and students skip government ID checks, but restricts distribution to 20 devices.
  • Apps that take neither route fall to an advanced sideloading flow designed to add friction and slow social engineering.
  • F-Droid's open letter, signed by the EFF and FSFE, objects to the advanced flow and cites the project's practice of building apps from source and signing them.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision An F-Droid-listed developer has to confirm which key signs the copy users actually install before counting on a Full Distribution registration to cover it.
  • constraint A project with more than 20 installing devices has no ID-free verified route; it registers under Full Distribution or its users face the advanced flow.
  • exposure In the four launch countries, an alternative store's catalogue depends on each listed developer's verification status, because the rule applies whatever channel delivered the app.

According to a dev.to write-up of the policy, Full Distribution asks for formal identity verification. It also requires package names to be registered using an APK signed with the developer's own private key [4]. That registration is what ties a named developer to a package [4]. The rule then requires every app installed on a certified Android device to be linked to a verified developer, whatever channel delivered it [3]. Google's stated aim is to cut malware in sideloaded apps [8].

The other verified route is small by design. Limited Distribution, meant for individual developers and students, skips government ID and restricts distribution to 20 devices [5]. Apps on neither path fall to the advanced flow, which the write-up describes as a restrictive mechanism meant to add friction and slow social engineering [6]. A project with a public listing and more than 20 users has two options. It registers under Full Distribution, or its users meet that friction [2].

The rule leaves alone the one workflow where the developer and the user are the same person. Pushing debug builds over ADB to your own testing hardware by USB is unaffected [7].

F-Droid's build model is where the key requirement bites. The project raised concerns about the advanced flow in an open letter signed by the Electronic Frontier Foundation and the Free Software Foundation Europe [9]. The letter describes an architectural mismatch: F-Droid frequently builds applications from source code and signs them [9]. Put that beside the Full Distribution rule. An F-Droid-listed developer then has to find out whether the APK a user installs from F-Droid carries the key the developer registered [4][9]. The write-up does not explain how Android matches an installed APK to a registration. Until that is documented, I would not assume that a registration made with a developer's own key covers a copy someone else signed.

The client caught in this is careful work. F-Droid 2.0 shipped on September 24, six days before the mandate's September 30 start [1][2][1]. It is a ground-up rewrite in Kotlin and Jetpack Compose, finished after more than a year of development and fourteen public test releases [1]. The Open Technology Fund's Security Lab reviewed it with Convocation, with funding support from the Calyx Institute and NLnet [10]. An external audit before release is the right order of operations for software whose job is installing other software. Updates now fetch in the background by default, and the minimum SDK is Android 7 [12]. The panic trigger and the F-Droid Privileged Extension were paused to get the rewrite out [11].

What to watch

  • Google documentation on how Android matches an installed APK to a package-name registration; it decides whether F-Droid-signed builds count as verified.
  • The full text of F-Droid's open letter, and any change Google makes to the advanced flow in response.
  • Whether Google extends the mandate beyond Brazil, Indonesia, Singapore and Thailand.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories