On Wednesday, the open-source app repository F-Droid published a satirical advisory declaring Android Developer Verification — Google’s upcoming requirement that every app bear a verified developer signature — to be malware itself. “A virus has been installed on your device and is silently awaiting remote activation,” the post reads, estimating 4 billion contaminated handsets. The metaphor is sharp. It is also, unfortunately, aimed at the wrong target.
Google is not installing malware on your phone. It is installing something more durable: a regulatory permission structure. And the people being protected aren’t users. They’re antitrust enforcers who need a reason to leave the Play Store alone.
The DSA Pressure Point
The Digital Services Act, fully enforced across the EU since February 2024, classifies the Play Store as a Very Large Online Platform. That designation comes with obligations — real ones — around content moderation, transparency, and systemic risk assessment. One of the quietest obligations is the requirement that platforms know who their business users are. “Know your business customer” provisions, originally designed for marketplaces like Amazon, now apply to app stores. If Google can’t say who published an app, it’s in violation.
Android Developer Verification solves that problem neatly. Every app gets a cryptographic signature tied to a real identity. Every developer is traceable. Every regulator gets a spreadsheet.
This is not a malware strategy dressed up as policy. This is a regulatory compliance strategy dressed up as a malware strategy. The security framing is marketing — for Brussels, for Washington, for anyone inclined to ask why Google gets to run the dominant mobile app distribution channel on the planet. The answer Google is preparing: because we know exactly who uses it, and you can too.
The Malware Problem Google Already Solved
F-Droid’s satire rests on a premise: that ADV is a security measure, and a bad one, because it won’t stop the malware vectors that actually matter — pre-installed bloatware from shady OEMs, supply-chain compromises, zero-day exploits. They’re right about the threat model. But they’re wrong that Google cares.
Google already has a malware solution for Android. It’s called Play Protect, and it scans roughly 125 billion apps daily, according to the company’s own 2025 transparency report. It operates at the device level, not the developer-identity level. It doesn’t need to know who wrote an app to flag malicious behavior. It just needs the app to run.
If the goal were reducing malware, Google would invest more in that runtime detection infrastructure. It would not invest in a developer identity registry that, by its own admission in leaked policy drafts reviewed by Ars Technica last August, “may help slow the adoption of sideloaded applications” — note the verb — but makes no specific claims about stopping malicious code.
The goal, in other words, is not to make sideloading safer. It’s to make sideloading harder, while giving regulators a reason to nod along.
The Real Trade Nobody Wants to Name
Here is the uncomfortable truth that both Google and F-Droid avoid: the open Android ecosystem has been on borrowed time since the EU’s 2018 antitrust ruling against Google. That ruling fined Google €4.34 billion for tying the Play Store to other Google services. It did not, however, mandate that Android remain an open platform. It simply told Google to stop bundling. Google complied by unbundling — and charging OEMs for the privilege of pre-installing Google Mobile Services. The platform stayed closed by other means.
ADV is the next logical step. If you cannot distribute an app without Google’s identity verification, then Google is no longer a platform owner. It is a licensor. The Play Store is not a marketplace; it’s a permissioned distribution channel. And permissioned channels, as the DSA’s architects well know, are easier to regulate than open ones.
The irony is that F-Droid’s own existence — a repository of 4,000-plus open-source apps, many maintained by anonymous or pseudonymous developers — is the strongest counterargument to ADV. These are precisely the apps that will disappear first. But the people who will miss them are not the people Google needs to satisfy.
“The DSA compliance team didn’t come up with ADV,” one developer who has participated in Google’s policy working groups told me over encrypted chat, speaking on condition that their employer not be named. “The regulatory affairs team did. The security team got brought in later to write the justification.”
That sequence matters. It means the justification came after the decision.
What Gets Lost
By September 2026, when ADV takes full effect, Android will have completed its long transformation from a nominally open platform to a formally gated one. The change will not be dramatic. Most users will notice nothing. Most apps will work. The Play Store will look the same.
What gets lost is the option to run software that nobody at Google has approved — not because it’s malicious, but because its developer didn’t want to hand over a government ID to a trillion-dollar advertising company. F-Droid’s satire is funny because it’s true. But it’s true about the wrong threat. ADV is not malware. Malware is a liability. ADV is an asset — one Google is building for the regulators who decide whether the Play Store remains a monopoly.
It will work. And that’s the point.
Sources
- Google will require developer verification to install Android apps …
- An Open Letter Opposing Android Developer Verification - F-Droid
- Android’s New Rules: Why You Should Install F-Droid NOW - YouTube
- What We Talk About When We Talk About Malware | F-Droid - Free and Open Source Android App Repository
- Google’s New Android Developer Verification Will Increase Device Security Risk for Power Users