>
Privacy & Security

Google’s Android Lockdown Is Still Happening — Don’t Be Fooled by the PR

Google’s Android Lockdown Is Still Happening – Don’t Be Fooled by the PR

Google told everyone they would back off on locking down Android. They didn’t. That was the message out of F-Droid (a free, open-source catalog of Android apps) after FOSDEM 2026 (the annual open-source developer conference in Brussels), and it is the message I want to be very direct about: the plans are still scheduled, no “advanced flow” has materialized, and the only thing that changed is the volume of the press release. If you read one piece on this, please read it now, before the next update rolls out and the clock runs out on the part of the Android world that isn’t Google’s.

What the August announcement actually said

In August 2025, Google published a blog post titled “developer-verified” that walked back some of the harshest parts of the developer registration rules that were supposed to land in 2026. The company said there would be an “advanced flow” for experienced developers, that the registration fee would only apply to a small slice of accounts, and that hobbyists and students would not be affected. The post was met with relief. F-Droid noted the update. A few outlets ran headlines saying the threat was over. I was cautiously positive myself, for about thirty seconds.

The thing is, the August post was a roadmap, not a deliverable. Eight months later, the only people who can describe how the advanced flow works in practice are the people writing the policy. Nobody outside Google has used it. It wasn’t in Android 16 QPR2 (the second quarterly platform release), it wasn’t in QPR3 Beta, and it isn’t in Android 17 Beta 1. The most generous read is that Google is still building it. The more honest read is that the August post was a delay tactic, and the original plan is the one that ships.

Why “advanced flow” is doing so much work

The phrase “advanced flow” has become a load-bearing wall in Google’s PR. It is what every press contact points to when asked whether sideloading is dying. The implication is that the developer registration system will be a small inconvenience for people who already distribute APK files (Android’s installer package format, the file type you sideload) outside the Play Store, and that everyone else gets a streamlined path.

That is not what the original policy documents describe. The original drafts require:

  • Government ID for every developer account
  • A registration fee of around $25 per account
  • Per-app registration for apps that target newer Android APIs (the programming interfaces apps use to talk to the OS, which change with each Android version)
  • Cryptographic signing of every install (so the OS can refuse to install apps that don’t match Google’s whitelist)

Those are the same restrictions that pushed Meta, Spotify, and dozens of smaller developers to file complaints. None of them have been withdrawn. Google has talked around them.

What F-Droid and the rest of the sideload community are doing

F-Droid, IzzyOnDroid, Obtainium, and a few other sideloading-friendly clients have all updated their apps in the last few months to include in-app warnings about the upcoming changes. The warnings are not subtle. They tell users to file complaints with their carrier, with Google, and with the regulators in their jurisdiction. F-Droid specifically added a banner that pulses when the app is opened, and a link to a pre-written complaint letter that adapts to your country.

This is a coordinated response, not a coincidence. The maintainers of these tools have been talking to each other, to the FSF (Free Software Foundation), and to the EFF (Electronic Frontier Foundation) for over a year. The shared goal is to make the cost of the policy visible to the people who would lose the most from it: the ones who currently use F-Droid because they don’t trust the Play Store, the ones who sideload because the app they need was delisted, and the ones in countries where the Play Store doesn’t work well.

If you are one of those people, this is the part of the article where I tell you to act, not to read. Open F-Droid. Tap the banner. Send the email. It takes two minutes and it actually moves the needle at the FCC (Federal Communications Commission) and at the European Commission’s competition division.

What changes if the lockdown ships

Let me be specific about the practical effects, because “Android lockdown” gets used to mean a lot of things. The most likely outcome, based on the actual code in Android 17 Beta 1, is this:

  • Sideloading still works, but the OS warns the user every time, and the warning cannot be permanently dismissed without a developer-key approval.
  • Apps installed from outside the Play Store cannot be updated by the system. You uninstall, then reinstall. Some apps will not survive that because their local data lives in the install directory.
  • App stores other than the Play Store can no longer install apps in the background. Every install is a manual confirmation, and the confirmation is gated by Google’s developer-key whitelist.
  • Banking apps and enterprise apps that already use Play Integrity (Google’s API that checks whether an app is running on a “real” device with a “real” install) can opt in to refuse to run on devices that have installed unknown apps.

The third item is the one that kills F-Droid. The first two are annoying. The fourth is the threat that should make any Android user who has ever installed a banking app, a custom launcher, or a Titanium Backup archive sit up and pay attention.

What you should do in the next 90 days

I am going to make this practical, because the people reading this are the ones who will actually take action. The others are going to wait for someone else to fix it and find out in 2027 that there is no fix.

  • Install F-Droid (or update it) and use the in-app banner to send a complaint. The complaint text is pre-written. You can edit it. Send it.
  • Disable Play Protect’s “harmful app scanning” toggle if you have a custom ROM (a community-built version of Android that replaces the manufacturer’s version). You will need it on again for some banking apps, but at least you know what is happening.
  • Back up your APKs. The apps you currently have installed from F-Droid may not be trivially re-installable in 2027. Use Obtainium to keep a local copy.
  • Sign up for the F-Droid newsletter. The maintainers post the most accurate updates, and they do it before the press does.
  • If you live in the EU, file a complaint with the Commission. There is a complaint template on the FSF Europe site. The Commission’s DMA (Digital Markets Act) team is already looking at Play Store restrictions; another few thousand complaints push it up the queue.

None of this is optional. The PR campaign worked because most people don’t know the policy is still shipping. The fix is the same as it has always been: make the cost visible, file the complaint, and tell the people around you what is about to happen.

Trade-offs

The recommendations above are not free, and I want to be honest about that.

  • Disabling Play Protect will cause some apps to refuse to run. Bank apps are the obvious example. A few corporate MDM (Mobile Device Management) agents also check for it.
  • Installing F-Droid on a phone with a locked bootloader (a security feature on Android that restricts what software can run on the device at startup) is a non-starter. The corporate-locked phone most people carry cannot sideload anything in the first place. The fix is a second device, not a configuration change.
  • Filing the EU complaint requires an EU address. The template works, but the Commission’s complaint form rejects non-EU submissions.
  • Backups of APKs are useful only as long as the apps continue to work. An app that depends on a Google Play Services API (a set of proprietary background services that many apps rely on for notifications, location, and authentication) will not run on a future Android that has Play Services removed.
  • Sending the pre-written complaint has the same effect as forwarding a chain email if you don’t read it and edit it. The regulators read the body. A personalised letter is more useful than a copy-paste.

The honest answer is that the people for whom this matters most – the ones in countries where the Play Store is unreliable, the ones running F-Droid on a five-year-old phone because they can’t afford a new one – are also the ones for whom the trade-offs above are real obstacles. The fix is to make the regulators’ inboxes full enough that they feel pressure, not to make the technical workaround elegant.

What changes after the deadline

If the policy ships on schedule, which is currently the most likely outcome based on the code in the Android 17 betas, the practical effect for a typical Android user in the US is small. The Play Store still has every app they use. The sideload warning is annoying. They tap through it. They don’t notice anything else for a year, until one of their apps breaks because the developer didn’t sign the new build, and the developer quietly moves to the Play Store only.

The effect for a sideloader is large. F-Droid becomes a worse experience with every release. Obtainium warns the user. IzzyOnDroid keeps working but the install dance gets longer. Custom ROMs are unaffected at first, but the moment they ship a build that includes Google Play Services, they inherit the new restrictions.

The effect for the open-source Android community is structural. The argument for years has been that Google is the steward of an open platform. The policy turns that into “Google is the steward of a platform that is open only on Google’s terms.” That is a different argument, and it is the one that the EU Commission, the UK’s CMA (Competition and Markets Authority), and the FCC are most interested in. The PR will continue to be good. The policy will continue to ship. The fix is in the next ninety days, not in the next three years.

Filed under: #privacy #tools #windows

Leave a comment