> F-Droid has signed apps.
If I'm remembering the discussion correctly [0], at the time that Moxie felt that distribution by F-Droid was entirely unsuitable because of -among other things- their insecure code signing key handling practices. Remember that Moxie's target audience is everyone, not just technical users. I elaborate on this point in a couple of my other comments in the sub-threads.
> Google is a known collaborator with three letter agencies...
People say this. I contrast it with the fact that Google now configures its US datacenters (and the links between them) as if they were sited in hostile nations such as China. Switching from the "friendly nation" configuration to the "hostile nation" configuration was a crash project after the Snowden revelations. The project was not cheap. The situation on the ground is -always- more nuanced than can be expressed in a soundbite.
> It's grossly unacceptable for security related software to require Google Play Services (spyware) on the end user's phone.
* Can you point to a reliable, credible source that has analysed Google Play Services and determined that they are spyware, by any reasonable definition?
* As I mentioned in other comments in this thread, Moxie is not opposed to either distribution in non-Google App Stores, nor is he opposed to replacing the use of GCM (AFAIK, the only part of GPS that Signal uses) with Websockets. However, any replacement must be at least as secure and functional as what it replaces. Check my other comments in the subthreads for more information.
[0] And I may not be, it's goddamn late.