Since then I've head that the F-Droid operators insist on signing all apps themselves, instead of the developers' signature. That's as bad as the TLS inteceptors that insist on accepting an extra CA.
Some people seem to think that F-Droid is obviously preferable to Googleplay. That is, at the very least, not obvious.