15 May 25


I can’t get behind this reasoning.

Which store is best depends on each user’s threat model. If the threat is that an app developer could insert a backdoor in their own app, F-Droid is better. If the threat is that the F-Droid team could insert a backdoor in an app, or that an app could contain a vulnerability that may be exploited if the app is not updated for one week, Accrescent is better.

“Protection against malicious devs isn’t necessary because it’s not in our ‘threat model’” is seriously a way some people think…?!

by 2097 7 months ago

17 Apr 25

Reproducible builds solve that.

So now we no longer have to face the choice between trusting one app (the app store itself) with thousands of eyes on it vs cumulatively trusting dozens and dozens of individual app devs including some weird niche apps that only you need, any of which could’ve included malware. We can know that the APK the dev built and the APK the app store built and the APK any security-conscious third party can build are all exactly the same and built from the same source dist.

by 2097 8 months ago

03 Sep 24

What are y’all’s take on this?

I hadn’t heard of it before. Seems to be built around a SIP stack and a DHT…?

by 2097 1 year ago saved 3 times

25 Dec 23

Marknaden räcker inte som styrande kraft för ett anständigt internet. Det vet vi ju. Vi behöver lagar och regler – online likväl som i den fysiska världen. Vi har parlament. Låt oss inte tveka att använda dem.

💯

by 2097 2 years ago