Global Feed Post Login
Replying to Avatar sommerfeld

Fdroid (and even Google Play) verify apk signatures and hashsums.

The lack of integrity and authenticity verifications in Obtanium (which just fetches apks over https) certainly put it at a severe disadvantage when it comes to security.

Obtanium is as much censorship resistance as possible but we should be clear about the trade-offs. Unless there is a standard way for devs to publish hashsums and sigs on Github Releases that Obtanium could use for verification, things are not likely to improve.

nostr:nevent1qqsx38wrmgcf78fu7yntp6y4psmgq0x4fdr4vjy5k4wrltlszenz0lcpz9mhxue69uhkummnw3ezuamfdejj7q3qgcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqxpqqqqqqzvh4att

ec
ec0114a5... 1y ago

You should push for signature verification to be implemented into Obtanium.

nostr:nevent1qqswehak0rjukxhxvne7908t4hlzx890tjfytwg3rp636hjhz7f0gvqpz3mhxue69uhhyetvv9ujuerpd46hxtnfdupzp5x7h70mzt00s86r6lrfg2dm0pyp9tq7f5k48gszmd42cl4yk3nvqvzqqqqqqy7fjueq

Reply to this note

Please Login to reply.

Discussion

No replies yet.