F-Droid has incredibly poor security practices and a strong anti-security attitude held by most of the people involved. They've consistently engaged in coverups of vulnerabilities and targeting multiple security researchers with libel and harassment.

It's a massive single point of failure and not worthy of the trust many people are placing in it. It's adding another trusted party compared to using the apps built and signed by the developers. It is not avoiding trust in the developers of apps.

Reply to this note

Please Login to reply.

Discussion

For apps that are signed by the npubs of the developers you know and trust, I understand it to be a better alternative. It will be amazing once all apps are signed by dev npubs.

AFAIK apps that at signed by ZapStore are requiring you to trust Zapstore's build processes, similar to Fdroid.

Baby steps. 👍

We do not build, but you're correct that you need to trust us (to provide the right hashes).

All indexed APKs are fetched from their original location, mostly from Github, this helps somewhat distribute the trust.

Appreciate the correction and love the project 🙏

Is Obtainium the way to go when available?

I use obtainium now and works just fine.

Did you know #F-Droid supports reproducible builds?

Aurora better?

zappstore it is.

This is worth the boost. Thank you for bringing this back into the feed

When we are pointing out that harassing, did u tried to black mail them 🤭🤭

Its weird to read this by GraphenOs profile 🤣🤣🤣🤣

One of my fav comments under one random YouTube video-

“One of the inherent advantages of Open Source is that when a project needs new leadership, but the current leadership doesn't recognize that fact, the project can simply be forked, perpetuating the good idea and leaving the failed leaders to howl into the abyss until / unless they decide to grow up.”

Last year we shared Zapstore with the Graphene community and it wasn't super well received.

Most folks there don't understand nostr nor the potential of Zapstore. That's okay, maybe timing was bad. They tend to like Accrescent, which is nice - but it is yet another centralized app store.

I will work more on documentation and how I present it, and try again in a few months.

what would you recommend in the place of F-Droid? cause I'm about to delete it now.