AFAIK, no native client uses an extension for signing. They all have up enter your nsec.

I also agree, open source only provides a false sense of security for 99% of people. They’re not (even if they’re like me, and *can*) going to read all that code, especially for every update.

On iOS every app is essentially closed source anyways, as you cannot provide a reproducible build. Builds are done by the App Store account holder, signed, and uploaded.

With software, reputation is everything. In my personal opinion (which I am humble enough to acknowledge should hold no weight with anyone else on here) plebstr’s team has earned good will and trust. There has been no evidence of funny business thus far, and I’m someone who looks for that sort of thing, and uses it daily.

For FOSS options, there is always Damus, Nostur, and Kiwi. Their code is open, but again, the trust is on the devs that the code in the repo is what runs on your phone unless you install Xcode and build it yourself for your phone.

Just my two cents as an erstwhile dev.

Reply to this note

Please Login to reply.

Discussion

how do we know your not one of plebstr devs? jk 😂

I’m not nearly that cool 😎. Besides, they don’t seem to have any cats on the team.

Seems like discrimination. 🤣