Hmmm, your last paragraph is a misconception. Third time I hear it, I must be doing something wrong.
You are conflating APK signatures with nostr signatures:
- Obtainium: original dev signed APK
- Zapstore: original dev signed APK + nostr signature
In both places you install the same developers APK. Both pull from Github or whatever original source.
Zapstore in addition links them to a nostr profile which allows for web of trust verification and more.
Obtainium is in no way more secure than Zapstore. It does have more apps, yes, for now.