So, how you guys verify signatures when downloading APK on GrapheneOS ?

Reply to this note

Please Login to reply.

Discussion

On the PC than pass the file

Good on you for actually doing that

DeadHash (Hashsum calculation utility)

https://f-droid.org/packages/com.codedead.deadhash/

Oh so I have to install F droid store 🤔

You dont HAVE tonuse fdroid store to use fdroid builds.

Oh, checking it rn

Use https://github.com/ImranR98/Obtainium you can then add the git repo links

Can outsource it to fdroid or aurora

I think probably the easiest way is to verfiy the apk before first install on a computer.

Theres also https://github.com/soupslurpr/AppVerifier

FOSS Terminal CLI app from github. Then run commands from there

Again no good GUI yet

I use #Obtainium for apk managment on #GrapheneOS 👌

https://github.com/ImranR98/Obtainium

And when needed i use #hash-checker to verify hashes.

https://github.com/hash-checker/hash-checker

upload to virustotal

Sparrow wallet has a new tool

AppVerifier