TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

F-Droid Security Issues (2022)

17 点作者 karlzt4 个月前

3 条评论

oez4 个月前
I now use Obtanium[1] for my open source android apps, it grabs apks straight from the source (github, gitlab etc.). Once you get each app set up its a breeze and you don&#x27;t have to deal with fdroids strangeness.<p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;ImranR98&#x2F;Obtainium">https:&#x2F;&#x2F;github.com&#x2F;ImranR98&#x2F;Obtainium</a>
评论 #42764590 未加载
评论 #42764446 未加载
blendergeek4 个月前
This is from 2022. The only recent update is to add a reference to the Sniket blog post which is also from 2022. So this should have (2022) in its title.
评论 #42764496 未加载
beeflet4 个月前
This mostly seems like a cope that f-droid takes action on behalf of users and makes sure that apps are a open source as they claim.<p>Good. I don&#x27;t trust application developers. I trust f-droid to do due diligence and ensure that the app is safe, not the app developer. Screw the &quot;android security model&quot;, it&#x27;s designed for containerizing closed-source software.<p>P.S. Edit:<p>Interestingly, the article contains a &quot;Meta&quot; section that claims that their criticisms are completely technical (I would disagree, they&#x27;re largely subjective organizational criticisms based on &quot;best practices&quot;). The &quot;Meta&quot; section also claims that the project isn&#x27;t associated with grapheneOS, which I didn&#x27;t make much of until I read the page of the alternative app store they recommend (<a href="https:&#x2F;&#x2F;accrescent.app&#x2F;" rel="nofollow">https:&#x2F;&#x2F;accrescent.app&#x2F;</a>) which seems to shout out grapheneOS users in particular.<p>Also, this section is really weird and sounds a lot like grapheneOS developers, who seem to be easily sidetracked by supposed &quot;harassment campaigns&quot;:<p>&quot;In spite of this, the release of this article has unfortunately triggered a mostly negative response from the F-Droid team and some of their community, who seem to take a dismissive stance toward this article rather than bringing relevant counterpoints. Some of these individuals go as far as engaging in harassment campaigns against projects and security researchers that do not share their views; hopefully they realize that such unethical behavior undermines their own project and reputation. Creating a rift between developers and security researchers is not in anyone’s best interest.&quot;<p>Also also, I think that this article focuses too much on technical gimmicks to the detriment of the openness of the system as a whole, which I think is a common theme around grapheneOS. For example, grapheneOS&#x27;s decision to only use the google pixel platform due to the specific trusted computing features of those phones, to the detriment of the portability and usability of the OS. So I suspect there may be some weird association with grapheneOS here.<p>I don&#x27;t know what to think of this, it&#x27;s very weird. I used to use grapheneOS but stopped mostly due to the erratic public behavior of grapheneOS developers. I don&#x27;t think that it is malicious, but it indicative of a personality disorder which isn&#x27;t conducive to leadership.
评论 #42765459 未加载
评论 #42764565 未加载