zlacker

[return to "F-Droid Fake Signer PoC"]
1. bsimps+nc[view] [source] 2025-01-04 00:41:44
>>pabs3+(OP)
Tangential, but:

I often wonder how secure these open source projects actually are. I'm curious about using Waydroid in SteamOS, but it looks like it only runs LineageOS (apparently a derivative of CyanogenMod).

I know that people claim that open source is more secure because anyone can audit it, but I wonder how closely its security actually interrogated. Seems like it could be a massive instance of the bystander effect.

All of it gives me a bias towards using official sources from companies like Apple and Google, who presumably hire the talent and institute the processes to do things right. And in any case, having years/decades of popularity is its own form of security. You know anyone who cares has already taken shots at Android and iOS, and they're still standing.

◧◩
2. Idesmi+P11[view] [source] 2025-01-04 12:12:50
>>bsimps+nc
> CyanogenMod

Has been dead for 8+ years. LineageOS is its own thing by now.

> anyone who cares has already taken shots at Android and iOS

LineageOS is based on AOSP, plus some modifications that do not affect security negatively.

[go to top]