zlacker

[parent] [thread] 7 comments
1. pserwy+(OP)[view] [source] 2025-01-04 04:38:03
While this is true of many projects, F-Droid has a track record of sourcing funding for security audits. To date there have been at least three audits, in 2015, 2018, and 2022.

https://www.opentech.fund/security-safety-audits/f-droid/

https://f-droid.org/2018/09/04/second-security-audit-results...

https://f-droid.org/2022/12/22/third-audit-results.html

I was involved in addressing in issues identified in the first one in 2015. It was a great experience, much more thorough than the usual "numerous static analysers and a 100 page PDF full of false positives that you often receive.

replies(1): >>udev40+eb
2. udev40+eb[view] [source] 2025-01-04 07:28:30
>>pserwy+(OP)
I'm surprised that several audits didn't uncover this signing issue. GrapheneOS devs do not recommend f-droid. Instead, Play Store is the safest option for now, after Aurora Store
replies(2): >>cenamu+Oe >>t0bia_+Cy
◧◩
3. cenamu+Oe[view] [source] [discussion] 2025-01-04 08:22:28
>>udev40+eb
But their goals are also kinda opposed, software security with not much concerns paid to freedom.
replies(1): >>udev40+6j
◧◩◪
4. udev40+6j[view] [source] [discussion] 2025-01-04 09:17:47
>>cenamu+Oe
What? That's so not true. They give heavy preference to security because without it, your freedom and privacy has no value
replies(2): >>fl0id+Wj >>t0bia_+My
◧◩◪◨
5. fl0id+Wj[view] [source] [discussion] 2025-01-04 09:31:23
>>udev40+6j
Well yeah so Theo goals are opposed. F-droid is foss first and probably say proprietary illusion of security has no value ;)
◧◩
6. t0bia_+Cy[view] [source] [discussion] 2025-01-04 13:32:31
>>udev40+eb
Aurora Store downloads apk files directly from gplay servers, why it should be less safe than Play Store?
◧◩◪◨
7. t0bia_+My[view] [source] [discussion] 2025-01-04 13:34:22
>>udev40+6j
How can you trust proprietary software, when you cannot inspect code? It's just a blind trust.
replies(1): >>gruez+qJ
◧◩◪◨⬒
8. gruez+qJ[view] [source] [discussion] 2025-01-04 15:26:14
>>t0bia_+My
You don't have to. On grapheneos google play service isn't given special privileges and is sandboxed like any other normal app.
[go to top]