• tetris11@feddit.uk
    link
    fedilink
    English
    arrow-up
    38
    ·
    18 days ago

    I gotta admit, I just don’t trust github apks.

    Yeah F-Droid isnt perfect, but it does list what liberties an app takes up front

    • msprout@lemmy.world
      link
      fedilink
      English
      arrow-up
      29
      ·
      18 days ago

      What I appreciate about F-Droid is how many eyes are on the same repository. Yes there are bad entries, but, having a million people refreshing six of the most popular repos is still a better scenario for people flagging and yanking bad apps than everybody and their mother offering an APK as an individual fork of a GitHub project.

      It took me a while to get into brew on MacOS, but once I did, I wondered to myself why I spent so long just downloading random binaries from the Internet and running them? Life before a good package manager seems so quaint.

    • The Cuuuuube@beehaw.org
      link
      fedilink
      English
      arrow-up
      9
      ·
      18 days ago

      yeah. in the “obtainium is more trustworthy because it distributes trust” vs “f-droid is more trust worthy because it reduces attack vectors” i tend to fall in the latter camp. sure, if f-droid is pwned, nearly your entire phone is pwned, but with obtainium you’re more at risk for death by a thousand papercuts.

      i’m not expert enough to speak authoritatively between the two stances, but i know enough people who are split between the two to say there’s compelling arguments on both sides, i just picked what matched my understanding of my vulnerabilities best