• 0 Posts
  • 41 Comments
Joined 1 year ago
cake
Cake day: June 13th, 2023

help-circle








  • Yes, that video is primarily complaining about F-Droid self-signing, and that it creates: a requirement to trust them; a single point of failure for security; and slows updates

    The trade off is that developers must maintain their key, if they lose it the user must uninstall and reinstall the app, as Android will not trust an update signed with a different key


  • F-Droid used to build and sign the APK for each app they distribute using keys owned by F-Droid

    That meant you had to trust F-Droid to distribute the app as per the source, and hope that the source hadn’t been compromised (as the developer wasn’t signing anything)

    Now when a new app is added to the repo, they build an APK from source and compare it with an APK distributed by the developer

    If they match exactly (and if there is no reason to think the developer key has been compromised) then F-Droid will instead distribute APKs signed with the developer key, and verify that the same key was used for each update

    If the same key was used, F-Droid doesn’t need to build the APK themselves but can distribute the update as-is

    The advantages then are that F-Droid is acting as an additional layer of security and assurance to the developer signing the APK, and updates can be distributed faster as F-Droid doesn’t have to build them






  • I use Firefox on desktop and Mull (fork) on Android. I have zero problems with Firefox. I don’t really use YT and don’t mind going to the website when I do so can’t comment on embedded videos

    I have used the Voyager PWA and it will hang after being in the background so you have to reopen, but not sure if this is a Firefox issue

    Only using basic extensions like UBlock Origin on Android, lots of extensions on desktop (and literally hundreds of tabs open)