@haskal I also love he went on a long rant about fdroid signing keys, meaning they could technically change the apps. And then he goes on to say:
"As for apps concerned by Play App Signing, while Google could technically introduce their own code like Amazon, they wouldn’t do that without telling about it since this will be easily noticeable by the developer and more globally researchers."
So you can't trust fdroid to not secretly change apps, but you can trust Google with this power?
mvgorcum@mastodon.technology's status on Wednesday, 02-Mar-2022 14:27:28 UTC
-
mvgorcum@mastodon.technology's status on Wednesday, 02-Mar-2022 14:27:28 UTC mvgorcum