Earlier quoted context omitted.
Note that most of that page is a matter of the authors having a completely different security model than F-Droid rather than what I would consider to be true defects.
It's not. Stop being in an echo chamber. Refer to this post for more valid criticism: https://news.ycombinator.com/item?id=42653176
F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
31–40 of 52 posts
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#32F-Droid is indeed a nice alternative for Play Store, but still, it's not perfect. https://privsec.dev/posts/android/f-droid-security-issues/
This reads really weirdly and seems to downplay concrete threats/malicious activity in the play store and emphasise best practice/security model violations on F-Droid. I get F-Droid is the subject, and it's reasonable to make space to highlight issues with it here but it doesn't seem reasonable to conclude your security posture is better if you go with the play store.
The criticism of the inclusion policy sticks out like a sore thumb for strangeness. They criticize f-droid for requiring hosted apps that don't include proprietary software or ads. which of all the things you could criticize F-Droid for, is very strange.
And instead of making like a systematic point about process or about best practices or standards, it meanders into an anecdote about one instance of an app where the developer packaged an outdated version of WebRTC to comply, and then blames F-Droid for the way that the developer packaged the app. And then bizarrely refers to this as a "case study". There's an informal sense in which you can say case study, which I guess is fair enough, but when speaking a bit more formally case studies are real research projects, not just one-off anecdotes loosely summarized in a paragraph.
A lot of the language here is used in this gray area of formal and informal, seemingly characteristic of a high school essay.
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#33I might just have my tinfoil hat on too tight, but this doesn't make me feel warm and fuzzy inside.
F-Droid also builds AND signs packages themselves on behalf of developers, and even though reproducible builds are a thing, they are not widely used properly or publicly verified often enough for my comfort.
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#34Earlier quoted context omitted.
It's not. Stop being in an echo chamber. Refer to this post for more valid criticism: https://news.ycombinator.com/item?id=42653176
Setting aside agreement or disagreement, what about that comment is striking you as symptomatic of coming from an echo chamber?
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#35Earlier quoted context omitted.
Note that most of that page is a matter of the authors having a completely different security model than F-Droid rather than what I would consider to be true defects.
It's not. Stop being in an echo chamber. Refer to this post for more valid criticism: https://news.ycombinator.com/item?id=42653176
It is; the authors appear to be operating in a model where they completely trust app authors and nobody else, though they never actually spell out the threat model (which really should make us view their assessment skeptically anyways), where F-Droid specifically avoids trusting app authors. Nearly all of their objections come down to this single difference.
What echo chamber? I'm not aware of anyone else arguing this position.
That post contains 3 items: One fixed audit finding that only affects initial install of an app, one claim of problems that are unspecified and therefore impossible to assess, and one allegation of poor behavior (which is worth noting but not a security concern).
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#36Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#37Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#38Earlier quoted context omitted.
It's not. Stop being in an echo chamber. Refer to this post for more valid criticism: https://news.ycombinator.com/item?id=42653176
In order: It is; the authors appear to be operating in a model where they completely trust app authors and nobody else, though they never actually spell out the threat model (which really should make us view their assessment skeptically anyways), where F-Droid specifically avoids trusting app authors. Nearly all of their objections come down to this single difference. What echo chamber? I'm not aware of anyone else a…
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#39[flagged]
This is like complaining about an agriculturist being awarded money for a novel agricultural technique they developed, but they aren't saving the penguins in the Antarctic...
Re: F-Droid Awarded Open Technology Fund's FOSS Sustainability Grant
#40[flagged]
Considering how absolutely useless CoCs are in other software I use, I'm pretty happy with where F-Droid is today.