‹ BackHN Continuity

Thread

F-Droid 2.0

1465 points · 420 comments · daveoc64

  1. mightysashiman · · focus · HN ↗
    Did they implement any GrapheneOS security complaints for it to be deemed actually secure?
    1. someonebaggy · · focus · HN ↗
      GrapheneOS security complaints about F-Droid are a load of nonsense except for one: the APK on the website is signed by a different key from the one that F-Droid updates itself with.
      1. eighthave · · focus · HN ↗
        > the APK on the website is signed by a different key from the one that F-Droid updates itself with

        Could you explain? I don&#x27;t understand what you mean here. <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;F-Droid.apk" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;F-Droid.apk is signed by the same key that signs <a href="https:&#x2F;&#x2F;f-droid.org&#x2F;repo&#x2F;entry.jar" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;repo&#x2F;entry.jar

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.