Thread

Zero-JS Hypermedia Browser

Relays: 5
Replies: 1
Generated: 15:44:14
Thing is f-droid uses the same github source. So a compromised project will simply affect everyone. On the otherhand f-droid could maliciously point to a different cloned compromised repo and end user wouldn't even know. So still best to take out the middle man and know your updating to the official repo and not a different unofficial clone.
2025-10-31 13:46:25 from 1 relay(s) ↑ Parent
Login to reply

Replies (1)

That's true, but it's also possible for an attacker to compromise a GH account and publish a new "release", without even changing any source code. Only you have all the accounts to secure, and only one F-Droid. I use Obtainium too, but it's unclear to me how to weigh up these risks.
2025-11-01 00:29:34 from 1 relay(s) ↑ Parent 1 replies ↓ Reply