What is Nostr?
zap.store
npub10r8…t2p8
2025-01-30 14:43:30
in reply to nevent1q…dm2c

zap.store on Nostr: The security issues had to do with their build process and infrastructure, not the ...

The security issues had to do with their build process and infrastructure, not the app.

F-Droid could be injecting malicious code and you would have no idea.

Same for Obtainium. Github et al (or their hackers) could be replacing the APKs with malicious ones, which are obviously cheap to fork in open source software, this actually happened with a Wasabi Wallet release for Windows a few months ago.

So "it's whatever the dev published" is kind of true, and we actually rely on it for lots of Zapstore apps, but thinking it's absolutely true is naive.
Author Public Key
npub10r8xl2njyepcw2zwv3a6dyufj4e4ajx86hz6v4ehu4gnpupxxp7stjt2p8