In the GrapheneOS forum, I encountered a claim that F-droid is insecure (and not good at privacy as well). These links (and more) were given as an evidence:

While there are some attitude against FOSS app, I think the arguments are generally sound and in good-faith. Which makes me confused, as I’ve been hearing good words about F-droid in lemmyverse.

I am not good at assessing arguments, so I want to ask you guys for more aspects and information.

Also, if not F-droid, what should I use? Is Aurora store, a frontend of play store, not fine to use as well?

  • kolorafa@lemmy.world
    link
    fedilink
    arrow-up
    10
    arrow-down
    1
    ·
    4 days ago

    In case of f-droid, it’s follow more the Linux distro phylosopy, where the binaries are build and offered to you not by the developer but by distro/repository maintainers people.

    You can add your own repository or use your friend repository or use f-droid ones.

    In case od f-droid repository, to get app published your app need to adhere to rules one of them is that the code need to be public so the repo maintainers can build the app from it.

    Comparing it to play store where the app is build and sign by the developer without making the code public, in turn making it almost impossible to know and follow what the app is doing.

    So its a matter of trust.

    For some apps I would rather install them from f-droid as I have higher confidence that someone looked at it if the app is not harmful or leaking my private data. For other apps like Banking apps I would rather install them from Aurora store where I dont know what the app is doing but I trust more to protect my money than some random dude on internet. And if bank does something bad I will sue them or just stop using their service.

    • shortwavesurfer@lemmy.zip
      link
      fedilink
      arrow-up
      2
      ·
      2 days ago

      I actually take it even one step farther than that. I don’t want a bank app on my phone because it’s proprietary and I don’t know what it’s doing. So I only access my bank through the web browser.

      • kolorafa@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        19 hours ago

        I use bank app for contactless payments. But the bank app have no other permissions, even location is fake.

        • shortwavesurfer@lemmy.zip
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          5 hours ago

          The one good thing about banks is they make these little plastic rectangles with metal chips in them that you can insert into a device at the terminal in order to pay for your stuff. No bank app required.

          At least in the United States, these little plastic rectangles have a series of 16 numbers on them, followed by a date and a year and a three digit code.

    • Autonomous User@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      edit-2
      4 days ago

      I trust those online far more than any offline rando to make my bank app.

      Suing, stopping, or looking at how its broken, does not fix an app. We cannot fix it, when we are banned from changing it, when we do not control it.