jonah,
@jonah@neat.computer avatar

It would be cool if took the opposite approach to Google Play App Signing, by using their build system to create a code transparency key that developers could then bundle with their app, and then developers could in turn sign that bundle with their own signing key.

That way F-Droid could distribute apps that they’ve verified reproducible builds for (and check the CT signature in the F-Droid app), without having to sign the app with their own key—a common complaint about the default F-Droid repo.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • cubers
  • DreamBathrooms
  • ethstaker
  • magazineikmin
  • thenastyranch
  • ngwrru68w68
  • Youngstown
  • slotface
  • modclub
  • love
  • kavyap
  • everett
  • InstantRegret
  • mdbf
  • megavids
  • khanakhh
  • tacticalgear
  • osvaldo12
  • rosin
  • tester
  • GTA5RPClips
  • cisconetworking
  • Durango
  • normalnudes
  • provamag3
  • Leos
  • anitta
  • JUstTest
  • All magazines