8 ms·
Beware, the binary .apk's have unreleased patches you can't get from compiling yourself.
by papermachete 6y ago
Beware, the binary .apk's have unreleased patches you can't get from compiling yourself.
- llarsson 6y agoThat sounds shady. Thank you for the warning. How does one determine that? Also not found on F-droid. Hard pass.
- sneak 6y agoF-Droid has the same potential tampering issue: apps there are signed by the F-Droid key, not the developer’s key. An F-Droid compromise could backdoor every app.
- ta1771 6y agoAny history of this? For anyone: Why don't they cross-sign with their key+dev key?
- ta1771 6y agoCheck out Bromite, they have an F-Droid repo that you can add to F-Droid! Not affiliated with Bromite, just cycling accounts, can point toward my last one if anyone's concerned about this acct's greenness.
- donio 6y agoYou got my hopes up but Bromite doesn't support extensions according to their FAQ https://github.com/bromite/bromite/blob/master/FAQ.md https://github.com/bromite/bromite/blob/master/FAQ.md
- ta1771 6y agoMy chosen threat model does not allow for significantly less security in exchange for extensions. Also, they may very well take PRs for extension support (haven't looked through their Issues/roadmap), but, I'm sure it's not on the top of a security-first project's to-do list.
- photon-torpedo 6y agoOn their Github page they say > This code is up-to-date and is matching the build on the Play Store. which seems to be in conflict with your statement.
- papermachete 6y agoHow did they check and verify that?
- csagan5 6y agoSince there is no commit history I would also like to know which Chromium version this is based on, so that a diff can be made.
- NikolaeVarius 6y agoEvidence