this post was submitted on 26 Sep 2025
20 points (100.0% liked)
DeGoogle Yourself
13767 readers
103 users here now
A community for those that would like to get away from Google.
Here you may post anything related to DeGoogling, why we should do it or good software alternatives!
Rules
-
Be respectful even in disagreement
-
No advertising unless it is very relevent and justified. Do not do this excessively.
-
No low value posts / memes. We or you need to learn, or discuss something.
Related communities
!privacyguides@lemmy.one !privacy@lemmy.ml !privatelife@lemmy.ml !linuxphones@lemmy.ml !fossdroid@social.fossware.space !fdroid@lemmy.ml
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
oh and also, nobody really verifies what gets into an apk uploaded to github releases. but f-droid does have an array of checks, and I like that they can catch if an app tried something fishy or had a build accident (like accidentally including google servifes dependencies that automatically run code, because another new or updated dependency pulled it in). in the past there were occasions where an app got unlisted, and when I went looking for the reason it was either developer negligence, or sometimes changes that were really not too good.
Last thing, I trust Appverifer more than I trust F-droid verification
I think Obtainium is objectively better since you have 24 sources including F-droid and Google play store with Shizuku or Sui
"Due to their process of building apps, apps in the official F-Droid repository often fall behind on updates. F-Droid maintainers also reuse package IDs while signing apps with their own keys, which is not ideal as it gives the F-Droid team ultimate trust. Additionally, the requirements for an app to be included in the official F-Droid repo are less strict than other app stores like Google Play, meaning that F-Droid tends to host a lot more apps which are older, unmaintained, or otherwise no longer meet modern security standards." This is what PrivacyGuides says. Also you have Appverifier integration in Obtainium which verifies signatures or smth, I know it's a lot better than comparing hashes