Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)WI
Posts
15
Comments
435
Joined
2 yr. ago

  • For fdroid the app is compiled on fdroid servers when dev tags a new release on GitHub. So the app matches the source, it's not possible to put a tainted APK to download

    Now, if the malicious code is slowly added to the source over the course of an year like it happened with the xz utils, this won't change the result, but it's easier to do so with a compiled binary. Release clean source and infected binary, it will take a longer time to get caught

    For the closed source app stores, on iOS there's the manual inspection (which is not infallible especially if they timebomb or geofence the bad feature) and for Google there's the automated inspection (which fails often seeing the news) that should find problems

  • When I saw the process to add Google drive support to an app I thought: "wouldn't be easier to just discontinue the public APIs?"

    If I was a dev I would immediately remove the integration instead of paying the required thousands (yearly!) to keep it. Then in the app explain the situation to the customer, add a referral link to Dropbox, onedrive or other competitors

  • how the hell someone can use pinterest for more than one hour a week? Just accidentally browse it when trying to search an image on the web and curse the ux team to have hidden the download button in a way that you click the image and brings you in a completely unrelated site with 10000 images except the one you wanted

  • LOL i thought "my 64gb iphone se 3 is enough, 32gb is gonna be enough" - while i completely forgot that the 64gb iphone was already small, in order to install ios 18 i had to wipe-install-restore because it was impossible to free enough memory

  • I don't understand, signal is open source, why would they need to purchase an unofficial fork from a foreign company? Isn't that an huge security issue?

    And what's the point of using end to end encryption if the app has been hacked to send messages to a remote server anyway

  • You don't need to put the "by their standards"

    He is an immigrant who lied in his application, worked with an invalid status and overstayed his student visa to start his criminal career

    His acquired citizenship needs to be stripped and deported to El Salvador