Oddbean new post about | logout
 Because open source devs insist on fragmentation 
 Because up 
 And how to justify the fake narrative to demand nothing?

I forgot 
 Zap.store is built on nostr identity layer, which other appstores lack. This means that on my follows list, I can check if e.g. @Alex Gleason uses, recommends, or verifies sha256 of a particular app. 

This may sound like a trivial change, yet it changes appstores to function more in line with recommendations from friends and family in real life 🌶️ 
 on top of this great answer, we will have developers signing releases with their own keys - so even without friend recommendations you'll be able to establish trust in a developer and get binaries directly, not through a middleman like F-Droid 
 Web-of-Trust all the things! 🧹✨ #WoT 
nostr:nevent1qqsrsvu9ddnl4794kvmu0ahklcwqc2krxzqf6wuav6r0tek0y7reahgpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgq3qzafcms4xya5ap9zr7xxr0jlrtrattwlesytn2s42030lzu0dwlzqxpqqqqqqz5grk0w 
 👀 
 Many things are wrong with fdroid, few are right:
https://privsec.dev/posts/android/f-droid-security-issues/