Elektrine lite

← Feed

@eighthave@social.librem.one

Post #3856976

2026-07-16 10:02 UTC

At the core of #AndroidDeveloperVerification are a couple potentially useful ideas. #Google has entirely wrapped them in a pile of anti-competitive garbage designed to defend their massive #monopoly profit margins, but nonetheless, those specific technical ideas might still be useful. #iOS's "notarization" is basically the same. That leads me to ask the key question: What would a #FOSS-respecting system of #verification look like? What #identity info is useful for trusting the #developer?

Replies (5)

  • @sirtao@social.sirtao.it 2026-07-16 14:52

    What #identity info is useful for trusting the #developer? If it's a commercial developer(as in: they ask\get more than 0 amount of money for their stuff), then the usual commercial identity info and a public GPG key. Otherwise, just a public GPG key. (here using "GPG key" as catch-all for whatever cryptographic signature system) The issue after all was never about the identity verification itself, but Google\Apple using it to limit access for developers.

    Open ##3861273

  • @eighthave@social.librem.one 2026-07-16 10:07

    @rene_mobile@infosec.exchange @marcprux@mastodon.social @fdroidorg@floss.social @GrapheneOS@grapheneos.social @lehtimaeki@snapp.social @ottok@mastodon.social @grote@chaos.social You are all people who have specifically thought about this kind of stuff in relation to software distribution, what do you think?

    Open ##4074190

  • @jexner@tooting.ch 2026-07-16 10:07

    @eighthave@social.librem.one I'm guessing there are different levels and maybe conflicting aspects? Anonymity on the dev side versus a need to trust on the users', and then the need to trust may be more or less strong depending on what the software does? (not an expert, just not happy about what Google is doing right now, and so musing as a way to not be hopeless)

    Open ##4074194

  • @mro@digitalcourage.social 2026-07-16 11:03

    Hi @eighthave@social.librem.one, being the same as last time and taking responsibility for the product. So individual trust can build over time. Translates to: install (and source tarball, promo material, etc.) is visibly signed by the same dev-generated key.

    Open ##4074199

  • @silverpill@mitra.social 2026-07-16 13:24

    @eighthave@social.librem.one A verified link to their fediverse profile.

    Open ##4311848