Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Network is reliable

@network_is_reliable@mastodon.social
mastodon 4.7.0-beta.1
  • Open on mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

0 Followers
0 Following
7 Posts
Joined June 15, 2021

Posts

Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Mar 27, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @organicmaps@mastodon.social
@organicmaps @forgejo Please, add link to Accrescent too to your badge list. Thanks. I would appreciate if you add fully FOSS version there too. Right now Accrescent contains only build with your ads. #accrescent #foss #floss #organicMaps
0
0
0
0
Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Mar 05, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @fdroidorg@floss.social
@fdroidorg@floss.social I like gradation you did in the article. Would be cool if you add a way to check that build is reproducible to the user before installation. I think it's highly important to understand that you only confirm reproducibility of a package without re-signing it. Someone can simply doubt to trust your build server, as it looks like another possible point of compromise. One possible way is to integrate with AppVerifier (like Obtainium does) to check certificate hash before installation.
0
2
0
0
Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Jan 28, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @network_is_reliable@mastodon.social
@lberrymage@infosec.exchange @normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange I could trust more or less to IronFox Accrescent badge because it's in the repository. https://gitlab.com/ironfox-oss/IronFox But that whole story of the domain verification does not seem bulletproof for me. Signer key check is a different story.
0
0
0
0
Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Jan 28, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @lberrymage@infosec.exchange

@lberrymage@infosec.exchange @normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange

Accrescent does require domain ownership verification for all new apps now so that you can verify the app ID is published by its respective developer.

More I think about it, less I like it. Does it mean that developer of com.exampleapp really controls the domain exampleapp.com? I don't think so. You just put trust to another entity. But developer may not be aware of Accrescent at all. He just hosts his repo on github with such package name.

0
4
0
0
Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Jan 28, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @lberrymage@infosec.exchange

@lberrymage@infosec.exchange @normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange

Accrescent does require domain ownership verification for all new apps now so that you can verify the app ID is published by its respective developer

Thanks for clarification. But it's absolutely not obvious from UI perspective.

It is also possible to verify that an app's signing key matches the developer's and is thus cannot be modified by someone else.

Is there any secure way to do it without app installation?

0
2
0
0
Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Jan 28, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @network_is_reliable@mastodon.social
@normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange If you can find any link on the official website of the app you want to install to the Accrescent store then it's probably worth to trust (like NeoStumbler does https://github.com/mjaakko/NeoStumbler in their repo). If official website/repo has no reference to the store, I would suggest to stay away even if the app is listed in Accrescent app.
0
0
0
0
Open post
network_is_reliable
Network is reliable @network_is_reliable@mastodon.social · Jan 28, 2025
Network is reliable
@network_is_reliable@mastodon.social

#GrapheneOS and #QubesOS user, #infosec enthusiast

mastodon.social
Replying to @normplum@fosstodon.org
@normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange That's the biggest problem with Accrescent I see. You can not ensure that an app you want to install is not really malicious one submitted by someone else. Also if there are multiple flavors/builds (foss/with proprietary blobs) you can not check which one you are going to install. You have to trust that Accrescent reviewer does their job well. So personally I would still prefer Obtainium over Accrescent. #obtainium #accrescent #fdroid
0
4
0
0

Remote instance

mastodon.social
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:42:19 UTC