#GrapheneOS and #QubesOS user, #infosec enthusiast
Network is reliable
#GrapheneOS and #QubesOS user, #infosec enthusiast
Posts
#GrapheneOS and #QubesOS user, #infosec enthusiast
#GrapheneOS and #QubesOS user, #infosec enthusiast
#GrapheneOS and #QubesOS user, #infosec enthusiast
@lberrymage@infosec.exchange @normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange
Accrescent does require domain ownership verification for all new apps now so that you can verify the app ID is published by its respective developer.
More I think about it, less I like it. Does it mean that developer of com.exampleapp really controls the domain exampleapp.com? I don't think so. You just put trust to another entity. But developer may not be aware of Accrescent at all. He just hosts his repo on github with such package name.
#GrapheneOS and #QubesOS user, #infosec enthusiast
@lberrymage@infosec.exchange @normplum@fosstodon.org @celenity@infosec.exchange @accrescent@infosec.exchange
Accrescent does require domain ownership verification for all new apps now so that you can verify the app ID is published by its respective developer
Thanks for clarification. But it's absolutely not obvious from UI perspective.
It is also possible to verify that an app's signing key matches the developer's and is thus cannot be modified by someone else.
Is there any secure way to do it without app installation?
#GrapheneOS and #QubesOS user, #infosec enthusiast
#GrapheneOS and #QubesOS user, #infosec enthusiast