NHacker Next
- new
- past
- show
- ask
- show
- jobs
- submit
login
Do I understand correctly that the main workflow is "pick the first Github repo returned by the search, check that it is legit by clicking the link, then install the app from it"? It seems very easy to make a mistake and install a malicious fork.
Yes, that is a weakness. But people have to do the same thing when they install F-Droid, or any other software directly from a developer's website. Maybe it is safer to trust an app store, but I've recently heard stories of hundreds of malicious apps getting past app store verification too.
Rendered at 04:53:59 GMT+0000 (Coordinated Universal Time) with Vercel.