From what I understand, F-droid regularly audits a few new apps for malicious code
That’s a good point, but how can a malicious code be add to a source code from github? I mean if you only use trusted applications repos (most of them are already on f-droid anyway) there shouldn’t be any concern right?
But reading from the link you posted there’s some chance of a MITM attack and send a malicious payload directly to Obtainium? (Correct me if I’m wrong).
Github is not neccesarily the same source used to generate their binaries.
Didn’t knew that :/
Thanks for sharing your knowledge !
Yeah, I had a Android application installed recently which strangely enough tried to reach my vaultwarden DNS? That sounded sketchy AF and just blocked it, removed it and cleaned every trace of it…