logoalt Hacker News

someonebaggy • today at 6:28 PM • 1 reply • view on HN

GrapheneOS security complaints about F-Droid are a load of nonsense except for one: the APK on the website is signed by a different key from the one that F-Droid updates itself with.


Replies

eighthave • today at 7:46 PM

> the APK on the website is signed by a different key from the one that F-Droid updates itself with

Could you explain? I don't understand what you mean here. https://f-droid.org/F-Droid.apk is signed by the same key that signs https://f-droid.org/repo/entry.jar