Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I personally see no upside to shoving an unpaid third party between user and developer.

I think F-Droid is a good example of striking a balance between those two extreme models. Their existence enforces community vetting of apps as well as somewhat-reproducible thanks to their standardized build infra, which are two major wins.

I personally have much more trust in such schemes (such as guix/nix) because i don't necessarily trust all of the developers of apps i use not to get hacked, and i believe enabling one-click updates to every user of an app without review is a dangerous pattern for security.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: