5 ms·
Thanks! The backup feature is already on my roadmap to offer it as an optional feature - but since you can manually import and export your data, it's not a high
by stormqueen 2y ago
Thanks!
The backup feature is already on my roadmap to offer it as an optional feature - but since you can manually import and export your data, it's not a high priority yet.
F-Droid may be an option - but for now the project is not open source. so I think that's not possible
- alimbada 2y agoI may be wrong but I don't think your app needs to be open source to publish it on F-Droid. Edit: Sorry, seems I was wrong [1] but you can host your own F-Droid repository which can be added to F-Droid by users to install your app from. https://forum.f-droid.org/t/non-open-source-apps-are-allowed/1221/2 https://forum.f-droid.org/t/non-open-source-apps-are-allowed...
- earthling8118 2y agoI'd argue that it's a falsehood to call a closed source application privacy friendly.
- bee_rider 2y agoYou would? How?
- pitched 2y agoThe only proof we have of privacy is a claim made by an internet account. With source code, auditing that claim is a lot easier. “Trust but verify.”
- bee_rider 2y agoI agree that it isn’t as easily verifiable that it is privacy-respecting without the source code but that’s a couple steps from saying that it is “a falsehood” to say it is. What made me wonder about it is that this is very specific wording that indicates that they proactively know the author is lying, when it would be very easy to instead say something along the lines of what you said, that it is too hard to verify without access to the source code.
- pitched 2y agoI agree that the language used wasn’t perfect, but… If a claim is not verifiable, it can only be taken on faith. Same as all the existing apps in the category that this one aims to replace. Is there a better word we can use to describe this sort of situation?
- bee_rider 2y agoI can’t think of one specific word to swap out for “falsehood,” it would be better to just replace the whole phrase. Various things have been bounced around here in the discussion. I’d go with something like “without the source code, unfortunately that can’t be verified.” This is a better phrase all around. It describes the actual problem. And it isn’t unnecessarily accusatory.
- GlumWoodpecker 2y agoPresumably because there is no way to verify the claim.
- stormqueen 2y agoThere are ways to check what data is send trough the network...
- freedomben 2y agoNot really, not anymore. Many apps are now using certificate pinning to make it impossible for the user to to modify the trust store. This means that unless it is open source, it is very difficult for people to verify, even when they know very well what they are doing.
- Technetium 2y agoThere's always a way, even if it's a lot more painful now! https://mas.owasp.org/MASTG/techniques/android/MASTG-TECH-0012/ https://mas.owasp.org/MASTG/techniques/android/MASTG-TECH-00...
- zerr 2y agoBut you can verify that the app does not use the network at all, right?
- freedomben 2y agoYes you could, although the bar is still a lot higher than if it's open source. You will have to fully re-test all possible paths in the app every time a new release is made if it's closed source. If it's open, you just need to look at the git log. Plus if there is one legitimate network call, then this strategy is out since you can't know what that request contains. OP using in-app purchases, so I'm willing to be there's at least one network call in there. If there is no network access permission at all, then I think we agree, that's a reasonable guarantee.
- UncleEntity 2y agoThis is why we can't have nice things...
- freedomben 2y agoIndeed, I think it used to be doable because I installed an app without source available from F-Droid a few years ago, but I don't believe it is anymore. Would be super cool if you did though! My wife is still using pen and paper to track because of privacy concerns, but my daughter finds this abhorrent and wants to use an app :-D