Re: [guardian-dev] Manipulating App Bundles

2020-08-16 Thread Marcus Hoffmann
Hi Mark, I just wondered, did this ever get published somewhere? Best, Marcus On 22.06.20 13:20, Mark Murphy wrote: > On Sun, Jun 21, 2020, at 22:20, John Sullivan wrote: >> Just a quick comment on that last part. It may be worth mentioning for >> a fuller picture that F-Droid signs the builds

Re: [guardian-dev] Manipulating App Bundles

2020-06-27 Thread Nathan of Guardian
On Sat, Jun 27, 2020, at 7:06 AM, Michael Rogers wrote: > Or, even simpler, the developer could just upload the variant APKs. A > few hundred MB of bandwidth isn't a big cost to exclude the possibility > of targeted backdoors... > We do this today automatically with fastlane for a few apps,

Re: [guardian-dev] Manipulating App Bundles

2020-06-27 Thread Michael Rogers
On 22/06/2020 15:53, Marcus Hoffmann wrote: > Hi, > > (I work on F-Droid) > > On 22.06.20 13:20, Mark Murphy wrote: >> On Sun, Jun 21, 2020, at 22:20, John Sullivan wrote: >>> Just a quick comment on that last part. It may be worth mentioning for >>> a fuller picture that F-Droid signs the

Re: [guardian-dev] Manipulating App Bundles

2020-06-22 Thread Marcus Hoffmann
Hi, (I work on F-Droid) On 22.06.20 13:20, Mark Murphy wrote: > On Sun, Jun 21, 2020, at 22:20, John Sullivan wrote: >> Just a quick comment on that last part. It may be worth mentioning for >> a fuller picture that F-Droid signs the builds themselves because they >> build them themselves.

Re: [guardian-dev] Manipulating App Bundles

2020-06-22 Thread Mark Murphy
On Sun, Jun 21, 2020, at 22:20, John Sullivan wrote: > Just a quick comment on that last part. It may be worth mentioning for > a fuller picture that F-Droid signs the builds themselves because they > build them themselves. They publish all of the source that they are > building as well as the

Re: [guardian-dev] Manipulating App Bundles

2020-06-21 Thread John Sullivan
On Sun, Jun 21, 2020 at 05:32:35PM -0400, Mark Murphy wrote: > On Wed, Jun 17, 2020, at 19:08, Nathan of Guardian wrote: > > > I am sincerely hoping that I'm forgetting something that prevents this. > > > > I don't think you are. If there was some kind of binary transparency > > where you could

Re: [guardian-dev] Manipulating App Bundles

2020-06-21 Thread Mark Murphy
On Wed, Jun 17, 2020, at 19:08, Nathan of Guardian wrote: > > I am sincerely hoping that I'm forgetting something that prevents this. > > I don't think you are. If there was some kind of binary transparency > where you could see all the builds that were done and released, that > might be a

Re: [guardian-dev] Manipulating App Bundles

2020-06-17 Thread Ted P. Samuel
I participated in a related discussion in the F-Droid Forum @ https://forum.f-droid.org/t/3146 https://www.rakuten.com/r/TPSAMU?eeid=6991100 On Wed, Jun 17, 2020, 10:00 PM Michael wrote: > > On 6/18/20 1:27 AM, Tom Ritter wrote: > > . This is horrible. Could anyone add a link to where they're

Re: [guardian-dev] Manipulating App Bundles

2020-06-17 Thread Michael
On 6/18/20 1:27 AM, Tom Ritter wrote: > . This is horrible. Could anyone add a link to where they're > proposing this? I'd like to circulate this internally... > Indeed. I think this is where I read about this first:

Re: [guardian-dev] Manipulating App Bundles

2020-06-17 Thread Marcus Hoffmann
On 18.06.20 01:27, Tom Ritter wrote: > > > On Wed, Jun 17, 2020, 6:09 PM Nathan of Guardian > mailto:nat...@guardianproject.info>> wrote: > > > > On Wed, Jun 17, 2020, at 5:59 PM, Mark Murphy wrote: > > I am guessing that you have seen that Google is proposing making app > >

Re: [guardian-dev] Manipulating App Bundles

2020-06-17 Thread Tom Ritter
On Wed, Jun 17, 2020, 6:09 PM Nathan of Guardian < nat...@guardianproject.info> wrote: > > > On Wed, Jun 17, 2020, at 5:59 PM, Mark Murphy wrote: > > I am guessing that you have seen that Google is proposing making app > > bundles a requirement next year: > > Yes. /me puts head in hands > .

Re: [guardian-dev] Manipulating App Bundles

2020-06-17 Thread Nathan of Guardian
On Wed, Jun 17, 2020, at 5:59 PM, Mark Murphy wrote: > I am guessing that you have seen that Google is proposing making app > bundles a requirement next year: Yes. /me puts head in hands > I am sincerely hoping that I'm forgetting something that prevents this. I don't think you are. If there