• AncientFutureNow@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    5
    ·
    edit-2
    1 year ago

    Fennec from fdroid, for android, is even better as it didnt originate from google play store. My understandong is Google Playstore injects data into the app package. I use fennec for my day to day access. It syncs with desktop Firefox so all my passwords and logins are there.

    There is also Firefox Nightly for “developers”. I use it for the custom add on packages and doom scrolling.

    • VerPoilu@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      1 year ago

      Google playstore does not inject data in app packaging because it doesn’t own the signature key. F-Droid, however, does. I mean, they own the signature, but they do not inject or modify apps. They could, though.

      • barryamelton@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        edit-2
        1 year ago

        do you know of any app developers that publish their signature, so one can compare it with the one in Google Play?

        I would love for my banks to do this, for example…

        • VerPoilu@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 year ago

          Some developers will publish their apps on github, you can download it, and use a different app to get the apk file from the app you get from the play store, and compare the hash of the file. If they’re identical then Google didn’t meddle with it. If they’re not, either Google did, or the developer releases a different version to Google Play.