<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Fdroid on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/fdroid/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/fdroid/index.xml" />
  <subtitle>Recent content in Fdroid on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/fdroid/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2023-03-20T10:00:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>Obtainium overview | My favorite way to track Open Source apps</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/obtainium-overview/" />
        <id>https://staging.sideofburritos.com/blog/obtainium-overview/</id>
        <published>2023-03-20T10:00:00Z</published>
        <updated>2023-03-20T10:00:00Z</updated>
        <summary type="html">Using an RSS reader is a popular way to tack OSS apps directly from their source. Obtainium automates this process and simplifies it.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode105s0hbhb">🎥 


<a href="https://youtu.be/JiN37bn0OE8" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-infor-video">Links referenced in/for video</h2>
<ul>
<li>


<a href="https://github.com/ImranR98/Obtainium/issues/25" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium/issues/25</a> - Obtainium Issue 25 | <strong>Help wanted</strong></li>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
<li>


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">https://youtu.be/FFz57zNR_M0</a> - You should use this instead of F-Droid | How to use app RSS feed</li>
<li>


<a href="https://github.com/ImranR98/Obtainium" target="_blank" rel="noopener" class="text-break">https://github.com/ImranR98/Obtainium</a> - Obtainium GitHub</li>
<li>


<a href="https://github.com/TeamNewPipe/NewPipe" target="_blank" rel="noopener" class="text-break">https://github.com/TeamNewPipe/NewPipe</a> - NewPipe GitHub</li>
<li>


<a href="https://github.com/bitfireAT/davx5-ose" target="_blank" rel="noopener" class="text-break">https://github.com/bitfireAT/davx5-ose</a> - DAVx⁵ GitHub</li>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepage</li>
<li>


<a href="https://github.com/adrcotfas/Goodtime" target="_blank" rel="noopener" class="text-break">https://github.com/adrcotfas/Goodtime</a> - Goodtime Productivity GitHub</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>Six months ago, I made a few videos on F-Droid and why you should stop using it. Shortly after the release of those videos, someone sent me a project on GitHub that says in the readme it was motivated by one of those videos. I didn&rsquo;t start using it then, but I kept an eye on the project.</p>
<p>Now, just over six months later, the project has over 900 stars on GitHub, and it has come a long way, to say the least.</p>
<p>In my original video, I covered how you could manually add the source for APKs you wanted to track and download to an RSS reader. While this method did work, it was cumbersome.</p>
<p>The app I&rsquo;m talking about today is Obtainium, and it aims to automate the process of tracking and updating apps. While it doesn&rsquo;t solve the inherent problem with F-Droid and third-party app repositories, I do think it provides some viable alternatives to help reduce or even eliminate some of those concerns. As always, you should use my advice and experience as a starting point for your own research. Make sure to test and validate everything you hear, especially if you are considering using it.</p>
<p>I&rsquo;m going to cover a few use cases and then talk about my experience the last two weeks using Obtainium on my main device, a Pixel 7. The demo you see today will be from my testing device, which is a Pixel 6A.</p>
<p>So, to obtain Obtainium, we&rsquo;re going to head on over to the official GitHub page. All links will be down below in the description box.</p>
<p>So, we&rsquo;re going to open up our browser and search for Obtainium GitHub. And this first one here is the one we want. And if you scroll down, we&rsquo;re going to select the &ldquo;Get it on GitHub&rdquo; under installation. We&rsquo;re going to expand the assets, and the one we want to select for the Google Pixel is the &ldquo;app-arm64-v8a.&rdquo;</p>
<p>Select that, download anyway. Once that finishes, select &ldquo;Open.&rdquo; If you&rsquo;ve never used your browser to install an app before, you&rsquo;ll have to allow this permission. Once you see the install window pop up, select &ldquo;Install.&rdquo;</p>
<p>Done, and we have now obtained Obtainium. You should now see it on your home screen, or if you swipe up, it should be in your app drawer. Ignore the X Recorder; I&rsquo;ve had some issues with the built-in Android screen recorder, so I&rsquo;m trying a different one.</p>
<p>You can now open the app, allow notifications. Notifications are done locally, so there&rsquo;s no need for Google Play services for notifications to work.</p>
<p>And I first want to start off by saying how refreshing it is to use an open source app that took design into consideration. I&rsquo;ve noticed a lot of times that aesthetics is an afterthought, which is fine, but I think it hurts long-term adoption. I personally have motivation from a security and privacy perspective to use an app, even if the interface is less than ideal. Others who might not have as strong of a motivation to use an app could get quickly turned off by its looks.</p>
<p>So when I first opened Obtainium, I was pleasantly surprised by the design. The developer is very active on this project, so what you see on my screen right now might not be what you see if you&rsquo;re watching this video in the future, but the general overall concept should be the same.</p>
<p>Going through the interface, the first option is the apps. This is our apps list that we&rsquo;re tracking. Obtainium is added here by default so it can track and update itself, so that&rsquo;s pretty handy. We have add app, which we&rsquo;ll come back to shortly. Then we have import/export. If you&rsquo;re currently using an RSS reader like I talked about in my previous videos, there&rsquo;s an option here to import from URLs and file like OPML. The Repla app, the main export type that I had was OPML for its backups, so you could perform an export from that and import it to Obtainium. I didn&rsquo;t test this functionality; I just manually added the apps that I wanted. You can also perform an Obtainium export, so once you get everything set up, that&rsquo;s handy. You can export it, save it, and then if you switch devices or your phone gets lost or stolen, you can always import that backup so you don&rsquo;t need to set it up all over again.</p>
<p>The last option on the bottom is settings. I just left this set to the default, but feel free to change anything you might want.</p>
<p>Now let&rsquo;s add our first app. So select add app. We can see down here listed are the supported sources, and if we look next to GitHub and Codeberg, those are labeled as searchable. So in the second box here, we can search for an app. In this case, I&rsquo;m going to search for NewPipe because that&rsquo;s on GitHub. Search, so you&rsquo;re going to be presented with a lot of results, especially for a project that&rsquo;s popular. But this first one here is the official one, Team NewPipe. Just to be safe, I always suggest that you check first to validate that it is the correct one. So let&rsquo;s go to that repo. We can see here, this is the correct one, the official NewPipe. So once you validate that, we&rsquo;re going to go back, select the first one, and then press pick.</p>
<p>There&rsquo;s a separate section for additional options for GitHub. The first one is to include pre-releases. By default, you should leave this unchecked.</p>
<p>Prereleases technically aren&rsquo;t releases that you should be using, so that&rsquo;s why it&rsquo;s left unchecked by default. The next option is fallback to older releases, and that is enabled by default. This option is for when developers on GitHub do not do the releases correctly, and they might have one release for iPhone and one for Android. If they are listed in different releases, when Obtainium goes to check what the latest version is, if the iPhone one was released latest, it will see that there&rsquo;s no Android APK available to install. Therefore, this option lets it fall back to an older release, which would be the Android version, and you can then update that.</p>
<p>Probably sounds confusing, so just leave that enabled like it is. There&rsquo;s another option here for filter release titles by regular expression. Again, this is for edge cases. I haven&rsquo;t needed this yet for any of the apps I&rsquo;m tracking on my main device. The last option down here is for track only, and what this will do is it will just track it and will not actually try to download the updates and let you install them. I leave this disabled because I want Obtainium to download the APKs for me so I can install them, and then standard version detection, I just leave that set to the default. So those are the options that are listed.</p>
<p>We can now select Add. Obtainium needs permission to install unknown apps, a lot from this source. Let&rsquo;s go back. You&rsquo;ll see this screen next. We can see latest version 0.25.0 installed, a version none. I want to install it. Install done. And now if we go back to our apps list, we can see New Pipe is now here and being tracked. Latest version 0.25 installed version 0.25. Nice clean interface, and as expected, New Pipe is installed.</p>
<p>So, I know that took a few minutes to go through and talk about, but in reality, it only takes 30 seconds to add an app, and now in the future, Obtainium will check for updates in the background and notify you when they are available. As always, you should be skeptical of anything open source or any app for that matter, especially something that will be installing apps on your behalf or for you. So one extra precaution that you can take is to install the app manually first from the source, and then add it to Obtainium. When you install an app, Android pins the certificate and enforces signature checks for app updates, so even if something malicious was happening with Obtainium, it wouldn&rsquo;t be able to install a malicious app update because the signature check would fail.</p>
<p>So as an example, let&rsquo;s go ahead and install Dev X5. I know their source code is on GitHub, so I&rsquo;m going to search for that. I know this is the official repo for it. I&rsquo;m going to go to the releases and download the latest one. Let&rsquo;s open and install that.</p>
<p>So now at this point, Dev X5 has been installed. We downloaded it from the trusted source that we know; therefore, the certificate has been pinned by the OS. So any updates that are installed either manually by us or using Obtainium must pass the signature check, which means that the APK is signed by the developers. We can see Dev X5 was installed. Let&rsquo;s now add it to Obtainium. We just copy this URL, go back to Obtainium, add app, paste in the URL, select add. We can see that it found that Dev X5 is installed, latest version 4.3, installed version 4.3.</p>
<p>There&rsquo;s no updates to install. So now, if we go back, then go back to the apps list, we can now see that DAV X5 is listed there. We installed it from a trusted source, and now we&rsquo;re going to let Obtainium handle any future updates.</p>
<p>There are a few other caveats or features that I want to go over. So, going back to the &ldquo;add app&rdquo; option, we can see here that Malvad and Signal are both listed as sources. If we select one of those, Malvad publishes their APK on their website, so we can just copy this, and Obtainium on our behalf will find the APK for us and download it.</p>
<p>Select &ldquo;add,&rdquo; and we can see in the background downloading Malvadvpn. So it&rsquo;s pretty handy that the developer went ahead and built in this functionality for us already. Even though we&rsquo;re not actually adding the exact page the APK is on for the apps listed there. In this case, Malvad and Signal, the app automatically knows where to look. It&rsquo;s a good minute to finish.</p>
<p>Once it finishes, we&rsquo;re prompted to install. Now, if we go back to the apps list and refresh, we can now see Malvad is shown here and being tracked.</p>
<p>Just to show an example of what updates look like, I went ahead and installed an older version of New Pipe. You&rsquo;ll receive a notification, and then when you go inside the app, you&rsquo;ll see a notification next to the app that needs to be updated. In this case, New Pipe. Select the purple download icon, and you can see the download. So Obtainium went ahead and downloaded the APK for us. We now select &ldquo;update,&rdquo; and now New Pipe was successfully updated.</p>
<p>One of the easiest ways to find where the source code for an open-source app is hosted is to use the F-Droid website. So if we go to f-droid.org in our browser and then scroll down and let&rsquo;s search for New Pipe as an example, the second one is the one we want.</p>
<p>To access the source code for the application, we need to scroll down to the section above the donate button and click on the link to the source code. By examining the URL, we can see that the source code is hosted on GitHub. If we scroll down further to the releases section, we can see that NewPipe publishes their APK on GitHub, which means Obtainium can download it from there.</p>
<p>Returning to fdroid.org, we can find that some developers only publish the APK on F-Droid, even if they have already published the source code on GitHub. As an example, let&rsquo;s search for a productivity app that starts with &ldquo;Good Time,&rdquo; which is the fifth one down. Looking at the source code, we can see that it is also hosted on GitHub. However, when we scroll down to the releases section, we notice that they do not publish the APK on GitHub; only the source code is available. In this scenario, our only option is to return to F-Droid, copy the F-Droid link, and paste it inside Obtainium.</p>
<p>After adding the app and pasting the F-Droid URL, we can see that Obtainium found the app and we can proceed to install it. Upon returning to our list of apps, we can see that Productivity is now installed, and it shows that it is signed by F-Droid.</p>
<p>Using Obtainium is still a better option than the official F-Droid app because it avoids some of the shortcomings mentioned in the previous video, such as targeting out-of-date SDKs. Although the process might seem complicated, it is relatively simple once you go through the steps yourself. It has made the process of downloading, installing, and updating apps much more accessible for the past two weeks, and the update functionality and tracking have worked flawlessly. The experience so far has been enjoyable, and the plan is to continue using it.</p>
<p>However, there are a few limitations to be aware of that are listed on the GitHub readme. The first one is that app installs occur asynchronously, and the success or failure of an install cannot be determined directly. This results in install statuses and versions sometimes being out of sync with the OS until the next launch or until the problem is manually corrected. If you notice any unusual behavior, close the app and relaunch it.</p>
<p>The second limitation, which will be revisited later, is that auto unattended updates are unsupported due to the lack of a capable Flutter plugin. Also, for some sources, data is gathered using web scraping, which can easily break due to changes in website design. In such cases, more reliable methods may be unavailable, and scraping is an unreliable method to gather data. If you have ever used NewPipe and noticed that it broke randomly because YouTube changed its layout one day, that is a similar situation to what the developer is describing here. It is not the app developer&rsquo;s fault, but rather the nature of web scraping.</p>
<p>Regarding the second limitation mentioned above, before making this video, the app developer was contacted to see if there was anything specific they wanted to mention. They requested that any Android developers watching the video take a look at issue number 25, linked below, to help complete the auto-update feature before releasing version one of Obtainium. Contributions to help with that would be greatly appreciated.</p>
<p>Overall, using Obtainium has been a great improvement and has made the manual tracking process much more efficient. Although it is not a solution to the underlying problems that still exist, it is a step in the right direction. The plan is to continue using it, and there are no plans to go back to the RSS reader method.</p>
<p>And while it&rsquo;s not a solution to the underlying problems that still exist, which I covered in my previous videos, it is a great improvement and makes the manual tracking process much more efficient. So, I hope you enjoyed this video. If you did, check out this top one here, and the bottom one has been automatically selected for you.</p>
]]></content>
      </entry>
      <entry>
        <title>F-Droid - App not installed as package appears to be invalid</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/fdroid-app-not-installed/" />
        <id>https://staging.sideofburritos.com/blog/fdroid-app-not-installed/</id>
        <published>2023-02-06T10:00:00Z</published>
        <updated>2023-02-06T10:00:00Z</updated>
        <summary type="html">The F-Droid website hosts an outdated version of the APK which causes issues for users who try to install it in multiple user profiles.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode56s0hbhb">🎥 


<a href="https://youtu.be/E3erRhXPPNY" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://f-droid.org/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/</a> - F-Droid homepaage</li>
<li>


<a href="https://f-droid.org/en/packages/org.fdroid.fdroid/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/en/packages/org.fdroid.fdroid/</a> - F-Droid package</li>
<li>


<a href="https://www.sisik.eu/apk-tool" target="_blank" rel="noopener" class="text-break">https://www.sisik.eu/apk-tool</a> - Browser APK analyzer</li>
<li>


<a href="https://forum.f-droid.org/t/cannot-install-f-droid-invalid-package-using-profiles/16122" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/cannot-install-f-droid-invalid-package-using-profiles/16122</a> - F-Droid forum post 1</li>
<li>


<a href="https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234</a> - F-Droid forum post 2</li>
<li>


<a href="https://hub.libranet.de/wiki/and-priv-sec/wiki/apps" target="_blank" rel="noopener" class="text-break">https://hub.libranet.de/wiki/and-priv-sec/wiki/apps</a> - Android apps</li>
<li>


<a href="https://grapheneos.org/features#install-available-apps" target="_blank" rel="noopener" class="text-break">https://grapheneos.org/features#install-available-appss</a> - GrapheneOS install available apps feature</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong> ✔️</p>
<p>It&rsquo;s good practice to document answers to frequently asked questions, as it allows other users to reference them. For example, I&rsquo;ve been asked multiple times through email and video comments why a user is unable to install F-Droid in another user profile. To avoid answering these questions individually, I decided to make a video explaining the reason behind this issue. To demonstrate the process, a user can go to f-droid.org on their Android device and click the &ldquo;Download&rdquo; button on the home page to download F-Droid. Once the download is complete, they can install the APK.</p>
<p>Open the app, ignore the warning, allow it a minute to update the repositories. Now, if you go to updates because of the notification, the first thing the app wants you to do is update F-Droid to the newest version. The user now has the latest version of it installed. They go through and download whatever apps they want, install them, and then shortly after this, the user finds out about user profiles and wants to start separating their apps to different user profiles to separate user data.</p>
<p>So, they create a new user profile and we&rsquo;re on that new user profile. And again, the first thing they want to do is install F-Droid so they can download apps. They go to fdroid.org again, same process as before, click the download button, download once the download finishes, open, and install again. And they are presented with an error. This is the error I get asked about and that I see different posts about online.</p>
<p>So now that we see what is happening, let&rsquo;s talk about why this is happening. This diagram is overly simplified, but I think it&rsquo;ll help paint the picture of what&rsquo;s going on. At the bottom here, we have the system and part of the system is the Android Package Manager, which we can see here. And above the system level is the user profiles, as we saw in the example. We had our initial owner user profile that we were on and then switched to our user profile, which was that second user profile where the F-Droid install failed.</p>
<p>A common misconception is that when you install an app on a user profile, it&rsquo;s installed in that user profile and then when you switch to the other user profile, it&rsquo;s installed there as well. But that is not correct. What happens when you install an app on Android is that it is handled by the Android Package Manager. That app is installed and then linked, for lack of a better term, to the profile that you are presently in.</p>
<p>In this example, we installed F-Droid from our owner profile. We downloaded it and installed it, which was version one. And as we saw in the example, once we installed F-Droid, we were immediately prompted to update the app, so we went from version one to version two. These are not the actual version numbers. I&rsquo;m just doing this for the sake of simplicity. So at this point, we now had version 2 of it installed and being managed by the Android Package Manager.</p>
<p>We went to our second user profile, downloaded and installed F-Droid, or tried to install it, but the issue that was occurring was that when we downloaded F-Droid from the website, the version we downloaded was actually version one. Since Android packages are managed by the system, there&rsquo;s a protection in place that prevents an app from being downgraded. So in this case, we were trying to install version one of F-Droid, but the Package Manager saw that we had version 2 installed, therefore it blocked the install on that second user profile, and we were unable to install F-Droid on it.</p>
<p>Just to reiterate, because it was a misconception that I had as well, user profiles are meant to separate user data. The actual installation of apps is handled at the system level by the Android Package Manager. And if you try to install an app on a separate user profile that is an older version than the one currently being tracked by the Android Package Manager, the install will fail.</p>
<p>You may have noticed that when you update an app in one user profile, the same update is reflected in all other user profiles. This is because the package installation is handled at the system level, not at the user profile level. When the app is updated in one profile, the actual package is upgraded across the system, making all user profiles use the same updated version.</p>
<p>This is why the issue of updating F Droid continually occurs. F Droid hosts an outdated version of their app on their website, so every time a new user visits the site, they end up downloading an older version of the app, which then prompts them for an update. To avoid this, you can download the latest version of the app from the home page and save it in a folder titled &ldquo;F Droid&rdquo;. From there, you can search for &ldquo;F-Droid&rdquo; on the right side.</p>
<p>We can scroll down to the latest version labeled &ldquo;Suggested Download&rdquo;. Again, placing that in the &ldquo;F Droid&rdquo; folder. Now, for the sake of simplicity, I&rsquo;m going to use this online APK analyzer. Here we have our &ldquo;F Droid&rdquo; folder with the &ldquo;F Droid.apk&rdquo; that was downloaded from the home page and the &ldquo;org.fdroid&rdquo; that was the most recent suggested version we downloaded.</p>
<p>If we look at these, we can see that the one from the home page is version 1.15.4, and the version from the actual page in the search was 1.15.6. The 1.15.4 was published on December 2nd, 2022, and the most recent suggested version on January 14th, 2023.</p>
<p>That&rsquo;s why if you go to a separate user profile and try to download F Droid from the main home page, you receive an older version that&rsquo;s out of date and the install fails because Android&rsquo;s downgrade protection kicks in and blocks the install.</p>
<p>Now that we know what is happening and why, there are a couple of things you can do to get around this issue:</p>
<p>Instead of going to the F Droid home page, you can scroll down, search for &ldquo;Appdroid&rdquo;, select F Droid, and download the latest version with the tag &ldquo;Suggested&rdquo;. When you open this one and select &ldquo;install&rdquo;, it&rsquo;s not blocked by Android because you&rsquo;re not trying to install an older version of the app. This is probably the easiest for most people.</p>
<p>If you are running Graphene OS, you can go into &ldquo;Settings&rdquo;, &ldquo;System&rdquo;, &ldquo;Multiple Users&rdquo;, select the second user profile, and use the option &ldquo;Install Available Apps&rdquo;. Change the toggle next to F Droid, and it will be accessible from your second user profile. The reason the &ldquo;Install Available Apps&rdquo; feature works is that APK installation is handled by the package manager at the system level, so when you are in the owner profile, you can give additional profiles access to installed apps.</p>
<p>For the F Droid team, you could update the version on your home page to the latest stable version. It&rsquo;s not good security practice to intentionally host an outdated version of your app in the most popular place to download it. This one change of hosting the most recent version on your home page would save everyone time and make for a better overall user experience.</p>
<p>If you enjoyed this video, I think you&rsquo;ll like the top one listed here, and the engineers at Google think you will like the bottom one.</p>
]]></content>
      </entry>
      <entry>
        <title>You should use this instead of F-Droid</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/use-this-instead-of-f-droid/" />
        <id>https://staging.sideofburritos.com/blog/use-this-instead-of-f-droid/</id>
        <published>2022-07-10T12:57:39Z</published>
        <updated>2022-08-22T12:57:39Z</updated>
        <summary type="html">F-Droid has issues. Using this method is a way to completely bypass using F-Droid to install open source apps.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode122s0hbhb">🎥 


<a href="https://youtu.be/FFz57zNR_M0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="mobile-privacy-guide">Mobile privacy guide</h2>
<ul>
<li>


<a href="https://sideofburritos.com/docs/setup-guides/mobile-privacy/" target="_blank" rel="noopener" class="text-break">https://sideofburritos.com/docs/setup-guides/mobile-privacy/</a></li>
</ul>
<h2 id="my-previous-two-f-droid-videos">My previous two F-Droid videos</h2>
<ul>
<li>


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">https://youtu.be/IzpVI4zaso0</a> - You should uninstall F-Droid - Part 1</li>
<li>


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">https://youtu.be/lAbgeJau3eE</a> - You should uninstall F-Droid - Part 2</li>
</ul>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://en.wikipedia.org/wiki/RSS" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/RSS</a> - RSS Feeds</li>
<li>


<a href="https://github.com/Ashinch/ReadYou" target="_blank" rel="noopener" class="text-break">https://github.com/Ashinch/ReadYou</a> - Read You Github page</li>
<li>


<a href="https://discuss.grapheneos.org/d/16-f-droid-auto-updates/5" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16-f-droid-auto-updates/5</a> - Forum post about using RSS reader</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should uninstall F-Droid - Part 1</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt1/" />
        <id>https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt1/</id>
        <published>2022-06-19T10:00:00Z</published>
        <updated>2022-12-26T10:00:00Z</updated>
        <summary type="html">If you&amp;#39;re going to use F-Droid for apps, there are a few things that you should be aware of.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode127s0hbhb">🎥 


<a href="https://youtu.be/IzpVI4zaso0" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/posts/android/f-droid-security-issues/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/f-droid-security-issues/</a> - Main article referenced on F-Droid</li>
<li>


<a href="https://en.wikipedia.org/wiki/Android_version_history#Android_7.0_Nougat" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Android_version_history#Android_7.0_Nougat</a> - Android version history</li>
<li>


<a href="https://developer.android.com/studio/releases/platforms" target="_blank" rel="noopener" class="text-break">https://developer.android.com/studio/releases/platforms</a> - SDK Releases</li>
<li>


<a href="https://gitlab.com/fdroid/fdroidclient/-/blob/2a8b16683a2dbee16d624a58e7dd3ea1da772fbd/app/build.gradle#L33" target="_blank" rel="noopener" class="text-break">https://gitlab.com/fdroid/fdroidclient/-/blob/2a8b16683a2dbee16d624a58e7dd3ea1da772fbd/app/build.gradle#L33</a> - F-Droid code showing legacy SDK</li>
<li>


<a href="https://github.com/NeoApplications/Neo-Store" target="_blank" rel="noopener" class="text-break">https://github.com/NeoApplications/Neo-Store</a> - Droidi-fy</li>
<li>


<a href="https://f-droid.org" target="_blank" rel="noopener" class="text-break">https://f-droid.org</a> - F-Droid homepage</li>
<li>


<a href="https://discuss.grapheneos.org/d/16-f-droid-auto-updates/4" target="_blank" rel="noopener" class="text-break">https://discuss.grapheneos.org/d/16-f-droid-auto-updates/4</a> - F-Droid discussion on auto-updates</li>
</ul>
]]></content>
      </entry>
      <entry>
        <title>You should uninstall F-Droid - Part 2</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt2/" />
        <id>https://staging.sideofburritos.com/blog/you-should-uninstall-fdroid-pt2/</id>
        <published>2022-05-22T10:00:00Z</published>
        <updated>2022-08-22T10:00:00Z</updated>
        <summary type="html">The F-Droid app repository has some issues that could potentially affect your security.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode128s0hbhb">🎥 


<a href="https://youtu.be/lAbgeJau3eE" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://privsec.dev/posts/android/f-droid-security-issues/" target="_blank" rel="noopener" class="text-break">https://privsec.dev/posts/android/f-droid-security-issues/</a> - Main article referenced on F-Droid</li>
<li>


<a href="https://github.com/signalapp/Signal-Android/issues/127" target="_blank" rel="noopener" class="text-break">https://github.com/signalapp/Signal-Android/issues/127</a> - GitHub issue regarding Signal/TextSecure</li>
<li>


<a href="https://en.wikipedia.org/wiki/Moxie_Marlinspike" target="_blank" rel="noopener" class="text-break">https://en.wikipedia.org/wiki/Moxie_Marlinspike</a> - Moxie Marlinspike</li>
<li>


<a href="https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning" target="_blank" rel="noopener" class="text-break">https://www.digicert.com/blog/certificate-pinning-what-is-certificate-pinning</a> - Certificate Pinning</li>
<li>


<a href="https://f-droid.org/en/docs/Reproducible_Builds/" target="_blank" rel="noopener" class="text-break">https://f-droid.org/en/docs/Reproducible_Builds/</a> - F-Droid build process</li>
<li>


<a href="https://arxiv.org/pdf/1904.05572.pdf" target="_blank" rel="noopener" class="text-break">https://arxiv.org/pdf/1904.05572.pdf</a> - Android Playform Security Model</li>
<li>


<a href="https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234" target="_blank" rel="noopener" class="text-break">https://forum.f-droid.org/t/why-does-the-f-droid-website-nearly-always-host-an-outdated-f-droid-apk/6234</a> - f-droid.org hosting out of date APK</li>
</ul>
]]></content>
      </entry>

</feed>
