← Back to context

Comment by Gargyle

5 years ago

Last time I looked at your servixe it was web only and did in-browser crypto. This is essentially useless for 2 reasons: - There is no effetive Versioning. - Application and Storage-Vendor are the same entity. Therefore if you are hacked or coerced you can push code to me. The only defense is proper version pinning and compiling myself / taking it from FDroid.

Photos are among the highest value phone data. I dont take chances here. You do not post the apk signing key prominently on your front page. Your commits are not signed. You host on Microsoft owned Github.

Why would I trust you? This seems like yolo-development.