Comment by Gargyle
5 years ago
Last time I looked at your servixe it was web only and did in-browser crypto. This is essentially useless for 2 reasons: - There is no effetive Versioning. - Application and Storage-Vendor are the same entity. Therefore if you are hacked or coerced you can push code to me. The only defense is proper version pinning and compiling myself / taking it from FDroid.
Photos are among the highest value phone data. I dont take chances here. You do not post the apk signing key prominently on your front page. Your commits are not signed. You host on Microsoft owned Github.
Why would I trust you? This seems like yolo-development.
No comments yet
Contribute on Hacker News ↗