Damus
lia, a bun type creature :user_online: profile picture
lia, a bun type creature :user_online:
@lia, a bun type creature :user_online:
I'm increasingly worried about the vetting process of applications uploaded to #FDroid.

There appears to be no anti-AI policy for the F-Droid repository, and there's a ton of obviously machine-generated apps clogging up the recent apps feed. That includes sensitive categories like password managing, health data, diaries, personal to-do lists, contacts, galleries, file-sharing and such.

Of course, being human-made is no guarantee or even an indicator that something is safe. And any app regardless of what it appears to do has the potential to be malicious.

But it does feel like previously, the barrier of entry to app (and malware) development was high enough to dissuade random script-kiddies without any skills from trying a fast one on a whim. But nowadays, they could easily 'vibe-code' a crappy, hardly functional, but malicious 'password manager' and upload it to F-Droid, no?

What does the approval process for F-Droid actually look like? Are the repositories actually audited thoroughly before an app is approved? Is it an automated system based on easy anti-feature indicators like binary content, URLs, library imports and permission requests?

#Android