Laser
· 6d
What's your long term thinking on securing app installs/updates?
The main issue Zapstore attempts to solve is trust on first use. Updates are secured by the OS, though some developers leak keys so we can also help there.
There will be a security & privacy report for each listing, provided by each catalog relay. In ours (default) we strive to do as few takedowns as possible -only terms violations- and defer responsibility to the user by giving them the highest signal possible for their decision.
So on top of the report, we are going to have a transparent reputation rating for each certificate (with a breakdown) and other inputs like attestations for reproducibility and nostr web of trust โ don't expect the latter to be abundant for now.
Is there anything in particular you wished in terms of security?