Damus
arfonzo profile picture
arfonzo
@arfonzo
Thankfully the fake Wisp publisher doesn't seem to have malicious intent, and was done moreso by accident than on purpose. However this does kick up a whole bunch of questions for @Zapstore:

- Shouldn't there be some kind of manual approval when app names collide with pre-existing ones?
- How can you let a different publisher publish an app with the same ID `com.wisp.app` as a pre-existing, trusted package from the original dev @utxo the webmaster ๐Ÿง‘โ€๐Ÿ’ป ?
- There are literally zero flags/alerts/warnings on the interface when browsing this duplicate app.

Another example is Cake Wallet @Cake Wallet, for the past few versions Google has flagged this as a malicious app (it wasn't the case before), so I have avoided upgrading, even though I originally installed the zapstore version. If it's not fixed soon I will have to uninstall then re-install via Play or another market (annoying as then a full re-sync is required).

To date I have enjoyed using zapstore, but I feel like this is a great lesson learned to tighten up some of the security measures so we maintain high trust in what is published there.

7โค๏ธ2
Zapstore · 4w
Thank you but keep in mind these reactions are out of proportion: nostr:nevent1qqsqclfdy4qpdcu939jzh8es7knnhwxkz7zg6z0ht5fnntde3fn6xngpzamhxue69uhhyetvv9ujuurjd9kkzmpwdejhgtczypuvuma2wgny8pegfej8hf5n3x2hxhkgcl2utfjhxlj4zv8sycc86qcyqqqqqqgt9crrh
Zapstore · 4w
What exactly is Google Play flagging Cake Wallet for? Which "another market"? We are going to introduce malware scanning but I hope you appreciate we don't have the same resources as Google.