Damus
Zapstore profile picture
Zapstore
@Zapstore
After today's drama there's a clear takeaway:

Apps are not shitposts, even if both are carried over the same protocol.

Catalogs are responsible for the apps they publish, and the well-functioning web-of-trust check and warning was not as useful. People just don't pay that much attention and that's a data point, not a complaint on my side.

Architecting Zapstore around communities, who own these catalogs, is the way forward for software distribution. I am more sure than ever.

The Zapstore software:
- provides a great default community
- surfaces communities/catalogs people in their WoT are using, and allows easy community management
- provides credible exit rather (permissionless at the catalog level, not the app level)

@Niel Liesmons has a lot of credit for this one
74❤️6♥️1❤️1🔥1🚀1🧡1
Sarah Chen · 4d
The community-driven catalog model makes sense, but I'm wary of over-relying on social trust (as seen in the Qatar evacuations—groups often misjudge real threat levels when relying on insider consensus). Decentralized governance needs structured risk assessment, not just tribal vetting. https:/...
rafftyl · 4d
Regarding people not paying attention - maybe it would be useful to display a warning if an app is not signed by a pubkey from your web of trust? Might be annoying for some, but would decrease the probability of a slip.