Damus
Zapstore profile picture
Zapstore
@Zapstore

The open app store powered by your social network

Download 1.1.0 for Android: https://zapstore.dev/

SHA-256 checksum: 25bc797d64b8a6c5a9bfd4224598f3875e5c0b07beed985e9e29bc94899c0164

APK certificate hash (for AppVerifier): 99e33b0c2d07e75fcd9df7e40e886646ff667e3aa6648e1a1160b036cf2b9320

Support: https://zapstore.dev/community/forum

Nostr DMs will be ignored, tag us instead.

Relays (3)
  • wss://relay.damus.io/ – read & write
  • wss://relay.primal.net/ – read & write
  • wss://nos.lol/ – read & write

Recent Notes

Matt Lorentz · 14h
I burned several days over the last few months jumping through Apple and Google's App store hoops - DUNS numbers, identity verification, encryption documentation, half a dozen wizards about content in...
Zapstore profile picture
Thank you sir! Also hope these ecosystems to flourish. There are a lot of things to improve on the security side - working on them for v2.

We believe it's possible to craft a private and secure experience for all users without the low-IQ path of KYCing everyone.
❤️1👏1
Leo Wandersleb · 1w
At this point, we would not emit those attestations. I assume nostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg red team and nostr:npub1ug8c5wp6chs4xessrstq3mj0x0agkttey5xwk26632a2gw22de7qkfd9ry Project Loupe would. As for how such an event should look like: Pick a kind and refe...
Mr Dao · 1w
okay, great to know it will come at some point. Thanks for the awesome work!
Juraj🏴💛🌘 · 1w
Very nice. I'll try to tackle this somehow. A bit more community ideas before. Questions: I would tie this to source code, not APK. Problem is most don't do reproducible builds and we probably audit ...
Zapstore profile picture
Good point, and true there are few reproducible apps.

Would be nice to tag a version (as per Software Applications NIP) against which the latest analysis was run, rather than a git commit.

These reports also contribute to reputation to the keystore/certificate signing the APK so they help anyway.
2❤️1
incoghs102 · 1w
Your doing great work!
Juraj🏴💛🌘 · 1w
Yes, let's do both. Commit is what was audited, version tag is what developer claims the apk is from. BTW it's possible to also audit a binary APK these days, so I wouldn't rule out APK audits, it's just not what most people will do.
Based Truth · 1w
Bill Gates' Microsoft and Google's Alphabet will love this vague "reputation" system, further entrenching their monopoly.
Primal Protocol · 1w
Version tagging is crucial for reproducibility.
Juraj🏴💛🌘 · 1w
Very nice. I'll try to tackle this somehow. A bit more community ideas before. Questions: I would tie this to source code, not APK. Problem is most don't do reproducible builds and we probably audit source code, not APKs. Also, the check probably won't last for long anyway, people do releases all t...
Primal Protocol · 1w
Implementing tech solutions is like optimizing our diets, requires precise data and hashing out the details.