Damus
Zapstore profile picture
Zapstore
@Zapstore

The open app store powered by your social network

Download 1.0.0 for Android: https://zapstore.dev/

SHA-256 checksum: 37090571d00ca53ff1e4d21564a1b45e89feb09f47937d818156d48cf618e402

APK certificate hash (for AppVerifier): 99e33b0c2d07e75fcd9df7e40e886646ff667e3aa6648e1a1160b036cf2b9320

Tech support for developers: https://signal.group/#CjQKIC0VCHf6gGeeHKcIrKcaI-B5Kjvge2NKw2i4P55tMkCwEhBaOk9B80F3_MhMYVbgj7lL

Tech support for users: https://signal.group/#CjQKIK20nMOglqNT8KYw4ZeyChsvA14TTcjtjuC2VF6j6nB5EhDLZ7pQHvOeopr36jq431ow

Nostr DMs will be ignored, tag us instead.

Relays (3)
  • wss://relay.damus.io/ – read & write
  • wss://relay.primal.net/ – read & write
  • wss://nos.lol/ – read & write

Recent Notes

Niel Liesmons · 20h
I've had the same sometimes via phone internet. Server does time out. Displays just one line about timing out under those progress bar percentage lines. Forgot exact message.
DZC · 1d
Thanks for your work!! 🫂
ethfi · 2d
Makes you think
Zapstore · 2d
I mean, I can't force people to read. When I do with red flashy warnings they just come here asking what is this scary message? True story
ZAPU · 2d
❤️🫂zap store! At first I didn't even remember if there was a warning, but then I do remember there is actually the warning! But people have been *conditioned* that warnings are not optional, that they just have to accept the warning anyway, so they just forget it and click yes anyway! But w...
rafftyl · 2d
Clear to me, but people are retarded 😁
Zapstore profile picture
After today's drama there's a clear takeaway:

Apps are not shitposts, even if both are carried over the same protocol.

Catalogs are responsible for the apps they publish, and the well-functioning web-of-trust check and warning was not as useful. People just don't pay that much attention and that's a data point, not a complaint on my side.

Architecting Zapstore around communities, who own these catalogs, is the way forward for software distribution. I am more sure than ever.

The Zapstore software:
- provides a great default community
- surfaces communities/catalogs people in their WoT are using, and allows easy community management
- provides credible exit rather (permissionless at the catalog level, not the app level)

@Niel Liesmons has a lot of credit for this one
74❤️6♥️1❤️1🔥1🚀1🧡1
Sarah Chen · 2d
The community-driven catalog model makes sense, but I'm wary of over-relying on social trust (as seen in the Qatar evacuations—groups often misjudge real threat levels when relying on insider consensus). Decentralized governance needs structured risk assessment, not just tribal vetting. https:/...
rafftyl · 2d
Regarding people not paying attention - maybe it would be useful to display a warning if an app is not signed by a pubkey from your web of trust? Might be annoying for some, but would decrease the probability of a slip.
Zapstore · 2d
All indexed apps on Zapstore, by the way, are pulled from their original location so its exactly the same as Obtainium in that regard
arfonzo · 2d
Agreed, as nostr:npub10r8xl2njyepcw2zwv3a6dyufj4e4ajx86hz6v4ehu4gnpupxxp7stjt2p8 said, striking a balance between permissionless and secure, is a real challenge. I think WOT is useful but things like ...
Zapstore profile picture
Not sure what you mean by "signatures", everything is signed - all APKs and all nostr events - the who signs is the signal and thus WoT.

As for indexed apps its impossible to apply WoT on Github usernames.

If random npubs with built reputation sign there's little we can do about that, other than scan for malware or impersonation (coming soon). At this point personal responsibility kicks in.
ethfi · 2d
VIP treatment
Dikaios1517 · 2d
No, the need for seeing WoT before updating is resolved by the fix you made today, assuming that was a general fix and didn't only apply to Wisp. I'm talking about having WoT visible on the app info page simply because people viewing that page may find the information useful. If they have never ins...