Important clarification:
While the UX is confusing, this is not a catastrophe as it may have sounded.
The word "download" is ambiguous. This posed no risk whatsoever to current Wisp users who wanted to *update*. Android protects you from APKs signed by a different developer certificate.
However, there was a risk for new *installs* but:
- users would have noticed this app did NOT come from
@utxo the webmaster ๐งโ๐ป but instead from a repository "github.com/captain-stacks/wisp" very clearly displayed in the UI.
Moreover this appared to be an auto-indexed app added by mistake by a nostr user, no malicious code.
That said thank you utxo for sounding the alarm, now this critical bug has been fixed.
Just keep in mind forks will appear and this is EXACTLY my thesis of why catalogs need to be protected.
Striking the balance between permissionless and safe, is fucking hard.