Found this notification this morning on my pixel 6.

      • sugar_in_your_tea@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 months ago
        • Fennec - Firefox build with some proprietary stiff removed; repo
        • IronFox - Firefox fork (forked from Mull) with a bunch of hardening changes (notably resistFingerprinting enabled); repo

        IronFox is more ambitious, which means higher maintenance load and more likely to fall behind. Fennec is much simpler, so less likely to fall behind, but also doesn’t change much from Firefox.

    • Mr. Camel999@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      ·
      10 months ago

      I’ve not heard of ironfox before this thread! Could you possibly link it? Doesn’t seem like it’s on FDroid or IzzyOnDroid

          • sem@lemmy.blahaj.zone
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            10 months ago

            The main difference is of philosophy of trust. With F-droid you trust F-droid to build the binary from the developers’ source code. With Accrescent, you trust the developers to build the binary from the source code.

              • sem@lemmy.blahaj.zone
                link
                fedilink
                English
                arrow-up
                1
                ·
                10 months ago

                In the play store you’re trusting Google and the developer.

                I’m not sure how obtainium works. But if you download binaries from GitHub, you’re trusting the developer to accurately build their source code into the binary without adding anything. You’re also trusting GitHub implicitly – way back when, source forge was sometimes adding malware to downloads iirc.

                • MaggiWuerze@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  10 months ago

                  And here I’m trusting Accrescent to actually deliver me an executable that has not been tampered with

                  • sem@lemmy.blahaj.zone
                    link
                    fedilink
                    English
                    arrow-up
                    0
                    ·
                    10 months ago

                    Yes you are trusting them, and the developer. Just like you are trusting F-droid if you download from them. You also have to trust that the compiler program doesn’t do anything fishy. It’s trust all the way down.

                    The good news is that lots of people are working on making the systems trustworthy, and you as a consumer can learn to distinguish between what can be trusted for your usecase and what can’t.

            • carrylex@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              10 months ago

              With F-droid you trust F-droid to build the binary from the developers’ source code

              Not when using a self-hosted F-Droid Repo - which is the case for Ironfox.