| ▲ | hasperdi 8 hours ago | ||||||||||||||||
I don't think that's a realistic suggestion as as the quantity of applications are huge who are going to spend time reviewing them one by one. And and even then it's not realistic to expect that that undesirable things can be detected as these things can be hidden externally for instance or obfuscated | |||||||||||||||||
| ▲ | lukeschlather 8 hours ago | parent | next [-] | ||||||||||||||||
F-Droid exists and they have a much better track record than Google. I'm not actually serious, I just think if there's a single app repo that should be allowed to install apps without a scary 24h verification cooldown, it's Google's proprietary closed-source app store that needs the scary process, not F-Droid. | |||||||||||||||||
| |||||||||||||||||
| ▲ | collabs 8 hours ago | parent | prev [-] | ||||||||||||||||
I think compared to the alternatives, this is the best answer. Even if you are a bank or whatever, you shouldn't store global secrets on the app itself, obfuscated or not. And once you have good engineering practices to not store global secrets (user specific secrets is ok), then there is no reason why the source code couldn't be public. | |||||||||||||||||