@eighthave Well, if you think AllowedSigningKeys is the only protection we're using, you're a bit misinformed Of course we have multiple layers in place, too. But not all binary APK repos have, some are relying on the "built-in protection".
Mastodon is the best way to keep up with what's happening.
Follow anyone across the fediverse and see it all in chronological order. No algorithms, ads, or clickbait in sight.