Bazaar

Complete, reproducible app distribution achieved!

February 11, 2015

With F-Droid, we have been working towards getting a complete app distribution channel that is able to reproducibly build each Android app from …

Reducing metadata leakage from software updates

October 16, 2014

Update: now you can do this with Tor Onion Services Many software update systems use code signing to ensure that only the correct software is …

CipherKit updates: IOCipher and CacheWord

September 26, 2014

We’ve been on a big kick recently, updating the newest members of our CipherKit family of frameworks: IOCipher and CacheWord. There also are is a …

Question: central server, federated, or p2p? Answer: all!

September 18, 2014

There are many ideas of core architectures for providing digital services, each with their own advantages and disadvantages. I break it down along the …

New Official Guardian Project app repo for FDroid!

June 30, 2014

We now have an official FDroid app repository that is available via three separate methods, to guarantee access to a trusted distribution channel …

Our first deterministic build: Lil’ Debi 0.4.7

June 9, 2014

We just released Lil’ Debi 0.4.7 into the Play Store and f-droid.org. It is not really different than the 0.4.6 release except in has a new, …

Automatic, private distribution of our test builds

June 6, 2014

One thing we are very lucky to have is a good community of people willing to test out unfinished builds of our software. That is a very valuable …

Security in a thumb drive: the promise and pain of hardware security modules, take one!

March 28, 2014

Hardware Security Modules (aka Smartcards, chipcards, etc) provide a secure way to store and use cryptographic keys, while actually making the whole …

Tweaking HTTPS for Better Security

February 12, 2014

The HTTPS protocol is based on TLS and SSL, which are standard ways to negotiate encrypted connections. There is a lot of complexity in the protocols …

Turn Your Device Into an App Store

November 18, 2013

As we’ve touched upon in previous blog posts the Google Play model of application distribution has some disadvantages. Google does not make the Play …