Not hiding the fact the published source code isn't that built into the app then...
Not hiding the fact the published source code isn't that built into the app then...
Edit: some digging. NHSX is run by Matthew Gould. Former Israel diplomat and tied via UK-Israel technology hub to NICE (Neptune Intelligence Computer Engineering) Ltd which is a former Israeli army surveillance and data security company among other functions.
So basically a hotpot of reasons not to install this thing.
EDIT: if I'm wrong please leave some details for myself and others to learn more. I've worked on iOS apps for several years, and as far as I know there's no way to verify if an app downloaded from the App Store was compiled from a particular code revision. Even the same code compiled on separate machines can produce different unique binary IDs. And on the scale of difficulty, I'd say that sideloading is less difficult than jailbreaking, if that method even really works for this problem.
[0]: https://github.com/signalapp/Signal-iOS/issues/641
[1]: https://core.telegram.org/reproducible-builds#reproducible-b...
We personally opted out of it because the user's device's security would ultimately fall into our hands and at worst we have a root kit on the user's device someone might exploit.
Ideally, if the builds are fully repeatable, the only differences should be in the signatures, but of course, you need to confirm that the signature doesn't drive unexpected differences in behavior.
I don't have the skills or the tools to do this, but it's not like it's some impossible mystery.
Without a jailbreak, which isn’t a sure thing and even if available is not nearly as feasible as sideloading, it in fact is an impossible mystery to decrypt an iOS app store build to inspect it.
[0]: https://ivrodriguez.com/reverse-engineer-ios-apps-ios-11-edi...
I'm not saying that guarantees no skullduggery is afoot, but it goes a long way - at least in it's current form, at that point in time.
I will install this app happily from F-Droid, and no other place.