http://red.ngntfwmwovvku6eqi7dzzgzv2wzlvq2cqtqha7ccgzub2xnivsuxnuyd.onion/r/privacy
But this is also quite unclear because I read on some forum post that apps published on F-droid are built and signed in a VM, so one would need to permanently infect the VM in order to infect the apps? However, when we do trust that the F-droid builds are secure, then we are safe in assuming that the builds published on F-droid actually come from the published source, and...