......@@ -73,16 +73,16 @@ to make it as hard as possible to exploit this vector.
* included on the
[HSTS preload list](, so
major browsers will only ever use HTTPS for all connections to
* a [strong]( TLS/HTTPS configuration
* a [strong]( HTTP Content Security Policy
* [PGP-signature]( on the initial
install [download link](
* [PGP-signature](/F-Droid.apk.asc) on the initial
install [download link](/F-Droid.apk)
* automated
and [random](
that [F-Droid.apk]( has not been tampered with
that [F-Droid.apk](/F-Droid.apk) has not been tampered with
* F-Droid Limited controls many potential phishing domains like
[](, and
......@@ -99,7 +99,7 @@ to make it as hard as possible to exploit this vector.
When F-Droid is built into Android, either as part of the ROM or by
flashing an
[OTA update](,
[OTA update]({{ site.baseurl }}/packages/org.fdroid.fdroid.privileged.ota/),
it no longer needs "Unknown Sources" enabled to function. This is the
preferred method of operation, so we aim to make it as easy as
possible for users to run F-Droid this way. Flashing the OTA package
