

If it’s something with a solid reputation, and a history of good code curation. Maybe backed by a non-profit foundation ( e.g FUTO, KDE’s mobile apps ). I dont have any issue allowing whatever permissions it requests right off the bat.
If something ever ever happened with KDE Connect. There’d be hellfire, and shouting all over the internet for miles and miles. KDE is one of the organizations that actually has the resources and manpower to properly vet contributions. KDE hosts their own git client, with their own credentials, and their own dedicated team ( A bad actor can’t just push a harmful update directly without humans reviewing it). They’ve also been doing this for longer than I’ve even been alive, they don’t ask for a profit, and they make a damn good desktop environment so I guess I feel comfortable trusting apps from their F-droid repo xD
You could spend time manually reviewing the source for every FOSS application you install, which isn’t a terrible idea. But at the end of the day it does matter to an extent how much you trust an individual / organization. And how open that individual / organization is to the community.





















What do I do if I don’t have any of the supported devices : (