@robin @fdroidorg only signs what it has built itself from the source code. And yes, signing is a manual step here. But that doesn't prevent your going to fishysite.com and load some malicious APK of some (other) app, no 😉
Why is this step necessary? mastodon.technology might not be the server where you are registered, so we need to redirect you to your home server first.
Don't have an account? You can sign up here