Redoubt

Install & updates

Redoubt is distributed as signed APKs on GitHub Releases. There is no app store behind it yet, so you choose how to hear about updates.

Install the APK directly

  1. Open the latest release on GitHub.
  2. Download the APK for your device — for almost any recent phone that is fenix-arm64-v8a-release.apk — and SHA256SUMS.signed.
  3. Verify it before installing.
  4. Open the APK. When Android asks, allow installs from the app you opened it with, then install.

A newer beta installs over the previous one as an update and keeps your data. Android only accepts an update signed with the same key as the installed app, so once you have verified the first install, a tampered update is refused by Android itself.

Verify the download

sha256sum -c --ignore-missing SHA256SUMS.signed
apksigner verify --print-certs fenix-<abi>-release.apk | grep -i SHA-256

The signing certificate’s SHA-256 digest must be:

64:14:EB:33:46:81:CF:6E:92:90:34:B5:6A:06:2D:2B:8D:A0:90:82:21:72:F7:A3:95:2C:85:FD:D1:28:3B:D0

Every Redoubt APK is signed with this one key (APK signature schemes v2 and v3). If the digest differs, do not install it, and report it privately. The key and its custody are documented in SIGNING.md.

On a phone without apksigner, an app that shows an installed app’s signing certificate (for example AppVerifier) can do the second check after installation: compare the SHA-256 it shows for org.redoubtbrowser with the digest above, and uninstall if it differs.

Updates with Obtainium

Obtainium is an Android app that watches release pages and offers you new APKs. It works with Redoubt’s GitHub Releases today.

  1. Install Obtainium from its own release channel (F-Droid or its GitHub page).
  2. In Obtainium, tap Add App and enter the source URL https://github.com/CPlusPlus17/Redoubt. Obtainium recognises it as a GitHub source.
  3. Several APKs are attached to each release. Either pick yours when Obtainium asks, or set Filter APKs by regular expression to arm64-v8a (or armeabi-v7a on older 32-bit devices) so it always takes the right one.
  4. Tap Add. If Redoubt is already installed, Obtainium tracks it; otherwise install it from Obtainium.
  5. Obtainium then checks the release page on its own schedule and notifies you; it does not install anything without you confirming.

Verifying the signature with Obtainium

Obtainium downloads the APK from the same GitHub release, but it does not compare the signing certificate with Redoubt’s published digest for you. So:

An in-app update check is coming

The current betas have no update check of their own. A later build adds an opt-in check that is off by default: when you turn it on it runs only while the app is in the foreground, at most once a day, fetches a small signed file from redoubtbrowser.org/update/, and tells you a new version exists with a link to download it. This site is hosted on GitHub Pages, so GitHub sees your IP address and the time of that request. It does not download or install anything, and it sends nothing that identifies you beyond the request itself. The full contract is in DISTRIBUTION.md. Until it ships, use Obtainium or watch the Releases page.

F-Droid and Accrescent

Redoubt is not in any store yet. When it is, it will be Redoubt’s own F-Droid repository (not f-droid.org’s main repository, which would re-sign the app with a different key) and Accrescent, both signed with the same key and showing the same digest as above.