use GPG and PGP
7 points
Open source is not sufficient, you also need to be sure that the version you install is the version you inspected. In Appstore or Playstore for mobile this is not straightforward. Hell, even linux packages sometimes contain tons of maintainer patches that are not upstreamed
2 points