Spyke

Today I got this POP-UP, anyone?

Originally I've download the signal app through playstore, but often it also get updates from Droid-ify(Fdroid client). Today its weird and I got this . Explain to me this.

On the Droid-ify the signal app is provided by: org.thoughtcrimes.securesms

View original on lemmy.dbzer0.com
feddit.de

The package name is correct, but signal was never on F-droid.

Do you have a third party repo that might be compromised?

Edit: Package name isn't correct, so that's almost definitely a compromised version. Get rid of it ASAP.

265
lemmy.ml

To add to that:

Always check the projects' website to see the official ways it's distributed, before you just download it from anywhere.

110
Pantherinareply
feddit.de

Not applying for signal though, as their apk site is hidden away

5
lemmy.ml

Not a fan of that either, that really is unfortunate. But with a bit of common sense, a person should then ask about that, if the Play Store is not an option. It's still not a reason to download it from a source you haven't verified to be official

1
Pantherinareply
feddit.de

No thats absolutely a reason. Signal is 100% to blame that they have no fully FOSS code repository that could then simply be compiled by FDroid and shipped there.

Instead I have to rely on some Dude I know nothing about, Twinhelix could just as well spread Malware. But I like my updates through FDroid, I like a blob Free Signal

4
lemmy.ml

Call it blame, but that decision is fully within their right, and what Twinhelix does technically violates F-Droids' guidelines. If a creator doesn't want their app on there, F-Droid calls to respect that.

The official Signal apk updates itself, so that's not even an issue.

If your unoffical build from a third-party gives you issues one day, you are fully responsible for that.

2

Huh? They could just as well provide a blobfree APK themselves. They have their Google Play crap already, everyone not using that will probably also have a googlefree OS.

They have a FOSS client and provide no FOSS binaries, which is totally their right. I heard their Desktop clients are not reproducible though, maybe because of Electron?

1
Otterreply
lemmy.ca

org.thoughtcrimes.securesms

It actually might not be, googling "org.thoughtcrimes.securesms" doesn't get results.

thoughtcrimes vs. thoughtcrime


My question though is how this popped up in droidify, would someone need to manually add some special repo?

64
feddit.de

I missed that, thanks for pointing it out. The one without S is the correct one.

But that makes me wonder, how did OP not end up with two signal apps then?

37
Cegorachreply
feddit.de

how did OP not end up with two signal apps then?

by that popup blocking him from installing the wrong one?

37
feddit.de

Oh, that's from the installer and not one of those warnings you get after opening apps. Makes sense.

23

Technically it's from "Google Play Protect" that got triggered during the install but yeah.

10
Pantherinareply
feddit.de

Twinhelix is the only one compiling the app from source without proprietary blobs

10
lemmy.zip

Google is actually right here for once. Signal is not offered on F-Droid, and its package name is org.thoughtcrime.securesms, not org.thoughtcrimes.securesms.

Only official places to download Signal are through the Google Play Store or their website (which self-updates).

105
lemm.ee

I recommend checking the official website or the Play Store to ensure that you are downloading the latest and official version of the app.

69

If the official website redirects you to the Play Store, then it is safe to download the app from there.

And to be noted, I don't think that the Android app client for Signal is available on F-Droid.

22
lemmy.one

From which (enabled) repository does the app come. Signal is not on F-Droid or Izzydroid.

61

Yes, I heard that it is in the CalyxOS repo. This seems to be a legit version.

3
lemm.ee

"This app tries to spy on your personal data"

Needless to say Google hates competition

53

Google is like your big brother. They will beat the shit out of you. But If anyone else tries to beat you they will kick their ass.

18

org.thoughtcrimes.securesms specifically?
I may be wrong but isn't the real one org.thoughtcrime.securesms, not "crimes"?

41
lemmy.ml

It's a fake copy of Signal

The actual package name is org.thoughtcrime.securesms, not org.thoughtcrimes.securesms

Also Google officially recommends Signal on the Android website last I checked, so I don't see why Play Protect would flag it as malware

edit: attach screenshot of package name

edit 2: fix typo in package name (accidentally typed thoughcrime)

31
NullGatorreply
lemmy.ca

Uses the signal back end and is cross compatible

16

you don’t have to tell your peers that, you can still convince them to switch anyways

12

Android tablets as linked devices is why I use it. Something Signal seems to refuse to add.

10
Lemongrabreply
lemmy.one

Fully foss dependencies, degoogled (doesnt require Google Play services), and further hardening to the app. And you can still keep your signal contacts since it is just a fork. Available through Accressant, fdroid, and github.

9

It has an official F-droid repo.

Also it may work as a temporary solution for those who are having signal troubles

3

Maybe a botched version and goolag was triggered. On the safe side get rid of it.

Check the repo where it was downloaded.

9

Got something similar yesterday, but for KDE-Connect from F-Droid. Downloaded the Play Store version instead.

4

Either it got compromised or Google is warning you because it has a different signature than the Google play version

8

I have an EMUI system, it's very hard to tinker, but i uninstalled maps and playstore ecc

1
Cegorachreply
feddit.de

In most cases I'd be the first to support your idea.

but here it actually blocked malware?

112
Blizzardreply
lemmy.zip

Didn't notice the "droid-ify" part, whatever that is. Install apps from trusted sources like F-Droid or dev's website and you don't need Google to scan your phone and tell you what you can or cannot install.

-57
mapletreereply
sh.itjust.works

Droid-ify is just a different client for F-Droid. It should be safe and uses the same repositories

44
lemmy.world

I really like droid-ify. Its a nice, good-looking alternative to fdroid. Also I'd advice to use molly foss instead of the original signal app.

16

Here what I replied to someone else:

Fully foss dependencies, degoogled (doesnt require Google Play services), and further hardening to the app. And you can still keep your signal contacts since it is just a fork. Available through Accressant, fdroid, and github.

5