- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
@fdroidorg at this point is being used to push out an app with sensitive permissions that’s been taken over by an unknown individual who refuses to engage with its large community of users and developers.
I STRONGLY recommend disabling updates from Fdroid, if not uninstalling and manually installing 2.0.11.2, or installing the Google Play version which has a different maintainer.
this is extremely shady and it’s just looking worse as time goes on. I’ll link to the Syncthing forum thread from about where I left off last time in a subsequent post.


… This is somehow going to be a ridiculously strong argument for requiring signed deploys because users are idiots, huh?
What do you mean by signed deploys? The APK is already signed, and this new person got the signing keys. I’m not sire any additional signing would have helped.
Stealing another comment’s update (thanks @[email protected] ), because catfriend1 explicitly says the new maintainer reseachxxl was willingly given the key material, which is how the update was pushed in the first place l: