Originally I’ve download the signal app through playstore, but often it also get updates from Droid-ify(Fdroid client). Today its weird and I got this . Explain to me this.
On the Droid-ify the signal app is provided by: org.thoughtcrimes.securesms
I recommend checking the official website or the Play Store to ensure that you are downloading the latest and official version of the app.
https://www.signal.org/download/android/
The official website only links to Google Play for the Android client, even on the fairly “hidden” download page.
If the official website redirects you to the Play Store, then it is safe to download the app from there.
And to be noted, I don’t think that the Android app client for Signal is available on F-Droid.
You are using a fake app.
Just get a degoogled phone…
me poor
Degoogle your existsing device
I have an EMUI system, it’s very hard to tinker, but i uninstalled maps and playstore ecc
I generally agree, but in this case, Google Protect actually protected OP from installing a harmful app masquerading as Signal.
Sure? Why can people upload apps called signal there?
Got something similar yesterday, but for KDE-Connect from F-Droid. Downloaded the Play Store version instead.
Either it got compromised or Google is warning you because it has a different signature than the Google play version
I’ll just drop this here
What is the benefit of using this instead of Signal?
You get to convince your peers once more to use a different app.
Uses the signal back end and is cross compatible
you don’t have to tell your peers that, you can still convince them to switch anyways
It seems you are not cross compatible with my joke. I admit, I use an obscure back end.
Android tablets as linked devices is why I use it. Something Signal seems to refuse to add.
It’s named after a rave drug.
Hell yeah
It has an official F-droid repo.
Also it may work as a temporary solution for those who are having signal troubles
Fully foss dependencies, degoogled (doesnt require Google Play services), and further hardening to the app. And you can still keep your signal contacts since it is just a fork. Available through Accressant, fdroid, and github.
But note that you need to download the Fdroid version for the degoogled version
Use molly.Im. They have a repository for F-droid.
deleted by creator
KDEconnect from FDroid also go similar warnings. Might be related or OPs app might really be fake. https://twitter.com/albertvaka/status/1712954968477401478
From which (enabled) repository does the app come. Signal is not on F-Droid or Izzydroid.
I don’t know about OP, but it is available in https://thecapslock.gitlab.io/fdroid-patched-apps/fdroid/repo and https://calyxos.gitlab.io/calyx-fdroid-repo/fdroid/repo
Yes, I heard that it is in the CalyxOS repo. This seems to be a legit version.
It is but in a different repo
Yes. I had it too!
And I download directly from the website and it aelf-updates. Nothing but an annoyance.
On the Droid-ify the signal app is provided by: org.thoughtcrimes.securesms
That’s Signal.
“Thoughtcrime” shouldnt be plural at least its not on my version and for other posters on this thread
Didn’t spot that. Mine is singular…
Maybe a botched version and goolag was triggered. On the safe side get rid of it.
Check the repo where it was downloaded.
It’s a fake copy of Signal
The actual package name is org.thoughtcrime.securesms, not org.thoughtcrimes.securesms
Also Google officially recommends Signal on the Android website last I checked, so I don’t see why Play Protect would flag it as malware
edit: attach screenshot of package name
edit 2: fix typo in package name (accidentally typed thoughcrime)
Thanks mate
I think this app is pretty bullshit, if you want something secure just use Element… https://element.io/download
Signal isn’t even fully open source, there is an obscured closed source code to check if you are sending spam/scam which probably also allows them to read your messages. They are good coding and making protocols, but they are forced to leak any data to the USA by law and also forced to not say anything about this.
Ah, and Element is officially on F-Droid. No bullshits.
that closed source code part you mention is on the server side… the client and protocols used are fully open source and constantly peer reviewd. signal cant really “leak” your messages to anyone since they are end to end encrypted.
Yup, that’s it.
Explaining myself better, it might be secure as it looks, still I keep the “bullshit” words as Molly comments are mainly that, he didn’t want to upload it on F-Droid claiming it is too unsecure (no auto updates, lack of singing) so he decided to join Google Platform. He didn’t help F-Droid to fix anything, still there are many frontend clients that work pretty good. He just abandoned people outside Google dominion. When he saw many people got infected (as this current post shows) he created that link to download the APK directly (https://signal.org/android/apk/) so people could at least download it from official sources.
About the report of spam, we all used other chats that had already in the group chatbots to manage this “captcha verifications” plus moderators on groups to check on what’s happening. For unknown people talking to you, normally in other platforms you can “reject chat unless he has your phone number in contacts” and things like this.
The source code I was talking, doesn’t seem a big problem as only reported chats are being sent to that external service, I just don’t trust to an app that works with Google.
what i get from the playstore. i notice thoughtcrime vs thoughtcrimes fyi
I think it was a typo. I checked the droidfy (fdroid) version and
Google is actually right here for once. Signal is not offered on F-Droid, and its package name is org.thoughtcrime.securesms, not org.thoughtcrimes.securesms.
Only official places to download Signal are through the Google Play Store or their website (which self-updates).
deleted by creator