My signal app the other day had 2 seperate, a few days apart, updates from the app itself. Asking for install from unknown sources to check in the settings to be checked. Doing this outside of both stores which usually update the app from F droid or Aurora.

Seems odd that the signal app itself asked to update itself from a notification from the drop down menu. How can I make sure it has not been compromised? Anyone else experienced something of the sort?

  • Geodad@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    27 minutes ago

    Signal is trying to make its APK auto updating. This way they don’t have to wait for approval from Google to apply patches that might affect security.

  • 3aqn5k6ryk@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    6 hours ago

    Signal is not distributed outside Play store and signal own website. If you downloaded from F-droid, its probably from Guardian repo.

    If you download it from play store, signal will update through play store. If you download it from signal, it will update through itself. If you download it Guardian repo, it’s basically the same downloading from signal website, it will update it self.

    The thing you can do is just basically turn off the update notification and just update it from guardian repo. Or just disable the guardian repo and let the signal update itself.

  • ZeDoTelhado@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    9 hours ago

    My signal app tries to update itself. Installed from obtanium. It is a very irritating process, the thing tries to update, there is sometimes weird response times from clicking it (you click the notification and simply do not know if something is happening) and then without notice the thing restarts and then usually it works. But sometimes, the update notification still comes back. Because of that, I just update via obtanium

  • JoeKrogan@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    12 hours ago

    If you trust the initial install then unless there is a warning about the signing key you are good. Only signal devs can sign the builds so if you installed the play store version then updated with their standalone apk or fdroid version then it should just work as the signing key is the same.

    Guardian project are just publishing signals apk files as the signature matches.

    • Autonomous User@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      10 hours ago

      open-source

      development model

      whatever software

      🚩🚩🚩

      A blatant scam to backdoor our devices with software which fails to include a libre software license text file, software we do not control, anti-libre software.

    • Limonene@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      12 hours ago

      This article seems like a lot of FUD written from an anti-FOSS perspective. In their second point, they say that F-droid’s inclusion policy is “ridiculous” for requiring programs exclude proprietary software. I think the author is ridiculous for asking for this. This is what F-droid is for. I don’t want any proprietary apps or libraries on my phone. If developers only want to work on their proprietary software, they don’t get into F-droid. If they make a modified FOSS version and put it in F-droid, and let it bitrot and go unpatched when vulnerabilities are discovered, and F-droid issues a security advisory for that program, that’s not F-droid’s fault.

  • flatbield@beehaw.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 hours ago

    My Signal auto updates via Obtainium. That is outside of a store. I think I remember the two updates your talking about.

  • novacomets@lemmy.myserv.one
    link
    fedilink
    English
    arrow-up
    0
    ·
    13 hours ago

    Not native Signal but it happens with Signal forks that I install after adding repository to F-Droid, I have had a notification of a Signal update, even though I’m not using native Signal.

    I disable that notification in the phone app settings and wait for an F-Droid notification of an update to install.

    • OhVenus_Baby@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      13 hours ago

      So you don’t think it’s something to be concerned about? I turned off install from unknown sources. App store F-Droid says it’s up to date.

      • novacomets@lemmy.myserv.one
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 hours ago

        I’m completely open to hearing why the Signal update notification is a concern. I don’t worry about it but you may know something that I am not seeing.

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    13 hours ago

    I have the one installed from the Play Store, and it hasn’t done that. It sounds potentially suspect.

    • OhVenus_Baby@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      13 hours ago

      Does seem odd doesn’t it. How could I verify the app is authentic and no malware or anything has accessed my phone?

      • floofloof@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        12 hours ago

        There are virus scanners for Android - I have Bitdefender on mine - but I don’t know how effective they are. Back in the day they were a bit of a gimmick; I don’t know whether they’re better now.

        I have seen other apps from F-Droid do this. NewPipe, I think, used to prompt me for updates even though I had installed it from F-Droid. But I was always a bit unsure so I tended to just go back to F-Droid to install newer versions. Maybe it’s a thing some apps do but I don’t know why they should need to and I don’t entirely trust it.