• Wispy2891@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    13 minutes ago

    Maybe it’s actually true that catfriend1 knows the new owner in real life but… this is not a calculator app, this is something that has complete access to the phone storage… handing the keys without any communication is concerning…

    And the issues are locked so if something nefarious happens, discussion will only occur somewhere else instead of the repo

  • Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    9
    ·
    edit-2
    3 hours ago

    this entire thing has made me really rethink whether I want to swap to the new repo or not.

    Why was there no communication about it. The gplay repo maintainer wasn’t informed of anything, no public notice to anyone was given, just a transfer of the repo and a status issue here explaining it.

    Obviously the act is genuine as they were able to keep the original keys but like, this entire system seemed really sketchy.

    I’m also not happy with the fact that it seems the first thing they added was removing checksums, but that might be a temp thing.

    I also just noticed that it looks like they removed the entire public key for it, which if they had the original private keys using the existing public keys shouldn’t be an issue right?

  • Zwuzelmaus@feddit.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    3 hours ago

    I had intended to try it out, but now uninstalled for… just in case.

    Some kind guru please watch the source for unwanted effects.

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 minutes ago

      No.

      In my case I was using syncthing to backup /storage on my phone and turns out there are faster ways to do that

      My alternative:

      1. Ente for photos
      2. Borg via termux for the full /storage backup (including the photos)
  • spacelord@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    47
    ·
    10 hours ago

    I wouldn’t say it’s only for the extra paranoid, but rather for everyone.

    After reading the whole discussion, it’s clear that the repo transfer was handled in an extremely unorthodox way, at least by usual standards for repo handovers that I’m familiar/experienced with.

    Communication from Catfriend1 was absolutely nonexistent, and there was only minimal info from the person who took over using a GitHub account created just two days ago.

    Trust is something that must be earned, not given to someone you’ve never seen or heard of before.

  • smeg@infosec.pub
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    7 hours ago

    What’s wrong with original Syncthing? Why would anyone use a fork?

  • ultranaut@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    arrow-down
    1
    ·
    12 hours ago

    Not sure if I qualify as extra paranoid but this whole situation feels very sketchy and has me reconsidering my use of syncthing. Making significant changes like this without any explanation is extremely bad practice.

    • unexposedhazard@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      43
      ·
      edit-2
      12 hours ago

      has me reconsidering my use of syncthing

      This is about a third party piece of software that isnt directly related to syncthing. The devs of syncthing have however been recommending syncthing-fork as their choice for android, so it definitely needs clearing up.

      • ultranaut@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 hours ago

        Yes, I only use it via syncthing-fork so this is a distinction without a difference to me.

      • chaospatterns@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        ·
        8 hours ago

        We’re sort of in this situation because the official project decided not to continue providing an official Android app, yet people want to use it on Android forcing unofficial versions to be created and maintained.

        I get that they don’t want to deal with Google Play anymore, but somebody has to deal with it and them not owning the app is putting users at risk.

    • tychosmoose@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      8 hours ago

      Same here. It was already a little bit concerning that I was relying on a smaller fork to get syncthing on Android. It was on my to do list to figure out options. Now it’s at the top of the list, and I’m not doing updates for the time being on Android. That’s almost the entirety of my reliance on syncthing - phone to PC sync. I don’t really need it that much for sync between PCs.

  • Great Blue Heron@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    ·
    9 hours ago

    I installed mine from F-Droid. I just went there to turn off updates and it doesn’t exist. I have not been paying attention so it may have been gone for ages and not related?

  • BackgrndNoize@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    12 hours ago

    My policy with open source projects like these is to fork the repo and only bring in upstream updates when I’m certain it’s safe and necessary

    • Serinus@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      9 hours ago

      Which is just as risky as instantly updating unless you’re really closely keeping an eye on which updates are security related.