IzzyOnDroid, to security
@IzzyOnDroid@floss.social avatar

2 days ago I reported about a patch having been applied to the IzzyOnDroid F-Droid repo aka – but I didn't give much details. After it was tested now at the IoD test & staging area, and running smoothly for two days for the public one, I reported back to its author @obfusk that all seems smooth, and she decided to make POC & patch public. You can find the full details at https://github.com/obfusk/fdroid-fakesigner-poc & https://www.openwall.com/lists/oss-security/2024/04/08/8 now. @fdroidorg @eighthave be welcome using it!

1/2

IzzyOnDroid,
@IzzyOnDroid@floss.social avatar

@eighthave @fdroidorg and I am very happy having @obfusk and @SylvieLorxu supporting me and the – I couldn't think of anyone better. And haven't heard of anyone better known in the area of this and also of reproducible builds than Fay, or anyone who can hold a candle to Sylvia. Yes, both mostly worked in the background – but I guess you already got a clue what F-Droid lost having them leave.

SylvieLorxu, to github
@SylvieLorxu@chaos.social avatar

Catima 2.29.0 is out!

This release adds support for finding barcodes in PDF files[1] and dealing with multiple barcodes. It also properly colours the status bar during usage now.

As always, it's available on , will soon be available on and will slowly roll out to other app stores.

https://github.com/CatimaLoyalty/Android/releases/tag/v2.29.0

[1] Not sandboxed yet, help welcome in https://github.com/CatimaLoyalty/Android/issues/1804

IzzyOnDroid,
@IzzyOnDroid@floss.social avatar

@SylvieLorxu Arrived at the just an hour after your toot :awesome: Thank you!

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today brings you 10 updated and 1 added apps:

  • Voyage: a lightweight nostr client with a Reddit-like UI

https://apt.izzysoft.de/magisk hat 1 #magisk #module updated.

Enjoy your #free #Android #apps with the #IzzyOnDroid #IzzySoftRepo :awesome:

IzzyOnDroid, to random
@IzzyOnDroid@floss.social avatar

You've read about F-Droid's recently? Now, the repo makes use of that implementation. How, you ask?

Well: part of the process is to compare APKs and make sure they carry the signature of their authors. That's done by fdroidserver whenever the YAML file of an app has "AllowedAPKSigningKeys:" defined. APKs with not-matching signatures are rejected. That's used by my repo now to make sure updates are "legit" (and not placed to the repo by a malicious actor). (1/4)

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today with 10 updated and 1 added apps:

  • Linklater: unofficial Android client for LinkDing (a self-hosted bookmark manager)

Enjoy your #free #Android #apps with the #IzzyOnDroid #IzzySoftRepo :awesome:

IzzyOnDroid, to security
@IzzyOnDroid@floss.social avatar

🇺🇸 I've told you about additional APK checks having been implemented at the in January. Now finally I found the time to complete the article explaining the details, so you might wish to take a look at "Ramping up security: additional APK checks are in place with the IzzyOnDroid repo":

https://android.izzysoft.de/articles/named/iod-scan-apkchecks?lang=en

Edit: Tags:

IzzyOnDroid, to random
@IzzyOnDroid@floss.social avatar

Today is the first time I had to remove an app from the for potential security risks: author changed the signing key (happens a lot they lose it, unfortunately) – and instead of explaining what happened, simply deleted the issue where I reported it. So I must assume that repo was either compromised – or the author is not interested in security.

It should be safe to use my repo, so I had to remove that app (the "insecure" APK never went live here thanks to security checks).

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

at https://apt.izzysoft.de/fdroid today with 5 updated and 1 added apps:

  • Git Coach: learn to work with Git

Enjoy your with and the :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

at https://apt.izzysoft.de/fdroid today with 14 updated and 1 added apps:

  • Sayboard: on-device voice IME (keyboard) for Android using the Vosk library ("Speech-to-Text")

Enjoy your with and the :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

Yesterday I've promised starting to fill the gaps, so let's go: Today's at https://apt.izzysoft.de/fdroid brings you 9 updated and 3 added apps:

  • OTG Keyboard: use Android as A BT Keyboard
  • Tarifa luz: regulated electricity rate in Spain
  • Units: a powerful unit-aware calculator

Webierta's To-Do Manager switched to a proper release signing key, so you have to uninstall before you can install the new release.

Enjoy your with & the :awesome:

IzzyOnDroid, to random
@IzzyOnDroid@floss.social avatar

I've already told you about the additional APK checks now performed in my repo, and that you can find the first summary of explanations in the repo info (https://apt.izzysoft.de/fdroid/index/info#manifest).

Now the results of those checks on app permissions are being made transparent to you if you expand the permission section for an app. Not seen in the screenshots: on mouseover you now will get a short explanation for each permission.

Screenshot of the permissions section for an APK. Sensitive permissions are shown in bold, those not yet verified are highlighted with "chocolate" color so one knows where special care is needed.

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today brings you 15 updated and 1 added apps:

  • Logger: view and export call logs in CSV format

At https://apt.izzysoft.de/magisk 5 #Magisk #modules were updated.

Enjoy your #free #Android #apps with the #IzzySoftRepo :awesome:

frigoligo, to fdroid
@frigoligo@fosstodon.org avatar

Another day, another way to install #frigoligo. It is now available on #IzzySoftRepo!
https://apt.izzysoft.de/fdroid/index/apk/net.casimirlab.frigoligo

Official #fdroid repo is coming soon (hopefully in a few days).

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today with 9 updated & 2 added apps:

  • nocodb: a prototype client for NocoDB
  • Fossify Notes: To do list widget with a notebook organizer, checklist, simple shopping list (suite now contains 10 apps! :awesome:)

At https://apt.izzysoft.de/magisk 5 #Magisk #modules were updated & 1 #module was added:

  • AlterInstaller: Change PackageManager installer fields on boot

Enjoy your #free #Android #apps with the #IzzySoftRepo :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today with 7 updated and 2 added apps:

  • Overmorrow: a minimalistic weather app
  • Materialious: a modern material design for Invidious

At https://apt.izzysoft.de/magisk 2 #Magisk #modules have been updated.

Enjoy your #free #android #apps with the #IzzyOnDroid #IzzySoftRepo :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today with 11 updated and 3 added apps:

  • Android Owner: Manage your device with Device owner privilege
  • Hot Stuff: an offline app for home inventory
  • Android Virtual Pen: use your Android device to emulate a virtual pen on your PC

Enjoy your #free #Android #apps with the #IzzySoftRepo :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

at https://apt.izzysoft.de/fdroid today with 11 updated and 2 added apps:

  • NextTraceroute: traceroute app using Nexttrace API
  • Raise To Answer: simply hold your phone to your ear to answer an incoming call

Though Raise to Answer is a 1 year old release, it comes from the wonderful @SylvieLorxu who also brought you Catima, so it must be great! And an update is on its way.

Enjoy your with the :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

https://apt.izzysoft.de/fdroid goes Fibonacchi, now providng 1123 apps :awesome: Today's there brings you 6 updated and 1 added apps:

  • Kenko: a simple workout journal by the author of Droid-ify

Enjoy your with the :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

Missed the at https://apt.izzysoft.de/fdroid? There were plenty of updates while I was on vacation. Today it's 1 removed, 12 updated and 2 added apps:

  • removed: GeoCaching4Locus added Ads as 5th AntiFeature so it's gone now
  • Dhizuku: share DeviceOwner permissions to other application
  • CryptoTracker: Track cryptocurrency prices in real-time

Enjoy your with the :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

The #IzzySoftRepo (better known as #IzzyOnDroid – so I'll probably use that hashtag in the future) is used from all over the world, as this graph from GoAccess web statistics shows. Almost no country where it's not in use. I could only spot 3 small gray areas where no requests originated from.

I'm glad being able to help people from all over the world to get their #free and #OpenSource #Android #apps – and hope you enjoy them, too! :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today with 9 updated and 1 added apps:

  • CuteMusic: a simple and lightweight offline music player

At https://apt.izzysoft.de/magisk 1 #Magisk #module was updated and 1 added:

  • Zygisk Assistant: a Zygisk module to hide root

Enjoy your #free #Android #apps with the #IzzySoftRepo :awesome:

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

at https://apt.izzysoft.de/fdroid today brings you 11 updated apps. No added apps, no security patches today 😜 But those having installed the app

"Android Owner"

are advised for special care: it has been rebranded and got a new package name, so please switch over to

OwnDroid

And enjoy your with the :awesome:

IzzyOnDroid, to security
@IzzyOnDroid@floss.social avatar

Another patch has been applied at the to protect against what is described at https://www.openwall.com/lists/oss-security/2024/04/20/3

Though a full scan of the repo hasn't brought up a single affected APK, that doesn't mean any such cannot show up later – so better safe than sorry, right?

IzzyOnDroid, to free
@IzzyOnDroid@floss.social avatar

#AndroidAppRain at https://apt.izzysoft.de/fdroid today with 12 updated and 2 added apps:

  • USBDongleControl: control USB audio dongles
  • reciper: Simple, Open Source Recipe Management App

https://apt.izzysoft.de/magisk had 1 #Magisk #module updated.

Enjoy your #free #Android #apps with the #IzzyOnDroid #IzzySoftRepo :awesome:

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • cubers
  • tacticalgear
  • InstantRegret
  • magazineikmin
  • everett
  • rosin
  • Youngstown
  • slotface
  • ngwrru68w68
  • osvaldo12
  • kavyap
  • mdbf
  • DreamBathrooms
  • JUstTest
  • khanakhh
  • cisconetworking
  • Durango
  • provamag3
  • thenastyranch
  • ethstaker
  • modclub
  • tester
  • normalnudes
  • megavids
  • GTA5RPClips
  • Leos
  • lostlight
  • All magazines