this post was submitted on 23 Feb 2025
31 points (100.0% liked)

Privacy

37039 readers
1 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

My signal app a week ago had 2 seperate, a few days apart, app updates from the app itself. Asking to check install from unknown sources to be checked inside the settings. Giving prompts from the notification drop down. Such as app update available. Click it, asked for setting to be checked, I checked it, it said it updated, all seems well and fine.

But doing this outside of both stores which usually update the app from say F droid or Aurora. I've never seen this happen ever. It wasn't a user confirmation. It was a total app update.

Seems odd that the signal app itself asked to update itself from a notification from the drop down menu. How can I make sure it has not been compromised? Anyone else experienced something of the sort?

Android phone. Pixel. Gos.

all 38 comments
sorted by: hot top controversial new old
[–] JoeKrogan@lemmy.world 7 points 10 months ago* (last edited 10 months ago)

If you trust the initial install then unless there is a warning about the signing key you are good. Only signal devs can sign the builds so if you installed the play store version then updated with their standalone apk or fdroid version then it should just work as the signing key is the same.

Guardian project are just publishing signals apk files as the signature matches.

[–] nutbutter@discuss.tchncs.de 4 points 10 months ago (3 children)

You should consider using Molly, a fork of Signal with Unified Push.

[–] hddsx@lemmy.ca 4 points 10 months ago (1 children)
[–] nutbutter@discuss.tchncs.de -1 points 10 months ago (1 children)

Because, you won't have to guess where to download the app. And you can get a completely FOSS version. And if not using google services, unified Push can help you with notifications.

[–] hddsx@lemmy.ca 1 points 10 months ago

So Android only, and not in the play store?

[–] OhVenus_Baby@lemmy.ml 2 points 10 months ago

I've heard of Molly and read the repo. But I'm unsure how it would be more official and secure than the actual official app.

[–] jlow@beehaw.org 1 points 10 months ago

Love it in theory but when I tried it out a few weeks ago calls weren't working with it. I could still receive calls on desktop but it would never ring on my mobile. So tread carefully.

[–] ZeDoTelhado@lemmy.world 3 points 10 months ago (1 children)

My signal app tries to update itself. Installed from obtanium. It is a very irritating process, the thing tries to update, there is sometimes weird response times from clicking it (you click the notification and simply do not know if something is happening) and then without notice the thing restarts and then usually it works. But sometimes, the update notification still comes back. Because of that, I just update via obtanium

[–] OhVenus_Baby@lemmy.ml 1 points 10 months ago

I had this happen. I clicked the notification many times nothing happened. Then eventually it did. It was odd. I just wanted to make sure everything was still intact.

[–] floofloof@lemmy.ca 2 points 10 months ago* (last edited 10 months ago) (1 children)

I have the one installed from the Play Store, and it hasn't done that. It sounds potentially suspect.

[–] OhVenus_Baby@lemmy.ml 2 points 10 months ago* (last edited 10 months ago) (1 children)

Does seem odd doesn't it. How could I verify the app is authentic and no malware or anything has accessed my phone?

[–] floofloof@lemmy.ca 3 points 10 months ago

There are virus scanners for Android - I have Bitdefender on mine - but I don't know how effective they are. Back in the day they were a bit of a gimmick; I don't know whether they're better now.

I have seen other apps from F-Droid do this. NewPipe, I think, used to prompt me for updates even though I had installed it from F-Droid. But I was always a bit unsure so I tended to just go back to F-Droid to install newer versions. Maybe it's a thing some apps do but I don't know why they should need to and I don't entirely trust it.

[–] kn33@lemmy.world 2 points 10 months ago (1 children)

I have not had this happen. I just have the Play Store one.

[–] OhVenus_Baby@lemmy.ml 4 points 10 months ago

It seems odd. Given recent news about various signal things. I'd rather ask than not.

[–] zdhzm2pgp@lemmy.ml 2 points 10 months ago (1 children)

Not clear on where you installed it from...?

[–] OhVenus_Baby@lemmy.ml 6 points 10 months ago (1 children)
[–] zdhzm2pgp@lemmy.ml 4 points 10 months ago* (last edited 10 months ago)

Signal isn't on F-Droid out of the box, I don't think, but it is in the Guardian repo and probably in a few others as well. I downloaded the Signal apk directly from their website, and that version does auto update and has for quite some time.

EDIT: if you're worried about it, I suppose you could uninstall it and then download it from them directly (be sure to verify the certificate), after which it will prompt you to update it periodically from the app itself.

Even better, you could think about switching to Matrix.

EDIT EDIT: Although basically I'm just passing on dessalines's recommendation to you, I don't really understand Matrix too well, especially the bridges.

[–] novacomets@lemmy.myserv.one 2 points 10 months ago (1 children)

Not native Signal but it happens with Signal forks that I install after adding repository to F-Droid, I have had a notification of a Signal update, even though I'm not using native Signal.

I disable that notification in the phone app settings and wait for an F-Droid notification of an update to install.

[–] OhVenus_Baby@lemmy.ml 2 points 10 months ago (1 children)

So you don't think it's something to be concerned about? I turned off install from unknown sources. App store F-Droid says it's up to date.

[–] novacomets@lemmy.myserv.one 3 points 10 months ago

I'm completely open to hearing why the Signal update notification is a concern. I don't worry about it but you may know something that I am not seeing.

[–] furrowsofar@beehaw.org 1 points 10 months ago (1 children)

My Signal auto updates via Obtainium. That is outside of a store. I think I remember the two updates your talking about.

[–] OhVenus_Baby@lemmy.ml 1 points 10 months ago (2 children)

It was 10 days ago for the last update, then the first one was a few days prior to that. Those two were the only two ever to have that happen.

[–] furrowsofar@beehaw.org 1 points 10 months ago

Yes. I remember seeing the notifications. I then went to Obtainium and updated. What I do not know is if these were signal or obtainium notifications. It did seem odd at the time.

[–] thanksforallthefish@literature.cafe 1 points 10 months ago (1 children)

I had the same at the same time. I ignored the app request and updated from app store

[–] OhVenus_Baby@lemmy.ml 1 points 10 months ago (1 children)

Phew. OK. Thanks. I'd rather post and ask then be ignorant. Still unsettling.

[–] thanksforallthefish@literature.cafe 1 points 10 months ago (1 children)

I had the same "that's weird" reaction too. So not just you, would be good to know if it was kosher or a malware. I might have a dig now

[–] OhVenus_Baby@lemmy.ml 1 points 10 months ago (1 children)

Let me know if you find anything. Follow up. I'll check too.

[–] thanksforallthefish@literature.cafe 2 points 10 months ago (1 children)

Ok. So I found on announcements at https://community.signalusers.org/ that Signal added obtainium to the download options (due to google delays on releasing through play store). I also got another update notification from Signal app this morning, which went away once I upgraded to the latest version. Could be related ?

[–] OhVenus_Baby@lemmy.ml 1 points 10 months ago

I wonder too. It has to be them pushing the update through the app itself. I got another update notif. Last night. I checked both stores and no updates there. This must be it! Just seemed super odd at first.