Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security consern: why does the binary only available on separate resource? #5

Closed
netkgk opened this issue Jul 5, 2016 · 1 comment

Comments

@netkgk
Copy link

netkgk commented Jul 5, 2016

Does the author alter the binary with a malware or there is another good reason why it is not published via github and\or f-droid? I've read news about removal from playstore, but there is a plenty of other apps left based on the same idea (fake VPN connection), so it raises concerns if there was another good reason for the removal, except that was because of the fact it was an adblock.

@ggsava
Copy link
Owner

ggsava commented Jul 6, 2016

The binary is not available only for one reason - signature. I'm thinking about ways to put it on F-droid, the problem is the existing 50-100 users thousand will run into errors when updating the app (wrong signature). F droid uses their own signature to sign the binary, so if I switch to F droid I will have to exclusively distribute from their site and change the whole update process ( currently there are auto update notifications sent to users with a download button ) . Also every single user who has the app right now will have to reinstall it. It's a very hard thing to achieve now and yes it is a problem.

The code base is exactly the same though and if you don't want to take my word for granted, you can decompile the app using any java decompiling tool and look at it yourself. I'm not using any obfuscation for the code so it should be easy enough to read through and verify the APK you download from block-this.com.

@ggsava ggsava closed this as completed Jul 18, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants