Overview here
The new owner of the repo has a fresh github account and apparently has the signing keys from Catfriend1 too.
Time will tell if they are trustworthy, but for the extra paranoid it might make sense to pause updates for a while.
Overview here
The new owner of the repo has a fresh github account and apparently has the signing keys from Catfriend1 too.
Time will tell if they are trustworthy, but for the extra paranoid it might make sense to pause updates for a while.
64 Comments
arcterus@piefed.blahaj.zone · 98 pts · 271d
This whole situation has been bizarre and really poorly communicated.
spacelord@sh.itjust.works · 94 pts · 270d
I wouldn’t say it’s only for the extra paranoid, but rather for everyone.
After reading the whole discussion, it’s clear that the repo transfer was handled in an extremely unorthodox way, at least by usual standards for repo handovers that I'm familiar/experienced with.
Communication from Catfriend1 was absolutely nonexistent, and there was only minimal info from the person who took over using a GitHub account created just two days ago.
Trust is something that must be earned, not given to someone you’ve never seen or heard of before.
ultranaut@lemmy.world · 59 pts · 271d
Not sure if I qualify as extra paranoid but this whole situation feels very sketchy and has me reconsidering my use of syncthing. Making significant changes like this without any explanation is extremely bad practice.
unexposedhazard@discuss.tchncs.de · 74 pts · 271d
This is about a third party piece of software that isnt directly related to syncthing. The devs of syncthing have however been recommending syncthing-fork as their choice for android, so it definitely needs clearing up.
chaospatterns@lemmy.world · 42 pts · 270d
We're sort of in this situation because the official project decided not to continue providing an official Android app, yet people want to use it on Android forcing unofficial versions to be created and maintained.
I get that they don't want to deal with Google Play anymore, but somebody has to deal with it and them not owning the app is putting users at risk.
hersh@literature.cafe · 23 pts · 270d
Was that the reason? Shame they didn't just leave it on F-Droid and GitHub then. Nobody needs to use Google Play (at least not yet...)
chaospatterns@lemmy.world · 26 pts · 270d
https://forum.syncthing.net/t/discontinuing-syncthing-android/23002
According to this post, it was partly that and lack of maintainers. Given there's maintainers for a fork, I'm curious why they didn't bring them into the main project.
ultranaut@lemmy.world · 3 pts · 270d
Yes, I only use it via syncthing-fork so this is a distinction without a difference to me.
tychosmoose@lemmy.world · 8 pts · 270d
Same here. It was already a little bit concerning that I was relying on a smaller fork to get syncthing on Android. It was on my to do list to figure out options. Now it's at the top of the list, and I'm not doing updates for the time being on Android. That's almost the entirety of my reliance on syncthing - phone to PC sync. I don't really need it that much for sync between PCs.
midribbon_action@lemmy.blahaj.zone · 7 pts · 270d
I said this in another thread, but apparently it's not widely known: syncthing works fine on termux, there is no need to install any third party code. You do need to run
termux-setup-storageto get access to the shared storage that other apps can access, and I found it worth it to set up the termux:boot app to runsyncthingon phone boot. This way only uses the official syncthing repo.ueiqkkwhuwjw@lemmy.world · 4 pts · 270d
Thanks for the tips, was planning on trying this out.
tychosmoose@lemmy.world · 2 pts · 269d
I have heard that. Can it be given run conditions, like only on wifi, and respecting the Android battery saving setting?
My phone has an always on split tunnel VPN to home, so the other sync devices are always accessible. Without the Syncthing-Fork run conditions it chews through mobile data and battery.
midribbon_action@lemmy.blahaj.zone · 2 pts · 269d
You'll have to brew your own run conditions I think. For me, it's not a big deal, just a bunch of documents and pictures and not much gets added every day. But termux does have access to network state, and I'm pretty sure syncthing accepts stop and continue execution signals, so a shell script shouldn't be too difficult. Another possible option is to use termux:tasker.
tychosmoose@lemmy.world · 2 pts · 269d
Cool, thanks. I'll take a look.
CoyoteFacts@piefed.ca · 48 pts · 270d
Absolutely not trusting this. Uninstalling until we know more, and ideally just getting a different solution entirely. A new account tried to impersonate Catfriend1 directly at first, and then they switched to researchxxl when someone called it out (both are new accounts). Meanwhile the original Catfriend1 has provided no information about this, and we only have the new person's word as to what's going on. There's way too many red flags here.
Wispy2891@lemmy.world · 11 pts · 270d
Afaik don't need to uninstall yet, f-droid won't automatically get new builds from this repo until the situation is cleared
0_o7@lemmy.dbzer0.com · 3 pts · 270d
But but my outrage… means I can do stupid things and act smart online.
I'm uninstalling Android and installing iOS right now.
curiousfurbytes@programming.dev · 8 pts · 270d
I've done the same. Not trusting something until it can be trusted. Unfortunately it seems there's no easy alternative apps, so not sure how I'll handle my usage now
kmacmartin@lemmy.ca · 4 pts · 270d
Syncthing desktop in termux and handle triggers like battery + wifi via tasker?
curiousfurbytes@programming.dev · 1 pts · 269d
Well, it's not easy, but I like the idea, hadn't thought of that... I don't really use the triggers, only when files change, so that'll do it!
pulsewidth@lemmy.world · 35 pts · 270d
Update from Simon aka imsodin, Syncthing Maintainer
https://forum.syncthing.net/t/does-anyone-know-why-syncthing-fork-is-no-longer-available-on-github/25661/58
Wispy2891@lemmy.world · 34 pts · 270d
Maybe it's actually true that catfriend1 knows the new owner in real life but... this is not a calculator app, this is something that has complete access to the phone storage... handing the keys without any communication is concerning...
And the issues are locked so if something nefarious happens, discussion will only occur somewhere else instead of the repo
WhyJiffie@sh.itjust.works · 11 pts · 269d
people shouldn't count on that anyways because the repo owner can delete issues, comments, also edit them
Pika@sh.itjust.works · 25 pts · 270d
this entire thing has made me really rethink whether I want to swap to the new repo or not.
Why was there no communication about it. The gplay repo maintainer wasn't informed of anything, no public notice to anyone was given, just a transfer of the repo and a status issue here explaining it.
Obviously the act is genuine as they were able to keep the original keys but like, this entire system seemed really sketchy.
I'm also not happy with the fact that it seems the first thing they added was removing checksums, but that might be a temp thing.
I also just noticed that it looks like they removed the entire public key for it, which if they had the original private keys using the existing public keys shouldn't be an issue right?
tgxn@lemmy.tgxn.net · 15 pts · 270d
It's likely because the app will no longer be distributed on Google. They likely removed the Google play signing keys and configuration, which is completely fine. I'll have a look over their changes when I get home, but I doubt it's anything nefarious.
I also ditched this stuff when Google decided to start asking for my drivers license and will no longer distribute my apps within their closed marketplace.
Wispy2891@lemmy.world · 11 pts · 270d
I wish it was only the drivers license, I had to give up my Android dev account too because having my private home address + phone number + email publicly available on the dev profile page is completely unacceptable
tgxn@lemmy.tgxn.net · 1 pts · 270d
Yeah exactly, where does it end? next they will be asking for more. I'll just distribute APKs elsewhere.
ook@discuss.tchncs.de · 20 pts · 270d
hayalci@fstab.sh · 4 pts · 270d
Two people communicating one-to-one and starting a new account to solely dedicate to maintaining a pretty public open source project doesn't sound too fishy, tbh, if everything else checks out. (Catfriend1 confirms the handover, etc.)
ook@discuss.tchncs.de · 1 pts · 270d
AmbiguousProps@lemmy.today · 16 pts · 270d
The new repo has two releases in it now. These releases are not signed with the original key as far as I can tell. Further, GitHub is silently redirecting to the new repo, even in Obtainium, meaning it's possible that if you had this previously installed via Obtainium and updated now, you may have unsigned apks installed that may or may not contain the changes in the repo.
This is a mess. I deleted the repo from Obtainium (luckily I don't auto install updates) and will wait to see what happens over the next few months. Might just save my notes in a network share instead of using syncthing from my phone. Idk, notes are all that I was using it for.
pulsewidth@lemmy.world · 10 pts · 270d
Sounds like a really good reason not to use Obtainium, if any repo you have tracked for updates can just redirect you to a completely different repo If they have the keys - and throw no complaints when updating to an entirely different apk.
With F-Droid they at least have to have the same signing keys, and the code is built by F-droid from source - meaning the code for the supplied APK always matches the code on the repository for the build. Whereas Obtainium will just offer you any APK the dev releases on their GitHub/Gitlab/etc, this places much higher trust on the dev.
Edit:
my bad, I wrote earlier that all F-droid builds are reproducable. But that's not accurate F-droid does not enforce that all builds must be reproducible. They have been helping devs with the tools and assistance to do so since 2015, and all the apps that I use I'd checked in the past and are all using reproducable builds, so I wrongly presumed it was mandatory now. Eg, Syncthing-Fork from Catfriend has had all builds reproducible since v2: https://verification.f-droid.org/packages/com.github.catfriend1.syncthingfork/
WhyJiffie@sh.itjust.works · 2 pts · 269d
that's not a requirement. or was it already being built reproducibly?
pulsewidth@lemmy.world · 3 pts · 269d
Every Catfriend build since v2 has been reproducable. Most apps on F-Droid are and they are encouraging it for all devs, to build trust.
https://verification.f-droid.org/packages/com.github.catfriend1.syncthingfork/
BackgrndNoize@lemmy.world · 15 pts · 270d
My policy with open source projects like these is to fork the repo and only bring in upstream updates when I'm certain it's safe and necessary
Serinus@lemmy.world · 16 pts · 270d
Which is just as risky as instantly updating unless you're really closely keeping an eye on which updates are security related.
kokomo@lemmy.kokomo.cloud · 3 pts · 270d
that's probably what I might do and build apks myself with forgejo. and/or pull in nel0x's fork instead and build from his code.
Takios@discuss.tchncs.de · 14 pts · 270d
Thank you for the notice. This is a really bad look on the project. Thankfully I still have a version from before the takeover installed and disabled auto-updates just in case. Though I suspect f-droid will not accept builds by this person until trust has been established.
Lemmchen@feddit.org · 12 pts · 270d
What's the last "safe" version on F-Droid? 2.0.11.2?
ueiqkkwhuwjw@lemmy.world · 7 pts · 270d
That's the last version that was released before the transfer AFAIK. Someone in the linked thread also said they didn't see anything suspicious between 2.0.11.1 and 2.0.11.2.
https://forum.syncthing.net/t/does-anyone-know-why-syncthing-fork-is-no-longer-available-on-github/25661/17
Serinus@lemmy.world · 10 pts · 271d
Thank you!
hummingbird@lemmy.world · 8 pts · 270d
Yup thanks for the heads-up!
ueiqkkwhuwjw@lemmy.world · 6 pts · 270d
No prob :)
smeg@infosec.pub · 10 pts · 270d
What's wrong with original Syncthing? Why would anyone use a fork?
nekusoul@lemmy.nekusoul.de · 39 pts · 270d
First up, this fork is specifically about the Android client, not any other ones.
The fork of that always had some nice mobile battery saving features added, but morr importantly, the original version has been discontinued.
Kirk@startrek.website · 15 pts · 270d
https://forum.syncthing.net/t/discontinuing-syncthing-android/
Zwuzelmaus@feddit.org · 9 pts · 270d
I had intended to try it out, but now uninstalled for... just in case.
Some kind guru please watch the source for unwanted effects.
GreatBlueHeron@lemmy.ca · 8 pts · 270d
I installed mine from F-Droid. I just went there to turn off updates and it doesn't exist. I have not been paying attention so it may have been gone for ages and not related?
Sir_Kevin@lemmy.dbzer0.com · 6 pts · 270d
I'm still seeing it here?
https://f-droid.org/packages/com.github.catfriend1.syncthingfork
GreatBlueHeron@lemmy.ca · 6 pts · 270d
Interesting - mine is syncthing-fork 1.30.0.4. When I go to the App Info page it says "App installed from F-Droid" and when I tap on that button I get a small pop-up that says "No such app found."
zeca@lemmy.ml · 6 pts · 270d
The 2.0 update was made into a new package in fdroid, so that you paid close attention to the upgrade, as it could maybe break things.
Lfrith@lemmy.ca · 4 pts · 270d
xylene@sh.itjust.works · 3 pts · 270d
Same exact scenario here. Hmm
Kernal64@sh.itjust.works · 1 pts · 270d
Add me to the list with this exact issue.
ook@discuss.tchncs.de · 3 pts · 270d
Wispy2891@lemmy.world · 3 pts · 270d
I think everyone misses the upgrade except new installs, how users (including power users) can know that they have to uninstall the old app, potentially lose all the settings , then reinstall and reconfigure?
Lfrith@lemmy.ca · 4 pts · 270d
wax@feddit.nu · 1 pts · 270d
Perhaps you had the pre-fork android app?
anzo@programming.dev · 4 pts · 270d
For some reason, my version of syncthing-fork is old and source is not even on f-droid anymore. Was there any other before catfriend1? Perhaps I downloaded APK from GitHub... Can't recall.
ueiqkkwhuwjw@lemmy.world · 1 pts · 270d
Could be the same issue as here https://lemmy.ca/comment/20114092
anzo@programming.dev · 1 pts · 270d
Thanks. Sure it is. But I will call this a feature now ;)
captain_aggravated@sh.itjust.works · 3 pts · 270d
dammit I like Syncthing. does kdeconnect do a decent job at syncing files?
Wispy2891@lemmy.world · 6 pts · 270d
No.
In my case I was using syncthing to backup /storage on my phone and turns out there are faster ways to do that
My alternative:
ripcord@lemmy.world · 1 pts · 269d
Personally on Android for photos I use photosync as well as Immich
alphacyberranger@sh.itjust.works · 2 pts · 270d
I don't think so. Can KDE connect even sync files?
fin@sh.itjust.works · 2 pts · 270d
It can send files, but that's all. Also, kdeconnect doesn't work over the Internet
captain_aggravated@sh.itjust.works · 2 pts · 270d
I don't know, I played with it years ago, didn't need it and haven't really touched it until now.
I use Syncthing for several things, especially syncing photos between my phone and desktop.
ueiqkkwhuwjw@lemmy.world · 2 pts · 270d
Syncthing in Termux apparently works to some extent. Another option might be Nextcloud? Will def try out some alternatives just in case.
runiq@feddit.org · 3 pts · 270d