Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

SmartTube has been comprised

⁨43⁩ ⁨likes⁩

Submitted ⁨⁨20⁩ ⁨hours⁩ ago⁩ by ⁨King@blackneon.net⁩ to ⁨technology@lemmy.zip⁩

https://github.com/yuliskov/SmartTube/releases/tag/notification

source

Comments

Sort:hotnewtop
  • apotheotic@beehaw.org ⁨19⁩ ⁨hours⁩ ago

    I’m having a moment - do users need to manually install the app again to receive the new version with the new digital signature associated?

    source
    • King@blackneon.net ⁨19⁩ ⁨hours⁩ ago

      Yes, exactly.

      You need to manually install the new version with the new signature.

      source
      • apotheotic@beehaw.org ⁨19⁩ ⁨hours⁩ ago

        Cheers!

        source
  • BrikoX@lemmy.zip ⁨20⁩ ⁨hours⁩ ago

    The title doesn’t match the facts in the announcement.

    Only signature of the developer was leaked which could have lead to unsafe releases, but the point is moot as the developer is changing the signature key moving forward.

    source
    • breakingcups@lemmy.world ⁨19⁩ ⁨hours⁩ ago

      There’s a lot unclear, but it seems that an actual compromised update was released on official infrastructure (and subsequently removed from some devices by Play Protect). A transparency statement from the developer is still forthcoming. I’m not risking anything, not even updating to the new app, until all the dust has settled.

      source
      • BrikoX@lemmy.zip ⁨19⁩ ⁨hours⁩ ago

        The app id is being changed, so there is no way to push new updates with that signature anymore. Hence the need to re-install the app.

        Also it looks like the developer is adding VirusTotal scan workflow for all new releases moving forward.

        That said, I’m not familiar with the developr or the situation enough to comfortably say it’s safe.

        source
    • King@blackneon.net ⁨20⁩ ⁨hours⁩ ago

      I edited the title to be more specific.

      source