Google is now marking EVERY SINGLE APK at our repository as "Malware site issue". Congrats, "Safe" browsing.

Of course there is not a single malware there, everything is scanned multiple times. And I bet they excluded *.google.com from their scan or the entire PlayStore would be red by now, too…

Calling out to all of you: Please use safebrowsing.google.com/safebr… to report the links as "safe"!

apt.izzysoft.de/fdroid/repo/co… is the one console reports.

:boost_love:

#serviceToot #izzyOnDroid #fediPower

This entry was edited (2 days ago)

Sylvia reshared this.

in reply to murks

@murks The .apk they tell us is "malware" (it isn't, we scanned it repeatedly) is apt.izzysoft.de/fdroid/repo/co…. But right now every single .apk link under apt.izzysoft.de/fdroid/repo/ is blocked, almost 1300 safe, scanned, open source apps :(
in reply to murks

@murks The console points to apt.izzysoft.de/fdroid/repo/co… – which at our last check (see floss.social/@IzzyOnDroid/1159…) was reported clean even by their own scanner.

And this time they not only MARK it as POTENTIALLY malicious – they block the entire site. So if you have a browser with "SafeBrowsing" enabled, you cannot download a single APK.


Yupp, trust Google. The one running googleapis.com, where you can find your daily scam. They marked us once more for an APK their own scanner marks clean. See gitlab.com/-/snippets/4909577 for more details.

And always keep in mind: that's the actor that wants to define which apps are safe for you to install on your Android devices, and disable you from installing the others. Because, security, you know?

And here's the VT for the app you got red for: virustotal.com/gui/file/966dd1… – all green


in reply to leandro

@leandro The .apk they tell us is "malware" (it isn't, we scanned it repeatedly) is apt.izzysoft.de/fdroid/repo/co…. But right now every single .apk link under apt.izzysoft.de/fdroid/repo/ is blocked, almost 1300 safe, scanned, open source apps :(
in reply to Thomas

@thomas Thanks for checking!

It also doesn't make it better that they do not tell us WHICH files are affected and WHY. Their console just gives a single example (the linked APK), and says "go figure yourself".

And isn't it funny that the APK triggering this insane BS is an APK downloader? What was that with "allowing alternative app stores" (even Droid-ify is blocked now)? And the crap with "developer registration"? One ring to rule them all?!?

in reply to IzzyOnDroid ✅

@thomas Dunno if it is related, but it seems that besides Google, Ikarus is misdecting StreetMeasure APK from izzy as being infected by "Trojan-SMS.AndroidOS.FakeInst"

e.g. I've downloaded de.westnordost.streetmeasure_7.apk from izzy, and it is exactly the same file as one downloaded ages ago from Google Play (with sha256sum 9711592efeab66fc47454a628abcb88d25356d24a80de34882b2ff4cd1f921af)

and virustotal says this: virustotal.com/gui/file/971159…

in reply to Matija Nalis

@mnalis that "combination" is not uncommon, but hadn't caused any issues in the past. What I dislike there, is that especially Google never gives a reason: "detected" – what? "malicious" – why? How shall you fix "blind allegations"? And as for Ikarus: SMS Trojan, huh? Very funny. The only permission the app requests is to access the CAMERA. No SMS, no Internet, nothing. Snakeoil. @thomas
in reply to IzzyOnDroid ✅

@thomas Yeah, I fully agree that google is also driven by capitalism towards more and more #enshitification 😢 . And ability to reach a human there was getting very hard even decades before #AI, nowadays it is nigh impossible and incredibly frustrating.

I hope those "it is safe" reports would make it more likely for a problem to be fixed; but I worry it depends more on luck than that 😭

in reply to Bill

@Sempf even their own ones, I guess – like "back then"? support.google.com/webmasters/…

Yeah, nice description: "spam service". Pun intended? Most spam (or should I say: scam?) I see here nowadays is hosted at storage.googleapis.com. But yeah, tell us whom to trust…

Would be interesting to know who else is affected. Only us with the APKs – or e.g. ApkPure (which copies the APKs from PlayStore) as well? 🤔

@Bill
in reply to Nordafrica

@sousse Thanks! Let's hope we're shaking something loose there – and that it's just a quirk at their end, which they quickly fix, removing those unwarranted blocks and red pages.

I doubt they'll ever apologize for the mess they caused there. Wish they'd surprise me positively once. Like, "as reparation, we've filled your OpenCollective with a (6+ digit) sum" (that would even come out of their "petty cash")… Well, one can dream, right? *Sigh…*

in reply to LΞX/NØVΛ 🇪🇺

@lexinova Help with the latter appreciated! We're currently not sure if it's explicitly us (and other "app stores") being affected, or a general failure" of Google's systems (as we also got reports of "all incoming mails are being marked spam" and such).

If you know someone who would help us with such "legal stuff" (pro bono, as we could not cover much cost), please recommend.

We can also talk this when we meet at the weekend in Brussels (looking forward to meeting you!).

in reply to LΞX/NØVΛ 🇪🇺

@lexinova Thanks! @noybeu was also the first coming to my mind. We'd be really thankful if they'd take this up. I'm pretty sure we're not the only ones affected this way. As you've put them in copy already, let me link my snippet for reference again: gitlab.com/-/snippets/4909577 (document "02" there is about the multiple issues we had with them already, just within a single month). I'll try to keep that updated.

I'd say blocking ALL our Android app pages, can count as DMA violation, no?

in reply to Germán

This is Google "Safe browsing". Even Firefox has it enabled by default. So yes, this is Google.

As I understand it your browser downloads a list of banned sites from Google every now and then. So not actively scanning what you browse (though they can do that for most sites with all the trackers they have), but I have to be honest I don't know all the details on "Google Safe Browsing". Documentation is scarce.

This entry was edited (2 days ago)
in reply to Germán

@germanfr It's a "feature" called "Google Safebrowsing". In intervals, it downloads allegedly malicious URLs to your browser, which then compares each visited URL against those.

Google isn't hosting our repo – we do that (currently at Hetzner in Germany). But yes: this way, Google has the power to decide which pages you're allowed to see – and which… not. In this current case, one could count that as anti-competitive, and a violation of DMA.

in reply to Lanthanus

@Lanthanus No idea here, either. But our OpenCollective and our Liberapay are open to receive: opencollective.com/izzyondroid & liberapay.com/IzzyOnDroid @kneoghau
in reply to SlightlyCyberpunk

@admin I've updated my snipped with information collected from this thread, on how to disable Google Safebrowsing on Android browsers:

gitlab.com/-/snippets/4909577#…

So far, we have hints on Firefox and Brave. If you know it for other browsers, please let me know and I'll add it.

Note that, while I'm very much tempted to, this is no "recommendation to disable it". For our site it is safe (to our knowledge), but there are real dangers out there (like, googleapis.com 🙊). So be careful, please!

in reply to IzzyOnDroid ✅

Ah, so to follow the instructions on the error message you have to know how to bypass their attempts to block mobile users from using about:config. Lovely.

I filed a bug report with Mozilla too. As far as I'm concerned this is a serious UI defect, especially considering that the desktop version offers significantly more detail and also a bypass link. So sick of mobile users getting screwed over by Mozilla...

in reply to IzzyOnDroid ✅

Done! With a scathing message for ~them~ the AI bot to enjoy.

I can't WAIT to turn my back on #Android, literally my last and only tie to #Google.

We can only hope that this attack on 3rd party app stores, and #FOSS in general, leads to accelerated development of #mobilelinux and motivate devs to start porting their apps to it.

It's HIGH TIME to end this duopoly of iOS and Android as our only choices for our mobile phones and tablets.

@postmarketOS @ubports #mobian @jolla

in reply to IzzyOnDroid ✅

We've requested another review yesterday evening. But despite of that system being fully automated, and quite obviously no single human involved, there's still no response – 15+ hours later.

They still flag us for files which no longer exist even.

Are they incapable of running their own services properly? But then, powerful enough to decide how others have to run theirs? This is ridiculous.

Hard not to assume bad intention there.

#Google #DSA

Sylvia reshared this.