217

Can I get more info on why these are showing up? I've never seen such a thing on F-Droid before.

top 50 comments
sorted by: hot top controversial new old
[-] Kajika@lemmy.ml 34 points 6 days ago* (last edited 5 days ago)

The current version has a critical security vulnerability (https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/) but to fix it the new version compiled against libclang version 27 but Google decided to remove it from Android so the building pipeline needs to be adjusted.

There's a long discussion: https://gitlab.com/relan/fennecbuild/-/merge_requests/63 , about building the newer version

In the meanwhile the app is a security hazard.

[-] N4CHEM@lemmy.ml 47 points 6 days ago* (last edited 6 days ago)

There was a critical vulnerability found on Firefox some days ago: CVE-2024-9680. Fennec and Mull are forks of Firefox. They both fixed this issue already in their source code, BUT there is a problem preventing F-Droid from building these updated, fixed versions.

In the case of Mull, you can download the updated version from the DivestOS F-Droid repository: https://divestos.org/fdroid/official/, but if you are currently using the F-Droid version you will need to uninstall it first, since they have different signatures.

[-] mac@lemm.ee 24 points 6 days ago* (last edited 6 days ago)

There should really be push notifications around installed apps with known vulns... Its tracked here: https://forum.f-droid.org/t/vulnerability-warnings-in-f-droid-app/20505

Could someone with a gitlab account open a feature request on the f droid repo?

I tried to open an account but it required email + cell phone (it picked up my VoIP number) and a credit card....

EDIT: I generated an RSS feed based off of Mozilla's known vuln list. If anyone knows of a better way to do this, please let me know!

[-] DishonestBirb@lemmy.world 9 points 6 days ago* (last edited 6 days ago)

Uninstalling my primary browser isn't really a practical solution, what am I supposed to use, Chrome? How about fixing the version they're shipping? Or should I be looking somewhere other than F-Droid for Android Firefox?

[-] cyberwolfie@lemmy.ml 13 points 6 days ago* (last edited 6 days ago)

I changed to the Divest-repo for Mull, and they have an updated version that has fixed these security issues.

ETA: Different signing keys though, so you can't just update it, but have to reinstall.

[-] Moah@lemmy.blahaj.zone 2 points 6 days ago
[-] cyberwolfie@lemmy.ml 4 points 6 days ago

You add https://divestos.org/apks/official/fdroid/repo/ as a repo in F-Droid settings. After that you can choose which repo to prefer for Mull.

[-] Moah@lemmy.blahaj.zone 2 points 6 days ago
[-] kazaika@lemmy.world 9 points 6 days ago

Theyre the distributor, the dont fix apps and its not their job to do so. Getting the same app from a different source wont change anything

[-] Swedneck@discuss.tchncs.de 4 points 6 days ago

huh? no one's asking them to fix firefox, we're asking that they just ship the latest version.

the warning states that several vulnerabilities have been fixed since firefox version 130, f-droid's latest version of the package is 129: that very much makes it sound like the problem is wholly caused by f-droid not making version 130 available.

[-] AlpacaChariot@lemmy.world 5 points 6 days ago

To ship it they have to work out how to build that version themselves from source though - that's their whole thing. It's not like a normal app store where they take pre-built binaries from the developer.

[-] kazaika@lemmy.world 2 points 6 days ago

Well ok if thats the case you are completely right, as long as there isnt some kind of issue and others have already updated the package pushing security fixes asap is indeod important

[-] abbenm@lemmy.ml 0 points 5 days ago

huh? no one’s asking them to fix firefox, we’re asking that they just ship the latest version.

Huh to your huh? What's significant about the latest version, other than that it includes requested fixes? This is 12 of one, a dozen of the other.

[-] ace_garp@lemmy.world 3 points 6 days ago

Iceraven is a Mozilla based standin.

Can install FFUpdater here:

https://f-droid.org/packages/de.marmaro.krt.ffupdater/

and then select it from there.

[-] abbenm@lemmy.ml 1 points 5 days ago

Or should I be looking somewhere other than F-Droid for Android Firefox?

FFUpdater, on F-Droid, manages updates for Firefox and other browsers. I counted nine variations of Firefox or forks of Firefox. As well as eight variations of Chromium based browsers that aren't Chrome. So that's 17 options.

[-] victorz@lemmy.world 2 points 6 days ago

I just install Firefox from the Play Store. 🤷‍♂️ Is that bad?

[-] x00z@lemmy.world 8 points 6 days ago
[-] victorz@lemmy.world 5 points 6 days ago
[-] x00z@lemmy.world 1 points 6 days ago
[-] victorz@lemmy.world 3 points 6 days ago

But Firefox good..? Serious replies only please, I really am curious.

[-] abbenm@lemmy.ml 1 points 5 days ago

But Firefox good…?

Yes! They are the most important alternative to major corporate backed browsers, helping sustain a diversified browser ecosystem so that no one company can monopolize the web, and push it toward standards that reinforce their monopoly. Google has tried to lock down the phone, app market, browsing experience that sustains their ad networks, and regularly pushes new standards that de-emphasize things like RSS, and that break ad blocking functionality to sustain their monopoly and invade privacy.

Firefox reverses or mitigates most of those and are explicitly driven by a mission of sustaining an open web with standards that don't bend the web to corporate dominance. Google's cheeky dont be evil mantra was in reference to exactly the things they are doing now, and it's a little too on the nose to their actual behavior so it's no longer a slogan of theirs, cheeky or otherwise.

[-] usernameusername@lemm.ee 1 points 6 days ago* (last edited 6 days ago)

I think it's just that normal Firefox has more propietary stuff and more tracking by default

[-] victorz@lemmy.world 0 points 6 days ago

Ah okay, so in a way it's more about Firefox than about Google. 👍

[-] orcrist@lemm.ee 10 points 6 days ago

What would people recommend in the short run as an alternative?

[-] N4CHEM@lemmy.ml 18 points 6 days ago

You can download an updated version of Mull with the security issue fixed, from the DivestOS F-Droid repository: https://divestos.org/fdroid/official/. If you currently have the F-Droid version of Mull installed you will need to uninstall it first.

[-] 3dogsinatrenchcoat@slrpnk.net 9 points 6 days ago

You can get the updated mull from the divestos repo, the issue is fixed there

[-] FutileRecipe@lemmy.world 66 points 1 week ago* (last edited 1 week ago)

Fennec and Mull 129.0.2 in F-Droid.org repository have 42 known security issues

Ref: https://forum.f-droid.org/t/fennec-vulnerability-recommended-to-uninstall/

load more comments (4 replies)
[-] Quintus@lemmy.ml 21 points 1 week ago

Are these two from the same maintainer? If not, considering that they both use Firefox Android as their base, does this mean there is a vulnerability in Firefox Android?

[-] Piwix@lemm.ee 36 points 1 week ago

There was and it was fixed by the looks of it. Guessing these apps have not urgently pulled the fixes in and released an update, so F-droid is urging people not to use the apps until so

[-] WhyJiffie@sh.itjust.works 11 points 6 days ago

they pulled the fixes, but couldn't build because google fucked up the NDK. my other comment has more details

load more comments (4 replies)
load more comments
view more: next ›
this post was submitted on 25 Oct 2024
217 points (99.5% liked)

F-Droid

8078 readers
2 users here now

F-Droid is an installable catalogue of FOSS (Free and Open Source Software) applications for the Android platform. The client makes it easy to browse, install, and keep track of updates on your device.

Website | GitLab | Mastodon

Matrix space | forum | IRC

founded 3 years ago
MODERATORS