Security

NetCipher update: global, SOCKS, and TLSv1.2

June 25, 2019

NetCipher has been relatively quiet in recent years, because it kept on working, doing it was doing. Now, we have had some recent discoveries about …

PanicKit 1.0: built-in panic button and full app wipes

June 4, 2019

Panic Kit is 1.0! After over three years of use, it is time to call this stable and ready for widespread use. Built-in panic button This round of work …

Use Onions/HTTPS for software updates

January 23, 2019

There is a new vulnerability in Debian’s apt that allows anything that can Man-in-the-Middle (MITM) your traffic to get root on your Debian/Ubuntu/etc …

IOCipher is the antidote to “Man-in-the-Disk” attack

August 17, 2018

Recently, at DEFCON 2018, researchers at Check Point announced a new kind of attack made possible by the way many Android apps are implemented. In …

Building a Signing Server

December 18, 2017

The Android APK signing model sets the expectation that the signing key will be the same for the entire lifetime of the app. That can be seen in the …

No more “Root” features in Orbot… use Orfox & VPN instead!

October 27, 2017

Since I first announced the available of Orbot: Tor for Android about 8 years ago (wow!), myself and others have been working on various methods in …

Announcing new libraries: F-Droid Update Channels

May 31, 2017

In many places in the world, it is very common to find Android apps via a multitude of sources: third party app stores, Bluetooth transfers, swapping …

New research report on the challenges developers face

May 15, 2017

The Guardian Project has been working with the F-Droid community to make it a secure, streamlined, and verifiable app distribution channel for …

Build Android apps with Debian: apt install android-sdk

March 13, 2017

In Debian stretch, the upcoming new release, it is now possible to build Android apps using only packages from Debian. This will provide all of the …

Build Your Own App Store: Android Media Distribution for Everyone

February 22, 2017

Most people get their Android apps from Google Play. It is usually the simplest and most secure option for them. But there are also many people who do …