Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Muntashir Akon

@muntashir@infosec.exchange
  • Open on infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager@floss.social. My interests are security, privacy, linguistics, medical science and physics.

0 Followers
0 Following
12 Posts
Joined October 12, 2023
Website:
https://muntashir.dev
GitHub:
https://github.com/MuntashirAkon
Blog:
https://blog.muntashir.dev

Posts

Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Jul 26, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
“The tune had been haunting London for the past three weeks. It was one of countless similar songs published for the benefit of the proles by a sub-section of the Music Department, called a versificator. The words of these songs were composed without any human intervention whatever on an instrument.[..] But the woman sang it so tunefully as to turn the dreadful rubbish into an almost pleasant sound.” — George Orwell, 1984
0
0
0
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 15, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @muntashir@infosec.exchange
Google has added an “other ways to verify” option now. So, now it may be possible to bypass the 50% rule.
10
0
0
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 14, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @y20k@chaos.social
@y20k@chaos.social Once F-Droid makes a successful build, you can add the key to your existing package ID and upload the APK built by F-Droid for verification. After that, Play Protect will stop complaining about the app if it's installed from F-Droid.
1
0
0
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 14, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @grote@chaos.social

@grote@chaos.social @y20k@chaos.social This issue can be addressed in several different ways depending how the app was published on F-Droid.

For apps published with the explicit consent from the maintainer: F-Droid can ask the maintainer to include an adi-registration.properties with the maintainer's own unique key if the developer has an account with Android developer verification program. Otherwise, they can ask the maintainer to use F-Droid's own key and let F-Droid claim the package ID instead.

If the developer doesn't care, inactive, or no explicit consent has been given, F-Droid can claim it using an skeleton package (https://github.com/android/security-samples/tree/main/AndroidDeveloperVerificationAPKSigningExample) for verification. But this can be complicated depending on the package ID. If F-Droid uses a different package ID, it should be easy. If not, F-Droid needs to ask Google to explicitly allow them to use the same package ID since Google wants to reduce collision as much as possible.

4
1
2
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 14, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @y20k@chaos.social
@y20k@chaos.social If you see the warning like in the screenshot, it means someone else has claimed the package ID, not F-Droid. For me, it was easy since the domain name that I use (muntashirakon.github.io) has already been verified.
2
0
0
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 14, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @muntashir@infosec.exchange
UPDATE: #Google seems to have fixed the issue anyway. I was able to register both App Manager and Captive Portal Controller in the Android developer verification console.
37
1
5
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 14, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @muntashir@infosec.exchange
Today I've received the following generic-looking response from "Android developer verification support":
17
2
1
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 09, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @y20k@chaos.social

@y20k@chaos.social I think a potential solution is creating a verifiable build by pushing adi-registration.properties file into the version control system. Once it's published on F-Droid, you can add that signature as an additional key in the Android developer verification page.

4
1
0
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 09, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @muntashir@infosec.exchange

Apps subjected to potential impersonation attack:

  • App Manager
  • Captive Portal Controller

Apps with F-Droid priorities:

  • SetEdit
  • UnApkm
  • Metro (since this app is exclusive to F-Droid)
15
3
4
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 09, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @muntashir@infosec.exchange
Also, since I do not have access to the signing keys used by F-Droid, it's effectively a dead-end. Taking down apps from F-Droid (and move to IzzyOnDroid completely) potentially forfeiting all the users who rely on updates from F-Droid.
19
4
4
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 09, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange
Replying to @muntashir@infosec.exchange
Another issue is the 50% download requirements. Traditionally, most people would download the apps from #FDroid which historically used their own signing keys to sign the apps. Since most people have used #FDroid instead of other methods, only that signing key shows up there, and currently, it doesn't offer an option to choose a different key.
21
2
4
0
Open post
muntashir
Muntashir Akon @muntashir@infosec.exchange · Apr 09, 2026
Muntashir Akon
@muntashir@infosec.exchange

Ph.D. student at UC Riverside. Creator of @appmanager. My interests are security, privacy, linguistics, medical science and physics.

infosec.exchange

It appears one or more impersonators have already registered some of the #Android applications that I maintained, including @appmanager@floss.social. I've reported this to #Google, but not sure what's going to happen. The Android developer verification is still in beta, and it doesn't have a lot of features now to deal with this kind of problems.

100
16
67
1

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 07:17:43 UTC