this post was submitted on 12 Dec 2025
56 points (98.3% liked)

Open Source

42767 readers
157 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 6 years ago
MODERATORS
 

Hello,

I downloaded SchildiChat to access matrix as their UI is more conveniant than Element. Exodus and TC slim however found "Google Admob" within the app.

As you can see on the screenshot. I asked developers about it, and they told me there's no trackers on the app.

Who's right, who's wrong ?

Thanks

all 22 comments
sorted by: hot top controversial new old
[–] deadcade@lemmy.deadca.de 72 points 1 week ago (2 children)

The version from their F-Droid repo, SchildiChat[f], has no Google libraries. The version from the playstore includes proprietary blobs to support Firebase Cloud Messaging (Google notifications system). Exodus may be misidentifying this as "Google Admob", which is not present in the app.

[–] Ghoelian@piefed.social 9 points 1 week ago (1 children)

The f-droid version also supports FCM, which I was a bit surprised by.

[–] harfang@slrpnk.net 1 points 1 week ago (1 children)
[–] Ghoelian@piefed.social 3 points 1 week ago

Firebase cloud messaging

[–] harfang@slrpnk.net 3 points 1 week ago

I got it from F-Droid that's why. so confusing

[–] Rikj000@discuss.tchncs.de 21 points 1 week ago (1 children)

You can install ClassyShark3xodus,
which can de-compile apps and scan them for trackers on the fly to figure it out yourself.

Do let us know the results :)

[–] redti@lemmy.zip 2 points 1 week ago

Exodus brings up false positives

[–] redti@lemmy.zip 8 points 1 week ago

I can confirm that schildichat from f-droid contains 2 Google trackers after analysis :

603 tested signatures on 67125 classes (40361329)

Google AdMob Sentry

*Google AdMob 9com.google.ads.

*Sentry 698io.sentry.

file:///data/app/~~Opb2slJC07NYLm9e2C2ikw%3D%3D/de.spiritcroc.riotx-uWSIGBd1PzyWdDEl86q5NA%3D%3D/base.apk

MD5sum: 55da2edbc904165755632ae132f30ed5 SHA1sum: ed27b82c54dd62315c6a46935af66e4666549a3d SHA256sum: de365d9e2d8e3fa08b1501a0079a95cd0b37fee6186dbd9eba2a4c22d7268473

CN=FDroid,OU=FDroid,O=fdroid.org,L=ORG,ST=ORG,C=UK

SHA256withRSA

CERTIFICATE fingerprints: md5: c78350850dd5f3421f36d7cfbe0927bc sha1: 63ec0e3261dc3be0469bc68955bf58c0684ba52d sha256: 5d473a5169ef71aedcbca1da511210bab4aaff278c5ef785760df882954b1a99

[–] redti@lemmy.zip 6 points 1 week ago (1 children)

Its a bit confusing because F-Droid ship the schildichat version with Google trackers without saying it. One have to add the schildi repo to F-droid and download the FOSS version: https://s2.spiritcroc.de/fdroid/repo/?fingerprint=6612ade7e93174a589cf5ba26ed3ab28231a789640546c8f30375ef045bc9242

[–] harfang@slrpnk.net 1 points 1 week ago

How is that possible that I depend from the source ?

[–] redti@lemmy.zip 4 points 1 week ago* (last edited 1 week ago) (1 children)

https://gitlab.com/fdroid/fdroiddata/-/issues/3717

Opened an issue about it

Closed this issue, false positives from exodus.

[–] harfang@slrpnk.net 1 points 1 week ago

Thank you very much. 🙏🏼

[–] redti@lemmy.zip 3 points 1 week ago* (last edited 1 week ago) (1 children)

Well according to the Dev this might be false positives. Adding to the confusion. And indeed they are. The sources code don't have them.

[–] harfang@slrpnk.net 1 points 1 week ago

So how we're sure it do jot contain any tracker ?

[–] uxellodunum@lemmy.ml 2 points 1 week ago (2 children)

Use Obtanium or Zapstore to get the non-Google and non-F-Droid .apk, as those contain trackers for the notification system to work.

[–] harfang@slrpnk.net 1 points 1 week ago (2 children)

Those are alternative stores ?

[–] Catalyst_A@lemmygrad.ml 2 points 1 week ago

Obtanium is an app where you enter webpage links to github repositories. Its easy. Its just simple copy and paste. Then it downloads and installs it for you while constantly checking for new versions just like an app store. Its great for apps not on F-Droid.

[–] uxellodunum@lemmy.ml 2 points 1 week ago

Indeed. They offer up the original .apks from their respective github sources, so generally don't include trackers etc as you'd find on the Google store versions, or even f-droid at times.

[–] parale@mastodon.social 0 points 1 week ago (1 children)

@uxellodunum @harfang então o abtanium é melhor do que o F-Droid ou Aurora store? Tipo, só para atualização?

[–] uxellodunum@lemmy.ml 1 points 1 week ago (1 children)

Claro. Obtanium (e Zapstore) vão directamente à página de Github buscar da fonte. F-Droid tem builds que seguem certas regras estritas, e por isso às vezes tem mudanças. Aurora store é apenas um proxy para Google Play Store.

[–] parale@mastodon.social 1 points 1 week ago

@uxellodunum obrigado pela dica.