Skip to content

expanded reporting from AndroidManifest.xml, Exodus ETIP, SUSS

A collection of improvements related to data in the AndroidManifest.xml and from Exodus ETIP and fdroid/suss. Details in the commit messages.

If you hover over a 🚩 Tracking(ε) link, it will show you the pattern that triggered the warning.

Scan APK

app-full-debug.apk
targetSdkVersion

This APK targets an older Android SDK version. This app should be updated to a recent SDK version to gain stronger security and privacy protections, as long as this app does not need any of the features removed by targeting newer SDKs.

uses-permission
android.permission.WAKE_LOCK
android.permission.REQUEST_INSTALL_PACKAGES 🚩 install
android.permission.REQUEST_DELETE_PACKAGES
android.permission.UPDATE_PACKAGES_WITHOUT_USER_ACTION
android.permission.NFC
android.permission.QUERY_ALL_PACKAGES 🚩 Tracking
android.permission.POST_NOTIFICATIONS
org.fdroid.fdroid.debug.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
android.permission.CAMERA
uses-permission-sdk-23
android.permission.ACCESS_COARSE_LOCATION 🚩 Tracking
activity
org.fdroid.fdroid.views.InstallHistoryActivity
org.fdroid.fdroid.installer.FileInstallerActivity
androidx.compose.ui.tooling.PreviewActivity
org.acra.dialog.CrashReportDialog 🚩 Tracking(ε)
cleartextTrafficPermitted
<base-config cleartextTrafficPermitted="true" /> 🚩 privacy leak
meta-data
android.hardware.usb.action.USB_DEVICE_ATTACHED
android.hardware.usb.action.USB_DEVICE_DETACHED
android.app.searchable
android.support.FILE_PROVIDER_PATHS
android.support.FILE_PROVIDER_PATHS
provider
org.fdroid.fdroid.installer.ApkFileProvider
androidx.core.content.FileProvider
org.fdroid.fdroid.nearby.PublicSourceDirProvider
org.acra.attachment.AcraContentProvider 🚩 Tracking(ε)
service
androidx.work.impl.foreground.SystemForegroundService
androidx.room.MultiInstanceInvalidationService
org.acra.sender.LegacySenderService 🚩 Tracking(ε)
org.acra.sender.JobSenderService 🚩 Tracking(ε)
URLs in classes.dex and resources.arsc
http://logback.qos.ch/codes.html
http://logback.qos.ch/manual/
http://ns.adobe.com/xap/1.0/
https://developer.android.com/training/articles/direct-boot
http://schemas.android.com/apk/res-auto
http://schemas.android.com/apk/res/android
https://flattr.com/thing/
https://github.com/journeyapps/zxing-android-embedded
https://gitlab.com/fdroid/fdroidclient
https://issuetracker.google.com/issues/new?component=413107&template=1096568 🚩 Tracking(ε)
https://journeyapps.com/
Edited by Hans-Christoph Steiner

Merge request reports