@fdroidorg at this point is being used to push out an app with sensitive permissions that’s been taken over by an unknown individual who refuses to engage with its large community of users and developers.

I STRONGLY recommend disabling updates from Fdroid, if not uninstalling and manually installing 2.0.11.2, or installing the Google Play version which has a different maintainer.

this is extremely shady and it’s just looking worse as time goes on. I’ll link to the Syncthing forum thread from about where I left off last time in a subsequent post.

  • sabreW4K3@lazysoci.al
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    8
    ·
    2 days ago

    Let’s look at the timeline.

    Developer was maintaining app, didn’t wanna do it any more and suggested everyone use the most popular fork.

    The maintainer of said most popular fork, after a while, didn’t wanna do it any more and after asking for maintainers for a while, found one on her own and handed him the project.

    Entitled AF users, who aren’t looking to maintain the project, don’t like the cut of the new maintainers jib and thus kick up a fuss.

    At this point, there’s zero new forks available on F-Droid or IzzyOnDroid, proving it’s not about anything other than kicking up a fuss.

    Anyone that is so outraged, put your time and effort where your mouth is. Stop with the brigading and actually maintain and publish a fork.

    Personally, I trust nutomic and catfiend and if I trusted catfiend to maintain the app, I will trust their vouch for the new maintainer too.

    • Ephera@lemmy.ml
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      To my knowledge, the only problem was that there was no communication about the handover. If there had been a post on the original repo with reasoning for Catfriend stepping down, instead of the repo just disappearing (from what I heard), there would’ve been no drama…

      Admittedly, I did not look into it too deeply, though.

      • sabreW4K3@lazysoci.al
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 days ago

        Catfriend was actively openly looking for a replacement for ages and couldn’t find one. No one was stepping up. When she eventually found someone, suddenly everyone wants to have a say. What was she supposed to do, put her life and mental health on hold until the community that wasn’t helping maintain the project, vetted the replacement she found? I don’t know how people can’t see that their expectations are out of whack here. As I said before, if any one of the people who are whipping up the storm had stepped up to takeover, there’d somewhat of point to this, but that’s not happening. It’s just pitchforks for the sake of pitchforks.

        • leetnewb@beehaw.org
          link
          fedilink
          English
          arrow-up
          3
          ·
          5 hours ago

          I don’t think this framing is completely accurate. nel0x, one of the people stepping up to maintain a fork, made reasonable requests to researchxxl that were ignored and denied. Basic stuff like “can you join the official syncthing forum”. Trust is incredibly important when you are taking over distribution of an existing app, let alone one that has permissions to your filesystem and can push changes to other devices through NAT/firewalls. Processes to develop trust can be tying your online identity to real life identity, and/or being a visible, contributing member of a community over time. A transparent handover process would also be important. None of those conditions for trust were met and auto installed updates were pushed.

        • Lfrith@lemmy.ca
          link
          fedilink
          English
          arrow-up
          11
          ·
          edit-2
          2 days ago

          It’s just the process of the handover that is making people skittish with the github going private then reappearing with a new maintainer.

          I think best route would have been for researchxxl to just fork syncthing-fork to put on F-droid, and catfriend1 just leave their branch archived with an endorsement of researchxxl.

          After some time passes and researchxxl gains trust in the community I’m sure people will trust their work. The transition just wasn’t handled well.

          • Marcus@scribe.disroot.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            4 hours ago

            Exactly; would have been much cleaner. The recent update to v2 already required migrating one’s config. So doing it again (now knowing the process) to such new “fork-fork” would’ve been a no-brainer.

            But the whole situation has a more critical aspect than this technical issue: the new dev’s appearance out of nowhere, lack of reasonable communication, and arrogance.