25 Aug 2021 |
| Betal joined the room. | 16:59:27 |
| fax joined the room. | 17:05:21 |
| aakashi2001 left the room. | 17:17:20 |
| rejoicetreat left the room. | 17:22:38 |
Brainstorm | Redacted or Malformed Event | 17:41:07 |
Brainstorm | Redacted or Malformed Event | 17:44:17 |
| fax left the room. | 17:47:14 |
| fax joined the room. | 17:47:40 |
| atwly joined the room. | 17:55:33 |
| perepujal joined the room. | 18:18:25 |
εΉΈη« (πππΎπ/πππΎπ) | In reply to @eighthave:matrix.org I think it'll be generally useful to have a tool to detect Google signatures We may have one: https://bi-zone.medium.com/easter-egg-in-apk-files-what-is-frosting-f356aa9f4d1 + https://github.com/obfusk/apk-signing-block-parser | 18:37:25 |
cde | εΉΈη« (πππΎπ/πππΎπ): so you're de-obfuscating the signing block? | 18:37:58 |
εΉΈη« (πππΎπ/πππΎπ) | cde: partially. I don't know what's in the "google play metadata block" though. | 18:38:39 |
εΉΈη« (πππΎπ/πππΎπ) | See also: https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/246 | 18:38:50 |
cde | yes I'm subscribed to that :P | 18:39:06 |
| * cde just wanted to make an obfuscation joke | 18:39:15 |
εΉΈη« (πππΎπ/πππΎπ) | cde: ah. in that case I'm obfusKating the signing block :p | 18:39:56 |
εΉΈη« (πππΎπ/πππΎπ) | (not to be confused with obfusking, which would be the correct conjugation of "to obfusk" :p) | 18:40:46 |
| * cde will use that. | 18:41:22 |
εΉΈη« (πππΎπ/πππΎπ) | In reply to @obfusk:matrix.org We may have one: https://bi-zone.medium.com/easter-egg-in-apk-files-what-is-frosting-f356aa9f4d1 + https://github.com/obfusk/apk-signing-block-parser maybe not. it seems also to be added to apps distributed via gplay that don't have google-held signatures. still useful I suppose. | 18:56:31 |
| fling joined the room. | 19:08:01 |
| audace joined the room. | 19:30:28 |
| atwly set a profile picture. | 19:45:40 |
_hc | yeah still sounds useful to have in diffoscope and perhaps elsehwere | 20:01:33 |
_hc | εΉΈη« (πππΎπ/πππΎπ): do you think that the frosting block could be stripped from an APK and it would still verify? | 20:06:04 |
_hc | seems likely | 20:06:10 |
_hc | I guess not v4 sig, but v1-3 | 20:06:35 |
εΉΈη« (πππΎπ/πππΎπ) | I tried doing that. but I probably got the alignment wrong or something. should work though, in theory. | 20:08:00 |
juri_ | chaotic evil? ;) | 20:11:37 |
| Ryu945 joined the room. | 20:22:48 |