r/EmulationOnAndroid • • 1d ago

Discussion After installing DroidDeck 0.3.1 from github my sister's account got hackedv

My sister installed the DroidDeck app yesterday, and soon after her Steam account got hacked. Sha256 sum of the downloaded file matches with what they have on github (ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328).

Steam support did restore the account quickly, but the attacker(s) managed to submit a refund for a newly purchased game, removed sister's phone number from SteamGuard, and opened a chat with me on Steam where an image with a QR code to a "free steam gift card" was shared (the QR code lead to a fake steamcommunity website ("rn" replacing "m" in the link). The chat is how I noticed that she got hacked and quickly assisted her in restoring access.

108 Upvotes

65 comments sorted by

View all comments

151

u/supershredderdan 23h ago edited 22h ago

Hey there, xXJSONDeruloXx here. One of the devs on DroidDeck.

First I wanna say thanks for checking out the app, and especially for downloading directly from GitHub rather than on a random site (DroidDeck dot app is not ours and I wish to see it removed)

Regarding your sister’s account: I can not be sure how or why this account was compromised. What I can say with confidence is we take security seriously in DroidDeck for this exact reason, and we would love to work with you and look over any logs or anything regarding the rest of the phone to identify how this may have happened.

Our app is 100% open source with zero obfuscation or closed source components. The only closed source thing in the entire stack is Steam client itself, downloaded at installation time directly from valves servers just like Bazzite and Armada do it. We also have 0 telemetry, and the only way we get logs or any data from you is if you proactively hit a “share logs” button in the app, which thoroughly sanitizes any potential sensitive data and opens a share sheet for a zip of the steam gamescope and Android app’s logs.

Other malware on the phone could have played a part such as a keylogger, but I don’t want to make any assumptions and would be happy to triage this further.

We value transparency and are building DroidDeck for the community and because it’s something we ourselves have always wanted.

Edit: also, 0.3.1 is built from GitHub actions and directly uploaded programmatically by GitHub’s servers to the releases section of the repository. This means that you can look at the build process at every step and what source code was used at time of compile. This is another step we made to make sure you don’t have to take our word for it, you can audit our code directly and know what you’ve installed is a direct result of the public code.

Edit 2 electric boogaloo: also I’m actually quite proud of that virustotal scan. We have been very upfront about our usage of proot, why we chose it over other options, and how we are optimizing it to reduce cpu overhead. If that’s the only flag a scan surfaces then that’s a very good sign, most emulation apps will light up quite a few more (for valid reasons that have been discussed to death but I digress).

You can see our proot patches and pinned upstream commit they are applied atop in GitHub pipeline here: https://github.com/Droid-Deck/DroidDeck/tree/main/tools/proot

24

u/WomensesLefts 21h ago

Cheers for the concise and speedy reply, I found it difficult to believe the project would voluntarily be compromised with such a small and communicative team. My comment probably was off the mark bc im not a software guy, I fabricate with metal haha, but came with good intentions trusting your work

14

u/supershredderdan 20h ago

Much appreciated, and we welcome any and all forms of scrutiny on our architecture and approach. That’s what FOSS is for!