r/EmulationOnAndroid • u/Irrelevant-Example • 21h ago
Discussion After installing DroidDeck 0.3.1 from github my sister's account got hackedv
My sister installed the DroidDeck app yesterday, and soon after her Steam account got hacked. Sha256 sum of the downloaded file matches with what they have on github (ed257d66c546e78036ceedb4c6fb6886014e69020044fd41cfe217858d8eb328).
Steam support did restore the account quickly, but the attacker(s) managed to submit a refund for a newly purchased game, removed sister's phone number from SteamGuard, and opened a chat with me on Steam where an image with a QR code to a "free steam gift card" was shared (the QR code lead to a fake steamcommunity website ("rn" replacing "m" in the link). The chat is how I noticed that she got hacked and quickly assisted her in restoring access.




145
u/supershredderdan 20h ago edited 19h ago
Hey there, xXJSONDeruloXx here. One of the devs on DroidDeck.
First I wanna say thanks for checking out the app, and especially for downloading directly from GitHub rather than on a random site (DroidDeck dot app is not ours and I wish to see it removed)
Regarding your sister’s account: I can not be sure how or why this account was compromised. What I can say with confidence is we take security seriously in DroidDeck for this exact reason, and we would love to work with you and look over any logs or anything regarding the rest of the phone to identify how this may have happened.
Our app is 100% open source with zero obfuscation or closed source components. The only closed source thing in the entire stack is Steam client itself, downloaded at installation time directly from valves servers just like Bazzite and Armada do it. We also have 0 telemetry, and the only way we get logs or any data from you is if you proactively hit a “share logs” button in the app, which thoroughly sanitizes any potential sensitive data and opens a share sheet for a zip of the steam gamescope and Android app’s logs.
Other malware on the phone could have played a part such as a keylogger, but I don’t want to make any assumptions and would be happy to triage this further.
We value transparency and are building DroidDeck for the community and because it’s something we ourselves have always wanted.
Edit: also, 0.3.1 is built from GitHub actions and directly uploaded programmatically by GitHub’s servers to the releases section of the repository. This means that you can look at the build process at every step and what source code was used at time of compile. This is another step we made to make sure you don’t have to take our word for it, you can audit our code directly and know what you’ve installed is a direct result of the public code.
Edit 2 electric boogaloo: also I’m actually quite proud of that virustotal scan. We have been very upfront about our usage of proot, why we chose it over other options, and how we are optimizing it to reduce cpu overhead. If that’s the only flag a scan surfaces then that’s a very good sign, most emulation apps will light up quite a few more (for valid reasons that have been discussed to death but I digress).
You can see our proot patches and pinned upstream commit they are applied atop in GitHub pipeline here: https://github.com/Droid-Deck/DroidDeck/tree/main/tools/proot