I went to update Orbot on my Android phone yesterday...

I went to update Orbot on my Android phone yesterday, but it wouldn't proceed with the update until I approved new permissions. Pic related.

Why does Orbot need to know my phone number and device ID, when I'm making a phone call, and whom I'm calling? This is fishy.

Is it related to this piece of news about The Guardian Project starting to track users? (Which is chilling enough in itself).


Download the orbot apk directly from here. The one marked 'latest'. Be careful of any mitm ruses.

This one, actually (they don't mark one 'latest' in that list apparently).

How would that help? They're integrating the tracking into the software itself though the Clean Insights Android SDK. It's not specific to the Play Store as far as I can tell.

I've never had Orbot ask for increased permissions, and I'm using the latest stable version. If I were you, I'd compare the checksum of the apk on your device to a known good copy. I kind of doubt that the Guardian Project is going to do anything intrusive. I'd be more inclined to think you got mitm'd and passed a bad apk.

That's a good suggestion. I'll check.

It does strike me as odd that this happened on the same day they put out the aforementioned blog post, though.

The apk checks out. They also list the "Device ID & call information" permission in the permissions details for the app.


The F-Droid version does not require these permissions, because it is a couple of years out of date (!).

Maybe I'm using an older version than you. It's the latest stable version, and downloaded directly from the Guardian Project site. I never install from the Play Store if I can avoid it. You could be using a beta or rc? Mine asks for no permissions at all on a new, clean install. Following is the apk name and sha-256:

Orbot 15.2.0-RC-8-multi.apk


No, it isn't and asks for these

Or what the fuck? Last time I used it it was up-to-date.

That's the previous version from Oct. 2016. It's what I was running. The new version is


released June 1, 2017.



The F-Droid version is out of date.

But the guardian project repo that comes with f-droid have it updated, not? I did clean install yesterday and didn't check the guardian project repo like I always do, my wrong.

Ok, I just upgraded via the Play store just to see what's going on. Then I saved the apk, uninstalled it, and reinstalled it, so I could get a clear picture of what permissions it wanted. Pic-related is what I got. And, yes, it's the version you mentioned. I don't have any hidden services though. That's what the new permissions are for, hidden service backup. It does say they're optional.

Sorry, I only know what I see on f-droid.org. Perhaps the website is out of date and the actual repo is newer.

What version of Android are you running?

I'm using Cyanogenmod 13 which is Marshmallow based. I haven't switched to Nougat based LineageOS because I like to use some Xposed Framework modules.
The apk name I upgraded to on Play store and SHA-256 are listed below. It asked for no permissions on install, as shown in the previous screenshot.

Orbot 15.4.1-RC-1-multi.apk


Ah, Marshmallow allows fine-grained permissions. And manual control on a per-permission basis.

I'm on Lollipop, unfortunately.

I guess I should finally look into installing LineageOS.

Where did you find the information that the new permissions are for hidden service recovery?

That's what it said when I looked through the Play Store Orbot comments.
Btw, the SHA-256 does match the apk on the Guardian Project site, so that's not a problem.
Yep, sounds like it might be a Lollipop thing then.

Thanks for your help.

I suppose I should install Lineage soon. In the meantime, I'm just going to uninstall Orbot.

Use F-droid nigger

Orfox is good because it gives you proxy layers while web browsing, but it isn't a super-encrypted-private VPN for hackermen.

Permissions change nothing if you run software as root.

Write them to release a non-tracking version, so users can select their privacy preference at the time of download, not at the time of installation.

Lay off the meth or crack or whatever is making you act like an asshole. You'll feel better. Enjoy your day.

"""Nathan Freitas""" cares not for your freedom.

If you run hashes on the orbot apks from google play, f-droid, or the guardian project site itself, they all match.
