3 ms·
>The same also applies, by the way, to Windows and also to Linux if you trust remote code repositories Curiously, Google/Android has developers sign the app, a
by SomeCallMeTim 11y ago
>The same also applies, by the way, to Windows and also to Linux if you trust remote code repositories
Curiously, Google/Android has developers sign the app, and that exact signed package is what's distributed, so at least the app developer can verify that the distributed app is identical to the one shipped to the store.
On the other hand, Amazon/Android signs apps with their own keys, so they suffer from the same issue as Apple.
- joosters 11y agoUsers don't check the signature of apps that they download, their phone does it for them. So even if apps are signed by the developer, the app store owner can throw away the signature, modify the app and then sign it with their own key. People downloading and running the app won't see a difference.
- SomeCallMeTim 11y agoIf a developer downloads the app, they can verify it. But more to the point, I published an app on the Play Store that actually verified its own signatures (as an anti-piracy measure) and it worked correctly. Not only that, but it used the signature as a key to decrypt some of the assets, so a changed signature would mean the app would completely fail to work. So it's a solvable problem on Android. But not at all on other ecosystems.
- donarb 11y agoYour digital signature on your app is a contract between you and Apple, not you and your customer.