4 ms·
> The JAR signature scheme only takes into account the zip entries. It ignores any extra bytes when computing or verifying the application's signature. Why? is
by junke 9y ago
> The JAR signature scheme only takes into account the zip entries. It ignores any extra bytes when computing or verifying the application's signature.
Why? is there a use-case for this?
- freeone3000 9y agoBecause that's how `jarsigner` (the Java application) signs. The code signature was fixed in Android 7.0.
- kuschku 9y agoJarsigner is designed to be used by Java. And both Jarsigner, and the Java command used to actually run the code on Oracle Java and OpenJDK use the same code – so they both only see the zip entries. This issue only exists because Android reused a signing process designed for an entirely different execution environment.