3 ms·
I was under the impression that Google Play Store apps were cryptographically signed by the developer/publisher (not by Google), and the phone would refuse to u
by darkengine 8y ago
I was under the impression that Google Play Store apps were cryptographically signed by the developer/publisher (not by Google), and the phone would refuse to update the app if the key behind the signature had changed. Am I wrong on this?
- ShorsHammer 8y agoWouldn't playstore itself be the the simplest yet most effective target for these laws rather than Signal? Signal themselves aren't on f-droid which has far more protections and the apk download is basically hidden on their site. Google certainly has no qualms about China, is draconian Australia much of a stretch?
- eythian 8y agoApplications are signed by Signal, so Google can't make fake ones.
- deleted 8y ago[deleted]
- craftyguy 8y agoGoogle does implement the apk signing verification (shipped as a binary in their ROMs), and they could easily make exceptions for applications if they wanted to. Don't assume that what you see in AOSP is the source form of what google ships.