3 ms·
when i saw the headline, I knew google would use it as a pretext to do something disgusting. Everything they do has some dark pattern to it somewhere. AMP is a
by meesterdude 5y ago
when i saw the headline, I knew google would use it as a pretext to do something disgusting. Everything they do has some dark pattern to it somewhere. AMP is a great example.
You should never, ever give your signing key to anyone. Especially not google. you might think of google "they wouldn't" but in fact they can, they have, and they will again.
- tadfisher 5y agoNote that new apps don't provide the Play Store with the key, they just verify against the first certificate they receive.
- bhawks 5y agoNot the point. This turns the trust model of the ecosystem on its head. When I install an app like Signal today - I have cryptographic certainty that it was the code the Signal team intended me to have with 0 tampering. In the new model - I have to trust that Google, it's employees and processes have not been subverted by another actor. It is a fundamentally weaker model. I hope Google budgeted some legal time responding to government court orders to spin custom targeted versions of apps for persons of interest. It might also be a tempting honeypot to identify employees that have been compromised by nation-state actors. It would be interesting to hear what things would have looked like if changing the trust model was off the table. Surely it must have had at least some discussion.
- MrDresden 5y agoWhile I completely agree with what you say, I feel it must be pointed out that in the use case of using the bundled Play store application on the device, you have no way of being certain that it is delivering you the correct APK. It might just as well pull a modified version (there are caveats such as that the device can't already have a valid version of the application setup for this to go unnoticed). Pulling the apk from Play using something like Raccoon would allow you to verify the signature.
- whoknowswhat11 5y agoNo one cares about your signing key. Google can create a key on their own servers if you want (you can't export this key so can't use it to sign apps for multiple stores) but u can keep your own keys secret
- Avamander 5y agoYou're cleverly ignoring the main use of signing, knowing the app wasn't tampered with before installation. You're also incorrect, if people have apps signed with your signing key then you must provide it to Google.