3 ms·
> at least on the App Store and Google Play you can't verify that the open source code is what's shipped Is there a reason Google and Apple couldn't change the
by gregmac 4y ago
> at least on the App Store and Google Play you can't verify that the open source code is what's shipped
Is there a reason Google and Apple couldn't change their deploy flow to pull from a git repository? As in:
1. Developer pushes to a specific remote (or pushes a specific tag or branch)
2. Apple/Google run the build on their systems, sign it, etc
3. If passed, the app deploys and the published app is annotated with the specific git hash (which can also be displayed in the app store)
For open source, it gives the public verification ability.
For closed source, it is still useful for internal verification. I work adjacent to some mobile teams and most still do builds on a developer's desktop and upload that. I am working towards getting CI for everything, partly to reduce dependence on any one developer's system (eg: I hear things like "Only Tom knows how to do builds to give to Apple, but he's out today") and partly for security. As much as I believe we don't have developers with malicious intent, there's still no way to know that a build uploaded from a developer's desktop really is what's in source control.
- aaomidi 4y agoBinary transparency is slowly getting more popular
- kelnos 4y ago> Is there a reason Google and Apple couldn't change their deploy flow to pull from a git repository? Because doing so isn't something they'd realistically care about. They'd still have to maintain the existing flow for closed-source apps (the vast majority of them) that don't want to give outside parties access to their source code, so this would just mean more work for them. Another big downside is that app authors would not be signing the final product with their own keys. That would have to be done by Google/Apple, so authors would lose a bit of control over future distribution of their app.
- tadfisher 4y agoGoogle supports code transparency attestations in app bundles[0], which allows third parties to verify the shipped binaries. [0]: https://developer.android.com/guide/app-bundle/code-transparency https://developer.android.com/guide/app-bundle/code-transpar...