3 ms·
SMH at the lack of though or understanding some ppl have for layered device security... This has an obvious clear benefit: all of the people who have said "oh
by predictabl3 3y ago
SMH at the lack of though or understanding some ppl have for layered device security...
This has an obvious clear benefit: all of the people who have said "oh well Google could be compelled to sign a malicious update for a single user"... This is an attempt at solving that via a transparency log.
Granted, I think for this to matter much all-up, it would need to apply to PSF, Apex, general app updates, etc.... Which I'm pretty sure this doesn't even attempt to touch.
I'd love to hear Google speak to that but that seems like a huge can of worms compared to the image based hashing, signing, verification that is already part of the tooling, ecosystem and consciousness.