3 ms·
> I don’t get it: app can’t be updated if signed with a new key? That's correct. > Given that apps are sold all the time, I'm pretty confident that in 90%+ o
by phh 3y ago
> I don’t get it: app can’t be updated if signed with a new key?
That's correct.
> Given that apps are sold all the time,
I'm pretty confident that in 90%+ of those cases, developers just sell the signing keys with it.
FWIW, Android does have a mechanism to upgrade keys (app signed with the old key contains in its metadata the new key saying that this key is okay) since like 4-5 years ago. But I expect very few people use that. (I don't even know whether Google Play Store allows using this)
> and developers sometimes lose private keys themselves, this makes no sense.
I guess they don't when their revenue relies on it?
- rvnx 3y agoIn fact most of the developers do not manage the key themselves but instead use the default option: let Google generate and store one signed distribution key for you. This is the key that is used by the devices to verify that the APK can be installed on top of another. If an APK was signed by "Key A", only "Key A" can do updates. One advantage of that, is that malicious users cannot be served a malicious update of an app that didn't go through Play Store. Let's imagine it's the opposite, that France for example wants to spy on some users ? Other advantage, is that if you lose your developer private key, then you do not lose the capacity of doing updates. The minus of that, is that you have to count on Google to sign every single of your APKs. If they do not trust Google, VLC can add a checksum or integrity checks to the binaries loaded by the app during runtime.
- oefrha 3y ago> This is the key that is used by the devices to verify that the APK can be installed on top of another. Given that one option here is to let Google sign with a new key and keep things updated (dropping support for old devices in the process), this seems like a policy limitation, not an Android technical limitation?
- phh 3y agoOh yeah it's completely a Google Play policy issue. The original VLC thread on X is titled "App stores were a mistake"
- mschuster91 3y ago> One advantage of that, is that malicious users cannot be served a malicious update of an app that didn't go through Play Store. And the disadvantage of that is that it is almost impossible to patch APKs on your own without running into serious issues, even as root - particularly when the app you're trying to patch has shared permissions with other apps of the same developer.