3 ms·
Presumably this downloads new executable code (or bytecode) rather than data. I could put up a shell app which does the same thing to download exploits after a
by randallu 14y ago
Presumably this downloads new executable code (or bytecode) rather than data. I could put up a shell app which does the same thing to download exploits after a while. This is why Apple has the "don't download code" rule (and why they had a "no interpreters" rule).
So maybe it's OK in the ToS right now, but I can understand why it shouldn't be OK, especially on a platform with so many local exploits (like Samsung's world-writable /dev/mem equivalent, etc).
EDIT: Actually they're just grabbing a new APK, which is weirder in a way since they are literally duplicating the Play Store mechanism but avoiding the good things that the Play Store tries to do for customers (static analysis for security risks, etc). Why wouldn't they just notify the user that a new version is available from Play? Bizarre choice.