4 ms·
Except for the fact that Google does not have the signing keys that are used for the TextSecure binaries. They cannot silently distribute a binary that has been
by jlund 12y ago
Except for the fact that Google does not have the signing keys that are used for the TextSecure binaries. They cannot silently distribute a binary that has been tampered with. This distributed trust system is one of Android's strengths:
https://developer.android.com/tools/publishing/app-signing.html https://developer.android.com/tools/publishing/app-signing.h...
- dllthomas 12y agoThough don't they control the code that does the signature checking?
- petertodd 12y agoTo clarify, so Google can distribute a binary that has been tampered with, but it'd be trivial to prove that they had in fact done that?
- jlund 12y agoThat's correct. Android will warn you if the signatures don't match too. Even if we're in the full-on conspiracy theory territory of Google disabling that core security feature, impersonating a third-party developer, and dropping a binary onto a single user's phone, they still couldn't fake the signature.
- jacquesm 12y agoThey could simply disable the warning. It's android giving the warning, not the app.
- StavrosK 12y agoBut they own the OS, so I guess they can intercept whatever they want before it even reaches the app.
- pakled_engineer 12y agoUnless you have a phone still vuln to the Android signature bug, which is millions of devices still running unpatched carrier builds.