Hacker News new | ask | show | jobs
by colejohnson66 2115 days ago
Didn’t Epic initially go around the Play Store and require you to download an installer from their website? And then it turned out that it was a good malware vector? That’s what I fear will happen if we get alternate stores: lax security leading to malware.
2 comments

Yes, it had a bug that could lead to a different malicious application being able to install its own APKs: https://issuetracker.google.com/issues/112630336
Make it that you must sign the binaries. Google distribute/manage the keys, but are not allowed to veto legal things.
That serves no purpose. If Google can’t veto any signature requests, it’s no different than having no signature at all; You’ll just have signed malware.
They must have a valid reason, not "they don't use our payment processing"