Hacker News new | ask | show | jobs
by api 2049 days ago
In that case code signing can’t do much either.
1 comments

On the contrary code signing is the only current solution to this problem.

It allows fraudulent, malicious, or easily exploited code to be disabled.

How can revoking apps stop a phishing attack?
Easy: Revoke the certificate of the app doing the phishing.
To add, this is exactly what google's safe browsing is https://safebrowsing.google.com/