|
|
|
|
|
by pmoriarty
1876 days ago
|
|
Wouldn't a simple solution to this be a double signing of one and the same app by both Google and the app's author? That way, if Google changes the app and signs it, while the author only signed the unchanged app, then the author's signature would no longer validate on the new, changed app. Or am I missing something? |
|
The issue is that this inherently requires users and developers to trust Google to only make innocuous changes.