Hacker News new | ask | show | jobs
by remram 1870 days ago
I'm not suggesting we remove signing, just that Google use their own signing key for apps they build.
1 comments

That won't work. For google to take over the signing of existing apps they need the existing keys.
I see, so the limitation is that app updates have to keep using the same key, and that's enforced by the OS? Couldn't the Play Store uninstall then reinstall in that situation, to update to the new key?
That would delete any local files the app might have written, save files, that sort of thing.
Yes, but that destroys cached and local data and isn’t compatible with built in apps using the same package name.