Hacker News new | ask | show | jobs
by hughesjj 655 days ago
It offers a fingerprint you're supposed to validate over sneakernet but people are lazy
1 comments

and Google Play offers the possibility to distribute an update only to specific e-mail addresses, so if there is a need to compromise users with a malicious update that shows another fingerprint it's really doable (or just copy the messages, like Skype was doing with TOM-Skype).