Conversation

APKs can be end-to-end signed with keys under developer control. You can move between app stores or no store (data is preserved on update with same key). And Google can't fuck with it. (Well, they can fuck with the entirety of the rest of the phone, so that point's kinda moot.)
1
4
Replying to
Developers should release their apps outside the Play Store too rather than only on Play Store. The OS package manager pins the key after the initial install but you still always trusted the Play Store for the initial install and they had Play Store App Signing before bundles.
1
2
Show replies