This is one of my biggest pet peeves about Android. I wish i could add my own signing key for apps I compile myself, rather than just being given the choice of Google play or anything at all.
This is one of my biggest pet peeves about Android. I wish i could add my own signing key for apps I compile myself, rather than just being given the choice of Google play or anything at all.
Is there a way around this where you can say "no, just let me install from anywhere" or is it forced unless you root the device?
An app you compile yourself (assuming you at least tried to read the source code, the open source Google Auth is pretty brief/readable, I've reviewed it before) is vastly more secure than installing whatever the Play Store serves you.
Literally billions of regular users cannot do that, and regularly install malware laden apks.
I have no way to easily determine that an app on the Play Store actually came from my bank. At best, I can look at the install count, hope the app store does a half way decent job looking for fraud, and hope for the best. Maybe if I'm lucky they have some sort of verification program?
The idea we actually trust app stores from Google or Apple over a direct install from the institutions we want to interact with is hilarious, especially considering all of the rampant malware and fraud issues on the Play Store.
If they dist an apk, how is the bank to provide updates for their app? Build their own updater architecture? If there was a mitmed update from a store they could cancel it centrally.
Telling people to prefer apks is setting them up to be hacked.