What prevents Google from replacing Signal on the Android Application store with their custom and backdoored version ? Can we check a hash or something ? Does the signal foundation do that on a regular basis ?
That said, Signal does apparently support reproducible builds so that people can check that the apk matches what’s on GitHub (though this is more of a way to detect malfeasance on Signal’s part rather than Google’s)
Ah, right, there's also that.
https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
(I work at Google, but not on Android)