Signing gives some semblance of control between the untrusted developer and the trusted App Store. It doesn’t do more that stop 3rd party app stores on the link between store and phone.
Signing gives some semblance of control between the untrusted developer and the trusted App Store. It doesn’t do more that stop 3rd party app stores on the link between store and phone.
Sure, but if they lied about that isn't it an open-and-shut case of fraud? What they're doing here instead is obfuscating away everything behind an announcement, so there is no legal recourse for the consumer against their bullshit. The best we can do is hope an anti-trust suit is brought against Google (I have approximately zero hope of it happening because of this, though).
It might be helpful to consider a simpler situation, where an FBI agent pretends to have a shipment of drugs which a drug dealer attempts to buy. If the dealer hands over money and doesn't receive the drugs, my non-expert understanding is that they can't then sue the government for fraud, presumably because of qualified or sovereign immunity.
The reason the government won't give back the money is that it will initially be evidence, and then subject to civil asset forfeiture. I don't believe that it matters that the item being bought was illegal, as if property law doesn't apply to illegal goods, since, in theory, if one drug dealer stole drugs from another drug dealer, the government could prosecute the perpetrator for both the theft and the possession of the drugs.
https://arstechnica.com/tech-policy/2018/07/judge-slams-fbi-...
People have this notion that the court system just blindly agrees with three lettered agencies, when in reality they tend to hate each other.
Really? They wrote the code for a part of it, sure. But that code was compiled by my OEM, and modified to put the OEM's extra little bit of sauce on there. Besides, the certificates aren't shown to me. They are used by the OS itself to verify updates to the app.
Currently, signing gives control between a trusted developer of an app and any updates reaching my phone. This is enforced at the OS level. That means that the app store cannot just ship my phone false updates. At least, unless they can exploit the currently installed OS.
The Android system one that comes from the OEM? Or have they compromised the Java installation I have?
The latter being very difficult for Google alone to make output incorrect results.