I can't even.
I can't even.
Can't wait to hear Moxie's response on this. One of his (many) reasons for refusing to support FDroid was because it didn't allow developers to sign their own apps, and thus users had to trust that FDroid did not modify the app. Now FDroid has addressed that, but Google has not only removed that feature, but is demanding that developers allow Google to impersonate them.
Out of loop, what changed?
You should never, ever give your signing key to anyone. Especially not google. you might think of google "they wouldn't" but in fact they can, they have, and they will again.
This turns the trust model of the ecosystem on its head.
When I install an app like Signal today - I have cryptographic certainty that it was the code the Signal team intended me to have with 0 tampering.
In the new model - I have to trust that Google, it's employees and processes have not been subverted by another actor.
It is a fundamentally weaker model. I hope Google budgeted some legal time responding to government court orders to spin custom targeted versions of apps for persons of interest. It might also be a tempting honeypot to identify employees that have been compromised by nation-state actors.
It would be interesting to hear what things would have looked like if changing the trust model was off the table. Surely it must have had at least some discussion.
It might just as well pull a modified version (there are caveats such as that the device can't already have a valid version of the application setup for this to go unnoticed).
Pulling the apk from Play using something like Raccoon would allow you to verify the signature.
Google can create a key on their own servers if you want (you can't export this key so can't use it to sign apps for multiple stores) but u can keep your own keys secret
You're also incorrect, if people have apps signed with your signing key then you must provide it to Google.
https://android-developers.googleblog.com/2021/06/the-future...