That's not true. You can download APKs from sites like APKPure (which has been a top search result for "[app name] APK" for many years on... Google).
That's not true. You can download APKs from sites like APKPure (which has been a top search result for "[app name] APK" for many years on... Google).
- it's harder to trust apkpure than aurora
- apkpure has a lot of ads
- apkpure has some outdated packages
- apkpure is missing packages
apkpure is proprietary and store the apk in a intermediary opaque server. So basically they can inject pretty much anything in the packages you install, and it's much harder to check than aurora if they do.
Am I correct to assume that you have to compile it yourself in order to keep this trust? Otherwise, there's no way to know if the binary being distributed alongside the source fetches from the same place, and we're right back to untrusted apps.
APKs are fundamentally extended JARs so you can easily check if an APK has been tampered with using standard Java tools [1].
[1] https://stackoverflow.com/questions/7104624/how-do-i-verify-...
For a security conscious developer such as Signal who publish an APK (.apk) and signatures publicly[2], a user with a rooted device could theoretically unpack the official application bundle received from the Google Play Store and check the executable code and resources match those in the publicly available APK. Or just not use the Google Play Store and obtain your applications directly from the developer or an intermediary you place more trust in.
[1] https://developer.android.com/studio/publish/app-signing
Google could have tampered with the file before the mirror site got it, but you can verify that whatever a mirror site is offering was signed by them.
All apks are signed so if you don't trust apkpure checking the certificates you can check the certificates yourself.