Perhaps there's something here that affects that dynamic, but I don't know what it is. It would help this effort to point out what that is.
Perhaps there's something here that affects that dynamic, but I don't know what it is. It would help this effort to point out what that is.
This proposal aims at providing the same guarantees for web apps, without resorting to signed packages on the web (ie. not the same mechanism that FirefoxOS or ChromeOS apps used). It's competing with the IWA proposal from Google, which is a good thing.
Not quite. It is possible for an account to be taken over or bought and a new update deployed. It is also possible for the server the app gets its data from to be taken over just like in your example and serve you fake data to make you regurgitate whatever data the malicious actor wants
1) everyone gets the same code
2) it doesn't change too quickly
This means you can (esp with reproducible builds) audit that the code is correct and know that everyone is getting the correct code, and that misbehavior will be identified.