Yet Another Android Master Key Bug
saurik.com
saurik.com
I can't imagine a legitimate reason to use these zip file corner cases, so it seems like the perfect sort of issue to detect and flag. And it would be a good spot-check of Google's verifier since they've had a few months to add the check.
While they haven't gone into details, I've gotten the impression that their checks are primarily based on recognizing bad APKs rather than recognizing bad constructs. While that's certainly a good defense to include (for attacks that are expensive to recognize and as a general backup), it is limited because it's inherently backward-looking. I guess I'm wondering how deep their "not proactive" approach goes.
(FWIW, it is my understanding that Verify Apps is part of Play Services, so updates to it can be pushed at any time to all devices: if they previously were just sending a SHA-1 of the entire APK to the server, and now needed to check if the file size divided by the current day was a mersenne prime, they could push an update to do that on the client. They thereby are not limited to only "inherently backward-looking" techniques for this protection.)
That still leaves open the question of security issues that aren't well-known, of course. Thinking about it a bit more, I can see the attraction of not adding extra complexity to the Play Services verifier until they "had to". If they're doing server-side checks and analysis that include undisclosed/low-profile issues that could be a reasonable balance (even if there is some lag time involved for simulations and the like), but if they're not...
Sadly, we're unlikely to ever know the difference.
Is this a common strategy now for proving timestamps?