Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>get the APK from wherever

What an improvement over https. I'm glad the android sandbox has given us so much security.



I'm not sure what you mean by that. You can get the APK directly from the Play store with some clever trickery (see the Evozi downloader), but even downloading it from any of the dozen or so mirror sites is secure, if that's your concern, because APKs are signed with the developer's key.

The reason I said "from wherever" is that sharing APKs G Play is a legal grey area and I didn't want to mention one specific way of getting them because there are many, all with different pros and cons.


For apps that really need security, android porivdes attestation using secure element.

https://developer.android.com/training/safetynet/attestation

https://source.android.com/security/keystore/attestation

So it's not all wild west. But most apps don't need this level of security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: