• VerPoilu
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    2
    ·
    1 year ago

    Google playstore does not inject data in app packaging because it doesn’t own the signature key. F-Droid, however, does. I mean, they own the signature, but they do not inject or modify apps. They could, though.

    • barryamelton@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      1 year ago

      do you know of any app developers that publish their signature, so one can compare it with the one in Google Play?

      I would love for my banks to do this, for example…

      • VerPoilu
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 year ago

        Some developers will publish their apps on github, you can download it, and use a different app to get the apk file from the app you get from the play store, and compare the hash of the file. If they’re identical then Google didn’t meddle with it. If they’re not, either Google did, or the developer releases a different version to Google Play.