Google playstore does not inject data in app packaging because it doesn’t own the signature key. F-Droid, however, does.
I mean, they own the signature, but they do not inject or modify apps. They could, though.
Some developers will publish their apps on github, you can download it, and use a different app to get the apk file from the app you get from the play store, and compare the hash of the file. If they’re identical then Google didn’t meddle with it. If they’re not, either Google did, or the developer releases a different version to Google Play.
Google playstore does not inject data in app packaging because it doesn’t own the signature key. F-Droid, however, does. I mean, they own the signature, but they do not inject or modify apps. They could, though.
do you know of any app developers that publish their signature, so one can compare it with the one in Google Play?
I would love for my banks to do this, for example…
Some developers will publish their apps on github, you can download it, and use a different app to get the apk file from the app you get from the play store, and compare the hash of the file. If they’re identical then Google didn’t meddle with it. If they’re not, either Google did, or the developer releases a different version to Google Play.