[guardian-dev] Manipulating App Bundles

Nathan of Guardian nathan at guardianproject.info
Wed Jun 17 19:08:46 EDT 2020



On Wed, Jun 17, 2020, at 5:59 PM, Mark Murphy wrote:
> I am guessing that you have seen that Google is proposing making app 
> bundles a requirement next year:

Yes. /me puts head in hands

> I am sincerely hoping that I'm forgetting something that prevents this.

I don't think you are. If there was some kind of binary transparency where you could see all the builds that were done and released, that might be a small step... But still, once they have your private signing key, they can do anything they please.



More information about the guardian-dev mailing list