Psy-Q's Braindump

/home

/posts

Home/Posts/ Google’s monopoly on the APK trust chain

Google’s monopoly on the APK trust chain

Psy-Q

May 17, 2021

Tomáš has an interesting article on trusting APKs from third-party mirrors.

Since Google is the gatekeeper of the APK trust chain, it’s not easy to independently verify APKs; Google doesn’t even give you the package signatures. The article shows a nifty method for extracting them by (ab)using the εxodus privacy audit project.

Do you know of a better way?


←
Fix for keyboard layout resetting to US on every login after installing Zoom
Preventing MPD’s HTTP audio stream from turning silent on song change
→

back to top

Powered by Hugo and tomfran/typo