Comment by microtonal
1 hour ago
Privacy Guides is building a database of signing keys with a verifier app:
https://github.com/privacyguides/verified-apps-android
https://github.com/privacyguides/verified-apps/
I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.
No comments yet
Contribute on Hacker News ↗