← Back to context

Comment by microtonal

1 hour ago

Privacy Guides is building a database of signing keys with a verifier app:

https://github.com/privacyguides/verified-apps-android

https://github.com/privacyguides/verified-apps/

I think in general trust is established for Play Store apps by downloading the app with the Play Store on a phone with Google Certified Android. Then the app can get the signing key for storage in the database. Then this can be used to verify APKs downloaded outside the play store.