Proposal on Play Store security measures (alternative to Google's mandatory "developer verification")

TL;DR AI
2 min readKey summary
The post criticizes Google Play’s proposed developer verification as identity-focused rather than behavior-focused.
It argues app stores should require disclosure of embedded certificates, public keys, and hardcoded service endpoints to catch phishing and interception risks.
The author says hidden trust material and network targets can enable data exfiltration even when a developer is verified.
Telega is cited as an example of an Android app with hardcoded proxy and keys that could expose Telegram chats.
