Switch language한국어
Back to the list

Proposal on Play Store security measures (alternative to Google's mandatory "developer verification")

TL;DR AI

Key summary

2 min read
  1. The post criticizes Google Play’s proposed developer verification as identity-focused rather than behavior-focused.

  2. It argues app stores should require disclosure of embedded certificates, public keys, and hardcoded service endpoints to catch phishing and interception risks.

  3. The author says hidden trust material and network targets can enable data exfiltration even when a developer is verified.

  4. Telega is cited as an example of an Android app with hardcoded proxy and keys that could expose Telegram chats.

Read the original