Elektrine lite

← Feed

@eighthave@social.librem.one

Post #4311845

2026-07-16 12:02 UTC

@mro@digitalcourage.social I agree, highlighting the role of the signing key seems key. An app signing key is in effect a pseudonym. The hard part is that there is that there is no concrete way for users to verify what the key management practices of the developer are. Judging that from the outside means looking for any signs that the signing key was misused. If a dev wants to hide misuse of their signing key, that is pretty easy to do. For example, they could sign malware and only ship that to targeted users

Replies (1)

  • @mro@digitalcourage.social 2026-07-16 14:14

    Hi @eighthave@social.librem.one > users to verify what the key management practices of the developer are why should they? > looking for any signs that the signing key was misused why should they bother? They care if the payload at hand is legit. > If a dev wants to hide misuse of their signing key, that is pretty easy to do what attack vector comes to mind?

    Open ##4311847