Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It sort of does. The new app in your case would be signed by a different key and so wouldn't have access to the existing app's data. It would boil down to a phishing attack - the new app would have to impersonate the UI of the old one and get users to log in again.

Hence my concern with this part of the article:

"While it’s unlikely Google would ever do so, it is possible that it could sign apps on behalf of a developer"

Actually given the trend the company has been on over the past 6 years I'd say it's very likely Google would do this ...



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: