• Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    3
    ·
    2 months ago

    The problem with that is that certificates expire before someone would want to keep using the app.

      • Kairos@lemmy.today
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 months ago

        Correction: SSL certificates can expire before someone would want to continue being able to install any given app.

        • Zak@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          1
          ·
          2 months ago

          Sure, the developer needs to keep the certificate up to date and re-sign the APK on occasion.

          • Kairos@lemmy.today
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 months ago

            So any APK I download will just expire at some point in time that’s probably really annoying to know, and then I have to dig through the internet again so I can install the app again?

            • Pycorax@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              If it’s anything like how Windows does it, you would still be able to override it. It just gives you a scary warning and hides the option unless you click “more info” or something.

            • Zak@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              Another option is to allow otherwise-valid signatures after expiration. It’s generally still possible to check them.

                • Zak@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 months ago

                  How? Expiration doesn’t grant an unauthorized party access to the private key.